IAMeasy0-2 years
A Spring Boot service that worked yesterday now fails every upload with `AccessDenied` on `s3:PutObject` for `arn:aws:s3:::orders-uploads/invoices/2026/09/30/...`. Nobody admits to changing a policy. What are the only possible causes, and what is the first command you run?
IAM denies everything unless a policy allows it, and an explicit deny beats any allow. So an AccessDenied has exactly three causes: no policy allows this action on this resource, an explicit deny somewhere forbids it, or the caller is not the principal you think (a different role was assumed, or credentials for another user are in the environment). The third is the cheapest to rule out and the one people skip, so the first command is aws sts get-caller-identity, run with the same credentials the service uses. If the ARN it prints is the role you expected, read that role's policies and the bucket policy for the action and resource named in the error. If it is not, the policy was never the problem.
A service on ECS reads an access key and secret from `application.properties` (injected from a CI variable) to talk to S3 and Secrets Manager. You are asked to 'harden' it. What should replace the key, how does the SDK find credentials with no configuration, and what does the policy on the new identity look like?Two failures in one week. (1) A service's role allows `s3:GetObject` on `arn:aws:s3:::reports/*`, nothing on the role denies anything, yet a batch job using a library that defaulted to plain HTTP gets `AccessDenied`. (2) An analytics account's role is given a bucket policy statement allowing it to read the same bucket, and it is still denied. Walk the evaluation for each.