IAMmedium3-5 years
A service on ECS reads an access key and secret from `application.properties` (injected from a CI variable) to talk to S3 and Secrets Manager. You are asked to 'harden' it. What should replace the key, how does the SDK find credentials with no configuration, and what does the policy on the new identity look like?
A service on AWS should never hold an access key. It should run as a role: on ECS a task role, on EC2 an instance profile, on EKS a service account mapped to a role (IRSA or Pod Identity), on Lambda an execution role. The platform hands the SDK temporary credentials for that role and rotates them, and the SDK's default credential chain finds them on its own, which is why S3Client.create() works in production with nothing in application.properties. The role's policy is then the service's whole permission set, written with least privilege: PutObject on the uploads prefix and GetSecretValue on one secret, nothing else. The key goes away entirely, and then gets deactivated and deleted.
PreviousAn EC2 instance type comes with a fast local NVMe disk. A teammate proposes putting a self-managed PostgreSQL data directory on it 'for speed', and after a planned stop/start of the instance for a resize, a Redis cache on the same kind of disk comes back empty. Explain what happened, and which workload belongs on which kind of storage.Next Users upload invoices of up to 200 MB. The current endpoint accepts a multipart body in a Spring controller and streams it to S3 with the SDK; under load the service's heap and threads are exhausted. How would you redesign the upload, what does the service still own, and what does 'S3 is not a filesystem' mean for the rest of the design?
A Spring Boot service that worked yesterday now fails every upload with `AccessDenied` on `s3:PutObject` for `arn:aws:s3:::orders-uploads/invoices/2026/09/30/...`. Nobody admits to changing a policy. What are the only possible causes, and what is the first command you run?Two failures in one week. (1) A service's role allows `s3:GetObject` on `arn:aws:s3:::reports/*`, nothing on the role denies anything, yet a batch job using a library that defaulted to plain HTTP gets `AccessDenied`. (2) An analytics account's role is given a bucket policy statement allowing it to read the same bucket, and it is still denied. Walk the evaluation for each.