IntermediateIdentity, Secrets & Encryption← All questions

A Policy for One Bucket

A background worker needs to read files from one object storage bucket. Write the permissions you would give it.

Practical scenario

The worker deployment has been failing on Access Denied for two days. A pull request is open that attaches the account's administrator policy with the comment "unblock the pipeline, tighten later".

What it tests

Answer it out loud first. The guide below stays closed until you ask for it, on purpose.

  • Whether the candidate scopes both actions and resources, or only one
  • Whether they reach for a wildcard when the requirement is narrow
  • Whether the identity is a workload identity rather than a borrowed human credential

Reading a strong answer is not the same as producing one. Commit to what you would say, then compare.