Skip to content

CloudFront, "aws:PrincipalAccount", and s3:GetObject #47

@KevinHock

Description

@KevinHock

Hi AWS Folks,

I currently see a bucket policy that has trusts an account ID of "cloudfront", similar to some public examples [1]

I wanted to ask: will the "aws:PrincipalAccount" condition key will be set to "cloudfront"? E.g., if your identity perimeter RCP were to be put in place.

(Or if I should instead rely on the "aws:PrincipalIsAWSService" check.)

[1]
Searcharn:aws:iam::cloudfront:user/ in https://aws.amazon.com/blogs/modernizing-with-aws/how-to-build-an-automated-c-code-documentation-generator-using-aws-devops/ and https://www.kevinslin.com/notes/f2542b0c-5cbd-49b9-84d8-151ccab99dea/

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions