IAM policy patterns
Least-privilege examples for deploy users, asset buckets, logs, read-only diagnostics, and emergency break-glass access.
Takeaway
Deployment credentials should be narrow enough for routine releases and separate from read-only diagnostics or emergency access.
01
Split deploy and diagnostics
A CI deploy role usually needs write access to a specific bucket, invalidation access to a specific distribution, and read access to its own release state. It does not need broad account inspection permissions.
Read-only diagnostics should be a separate role. This keeps the automated release path small while still letting developers inspect logs, deployment state, and public configuration during incidents.
- Separate write permissions for deployment from read permissions for investigation.
- Give CI access only to the buckets, distributions, and secrets it needs.
- Avoid using personal administrator keys for routine release work.
02
Prefer resource-scoped permissions
Policies should name the bucket, distribution, log group, and secret paths they need. Broad wildcard access makes the first launch easier but turns every later incident into a permissions audit.
Resource-scoped permissions also make reviews easier. A teammate can see which infrastructure the app actually owns without scanning the whole account.
- Scope S3 access to the deployment bucket and required prefixes.
- Scope invalidations to the expected CloudFront distribution.
- Scope secrets access by application and environment path.
03
Prepare emergency access separately
Break-glass access should be explicit, monitored, and rarely used. Keeping it separate from normal deployment protects the release path while still giving the team a way to recover from account or CI failures.
The emergency path should not be mysterious. Document who can use it, how usage is logged, and what must be reviewed after it is used.
- Require multi-factor authentication for emergency access.
- Log and review every break-glass session.
- Rotate or revalidate credentials after emergency use.