Scenario
Our objective is to let the
Log Analysts group assume a role in the Production account to retrieve logs.
High-Level Architecture
- Create an IAM Role in the Production Account
- Attach an inline S3 policy to that role
- Update the S3 Bucket Policy to trust the role
- Assume the role from the Development Account and verify access

Cross-Account Access Components

Be explicit in your trust policy to avoid granting unintended access. Restrict
Principal to specific IAM roles or account IDs.Demo Walkthrough
Follow these steps to implement and test cross-account S3 access.1. Create the IAM Role in Production
Create a trust policy (trust-policy.json):
2. Attach an Inline S3 Access Policy
Defines3-access-policy.json:
3. Update the S3 Bucket Policy
Create or edit your bucket policy (bucket-policy.json):
Ensure the bucket policy’s
Principal matches the exact ARN of the role. Using wildcards may expose your bucket to unintended access.