Quick reference for cloud security — IAM policy patterns, storage hardening, and CLI audit commands.
IAMS3Shared ResponsibilitySecrets
Shared Responsibility
Identity, access, and data are always yours regardless of service model.
| Layer | IaaS | PaaS | SaaS |
| Hardware / network | Provider | Provider | Provider |
| OS / runtime | You | Provider | Provider |
| App code | You | You | Provider |
| IAM / data | You | You | You |
IAM Best-Practice Checklist
- MFA on root/owner; never use root for daily tasks.
- Roles with temporary credentials over long-lived access keys.
- No wildcards — scope
Action and Resource tightly.
- One role per workload; no shared credentials.
- Rotate keys, review access, remove unused identities regularly.
- Deny by default; grant explicitly.
Least-Privilege Policy Snippet
{
"Version": "2012-10-17",
"Statement": [{
"Effect": "Allow",
"Action": ["s3:GetObject", "s3:PutObject"],
"Resource": "arn:aws:s3:::my-app-uploads/*"
}]
}
Storage Hardening
- Enable account-level Block Public Access.
- Private ACLs by default; use pre-signed URLs for sharing.
- Encryption at rest (SSE-KMS) on every bucket/container.
- Enforce TLS-only access via bucket policy.
- Enable access logging and object versioning.
Provider Terminology
| Concept | AWS | Azure | GCP |
| Object storage | S3 | Blob Storage | Cloud Storage |
| Compute VM | EC2 | Virtual Machines | Compute Engine |
| Virtual network | VPC | VNet | VPC |
| Firewall | Security Group | NSG | Firewall Rules |
| Secrets | Secrets Manager | Key Vault | Secret Manager |
| Audit log | CloudTrail | Activity Log | Cloud Audit Logs |
| Threat detection | GuardDuty | Defender for Cloud | Security Command Center |
Audit CLI Commands
| Goal | Command |
| List buckets (AWS) | aws s3api list-buckets |
| Bucket ACL (AWS) | aws s3api get-bucket-acl --bucket B |
| Who am I (AWS) | aws sts get-caller-identity |
| List role assignments (Azure) | az role assignment list |
| List storage accounts (Azure) | az storage account list |
| Get IAM policy (GCP) | gcloud projects get-iam-policy PID |
| List buckets (GCP) | gcloud storage buckets list |
Secrets & KMS Quick Reference
# AWS Secrets Manager
aws secretsmanager get-secret-value --secret-id db/password
aws secretsmanager rotate-secret --secret-id db/password
# Azure Key Vault
az keyvault secret show --vault-name MyVault --name db-pass
# GCP Secret Manager
gcloud secrets versions access latest --secret=db-pass
# Rules: never hardcode; rotate on schedule; enforce IMDSv2 to
# block SSRF theft of instance role creds at 169.254.169.254
Common Misconfig → Fix
| Misconfiguration | Fix |
| Public storage bucket | Enable Block Public Access; private ACLs |
| Wildcard IAM policy | Scope actions + resource ARNs; least privilege |
| Long-lived access keys | Use roles / temporary credentials; rotate |
| SSH open to 0.0.0.0/0 | Restrict source; use bastion / SSM |
| Hardcoded secrets | Move to secrets manager; scan repos |
| IMDSv1 enabled | Enforce IMDSv2 (token required) |
| Unencrypted volume/DB | Enable KMS encryption at rest |
| No audit logging | Enable CloudTrail / Activity / Audit Logs |
| Privileged K8s pods | Drop privileges; RBAC; image scanning |