Cross-account read-only access without static credentials
Build controlsnot started
Click or drag services, connect directional handles, then validate the design rules.
Challenge brief
Pinebrook Freight runs a data account that owns the S3 bucket holding the curated shipment extract, and a separate analytics account whose EC2 reporting fleet rebuilds dashboards each night. The fleet needs read-only access to the curated/shipments/ prefix; the eleven other prefixes in the same bucket hold raw carrier invoices the analytics team is not cleared to open. The security lead adds two rules the design must respect: no long-lived access keys may exist in the analytics account, and no second copy of the extract may be stored outside the data account. Which design should the security lead approve for the reporting fleet?
Success criteria
- 1.Add the EC2 reporting fleet in the analytics account as the calling workload.
- 2.Add one IAM role in the data account for the fleet to assume, so access uses temporary credentials.
- 3.Add the S3 resource the role may read, scoped to the curated/shipments/ prefix.
- 4.Connect EC2 through the assumed IAM role to the scoped S3 prefix.
- 5.Remove any stored access key; the analytics account may hold no long-lived credential.
Service palette
Prepared guidance · deterministic simulation
Prewritten hints from this exercise's rules, not live AI.
Use typed validation whenever you want a deterministic check. Suggestions never change the graph without your action or confirmation.