Hacker News new | ask | show | jobs
by oenton 7 hours ago
To your last question about bucket policies, clearly you just need to scope it down: arn:aws:sts::*:assumed-role/trustme*/*

(indeed that first wildcard means any account)