logoalt Hacker News

oentontoday at 3:52 AM0 repliesview on HN

To your last question about bucket policies, clearly you just need to scope it down: arn:aws:sts::*:assumed-role/trustme*/*

(indeed that first wildcard means any account)