S3 Bucket Policies vs IAM Roles: Which Should You Use?
https://charliekzxa221.huicopper.com/how-storage-bottlenecks-crush-growing-platforms-5-practical-strategies-engineering-leads-can-use-now
S3 permissions and access control can feel like a maze. Engineers jump between IAM roles, bucket policies, access points, presigned URLs, and legacy ACLs while trying to keep things secure, simple, and auditable