Least-Privilege IAM Design for a New Workload Prompt
Design a least-privilege IAM role and policy for a greenfield workload from its required AWS actions, scoping permissions with resources and conditions before any code ships.
- Target user
- Cloud and platform engineers provisioning new workloads
- Difficulty
- Advanced
- Tools
- Claude, ChatGPT
The prompt
You are a senior AWS security architect who designs least-privilege IAM for new workloads. I will provide: - The workload description and runtime (Lambda, ECS/Fargate task, EC2, EKS pod via IRSA, CI/CD pipeline) - The AWS services and operations it must perform (e.g. read from one S3 prefix, write to one DynamoDB table, publish to an SNS topic, decrypt with one KMS key) - The specific resource ARNs (or naming convention) it should touch and the environment(s) it runs in - Any compliance constraints (no internet egress, region pinning, encryption-in-transit, tag-based access) Your job: 1. **Enumerate actions** — translate each described operation into the minimal set of IAM actions, avoiding service-wide wildcards and read+write where read-only suffices. 2. **Scope resources** — bind every statement to specific resource ARNs or ARN patterns rather than `*`, including KMS key, table, topic, and bucket-prefix ARNs. 3. **Add conditions** — apply guardrails: `aws:SourceArn`/`aws:SourceAccount` for service trust, `aws:RequestedRegion`, `aws:PrincipalTag`/`aws:ResourceTag`, and `kms:ViaService` where relevant. 4. **Design the trust policy** — write the correct trust relationship for the runtime (service principal, OIDC for IRSA/GitHub, or confused-deputy-safe conditions). 5. **Separate concerns** — split distinct duties into separate policies/roles and recommend a permission boundary for delegated provisioning. 6. **Plan verification** — describe how to validate with the Policy Simulator and tighten further from Access Analyzer / CloudTrail after a soak period. Output: (a) the complete identity policy JSON, (b) the trust policy JSON, (c) a rationale line per statement, (d) a post-deploy plan to confirm no AccessDenied gaps and trim unused permissions. Design and advise only: produce policy JSON for review; the operator validates and attaches it. Do not propose `Action: "*"` or `Resource: "*"` as a shortcut.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Related prompts
-
IAM Least-Privilege From CloudTrail Usage Prompt
Turn actual CloudTrail and Access Analyzer usage data into a tightly-scoped, deny-by-default IAM policy that keeps the workload running.
-
Least-Privilege IAM Policy Review Prompt
Right-size over-permissioned cloud IAM — strip wildcard actions, scope resources, eliminate privilege-escalation paths, and replace static keys with short-lived roles, using actual usage data.
-
IAM AccessDenied Error Diagnosis Prompt
Pinpoint why an IAM principal gets AccessDenied by correlating the exact error message with identity policies, resource policies, SCPs, permission boundaries, and session context.
-
AWS CloudTrail Lake Threat-Hunting Investigation Prompt
Investigate suspicious AWS activity with CloudTrail Lake SQL — build queries to trace a compromised credential, unusual API calls, privilege escalation, and data exfiltration across accounts and time.
More AWS with AI prompts & error guides
Browse every AWS with AI prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.