-IAM Conditions:
Aws SourceIp resitrict the client Ip from the API calls
AWS RequestdRegion restict regions Api calls are made to
EC2 resoucre tag:Restriction based on tags
Aws MultifactorAuthPresent to force MFA
-IAM for S3
S3:ListBucket,s3GetObject,s3PutObject,s3DeleteObject.
IamRoles vs ressource based Policies
-When we assume a role we give up all persmissions but ressource based, principale does not give up his permission
-Rules need permissions on target.
-Ressource based policy:Lambda,SNS,SQS,S3 bucket,Api gateway...
-IAM role:Kinesis stream,EC2 Auto scaling,ECS task