<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Notes on &gt; truongvu.dev</title>
    <link>https://truongvu.dev/tags/notes/</link>
    <description>Recent content in Notes on &gt; truongvu.dev</description>
    <image>
      <title>&gt; truongvu.dev</title>
      <url>https://truongvu.dev/static/images/default-cover.png</url>
      <link>https://truongvu.dev/static/images/default-cover.png</link>
    </image>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Sat, 21 Mar 2026 09:21:13 +0700</lastBuildDate>
    <atom:link href="https://truongvu.dev/tags/notes/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>AWS IAM Decision Mindmap</title>
      <link>https://truongvu.dev/categories/aws-sap-cheat-sheet/202603211-sap-iam/</link>
      <pubDate>Sat, 21 Mar 2026 09:21:13 +0700</pubDate>
      <guid>https://truongvu.dev/categories/aws-sap-cheat-sheet/202603211-sap-iam/</guid>
      <description>&lt;h3 id=&#34;-1-what-level-are-you-controlling&#34;&gt;🎯 1. What level are you controlling?&lt;/h3&gt;
&lt;h4 id=&#34;-a-account--organization-level&#34;&gt;🔹 A. Account / Organization level&lt;/h4&gt;
&lt;p&gt;&lt;strong&gt;Keywords:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&amp;ldquo;limit an account&amp;rdquo;&lt;/li&gt;
&lt;li&gt;&amp;ldquo;restrict services across accounts&amp;rdquo;&lt;/li&gt;
&lt;li&gt;&amp;ldquo;govern multiple accounts&amp;rdquo;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;👉 Use:
AWS Organizations + SCP&lt;/p&gt;
&lt;hr&gt;
&lt;h4 id=&#34;-b-user--role-level&#34;&gt;🔹 B. User / Role level&lt;/h4&gt;
&lt;p&gt;&lt;strong&gt;Keywords:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&amp;ldquo;user can access&amp;hellip;&amp;rdquo;&lt;/li&gt;
&lt;li&gt;&amp;ldquo;role permission&amp;hellip;&amp;rdquo;&lt;/li&gt;
&lt;li&gt;&amp;ldquo;least privilege&amp;rdquo;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;👉 Use:
IAM Policy&lt;/p&gt;
&lt;hr&gt;
&lt;h4 id=&#34;-c-cross-account-access&#34;&gt;🔹 C. Cross-account access&lt;/h4&gt;
&lt;p&gt;👉 Check next 👇&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id=&#34;-2-does-the-service-support-resource-policy&#34;&gt;🔍 2. Does the service support Resource Policy?&lt;/h3&gt;
&lt;h4 id=&#34;-yes--use-resource-policy&#34;&gt;✅ YES → Use Resource Policy&lt;/h4&gt;
&lt;p&gt;Examples: S3, SQS, SNS, Lambda&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
