<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>AWS SAP Cheat Sheet on &gt; truongvu.dev</title>
    <link>https://truongvu.dev/vi/categories/aws-sap-cheat-sheet/</link>
    <description>Recent content in AWS SAP Cheat Sheet on &gt; truongvu.dev</description>
    <image>
      <title>&gt; truongvu.dev</title>
      <url>https://truongvu.dev/static/images/default-cover.png</url>
      <link>https://truongvu.dev/static/images/default-cover.png</link>
    </image>
    <generator>Hugo</generator>
    <language>vi</language>
    <lastBuildDate>Sat, 21 Mar 2026 09:21:13 +0700</lastBuildDate>
    <atom:link href="https://truongvu.dev/vi/categories/aws-sap-cheat-sheet/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>AWS IAM Decision Mindmap</title>
      <link>https://truongvu.dev/vi/categories/aws-sap-cheat-sheet/202603211-sap-iam/</link>
      <pubDate>Sat, 21 Mar 2026 09:21:13 +0700</pubDate>
      <guid>https://truongvu.dev/vi/categories/aws-sap-cheat-sheet/202603211-sap-iam/</guid>
      <description>&lt;h3 id=&#34;-1-bạn-đang-control-ở-level-nào&#34;&gt;🎯 1. Bạn đang control ở level nào?&lt;/h3&gt;
&lt;h4 id=&#34;-a-level-account--organization&#34;&gt;🔹 A. Level Account / Organization&lt;/h4&gt;
&lt;p&gt;&lt;strong&gt;Keyword:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&amp;ldquo;limit account&amp;rdquo;&lt;/li&gt;
&lt;li&gt;&amp;ldquo;restrict services&amp;rdquo;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;👉 Dùng:
AWS Organizations + SCP&lt;/p&gt;
&lt;hr&gt;
&lt;h4 id=&#34;-b-level-user--role&#34;&gt;🔹 B. Level User / Role&lt;/h4&gt;
&lt;p&gt;👉 Dùng:
IAM Policy&lt;/p&gt;
&lt;hr&gt;
&lt;h4 id=&#34;-c-cross-account&#34;&gt;🔹 C. Cross-account&lt;/h4&gt;
&lt;p&gt;👉 Check tiếp 👇&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id=&#34;-2-service-có-resource-policy-không&#34;&gt;🔍 2. Service có Resource Policy không?&lt;/h3&gt;
&lt;h4 id=&#34;-có--dùng-resource-policy&#34;&gt;✅ Có → dùng Resource Policy&lt;/h4&gt;
&lt;p&gt;Ưu điểm:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Không cần STS&lt;/li&gt;
&lt;li&gt;Đơn giản&lt;/li&gt;
&lt;li&gt;Nhanh&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;h4 id=&#34;-không--dùng-sts&#34;&gt;❌ Không → dùng STS&lt;/h4&gt;
&lt;p&gt;Pattern:
Account A → AssumeRole → Account B&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
