Not OP but pretty sure they just mean this
`aws s3api create-bucket --bucket somecoolname --region us-west-2 --grant-write iamuser`
`aws s3api create-bucket --bucket somecoolname --region us-west-2 --grant-write iamuser`
I don’t know why all the hate for IAM permissions here.
They are complicated but also extremely powerful if setup correctly.
We manage all of our IAM policies and groups with terraform and it’s incredibly easy to understand imho
It’s a ton easier for on boarding and giving contractors temporary access to resources.
*former worker at 3rd party merchant