- ACLs / object ownership (which aren't deprecated -
https://docs.aws.amazon.com/AmazonS3/latest/userguide/access...)
- IAM / Bucket Policies as mentioned
- S3 Block Public Access (yes this is the name of a distinct feature)
- S3 Access Points
The interactions between all four of the above need to be taken into account to determine the access a consumer has to a bucket or its objects.
I'm not taking a swing at IAM - it's a great system. My grudge is with AWS having disparate interacting security controls for different services (of which S3 is probably the worst offender).
To heave back onto the topic at hand, let's hope R2 can do better having the benefit of a clean slate to build off!