Recently I tried hosting a static website on AWS with a catch: it should only be reachable from certain countries but remain reachable for the Google crawler. The original solution was working and simple and consisted of a python script that built a list ip adresses and a deny all statement in an .htaccess file.
Same setup on AWS: Identity center, AWS Organizations, SCPs, cloudtrail, cloudwatch, cloudfront and s3 with half a dozen Policies. The only tool available with fine grained IP Access restrictions is WAF which costs alone almost 10x what one would pay with the hoster.