Concept and mechanism
Delivery security depends on separating tasks and protecting controls used for delegation. A runtime role that only reads objects does not need deployment-pipeline privileges. On the identity-policy path, a permissions boundary limits granted permissions; it does not create grants itself. The intersection rule requires care with resource policies and direct grants to certain users or sessions, which have documented exceptions. Do not generalize an example without stating the path. If a team can create roles with a boundary but also remove it, the limit is bypassable. Protect creation, removal, and modification of policies supporting delegation.
Guided application
Credentials and certificates need a complete lifecycle. Secret rotation means coordinating the stored value, target system, and application consumption; writing new JSON does not necessarily change a database password. An ACM-imported certificate does not receive managed renewal: assign ownership, alerts, renewal, and validation of the served certificate. For evidence, CloudTrail management events do not automatically include S3 object GetObject access. Configure data events and selectors for required scope and track cost, retention, and access. Enabling collection today does not retroactively recover missing events. If a build exposes a secret, contain access, preserve controlled evidence, revoke or rotate the credential, and fix the logging cause.
The certificate appears in the console but was imported and expires in two days. Renewal ownership still needs action.
Common pitfalls
Boundary as universal grant; stored secret as completed rotation; ACM as renewal of every certificate; retention as event reconstruction.
Related topics: Pipeline, artifacts, and identity · Progressive delivery and rollback
Confirm effective permissions, synchronization, and evidence about the actual resource.
Reference: DOP-C02 domain 6 · DOP-C02