AWS mgn: Fix export role S3 permission from GetObject to PutObject
Summary
The IAM policy example for the export feature now grants s3:PutObject instead of s3:GetObject, aligning the documented permission with the write behavior of exporting.
Security assessment
Corrects the documented IAM permission for the role used by the export feature: export writes objects, so the previously documented s3:GetObject was wrong and could have led users to grant an incorrect (or, if paired with other statements, unnecessary) S3 permission, a least-privilege/authorization accuracy issue.
Evidence
"s3:PutObject"
Diff
diff --git a/mgn/latest/ug/export-main.md b/mgn/latest/ug/export-main.md index ec6048adb..b81207587 100644 --- a//mgn/latest/ug/export-main.md +++ b//mgn/latest/ug/export-main.md @@ -37 +37 @@ In order to use the export feature, you will need to create a role with the foll - "s3:GetObject" + "s3:PutObject"