AWS Security ChangesHomeSearch

AWS msk: Remove cross-account S3 Tables bucket policy guidance for MSK Iceberg role

Service: msk · 2026-09-27 · Documentation medium

File: msk/latest/developerguide/msk-data-delivery-iceberg-iam-service-role.md · Type: iam

Summary

Deletes the 'Cross-account S3 Table bucket access' section (and its TOC entry) that explained how a bucket owner in another account must attach a table bucket resource-based policy scoped to the MSK Channel service-role principal and needed S3 Tables actions.

Security assessment

The removed content was least-privilege / cross-account resource-policy guidance ('Scope the policy to the Channel service-role principal and the S3 Tables actions the role needs'). Removing it reduces documented IAM hardening guidance rather than fixing a specific vulnerability or incident, so it is security-adjacent documentation loss at most.

Evidence

-## Cross-account S3 Table bucket access

Diff

diff --git a/msk/latest/developerguide/msk-data-delivery-iceberg-iam-service-role.md b/msk/latest/developerguide/msk-data-delivery-iceberg-iam-service-role.md
index b38587425..7f9d9493b 100644
--- a//msk/latest/developerguide/msk-data-delivery-iceberg-iam-service-role.md
+++ b//msk/latest/developerguide/msk-data-delivery-iceberg-iam-service-role.md
@@ -7 +7 @@
-Trust policyPermission policy — streaming tables for Apache IcebergWhen you need each statementCross-account S3 Table bucket accessAdditional permissions
+Trust policyPermission policy — streaming tables for Apache IcebergWhen you need each statementAdditional permissions
@@ -158,6 +157,0 @@ The following explains when each statement in the preceding policy is required.
-## Cross-account S3 Table bucket access
-
-If your S3 Table bucket is in a different AWS account from your Amazon MSK cluster and the Channel service role, the bucket owner must grant access to the service role by attaching a table bucket policy (a resource-based policy) on the S3 Table bucket. Scope the policy to the Channel service-role principal and the S3 Tables actions the role needs (see the preceding Iceberg permission policy).
-
-For details and policy examples, see [Managing table bucket policies](https://docs.aws.amazon.com/AmazonS3/latest/userguide/s3-tables-bucket-policy.html) and [Resource-based policies for S3 Tables](https://docs.aws.amazon.com/AmazonS3/latest/userguide/s3-tables-resource-based-policies.html) in the _Amazon S3 User Guide_.
-