Recovering Locked S3 Buckets in AWS Organizations using AssumeRoot
📍 Scenario Imagine you’re the one managing all AWS accounts under your organization. One day, a developer while trying to tighten security, applies a policy so restrictive that the he blocks out everyone including himself in the process. The policy? Something like the one below { “Sid”: “DenyAllExceptPipeline”, “Effect”: “Deny”, “Principal”: “*”, “Action”: “s3:*”, “Resource”:…
