<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Danang Adi Nugroho</title>
    <description>The latest articles on DEV Community by Danang Adi Nugroho (@danang_adi).</description>
    <link>https://dev.to/danang_adi</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3807183%2F949e9fb8-ccdf-41ae-8b8f-6b632dbd15cb.jpg</url>
      <title>DEV Community: Danang Adi Nugroho</title>
      <link>https://dev.to/danang_adi</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/danang_adi"/>
    <language>en</language>
    <item>
      <title>S3 Security Best Practices: Require HTTPS and Restrict Access to a VPC Endpoint</title>
      <dc:creator>Danang Adi Nugroho</dc:creator>
      <pubDate>Thu, 08 Oct 2026 07:30:35 +0000</pubDate>
      <link>https://dev.to/danang_adi/s3-security-best-practices-require-https-and-restrict-access-to-a-vpc-endpoint-1c98</link>
      <guid>https://dev.to/danang_adi/s3-security-best-practices-require-https-and-restrict-access-to-a-vpc-endpoint-1c98</guid>
      <description>&lt;p&gt;Amazon S3 stores a lot of important data, so a weak configuration can expose it to the internet or to unwanted traffic. In this guide I walk through two practical ways I secure an S3 bucket: forcing HTTPS and limiting access to a specific VPC endpoint. It is written for beginners who already have an AWS account and want hands-on steps they can follow.&lt;/p&gt;

&lt;h2&gt;
  
  
  Prerequisites
&lt;/h2&gt;

&lt;p&gt;Before you start, make sure you have:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;An AWS account with access to the AWS Management Console.&lt;/li&gt;
&lt;li&gt;A test S3 bucket you can safely experiment with, with at least one object uploaded.&lt;/li&gt;
&lt;li&gt;Permissions to edit S3 bucket policies and to create VPC endpoints (for example, administrator access or equivalent IAM permissions).&lt;/li&gt;
&lt;li&gt;The AWS CLI installed and configured, so you can run the verification commands.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Throughout this guide I use &lt;code&gt;&amp;lt;YOUR_BUCKET_NAME&amp;gt;&lt;/code&gt; for the bucket name and &lt;code&gt;&amp;lt;VPC_ENDPOINT_ID&amp;gt;&lt;/code&gt; for the VPC endpoint ID. Replace them with your own values.&lt;/p&gt;

&lt;h2&gt;
  
  
  Require HTTPS
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Why it matters
&lt;/h3&gt;

&lt;p&gt;By default an S3 bucket can accept both HTTP and HTTPS requests. HTTP traffic is not encrypted, so data can be read in transit. This bucket policy denies any request that does not use HTTPS, which protects your data while it moves.&lt;/p&gt;

&lt;h3&gt;
  
  
  Steps
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;In the AWS Management Console, use the top search bar to search for and select &lt;strong&gt;S3&lt;/strong&gt;.

&lt;ol&gt;
&lt;li&gt;Click the bucket name.&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fg6oe8q9n0folmyb167i5.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fg6oe8q9n0folmyb167i5.png" alt="S3 console showing the test bucket contents, with one object listed in the test/ folder" width="800" height="249"&gt;&lt;/a&gt;&lt;br&gt;
   &lt;em&gt;The S3 object view for the test bucket.&lt;/em&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Click the &lt;strong&gt;Permissions&lt;/strong&gt; tab.&lt;/li&gt;
&lt;li&gt;Under &lt;strong&gt;Bucket policy&lt;/strong&gt;, click &lt;strong&gt;Edit&lt;/strong&gt;.

&lt;ol&gt;
&lt;li&gt;Copy the bucket policy below and paste it into the bucket policy editor.
&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;/ol&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="w"&gt;   &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
       &lt;/span&gt;&lt;span class="nl"&gt;"Id"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"S3-Security-Deny-unless-HTTPS"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
       &lt;/span&gt;&lt;span class="nl"&gt;"Version"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"2012-10-17"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
       &lt;/span&gt;&lt;span class="nl"&gt;"Statement"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[{&lt;/span&gt;&lt;span class="w"&gt;
           &lt;/span&gt;&lt;span class="nl"&gt;"Action"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"s3:*"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
           &lt;/span&gt;&lt;span class="nl"&gt;"Effect"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"Deny"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
           &lt;/span&gt;&lt;span class="nl"&gt;"Principal"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"*"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
           &lt;/span&gt;&lt;span class="nl"&gt;"Resource"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"arn:aws:s3:::&amp;lt;YOUR_BUCKET_NAME&amp;gt;/*"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
           &lt;/span&gt;&lt;span class="nl"&gt;"Condition"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
               &lt;/span&gt;&lt;span class="nl"&gt;"Bool"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
                   &lt;/span&gt;&lt;span class="nl"&gt;"aws:SecureTransport"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kc"&gt;false&lt;/span&gt;&lt;span class="w"&gt;
               &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
           &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
       &lt;/span&gt;&lt;span class="p"&gt;}]&lt;/span&gt;&lt;span class="w"&gt;
   &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Replace &lt;code&gt;&amp;lt;YOUR_BUCKET_NAME&amp;gt;&lt;/code&gt; with your bucket name.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fbqmmysq1qr76igjr6bre.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fbqmmysq1qr76igjr6bre.png" alt="Edit bucket policy screen in the S3 console showing the deny-unless-HTTPS JSON policy and the bucket ARN" width="800" height="361"&gt;&lt;/a&gt;&lt;br&gt;
   &lt;em&gt;The bucket policy editor with the HTTPS policy pasted in.&lt;/em&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Click &lt;strong&gt;Save changes&lt;/strong&gt;.&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  How to verify it worked
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;Test with an HTTP endpoint. This request should fail:
&lt;/li&gt;
&lt;/ol&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;   aws s3api head-object &lt;span class="nt"&gt;--key&lt;/span&gt; &lt;span class="o"&gt;[&lt;/span&gt;folder-name]/[filename] &lt;span class="nt"&gt;--endpoint-url&lt;/span&gt; http://s3.amazonaws.com &lt;span class="nt"&gt;--bucket&lt;/span&gt; &amp;lt;YOUR_BUCKET_NAME&amp;gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The command should return a 403 error, because the endpoint URL uses HTTP.&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Now test with an HTTPS endpoint. This request should succeed:
&lt;/li&gt;
&lt;/ol&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;   aws s3api head-object &lt;span class="nt"&gt;--key&lt;/span&gt; &lt;span class="o"&gt;[&lt;/span&gt;folder-name]/[filename] &lt;span class="nt"&gt;--endpoint-url&lt;/span&gt; https://s3.amazonaws.com &lt;span class="nt"&gt;--bucket&lt;/span&gt; &amp;lt;YOUR_BUCKET_NAME&amp;gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The command succeeds. Both commands use &lt;code&gt;s3api&lt;/code&gt;, and the only difference is the &lt;code&gt;--endpoint-url&lt;/code&gt;. So the bucket policy reacts to the transport, not to the tool.&lt;/p&gt;

&lt;h2&gt;
  
  
  Restrict Access to an S3 VPC Endpoint
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Why it matters
&lt;/h3&gt;

&lt;p&gt;A VPC endpoint lets resources inside your VPC reach S3 over the AWS private network instead of the public internet. This bucket policy denies every request that does not come through your VPC endpoint, so only traffic from your VPC can reach the bucket.&lt;/p&gt;

&lt;h3&gt;
  
  
  Steps
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;In the AWS Management Console, use the top search bar to search for and select &lt;strong&gt;VPC&lt;/strong&gt;.

&lt;ol&gt;
&lt;li&gt;In the left column, click &lt;strong&gt;Endpoints&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Click &lt;strong&gt;Create endpoint&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Give the endpoint a name.&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F9vedp3xqzp3zppcrd6m2.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F9vedp3xqzp3zppcrd6m2.png" alt="Create endpoint screen showing the Name tag field set to s3-endpoint and AWS services selected as the type" width="800" height="293"&gt;&lt;/a&gt;&lt;br&gt;
   &lt;em&gt;Naming the endpoint and choosing the AWS services type.&lt;/em&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Type &lt;code&gt;S3&lt;/code&gt; in the search bar and press Enter. This filters the list to the S3 endpoints. Select the Gateway type endpoint.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F4ningvmoaqwv5ah7nd0c.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F4ningvmoaqwv5ah7nd0c.png" alt="VPC service list filtered by s3, with the Gateway type com.amazonaws.us-east-1.s3 service selected" width="799" height="338"&gt;&lt;/a&gt;&lt;br&gt;
   &lt;em&gt;Selecting the S3 Gateway endpoint from the service list.&lt;/em&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Under &lt;strong&gt;VPC&lt;/strong&gt;, select your VPC.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fxmxsbymuy9nnlxkp41tz.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fxmxsbymuy9nnlxkp41tz.png" alt="Network settings section showing a VPC selected in the VPC dropdown" width="800" height="115"&gt;&lt;/a&gt;&lt;br&gt;
   &lt;em&gt;Choosing the VPC for the endpoint.&lt;/em&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Configure the route tables and set the &lt;strong&gt;Policy&lt;/strong&gt; to &lt;strong&gt;Full access&lt;/strong&gt;.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F68w8ft5jxw0m8jw7plbo.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F68w8ft5jxw0m8jw7plbo.png" alt="Route tables selection and the Policy section set to Full access" width="799" height="287"&gt;&lt;/a&gt;&lt;br&gt;
   &lt;em&gt;Selecting the route tables and setting the endpoint policy to Full access.&lt;/em&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Click &lt;strong&gt;Create endpoint&lt;/strong&gt;.

&lt;ol&gt;
&lt;li&gt;In the AWS Management Console, use the top search bar to search for and select &lt;strong&gt;S3&lt;/strong&gt;.&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;li&gt;Click the bucket name.&lt;/li&gt;
&lt;li&gt;Click the &lt;strong&gt;Permissions&lt;/strong&gt; tab.&lt;/li&gt;
&lt;li&gt;Under &lt;strong&gt;Bucket policy&lt;/strong&gt;, click &lt;strong&gt;Edit&lt;/strong&gt;.

&lt;ol&gt;
&lt;li&gt;Delete the existing bucket policy. Copy the bucket policy below and paste it into the bucket policy editor.
&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;/ol&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="w"&gt;   &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
       &lt;/span&gt;&lt;span class="nl"&gt;"Id"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"S3-Security-Deny-unless-VPC-endpoint"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
       &lt;/span&gt;&lt;span class="nl"&gt;"Version"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"2012-10-17"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
       &lt;/span&gt;&lt;span class="nl"&gt;"Statement"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[{&lt;/span&gt;&lt;span class="w"&gt;
           &lt;/span&gt;&lt;span class="nl"&gt;"Action"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"s3:*"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
           &lt;/span&gt;&lt;span class="nl"&gt;"Effect"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"Deny"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
           &lt;/span&gt;&lt;span class="nl"&gt;"Resource"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"arn:aws:s3:::&amp;lt;YOUR_BUCKET_NAME&amp;gt;/*"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
           &lt;/span&gt;&lt;span class="nl"&gt;"Condition"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
               &lt;/span&gt;&lt;span class="nl"&gt;"StringNotEquals"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
                   &lt;/span&gt;&lt;span class="nl"&gt;"aws:sourceVpce"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"&amp;lt;VPC_ENDPOINT_ID&amp;gt;"&lt;/span&gt;&lt;span class="w"&gt;
               &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
           &lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt;&lt;span class="w"&gt;
           &lt;/span&gt;&lt;span class="nl"&gt;"Principal"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"*"&lt;/span&gt;&lt;span class="w"&gt;
       &lt;/span&gt;&lt;span class="p"&gt;}]&lt;/span&gt;&lt;span class="w"&gt;
   &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Replace &lt;code&gt;&amp;lt;YOUR_BUCKET_NAME&amp;gt;&lt;/code&gt; with your bucket name and &lt;code&gt;&amp;lt;VPC_ENDPOINT_ID&amp;gt;&lt;/code&gt; with your endpoint ID.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fa3h4vureyuq9lfu4wpmw.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fa3h4vureyuq9lfu4wpmw.png" alt="Edit bucket policy screen showing the deny-unless-VPC-endpoint JSON policy" width="800" height="430"&gt;&lt;/a&gt;&lt;br&gt;
   &lt;em&gt;The bucket policy editor with the VPC endpoint policy pasted in.&lt;/em&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Click &lt;strong&gt;Save changes&lt;/strong&gt;.&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  How to verify it worked
&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;From an EC2 instance inside the VPC, run this command:
&lt;/li&gt;
&lt;/ol&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;   aws s3api head-object &lt;span class="nt"&gt;--key&lt;/span&gt; &lt;span class="o"&gt;[&lt;/span&gt;folder-name]/[filename] &lt;span class="nt"&gt;--bucket&lt;/span&gt; &amp;lt;YOUR_BUCKET_NAME&amp;gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The request succeeds because the EC2 instance can route its S3 request through the VPC endpoint, and the bucket policy allows requests that come through that endpoint.&lt;/p&gt;

&lt;h2&gt;
  
  
  Clean Up
&lt;/h2&gt;

&lt;p&gt;To avoid leftover resources and keep your account tidy, remove the test resources when you are done:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;In the &lt;strong&gt;S3&lt;/strong&gt; console, open the bucket, go to the &lt;strong&gt;Permissions&lt;/strong&gt; tab, and under &lt;strong&gt;Bucket policy&lt;/strong&gt; click &lt;strong&gt;Edit&lt;/strong&gt;, then delete the policy and click &lt;strong&gt;Save changes&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;In the &lt;strong&gt;VPC&lt;/strong&gt; console, open &lt;strong&gt;Endpoints&lt;/strong&gt;, select the endpoint you created, and delete it.&lt;/li&gt;
&lt;li&gt;If you created a test bucket only for this guide, empty the bucket and then delete it.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  Conclusion
&lt;/h2&gt;

&lt;p&gt;Key takeaways:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Force HTTPS with a bucket policy that denies requests when &lt;code&gt;aws:SecureTransport&lt;/code&gt; is &lt;code&gt;false&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Restrict access to a VPC endpoint with a bucket policy that denies requests from any other source.&lt;/li&gt;
&lt;li&gt;Verify each policy with the AWS CLI before you trust it.&lt;/li&gt;
&lt;li&gt;Remove test resources when you finish.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Relevant official AWS documentation:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.aws.amazon.com/AmazonS3/latest/userguide/security-best-practices.html" rel="noopener noreferrer"&gt;Security best practices for Amazon S3&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.aws.amazon.com/AmazonS3/latest/userguide/bucket-policies.html" rel="noopener noreferrer"&gt;Amazon S3 bucket policies&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.aws.amazon.com/AmazonS3/latest/userguide/security-best-practices.html#transit" rel="noopener noreferrer"&gt;Enforce encryption of data in transit (aws:SecureTransport)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.aws.amazon.com/vpc/latest/privatelink/vpc-endpoints-s3.html" rel="noopener noreferrer"&gt;Gateway endpoints for Amazon S3&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.aws.amazon.com/AmazonS3/latest/userguide/example-bucket-policies-vpc-endpoint.html" rel="noopener noreferrer"&gt;Control access from VPC endpoints with bucket policies&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>aws</category>
      <category>s3</category>
      <category>security</category>
      <category>beginners</category>
    </item>
    <item>
      <title>Passing AWS Cloud Practitioner in 2 Weeks: Study Strategy and Topic Focus</title>
      <dc:creator>Danang Adi Nugroho</dc:creator>
      <pubDate>Thu, 01 Oct 2026 11:12:54 +0000</pubDate>
      <link>https://dev.to/danang_adi/passing-aws-cloud-practitioner-in-2-weeks-study-strategy-and-topic-focus-2hmb</link>
      <guid>https://dev.to/danang_adi/passing-aws-cloud-practitioner-in-2-weeks-study-strategy-and-topic-focus-2hmb</guid>
      <description>&lt;p&gt;Hi, I'm Danang, a Cloud DevOps Engineer at a cloud services company in Jakarta, Indonesia. This is my first article on Dev.to. I want to share how a beginner can earn a first AWS certification, the &lt;strong&gt;AWS Certified Cloud Practitioner (CCP)&lt;/strong&gt;, with just two weeks of preparation.&lt;/p&gt;

&lt;h2&gt;
  
  
  How It Started: AWS Back-End Academy 2024 Batch 2
&lt;/h2&gt;

&lt;p&gt;The opportunity came in 2024 through the &lt;strong&gt;AWS Back-End Academy 2024 Batch 2&lt;/strong&gt; program, run by Dicoding, an Indonesian tech learning platform. I was selected as one of the &lt;strong&gt;top 40 participants out of hundreds of applicants&lt;/strong&gt; to receive a global AWS certification token. I received the announcement email on September 21, 2024.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fbk4gxnse73g7aglyu7fg.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fbk4gxnse73g7aglyu7fg.png" alt=" " width="799" height="244"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;One important note: this program no longer hands out free certification tokens, so please read this part as my personal story, not as an opportunity that is guaranteed to still be available. If you want to study from official sources, &lt;a href="https://skillbuilder.aws" rel="noopener noreferrer"&gt;AWS Skill Builder&lt;/a&gt; offers plenty of learning material, including Cloud Practitioner preparation.&lt;/p&gt;

&lt;h2&gt;
  
  
  Study Resources
&lt;/h2&gt;

&lt;p&gt;I started studying about two weeks before the exam, which I took on &lt;strong&gt;October 18, 2024&lt;/strong&gt;. The resources I used:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Stéphane Maarek's Udemy course&lt;/strong&gt;: udemy.com/course/aws-certified-cloud-practitioner-new/&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Official AWS documentation&lt;/strong&gt;: &lt;a href="https://docs.aws.amazon.com/" rel="noopener noreferrer"&gt;https://docs.aws.amazon.com/&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Articles from the internet&lt;/strong&gt; covering the services that appear in the exam, as a supplement whenever a concept was unclear.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  Study Strategy: Fundamentals First, Services Second
&lt;/h2&gt;

&lt;p&gt;The CCP exam (version CLF-C02) is split into four domains with the following weights. Always check the &lt;a href="https://aws.amazon.com/certification/certified-cloud-practitioner/" rel="noopener noreferrer"&gt;official AWS exam guide&lt;/a&gt;, since weights can change in newer exam versions.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Domain&lt;/th&gt;
&lt;th&gt;Weight&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Cloud Concepts&lt;/td&gt;
&lt;td&gt;24%&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Security and Compliance&lt;/td&gt;
&lt;td&gt;30%&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Cloud Technology and Services&lt;/td&gt;
&lt;td&gt;34%&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Billing, Pricing, and Support&lt;/td&gt;
&lt;td&gt;12%&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The principle I followed: &lt;strong&gt;understand the fundamentals before learning what each service does&lt;/strong&gt;. So my plan was:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Week 1&lt;/strong&gt;: Cloud Concepts and Cloud Technology and Services, to build a big-picture view of how the cloud works and what the core services are.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Week 2&lt;/strong&gt;: Security and Compliance, then finishing the remaining material such as Billing, Pricing, and Support.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;It did not go as smoothly as I had imagined. In week two I hit my biggest challenge: the security and compliance domain.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Biggest Challenge: Security and Compliance
&lt;/h2&gt;

&lt;p&gt;Security was not a familiar topic for me at the time, so I put in extra effort, especially on &lt;strong&gt;AWS security best practices and IAM&lt;/strong&gt;. These are the concepts I found most important to understand:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Shared responsibility model&lt;/strong&gt;: AWS is responsible for security &lt;em&gt;of&lt;/em&gt; the cloud (the infrastructure), while you are responsible for security &lt;em&gt;in&lt;/em&gt; the cloud (configuration, data, and access).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;IAM (Identity and Access Management)&lt;/strong&gt;: users, groups, roles, and policies. Roles are used for temporary access, for example, so one service can reach another without storing credentials.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Least privilege&lt;/strong&gt;: grant only the permissions that are truly needed, nothing more.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Root user&lt;/strong&gt;: protect it with MFA, and do not use it for everyday work.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Other security services&lt;/strong&gt; worth knowing at a high level: AWS Artifact (compliance reports), GuardDuty (threat detection), Inspector (vulnerability scanning), Shield (DDoS protection), WAF (web request filtering), and KMS (encryption key management).&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Exam Day Strategy
&lt;/h2&gt;

&lt;p&gt;I answered &lt;strong&gt;the easier questions first&lt;/strong&gt;. That kept my time under control and left a calmer amount of time for the harder ones.&lt;/p&gt;

&lt;h2&gt;
  
  
  Result
&lt;/h2&gt;

&lt;p&gt;I passed on my first attempt, and it became my first AWS certification. &lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ffeyexul2l98sp0qco5kh.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ffeyexul2l98sp0qco5kh.png" alt=" " width="800" height="483"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Frequently Asked Questions
&lt;/h2&gt;

&lt;p&gt;I also shared this experience at &lt;strong&gt;Tech Talk #2 by Dicoding Cloud Community&lt;/strong&gt; on December 6, 2025. These were the three questions participants asked most:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Where did you study?&lt;/strong&gt; Official AWS documentation, Stéphane Maarek's video course on Udemy, and supporting articles for the services in the exam.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How long did you study?&lt;/strong&gt; About two weeks in my case, though it depends on your background and how much time you have each day.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Which topics need extra attention?&lt;/strong&gt; Security and Compliance, especially IAM and AWS security best practices.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://www.linkedin.com/posts/cloudkraf-community_dicodingcloudcommunity-techtalk-aws-ugcPost-7403453774536892416-Qvao?utm_source=share&amp;amp;utm_medium=member_desktop&amp;amp;rcm=ACoAADc5rHoBQZ6YCbGO4qT-0l6X5sPUMQLKjdM" rel="noopener noreferrer"&gt;You can see the session documentation here&lt;/a&gt;:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F4k5iwpog26qadjgi43xl.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F4k5iwpog26qadjgi43xl.png" alt=" " width="800" height="800"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Key Takeaways
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;Start with cloud fundamentals before diving into what each service does.&lt;/li&gt;
&lt;li&gt;Two weeks can be enough if your focus is clear, but adjust to your own situation.&lt;/li&gt;
&lt;li&gt;Give extra time to Security and Compliance, especially IAM.&lt;/li&gt;
&lt;li&gt;On exam day, answer the easier questions first to manage your time.&lt;/li&gt;
&lt;li&gt;Always check the official exam guide, because the exam structure can change.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Thanks for reading. If you have questions or your own CCP experience to share, leave a comment. You can also connect with me on &lt;a href="https://www.linkedin.com/in/danangadi/" rel="noopener noreferrer"&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt;

</description>
      <category>aws</category>
      <category>certification</category>
      <category>cloudcomputing</category>
      <category>beginners</category>
    </item>
  </channel>
</rss>
