This repository contains the application assets and security configurations for a highly available static web application deployed on Amazon Web Services (AWS). The project demonstrates the provisioning of cloud storage via Amazon S3 and the enforcement of the principle of least privilege using AWS Identity and Access Management (IAM).
To maintain a strict separation of concerns, the application source code is isolated from the cloud infrastructure security policies.
├── aws-policies/ # Infrastructure security and access control configurations
│ ├── iam_least_privilege_policy.json # Admin policy restricting write/delete access
│ └── s3_bucket_policy.json # Bucket policy allowing public read access
├── css/ # Application stylesheets
├── images/ # Application graphical assets
├── contact.html # Web views
├── hours.html # Web views
└── index.html # Application entry point
The deployment utilized the AWS Management Console to provision resources. The resulting architecture relies on two critical security policies (documented in /aws-policies):
- S3 Public Read Policy: Attached directly to the S3 bucket to allow
s3:GetObjectactions globally, ensuring the web assets can be rendered by any browser without exposing the underlying AWS account. - IAM Administrative Policy: A custom IAM policy enforcing strict resource isolation. It restricts state-altering actions (
s3:PutObject,s3:DeleteObject) to authorized administrative roles only, preventing unauthorized modifications to the production bucket.
This architecture was provisioned and deployed within a secure AWS Academy Laboratory environment. Because these lab environments are ephemeral and designed to decommission resources automatically after session termination to optimize costs, a live production URL is no longer active.
This repository serves as the permanent documentation of the architectural configurations, security policies, and frontend assets implemented during the active deployment.