Your question is Secure AWS Pipeline Access Design. Take a moment with it on the right.
Talk me through your thinking if you like. When you're confident, submit your answer and I'll grade it like a real screen (7/10 or better passes).
You're working on a new data pipeline and want to set up access controls correctly before implementation. The pipeline will run on AWS, and different services and operators will need access to storage, compute, orchestration, and secrets.
How do you implement security best practices and the principle of least privilege in an AWS-based infrastructure?