2) Create a S3 bucket
3) Write a bucket policy that whitelists specific IAM Roles to specific key paths within the bucket.