Security
Scope IAM permissions to the specific destination bucket (and schema registry for Iceberg) used by each Channel.
Use the
aws:SourceArncondition in the trust policy to prevent other clusters or services from assuming the Channel role.Enable CloudTrail logging to audit all Channel API calls.