AWS 中的细化策略文档权限
我希望能够允许通过 IAM 创建的用户在管理控制台中查看一个特定存储桶。此外,我想将其限制为存储桶内的一个文件夹,以便权限为:
my-bucket/folder/* 的 S3 控制台访问权限
我将如何使用策略生成器执行此操作?我目前有:
{
"Statement": [
{
"Effect": "Allow",
"Action": "s3:*",
"Resource": "*"
}
]
}
但是,当我修改资源位置时 - arn:aws:s3:::my-bucket/folder
- 它根本阻止用户使用控制台。这可以吗?我需要做什么才能解决这个问题?
I want to be able to allow users created through IAM to be able to view one specific bucket in the management console. Furthermore, I want to restrict it to a folder within the bucket, such that the permissions would be:
S3 Console access for my-bucket/folder/*
How would I do this using the policy generator? I currently have:
{
"Statement": [
{
"Effect": "Allow",
"Action": "s3:*",
"Resource": "*"
}
]
}
However, when I modify the Resource location -- arn:aws:s3:::my-bucket/folder
-- it prevents the user from being able to use the console at all. Is this possible to do and what do I need to do to be able to fix this?
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
data:image/s3,"s3://crabby-images/d5906/d59060df4059a6cc364216c4d63ceec29ef7fe66" alt="扫码二维码加入Web技术交流群"
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(1)
这个政策让我想起了进行欧拉近似,但这就是我的做法(带有注释来解释):
The policy for this reminded me of doing an Euler apporximation, but this is how I did it (with comments to explain):