限制 AWS Cloudwatch Dashboard 仅供某些角色使用
我有一个为管理员和开发人员创建单独的 cloudwatch 仪表板(或视图)的用例,我可以根据用户假定的角色限制用户查看 cloudwatch 仪表板吗? AWS 是否允许为每个仪表板配置 IAM 访问策略?
谢谢
I have a use case to create a separate cloudwatch dashboard(or views) for admins and developers, can I restrict a user to view cloudwatch dashboard based on the user's assumed role ?
Is it something that AWS allows to configure a IAM access policy for each dashboard ?
Thanks
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
data:image/s3,"s3://crabby-images/d5906/d59060df4059a6cc364216c4d63ceec29ef7fe66" alt="扫码二维码加入Web技术交流群"
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(1)
您无法使用角色/IAM 共享/限制对特定仪表板的访问。
使用 CloudWatch 处理策略时,我们有以下内容:
cloudwatch:GetDashboard
和cloudwatch:ListDashboards
能够查看所有仪表板cloudwatch:PutDashboard
能够创建或修改仪表板cloudwatch:DeleteDashboards
能够删除仪表板使用这些选项,我们无法指定对特定仪表板的访问权限。
如果您想与特定用户共享仪表板,我们可以通过他们的电子邮件进行共享。要了解如何执行此操作,请查看此处:与特定用户共享单个仪表板
另外,请查看这些页面:
You can not share/restrict access to a specific dashboard using roles/IAM.
When working with policies using CloudWatch we have the following:
cloudwatch:GetDashboard
andcloudwatch:ListDashboards
to be able to view all dashboardscloudwatch:PutDashboard
to be able to create or modify dashboardscloudwatch:DeleteDashboards
to be able to delete dashboardsWith these options we do not have the option to specify the access to a specific dashboard.
If you want to share the dashboard with specific users, we can do this sharing with their emails. To understand how to do this, check here: Share a single dashboard with specific users
Also, take a look on these pages: