这是How can i enforce file type uploads with an AWS S3 bucket policy
的后续内容应用存储分区策略时:
{
"Version":"2008-10-17",
"Statement": [
{
"Sid":"AddPerm",
"Effect":"Allow",
"Principal": { "AWS": "arn:aws:iam::111122223333:group/admins" },
"Action": "s3:PutObject",
"Resource": "arn:aws:s3:::bucket/*.txt"
}
]
}
组“admins”肯定存在,但我收到错误: “政策中的无效主体 - ”AWS“:”arn:aws:iam :: 111122223333:group / admins“”
为什么不被识别?
答案 0 :(得分:18)
目前无法在Principal
中使用群组。见https://forums.aws.amazon.com/message.jspa?messageID=356160