访问RDS,基于特定区域

时间:2016-11-17 04:51:05

标签: amazon-web-services amazon-iam rds

  1. 我想在特定的aws区域使用RDS,使用特定的IAM用户。
  2. 我用过这个:但它对我不起作用......有人可以在上面帮助我

        {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Sid": "Stmt1479355543600",
          "Action": "rds:*",
          "Effect": "Allow",
          "Resource": "*",
          "Condition": {
            "Bool": {
              "rds:Vpc": "1"
            }
          }
        }
      ]
    }
    
        {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Sid": "Stmt145591112222",
          "Action": "rds:*",
          "Effect": "Allow",
          "Resource": "arn:aws:rds:ap-southeast-1:ACC_ID:db:*"
    
        }
      ]
    }
    

    收到错误:

    User: arn:aws:iam::123123123:user/rdstest is not authorized to perform: rds:DescribeDBInstances (Service: AmazonRDS; Status Code: 403; Error Code: AccessDenied; Request ID: 32e9f1dd-1231-1231-a701-77103c93efc4)
    

0 个答案:

没有答案