只读访问S3存储桶

时间:2017-05-30 19:20:55

标签: amazon-web-services amazon-s3

我希望此特定策略限制所有写入,我只希望这些特定实例从存储桶中读取。

此政策似乎允许我阅读和写作。

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "Stmt1424867341000",
            "Effect": "Allow",
            "Action": [
                "s3:GetBucketLocation",
                "s3:ListBucket"
            ],
            "Resource": [
                "arn:aws:s3:::MYBUCKETNAME"
            ]
        },
        {
            "Sid": "Stmt1424867403000",
            "Effect": "Allow",
            "Action": [
                "s3:GetObject"
            ],
            "Resource": [
                "arn:aws:s3:::MYBUCKETNAME/*"
            ]
        }
    ]
}

0 个答案:

没有答案