限制IAM用户访问特定的S3存储桶目录

时间:2019-01-14 07:56:37

标签: amazon-web-services amazon-s3

我正在设置IAM用户,使其只能访问要下载的特定存储桶文件夹对象,并仅限于其他存储桶和子文件夹

{
     "Version": "2012-10-17",
     "Statement":[
      {
         "Sid":"AllowListBucketIfSpecificPrefixIsIncludedInRequest",
         "Action":["s3:ListBucket"],
         "Effect":"Allow",
         "Resource":["arn:aws:s3:::mybucket"],
         "Condition":{
            "StringLike":{"s3:prefix":["downloads/*"]
            }
         }
      },
      {
        "Sid":"AllowUserToReadWriteObjectDataInDownloadsFolder", 
        "Action":["s3:GetObject"],
        "Effect":"Allow",
        "Resource":["arn:aws:s3:::mybucket/downloads/*"]
      }
   ]
}

0 个答案:

没有答案