桶策略,防止除特定角色外的桶删除

时间:2019-08-26 04:51:54

标签: amazon-web-services amazon-s3

我正在寻找一个存储桶策略,该策略限制所有用户/角色删除特定存储桶,并且仅允许root帐户用户和特定角色删除存储桶。像下面这样。请提出建议。

{
"Version": "2012-10-17",
"Id": "PutObjBucketPolicy",
"Statement": [
    {
        "Sid": "Prevent bucket delete",
        "Effect": "Deny",
        "Principal": *,
        "Action": "s3:DeleteBucket",
        "Resource": "arn:aws:s3:::test-bucket-s3"
        "Condition"
            StringNotEquals:
                { "AWS": "arn:aws:iam::AWS-account-ID:role/role-name" }
    }
]

}

0 个答案:

没有答案