授予EC2 跨账户访问S3的 权限

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "NotAction": [
                "iam:*",
                "organizations:*",
                "account:*"
            ],
            "Resource": "*"
        },
        {
            "Effect": "Allow",
            "Action": [
                "iam:CreateServiceLinkedRole",
                "iam:DeleteServiceLinkedRole",
                "iam:ListRoles",
                "organizations:DescribeOrganization",
                "account:ListRegions"
            ],
            "Resource": [
                "arn:aws-cn:s3:::*"
            ]
        }
    ]
}

 

 

匿名用户允许访问公开的S3桶
{
"Version": "2012-10-17", "Statement": [ { "Sid": "PublicReadGetObject", "Effect": "Allow", "Principal": "*", "Action": [ "s3:GetObject" ], "Resource": [ "arn:aws-cn:s3:::example.com/*" ] } ] }

 

posted @ 2020-05-21 09:35  慕沁  阅读(408)  评论(0)    收藏  举报