gpt4 book ai didi

amazon-web-services - 如何通过 CloudFormation 添加 AWS 托管策略

转载 作者:行者123 更新时间:2023-12-03 07:22:40 25 4
gpt4 key购买 nike

我想使用 CloudFormation 将 AWS 托管策略 (AmazonSSMFullAccess) 添加到角色。我尝试使用 AWS::IAM::ManagedPolicy 但它创建了一个客户托管策略,但我不希望这样。我希望它由 AWS 管理。你知道我该怎么做吗?

我正在尝试添加 AWS 托管的 AmazonSSMFullAccess,这是我在 mu CF 模板中使用的代码:

AmazonSSMFullAccess:
Type: AWS::IAM::ManagedPolicy
Properties:
PolicyDocument:
Version: '2012-10-17'
Statement:
- Effect: Allow
Action:
- 'cloudwatch:PutMetricData'
- 'ds:CreateComputer'
- 'ds:DescribeDirectories'
- 'ec2:DescribeInstanceStatus'
- 'logs:*'
- 'ssm:*'
- 'ec2messages:*'
Resource: '*'
- Effect: Allow
Action: 'iam:CreateServiceLinkedRole'
Resource: >-
arn:aws:iam::*:role/aws-service-role/ssm.amazonaws.com/AWSServiceRoleForAmazonSSM*
Condition:
StringLike:
'iam:AWSServiceName': ssm.amazonaws.com
- Effect: Allow
Action:
- 'iam:DeleteServiceLinkedRole'
- 'iam:GetServiceLinkedRoleDeletionStatus'
Resource: >-
arn:aws:iam::*:role/aws-service-role/ssm.amazonaws.com/AWSServiceRoleForAmazonSSM*
- Effect: Allow
Action:
- 'ssmmessages:CreateControlChannel'
- 'ssmmessages:CreateDataChannel'
- 'ssmmessages:OpenControlChannel'
- 'ssmmessages:OpenDataChannel'
Resource: '*'

First line if the policy I get from CF and second one is the one I need

最佳答案

作为 AWS 客户,您只能创建客户托管策略。您无法创建 AWS 托管策略,因为只有 Amazon 可以做到这一点。

关于amazon-web-services - 如何通过 CloudFormation 添加 AWS 托管策略,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/71660461/

25 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com