gpt4 book ai didi

amazon-web-services - IAM 用户策略在 Amazon S3 存储桶上返回 403 Forbidden

转载 作者:行者123 更新时间:2023-12-04 22:20:10 24 4
gpt4 key购买 nike

我正在努力使 AWS S3 IAM 用户策略起作用,这是我当前的 IAM 用户策略:

{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "Stmt1424859689000",
"Effect": "Allow",
"Action": [
"s3:DeleteObject",
"s3:GetObject",
"s3:PutObject"
],
"Resource": [
"arn:aws:s3:::vault-us/*"
]
}
]
}

当我发帖在 S3 存储桶中创建新对象时,我收到 403 Forbidden 错误,但是当我使用名为“AmazonS3FullAccess”的托管策略时,一切正常。

我想要做的是限制某些 IAM 用户上传/下载权限,但正在努力使其正常工作。

任何建议,将不胜感激!

最佳答案

我设法弄清楚,为了上传工作,我需要在下面包含操作“s3:PutObjectAcl”,这是我的 IAM 策略示例:

    {
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"s3:GetBucketLocation",
"s3:ListAllMyBuckets"
],
"Resource": "arn:aws:s3:::*"
},
{
"Effect": "Allow",
"Action": [
"s3:ListBucket"
],
"Resource": [
"arn:aws:s3:::vault-us"
]
},
{
"Effect": "Allow",
"Action": [
"s3:PutObject",
"s3:PutObjectAcl"
],
"Resource": [
"arn:aws:s3:::vault-us/*"
]
}
]
}

关于amazon-web-services - IAM 用户策略在 Amazon S3 存储桶上返回 403 Forbidden,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/28717593/

24 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com