【发布时间】:2014-11-18 23:06:20
【问题描述】:
试图将用户设置为只能访问一种类型的实例,并且只能停止和启动该实例。但是当我为它设置策略时,我只是收到一条错误消息,说未授权:
An error occurred fetching instance data: You are not authorized to perform this operation.
帐户 ID 已从安全页面检索到。
为了测试,我允许所有操作 (ec2:*) 并尝试了这些政策
{
"Version": "2012-10-17",
"Statement": [
{
"Action": "ec2:*",
"Effect": "Allow",
"Resource": "arn:aws:ec2:us-east-1:XXXXXXXXXX:instance/i-XXXXXXX"
}
]
}
带标签开发
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "Stmt1411556016000",
"Effect": "Allow",
"Action": [
"ec2:StartInstances",
"ec2:StopInstances"
],
"Resource" : "*"
"Condition": {
"ArnEquals": {
"ec2:ResourceTag/Environment": "dev"
}
}
}
]
}
【问题讨论】:
标签: amazon-web-services amazon-ec2 amazon-iam