【发布时间】:2021-01-20 14:42:12
【问题描述】:
我被指示阻止对 s3 的公共访问。所以我将其屏蔽如下:
现在我尝试授予自己查看或下载存储桶中 PDF 的权限。所以我创建了一个完全访问策略如下:
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "VisualEditor0",
"Effect": "Allow",
"Action": [
"s3:ListStorageLensConfigurations",
"s3:GetAccessPoint",
"s3:PutAccountPublicAccessBlock",
"s3:GetAccountPublicAccessBlock",
"s3:ListAllMyBuckets",
"s3:ListAccessPoints",
"s3:ListJobs",
"s3:PutStorageLensConfiguration",
"s3:CreateJob"
],
"Resource": "*"
},
{
"Sid": "VisualEditor1",
"Effect": "Allow",
"Action": "s3:*",
"Resource": "arn:aws:s3:::*"
}
]
}
并附加到我的 IAM 用户。即使在此之后,当我单击对象级别可用的对象 URL 时,我仍然收到拒绝访问消息:
【问题讨论】:
标签: amazon-web-services amazon-s3