【发布时间】:2019-09-11 19:13:46
【问题描述】:
尝试拒绝所有人的写入权限并仅允许单个用户写入 Amazon S3 存储桶,但我希望所有用户都可以查看它。因此,我在存储桶上设置了公共访问权限。
IAM 用户 Joe 拥有AmazonS3FullAccess。
这是存储桶策略:
{
"Id": "Policy98745183475249",
"Version": "2012-10-17",
"Statement": [
{
"Sid": "Stmt15681834712546",
"Action": [
"s3:PutObject"
],
"Effect": "Allow",
"Resource": "arn:aws:s3:::buketname/*",
"Principal": {
"AWS": [
"arn:aws:iam::98754131531:user/Joe"
]
}
},{
"Sid": "Stmt15681834478323",
"Action": [
"s3:PutObject"
],
"Effect": "Deny",
"Resource": "arn:aws:s3:::buketname/*",
"Principal": "*"
},
]
}
但是,它似乎无法正常工作。
【问题讨论】:
标签: amazon-web-services amazon-s3 amazon-iam