IAM允许用户访问区域上ec2的所有内容

Arn*_*Roa 4 amazon-ec2 amazon-web-services amazon-iam

我试图允许一个用户对我们 - west-2的所有操作,这是我的政策.

{
   "Version": "2012-10-17",
   "Statement": [{
      "Effect": "Allow",
      "Action": ["ec2:*"],
      "Resource": "arn:aws:ec2:us-west-2:837625274593:*"
    }
   ]
}
Run Code Online (Sandbox Code Playgroud)

我从实例上的"OWNER"参数中获取了帐号,不知道是不是.

Bri*_*ich 14

{
  "Statement": [
    {
      "Sid": "Stmt1375943389569",
      "Action": "ec2:*",
      "Effect": "Allow",
      "Resource": "*",
      "Condition": {
        "StringEquals": {
          "ec2:Region": "us-west-2"
        }
      }
    }
  ]
}
Run Code Online (Sandbox Code Playgroud)

这应该使用户能够仅在us-west-2区域中访问ec2