Dav*_*542 5 amazon-web-services amazon-iam
对于 IAM 策略,假设有两个策略:
例如:
// first document
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "AllowS3ListRead",
"Effect": "Allow",
"Action": ["s3:ListAllMyBuckets"],
"Resource": "*",
"Principal": { "AWS": "arn:aws:iam::12345:group/davidsgroup" }
}
]
}
Run Code Online (Sandbox Code Playgroud)
// second document
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "DenyS3ListRead",
"Effect": "Deny",
"Action": ["s3:ListAllMyBuckets"],
"Resource": "*",
"Principal": { "AWS": "arn:aws:iam::12345:user/david" }
}
]
}
Run Code Online (Sandbox Code Playgroud)
如果存在冲突的语句,如何确定该资源最终是否会被拒绝给用户?例如,是按文档顺序吗?原则的粒度?或者,当存在可能适用于给定用户的多个策略文档时,通常如何确定这一点。
| 归档时间: |
|
| 查看次数: |
459 次 |
| 最近记录: |