标记Amazon S3
1-给S3存储桶打标签
2-给授予权限的身份打标签
3-授予真人访问权限:编辑权限集的策略
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "ABACHuman",
"Effect": "Deny",
"Action": [
"s3:Get*",
"s3:Put*",
"s3:Delete*"
],
"Resource": "arn:aws:s3:::BUCKET-NAME/human-objects/*",
"Condition": {
"StringNotEquals": {
"aws:PrincipalTag/department": "${s3:ExistingObjectTag/department}"
}
}
}
]
}最后更新于