> For the complete documentation index, see [llms.txt](https://aws-gcr-wwso-security.gitbook.io/an-quan-zui-jia-shi-jian/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://aws-gcr-wwso-security.gitbook.io/an-quan-zui-jia-shi-jian/1.-iam-shen-fen-shi-bie-yu-fang-wen-kong-zhi/data-perimeters-shu-ju-fang-hu-bian-jie/vpc-duan-dian-ce-le-vpc-endpoint-policies-shi-li-ce-le/vpce-he-di-san-fang-zi-yuan.md).

# VPCE和第三方资源

允许VPCE访问第三方的资源则可以添加以下策略：

```
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "AllowRequestsByThirdPartyIdentitiesToThirdPartyResources",
            "Effect": "Allow",
            "Principal": {
                "AWS": "*"
            },
            "Action": "<action>",        
            "Resource": "<third-party-resource-arn>",
            "Condition": {
                "StringEquals": {
                    "aws:PrincipalAccount": [
                        "<third-party-account-a>",
                        "<third-party-account-b>"
                    ],
                    "aws:ResourceAccount": [
                        "<third-party-account-a>",
                        "<third-party-account-b>"
                    ]
                }
            }
        },
        {
            "Sid": "AllowRequestsByOrgsIdentitiesToThirdPartyResources",
            "Effect": "Allow",
            "Principal": {
                "AWS": "*"
            },
            "Action": "<action>",           
            "Resource": "<third-party-resource-arn>",
            "Condition": {
                "StringEquals": {
                    "aws:PrincipalOrgID": "<my-org-id>",
                    "aws:ResourceAccount": [
                        "<third-party-account-a>",
                        "<third-party-account-b>"
                    ]
                }
            }
        }
    ]
}
```
