仅限OU范围内共享存储桶

替换<bucket-name>为你自己的存储桶名称。

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "Access-to-specific-ou-only",
            "Effect": "Deny",
            "Principal": "*",
            "Action": "s3:*",
            "Resource": "arn:aws:s3:::<bucket-name>/*",
            "Condition": {
                "StringNotEquals": {
                    "aws:PrincipalOrgID": "<you-org-id>"
                }
            }
        }
    ]
}

最后更新于