> For the complete documentation index, see [llms.txt](https://aws-gcr-wwso-security.gitbook.io/an-quan-zui-jia-shi-jian/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://aws-gcr-wwso-security.gitbook.io/an-quan-zui-jia-shi-jian/1.-iam-shen-fen-shi-bie-yu-fang-wen-kong-zhi/xin-shou-qi-bu/ru-he-xie-condition/yun-xu-aws-fu-wu-fang-wen-awsprincipalisawsservice.md).

# 允许AWS服务访问 aws:PrincipalIsAWSService

`aws:PrincipalIsAWSService: null` 这种情况会在AWS IAM策略评估期间出现，表示请求的发出者**不是**一个AWS服务。 换句话说，请求并非来自AWS内部的服务，而是来自外部的实体，例如：

* **IAM用户:** 直接登录AWS控制台或使用AWS CLI的用户。
* **IAM角色:** 由IAM用户或其他AWS服务所承担的角色。
* **Federated用户:** 通过诸如SAML或OIDC之类的联合身份提供商进行身份验证的用户。

#### Bool in an <mark style="color:green;">Allow</mark> Statement

<table data-header-hidden data-full-width="true"><thead><tr><th width="295"></th><th></th><th></th></tr></thead><tbody><tr><td>Policy Condition</td><td>Request Context</td><td>Result</td></tr><tr><td><pre data-overflow="wrap"><code>"Bool": {
  "aws:PrincipalIsAWSService": "true"
}
</code></pre></td><td><code>aws:PrincipalIsAWSService: null</code></td><td><img src="https://iam.cloudcopilot.io/_astro/unknown.4jslFilM_ZFyvUV.svg" alt="Not Allowed"> Not AllowedStatement does not apply</td></tr><tr><td><pre data-overflow="wrap"><code>"Bool": {
  "aws:PrincipalIsAWSService": "true"
}
</code></pre></td><td><code>aws:PrincipalIsAWSService: true</code></td><td><img src="https://iam.cloudcopilot.io/_astro/allow.BKwnWDMp_Z2m9B7U.svg" alt="Allowed"> AllowedAssuming no explicit Deny elsewhere</td></tr><tr><td><pre data-overflow="wrap"><code>"Bool": {
  "aws:PrincipalIsAWSService": "true"
}
</code></pre></td><td><code>aws:PrincipalIsAWSService: false</code></td><td><img src="https://iam.cloudcopilot.io/_astro/unknown.4jslFilM_ZFyvUV.svg" alt="Not Allowed"> Not AllowedStatement does not apply</td></tr></tbody></table>

BoolIfExists in an <mark style="color:green;">Allow</mark> Statement

<table data-header-hidden><thead><tr><th></th><th></th><th></th></tr></thead><tbody><tr><td>Policy Condition</td><td>Request Context</td><td>Result</td></tr><tr><td><pre data-overflow="wrap"><code>"BoolIfExists": {
  "aws:PrincipalIsAWSService": "true"
}
</code></pre></td><td><code>aws:PrincipalIsAWSService: null</code></td><td><img src="https://iam.cloudcopilot.io/_astro/allow.BKwnWDMp_Z2m9B7U.svg" alt="Allowed"> AllowedAssuming no explicit Deny elsewhere</td></tr><tr><td><pre data-overflow="wrap"><code>"BoolIfExists": {
  "aws:PrincipalIsAWSService": "true"
}
</code></pre></td><td><code>aws:PrincipalIsAWSService: true</code></td><td><img src="https://iam.cloudcopilot.io/_astro/allow.BKwnWDMp_Z2m9B7U.svg" alt="Allowed"> AllowedAssuming no explicit Deny elsewhere</td></tr><tr><td><pre data-overflow="wrap"><code>"BoolIfExists": {
  "aws:PrincipalIsAWSService": "true"
}
</code></pre></td><td><code>aws:PrincipalIsAWSService: false</code></td><td><img src="https://iam.cloudcopilot.io/_astro/unknown.4jslFilM_ZFyvUV.svg" alt="Not Allowed"> Not AllowedStatement does not apply</td></tr></tbody></table>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://aws-gcr-wwso-security.gitbook.io/an-quan-zui-jia-shi-jian/1.-iam-shen-fen-shi-bie-yu-fang-wen-kong-zhi/xin-shou-qi-bu/ru-he-xie-condition/yun-xu-aws-fu-wu-fang-wen-awsprincipalisawsservice.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `automate deployments from our CI pipeline` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
