组织级别共享S3存储桶
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allowcloudtrairead",
"Principal": {
"Service": "cloudtrail.amazonaws.com"
},
"Action": "s3:Get*",
"Resource": "arn:aws:s3:::BUCKETNAME",
"Condition": {
"StringEquals": {
"aws:SourceOrgID": "o-organizationID"
}
}
},
{
"Sid": "allowcloudtraiwrite",
"Effect": "Allow",
"Principal": {
"Service": "cloudtrail.amazonaws.com"
},
"Action": "s3:Put*",
"Resource": "arn:aws:s3:::BUCKETNAME/*",
"Condition": {
"StringEquals": {
"aws:SourceOrgID": "o-organizationID"
}
}
}
]
}最后更新于