AWS CLI SDK IAM

IAM Role Policy

  • Role (์—ญํ• )
    • Policy 1 (์ •์ฑ…)
    • Policy 2
    • Policy 3

ex) MyFirstEC2 ์—ญํ• ์—๋Š” AmazonS3FullAccess ์ •์ฑ…, ๋“ฑ๋“ฑ ์—ฌ๋Ÿฌ๊ฐ€์ง€ ์ •์ฑ…์„ ๊ฐ€์งˆ ์ˆ˜ ์žˆ๋‹ค.

  • Policy

    • AmazonS3ReadOnlyAccess

      {
        "Version": "2012-10-17",
        "Statement": [
          {
            "Effect": "Allow",
            "Action": [
              "s3:Get*",
              "s3:List*"
            ],
            "Resource": "*"
          }
        ]
      }
      
      • Get, List ๋กœ ์‹œ์ž‘ํ•˜๋Š” API๋ฅผ ๋ชจ๋‘ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” ๊ถŒํ•œ ์ •์ฑ…
    • AmazonS3FullAccess

      • {
          "Version": "2012-10-17",
          "Statement": [
            {
              "Effect": "Allow",
              "Action": "s3:*",
              "Resource": "*"
            }
          ]
        }
        
      • S3 ์˜ ๋ชจ๋“  API ๋ฅผ ํ—ˆ์šฉํ•˜๋Š” ์ •์ฑ…

IAM Policy Simulator

์ •์ฑ…์— ๊ด€ํ•œ ์‹œ๋ฎฌ๋ ˆ์ด์…˜์„ ํ•  ์ˆ˜ ์žˆ๋Š” ๊ณต๊ฐ„

์–ด๋–ค ์œ ์ €/๊ทธ๋ฃน/์—ญํ•  ๋งˆ๋‹ค ์—ฐ๊ฒฐ๋œ ์ •์ฑ…(policy) ๋“ค์„ API ๊ฐ€ ์‚ฌ์šฉ๊ฐ€๋Šฅํ•œ์ง€ ์•ˆ๊ฐ€๋Šฅํ•œ์ง€ ํ™•์ธํ•ด๋ณผ ์ˆ˜ ์žˆ๋Š” ๊ณต๊ฐ„์ด๋‹ค.

User, Group, Role ๋งˆ๋‹ค ์—ฌ๋Ÿฌ๊ฐœ์˜ Policy ๋“ค์„ ๊ฐ€์ง€๊ณ  ์žˆ๋‹ค.



  • https://policysim.aws.amazon.com/home/index.jsp

image-20220731215632215

ํƒœ๊ทธ: , , ,

์นดํ…Œ๊ณ ๋ฆฌ:

์—…๋ฐ์ดํŠธ:

๋Œ“๊ธ€๋‚จ๊ธฐ๊ธฐ