本文属于机器翻译版本。若本译文内容与英语原文存在差异,则一律以英文原文为准。
AmazonElasticFileSystemServiceRolePolicy
描述:允许 Amazon Elastic File System 代表您管理 AWS 资源
AmazonElasticFileSystemServiceRolePolicy
是一项 AWS 托管式策略。
使用此策略
此附加到服务相关角色的策略允许服务代表您执行操作。您无法将此策略附加到您的用户、组或角色。
策略详细信息
-
类型:服务相关角色策略
-
创作时间:2019 年 11 月 5 日 16:52 UTC
-
编辑时间:2024 年 11 月 7 日 19:19 UTC
-
ARN:
arn:aws:iam::aws:policy/aws-service-role/AmazonElasticFileSystemServiceRolePolicy
策略版本
策略版本:v5 (默认值)
此策略的默认版本是定义策略权限的版本。当使用该策略的用户或角色请求访问 AWS 资源时, AWS 会检查策略的默认版本以确定是否允许该请求。
JSON政策文件
{
"Version" : "2012-10-17",
"Statement" : [
{
"Effect" : "Allow",
"Action" : [
"backup-storage:MountCapsule",
"ec2:CreateNetworkInterface",
"ec2:DeleteNetworkInterface",
"ec2:DescribeSecurityGroups",
"ec2:DescribeSubnets",
"ec2:DescribeNetworkInterfaceAttribute",
"ec2:ModifyNetworkInterfaceAttribute",
"tag:GetResources"
],
"Resource" : "*"
},
{
"Effect" : "Allow",
"Action" : [
"kms:DescribeKey"
],
"Resource" : "arn:aws:kms:*:*:key/*"
},
{
"Effect" : "Allow",
"Action" : [
"backup:CreateBackupVault",
"backup:PutBackupVaultAccessPolicy"
],
"Resource" : [
"arn:aws:backup:*:*:backup-vault:aws/efs/automatic-backup-vault"
]
},
{
"Effect" : "Allow",
"Action" : [
"backup:CreateBackupPlan",
"backup:CreateBackupSelection"
],
"Resource" : [
"arn:aws:backup:*:*:backup-plan:*"
]
},
{
"Effect" : "Allow",
"Action" : [
"iam:CreateServiceLinkedRole"
],
"Resource" : "*",
"Condition" : {
"StringEquals" : {
"iam:AWSServiceName" : [
"backup.amazonaws.com"
]
}
}
},
{
"Effect" : "Allow",
"Action" : [
"iam:PassRole"
],
"Resource" : [
"arn:aws:iam::*:role/aws-service-role/backup.amazonaws.com/AWSServiceRoleForBackup"
],
"Condition" : {
"StringLike" : {
"iam:PassedToService" : "backup.amazonaws.com"
}
}
},
{
"Effect" : "Allow",
"Action" : [
"elasticfilesystem:DescribeFileSystems",
"elasticfilesystem:CreateReplicationConfiguration",
"elasticfilesystem:DescribeReplicationConfigurations",
"elasticfilesystem:DeleteReplicationConfiguration",
"elasticfilesystem:ReplicationRead",
"elasticfilesystem:ReplicationWrite"
],
"Resource" : "*"
}
]
}