本文為英文版的機器翻譯版本,如內容有任何歧義或不一致之處,概以英文版為準。
AWS-SSM-Automation-DiagnosisBucketPolicy
描述:提供存取 SSM 診斷 S3 儲存貯體的許可,以診斷和修復問題。
AWS-SSM-Automation-DiagnosisBucketPolicy
是AWS 受管政策。
使用此政策
您可以AWS-SSM-Automation-DiagnosisBucketPolicy
連接至使用者、群組和角色。
政策詳細資訊
-
類型: AWS 受管政策
-
建立時間:2024 年 11 月 15 日 23:31 UTC
-
編輯時間:2024 年 11 月 15 日 23:31 UTC
-
ARN:
arn:aws:iam::aws:policy/AWS-SSM-Automation-DiagnosisBucketPolicy
政策版本
政策版本:v1 (預設值)
政策的預設版本是定義政策許可的版本。當具有 政策的使用者或角色提出存取 AWS 資源的請求時, 會 AWS 檢查政策的預設版本,以決定是否允許請求。
JSON 政策文件
{
"Version" : "2012-10-17",
"Statement" : [
{
"Sid" : "AllowReadWriteToSsmDiagnosisBucketInSameAccount",
"Effect" : "Allow",
"Action" : [
"s3:PutObject",
"s3:GetObject",
"s3:DeleteObject"
],
"Resource" : "arn:aws:s3:::do-not-delete-ssm-diagnosis-*/actions/*/${aws:PrincipalAccount}/*",
"Condition" : {
"StringEquals" : {
"aws:ResourceAccount" : "${aws:PrincipalAccount}"
}
}
},
{
"Sid" : "AllowReadWriteToSsmDiagnosisBucketWithinOrg",
"Effect" : "Allow",
"Action" : [
"s3:PutObject",
"s3:GetObject",
"s3:DeleteObject"
],
"Resource" : "arn:aws:s3:::do-not-delete-ssm-diagnosis-*/actions/*/${aws:PrincipalAccount}/*",
"Condition" : {
"StringEquals" : {
"aws:ResourceOrgId" : "${aws:PrincipalOrgId}"
}
}
},
{
"Sid" : "AllowReadOnlyAccessListBucketOnSsmDiagnosisBucketInSameAccount",
"Effect" : "Allow",
"Action" : [
"s3:ListBucket"
],
"Resource" : "arn:aws:s3:::do-not-delete-ssm-diagnosis-*",
"Condition" : {
"StringEquals" : {
"aws:ResourceAccount" : "${aws:PrincipalAccount}"
},
"StringLike" : {
"s3:prefix" : "*/${aws:PrincipalAccount}/*"
}
}
},
{
"Sid" : "AllowReadOnlyAccessListBucketOnSsmDiagnosisBucketWithinOrg",
"Effect" : "Allow",
"Action" : [
"s3:ListBucket"
],
"Resource" : "arn:aws:s3:::do-not-delete-ssm-diagnosis-*",
"Condition" : {
"StringEquals" : {
"aws:ResourceOrgId" : "${aws:PrincipalOrgId}"
},
"StringLike" : {
"s3:prefix" : "*/${aws:PrincipalAccount}/*"
}
}
},
{
"Sid" : "AllowGetEncryptionConfigurationOnSsmDiagnosisBucketInSameAccount",
"Effect" : "Allow",
"Action" : [
"s3:GetEncryptionConfiguration"
],
"Resource" : "arn:aws:s3:::do-not-delete-ssm-diagnosis-*",
"Condition" : {
"StringEquals" : {
"aws:ResourceAccount" : "${aws:PrincipalAccount}"
}
}
},
{
"Sid" : "AllowGetEncryptionConfigurationOnSsmDiagnosisBucketWithinOrg",
"Effect" : "Allow",
"Action" : [
"s3:GetEncryptionConfiguration"
],
"Resource" : "arn:aws:s3:::do-not-delete-ssm-diagnosis-*",
"Condition" : {
"StringEquals" : {
"aws:ResourceOrgId" : "${aws:PrincipalOrgId}"
}
}
}
]
}