用於設定和啟動產品的服務連結角色 AWS Marketplace - AWS Marketplace

本文為英文版的機器翻譯版本,如內容有任何歧義或不一致之處,概以英文版為準。

用於設定和啟動產品的服務連結角色 AWS Marketplace

AWS Marketplace 使用名為的服務連結角色AWSServiceRoleForMarketplaceDeployment AWS Marketplace 來允許您管理部署相關參數,這些參數會以密碼形式儲存在中AWS Secrets Manager。賣家可以在 AWS CloudFormation 範本中參考這些密碼,您可以在設定中啟用快速啟動的產品時啟用這些密碼 AWS Marketplace。

AWSServiceRoleForMarketplaceDeployment務連結角色會信任下列服務擔任該角色:

  • deployment.marketplace.amazonaws.com

使用名為AWSMarketplaceDeploymentServiceRolePolicy允許對資源完 AWS Marketplace 成動作的角色權限原則。

注意

如需有關 AWS Marketplace 受管理政策的詳細資訊,請參閱AWS Marketplace 買家的AWS管理政策

{ "Version": "2012-10-17", "Statement": [ { "Sid": "ManageMarketplaceDeploymentSecrets", "Effect": "Allow", "Action": [ "secretsmanager:CreateSecret", "secretsmanager:PutSecretValue", "secretsmanager:DescribeSecret", "secretsmanager:DeleteSecret", "secretsmanager:RemoveRegionsFromReplication" ], "Resource": [ "arn:aws:secretsmanager:*:*:secret:marketplace-deployment*!*" ], "Condition": { "StringEquals": { "aws:ResourceAccount": "${aws:PrincipalAccount}" } } }, { "Sid": "ListSecrets", "Effect": "Allow", "Action": [ "secretsmanager:ListSecrets" ], "Resource": [ "*" ] }, { "Sid": "TagMarketplaceDeploymentSecrets", "Effect": "Allow", "Action": [ "secretsmanager:TagResource" ], "Resource": "arn:aws:secretsmanager:*:*:secret:marketplace-deployment!*", "Condition": { "Null": { "aws:RequestTag/expirationDate": "false" }, "ForAllValues:StringEquals": { "aws:TagKeys": [ "expirationDate" ] }, "StringEquals": { "aws:ResourceAccount": "${aws:PrincipalAccount}" } } } ] }

您必須設定許可,以允許您的使用者、群組或角色建立、編輯或刪除服務連結角色。如需詳細資訊,請參閱IAM使用指南中的服務連結角色權限