- 规则如下:
存储桶策略,授权其它账户的某个 iam 资源访问此存储桶
arn:aws:iam::<aws_account_id>:<type>/<name>
- 示例配置如下:
{
"Version": "2012-10-17",
"Id": "Policy1564021125924",
"Statement": [
{
"Sid": "object1",
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::<account-id>:role/<role-name>"
},
"Action": [
"s3:Get*",
"s3:List*"
],
"Resource": "arn:aws:s3:::<open-bucket>/<open-path>/*"
}
]
}