Slide 19
Slide 19 text
IAM Policy를 좀더 상세하게 작성하기: Resource
{
“Version”: “2012-10-17”,
“Statement”: [
{
“Effect”: “Allow”,
“Action”: [
“dynamodb:BatchGetItem”,
“dynamodb:GetItem”,
“dynamodb:Query”,
],
“Resource”: “*”
}
]
}
{
“Version”: “2012-10-17”,
“Statement”: [
{
“Effect”: “Allow”,
“Action”: [
“dynamodb:BatchGetItem”,
“dynamodb:GetItem”,
“dynamodb:Query”,
],
“Resource”: [
“arn:aws:dynamodb:us-east-1::table/MyTableName”,
“arn:aws:dynamodb:us-east-1::table/MyTableName/index/*”,
]
}
]
}
DynamoDB의 지정된 테이블과
인덱스에 대해서 특정 action만을 허용
ARN (Amazon Resource Name)
형식으로 기술
최소 권한 부여