Slide 70
Slide 70 text
"Effect": "Deny",
"Principal": "*",
"Action": "s3:*",
"Resource": [
"arn:aws:s3:::bucket-a",
"arn:aws:s3:::bucket-a/*"
],
"Condition": {
"StringNotEquals": {
"aws:sourceVpce": [
“S3VPCe(I/F型)のID",
“S3VPCe(G/W型)のID"
]
},
"StringNotLike": {
"aws:userId": [
"{ReadOnlyRoleID}:*",
"{CFnRoleID}:*",
"{S3ReplicationRoleID}:*"
]
}
①~⑤のいずれかに一致しない場合
Denyする例。
S3バケットポリシー例 ※色々書き方はあるのでご参考程度に・・・
アカウントA
bucket-a
VPCe (I/F型)
VPCe (G/W型)
Read Only Role
S3
CloudFormation
S3 Replication
①
②
③
④
⑤
①
②
③
④
⑤