请参阅以下策略以限制用户仅将对象上传或列出到特定文件夹。我创建了一个策略,允许我仅列出文件夹 1 和文件夹 2 的对象,还允许将对象放入文件夹 1 并拒绝上传到存储桶的其他文件夹。该策略如下: 1.列出存储桶的所有文件夹 2.列出允许文件夹的对象和文件夹 3.仅将文件上传到允许的文件夹
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "AllowUserToSeeBucketListInTheConsole",
"Action": [
"s3:ListAllMyBuckets",
"s3:GetBucketLocation"
],
"Effect": "Allow",
"Resource": [
"arn:aws:s3:::*"
]
},
{
"Sid": "AllowListingOfFolder1And2",
"Action": [
"s3:*"
],
"Effect": "Deny",
"Resource": [
"arn:aws:s3:::bucketname"
],
"Condition": {
"StringNotLike": {
"s3:prefix": [
"folder1/*",
"folder2/*"
]
},
"StringLike": {
"s3:prefix": "*"
}
}
},
{
"Sid": "Allowputobjecttofolder1only",
"Effect": "Deny",
"Action": "s3:PutObject",
"NotResource": "arn:aws:s3:::bucketname/folder1/*"
}
]
}