天翼云对象存储(经典版)用户管理 | ||||||||||||||||||
产品推荐: 1、安全稳定的云服务器租用,2核/2G/5M仅37元,点击抢购>>>; 2、高防物理服务器20核/16G/50M/500G防御仅350元,点击抢购>>> 3、百度智能建站(五合一网站)仅880元/年,点击抢购>>> 模板建站(PC+手机站)仅480元/年,点击抢购>>> 4、阿里云服务器2核2G3M仅99元/年、2核4G5M仅199元/年,新老同享,点击抢购>>> 5、腾讯云服务器2核2G4M仅99元/年、新老同享,点击抢购>>> 点击这里注册天翼云特邀VIP帐号,立即体验天翼云对象存储>>> 天翼云对象存储(经典版)用户管理 某公司有多个员工需要访问、操作存储资源,由于每个员工的工作职责不同,需要的权限也不同:
目前该公司希望:
创建用户组并关联策略
保密数据组权限策略示例{ "Version": "2012-10-17", "Statement": [ { "Sid": "AllowGroupToSeeBucket", "Action": [ "oos:ListBuckets", "oos:Get*" ], "Effect": "Allow", "Resource": [ "arn:ctyun:oos::10rc2arpn6306:secretBucket", //secretBucket的存储桶资源 "arn:ctyun:oos::10rc2arpn6306:secretBucket/*" //存储桶secretBucket下所有对象 ] } ] } IAM管理组策略示例{ "Version": "2012-10-17", "Statement": [ { "Sid": "AllowGroupToManageIAM", "Effect": "Allow", "Action": "iam:*", "Resource": "*", "Condition": { "Bool": { "ctyun:MultiFactorAuthPresent": "true" } } } ] } 操作跟踪管理组策略示例{ "Version": "2012-10-17", "Statement": [ { "Sid": "AllowGroupToManageTrail", "Effect": "Allow", "Action": "cloudtrail:*", "Resource": "*" }, { "Sid": "AllowGroupToSeeBucket", "Effect": "Allow", "Action": [ "oos:GetObject", "oos:ListBucket" ], "Resource": [ "arn:ctyun:oos::10rc2arpn6306:trailbucket", "arn:ctyun:oos::10rc2arpn6306:trailbucket/*" ] } ] } 查看对象组策略示例{ "Version": "2012-10-17", "Statement": [ { "Sid": "AllowGroupToGetObject", "Effect": "Allow", "Action": "oos:GetObject", "Resource": "arn:ctyun:oos::10rc2arpn6306:appbucket/*" } ] } 上传对象组策略示例{ "Version": "2012-10-17", "Statement": [ { "Sid": "AllowGroupToPutObject", "Effect": "Allow", "Action": "oos:PutObject", "Resource": "arn:ctyun:oos::10rc2arpn6306:appbucket/*" } ] } |