View a markdown version of this page

Condition-key contoh-contoh kebijakan berdasarkan AWS Proton - AWS Proton

Pemberitahuan akhir dukungan: Pada 7 Oktober 2026, dukungan AWS akan berakhir untuk AWS Proton. Setelah 7 Oktober 2026, Anda tidak akan lagi dapat mengakses AWS Proton konsol atau AWS Proton sumber daya. Infrastruktur yang Anda gunakan akan tetap utuh. Untuk informasi selengkapnya, lihat Panduan AWS Proton Penghentian Layanan dan Migrasi.

Terjemahan disediakan oleh mesin penerjemah. Jika konten terjemahan yang diberikan bertentangan dengan versi bahasa Inggris aslinya, utamakan versi bahasa Inggris.

Condition-key contoh-contoh kebijakan berdasarkan AWS Proton

Contoh kebijakan IAM berikut menolak akses ke AWS Proton tindakan yang cocok dengan templat yang ditentukan dalam Condition blok. Perhatikan bahwa kunci kondisi ini hanya didukung oleh tindakan yang tercantum di T indakan, sumber daya, dan kunci kondisi untuk AWS Proton. Untuk mengelola izin pada tindakan lain, sepertiDeleteEnvironmentTemplate, Anda harus menggunakan kontrol Resource-level akses.

Contoh kebijakan yang menolak tindakan AWS Proton template pada template tertentu:

JSON
{ "Version":"2012-10-17", "Statement": [ { "Effect": "Deny", "Action": ["proton:*"], "Resource": "*", "Condition": { "StringEqualsIfExists": { "proton:EnvironmentTemplate": ["arn:aws:proton:region_id:123456789012:environment-template/my-environment-template"] } } }, { "Effect": "Deny", "Action": ["proton:*"], "Resource": "*", "Condition": { "StringEqualsIfExists": { "proton:ServiceTemplate": ["arn:aws:proton:region_id:123456789012:service-template/my-service-template"] } } } ] }

Dalam kebijakan contoh berikutnya, Resource-level pernyataan pertama menolak akses ke tindakan AWS Proton template, selainListServiceTemplates, yang cocok dengan template layanan yang tercantum dalam Resource blok. Pernyataan kedua menolak akses ke AWS Proton tindakan yang cocok dengan template yang tercantum dalam Condition blok.

Contoh kebijakan yang menolak AWS Proton tindakan yang cocok dengan template tertentu:

JSON
{ "Version":"2012-10-17", "Statement": [ { "Effect": "Deny", "Action": [ "proton:*" ], "Resource": "arn:aws:proton:us-east-1:123456789012:service-template/my-service-template" }, { "Effect": "Deny", "Action": [ "proton:*" ], "Resource": "*", "Condition": { "StringEqualsIfExists": { "proton:ServiceTemplate": [ "arn:aws:proton:us-east-1:123456789012:service-template/my-service-template" ] } } } ] }

Contoh kebijakan terakhir memungkinkan AWS Proton tindakan pengembang yang cocok dengan template layanan tertentu yang tercantum dalam Condition blok.

Contoh kebijakan untuk mengiz AWS Proton inkan tindakan pengembang yang cocok dengan template tertentu:

JSON
{ "Version":"2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "proton:ListServiceTemplates", "proton:ListServiceTemplateVersions", "proton:ListServices", "proton:ListServiceInstances", "proton:ListEnvironments", "proton:GetServiceTemplate", "proton:GetServiceTemplateVersion", "proton:GetService", "proton:GetServiceInstance", "proton:GetEnvironment", "proton:CreateService", "proton:UpdateService", "proton:UpdateServiceInstance", "proton:UpdateServicePipeline", "proton:DeleteService", "codestar-connections:ListConnections" ], "Resource": "*", "Condition": { "StringEqualsIfExists": { "proton:ServiceTemplate": "arn:aws:proton:region_id:123456789012:service-template/my-service-template" } } }, { "Effect": "Allow", "Action": [ "codestar-connections:PassConnection" ], "Resource": "arn:aws:codestar-connections:*:*:connection/*", "Condition": { "StringEquals": { "codestar-connections:PassedToService": "proton.amazonaws.com" } } } ] }