示例:AppStream 2.0 实例集机器角色跨服务混淆代理问题预防 - 亚马逊 AppStream 2.0

本文属于机器翻译版本。若本译文内容与英语原文存在差异,则一律以英文原文为准。

示例:AppStream 2.0 实例集机器角色跨服务混淆代理问题预防

aws:SourceAccount 条件:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "Service": [ "appstream.amazonaws.com" ] }, "Action": "sts:AssumeRole", "Condition": { "StringEquals": { "aws:SourceAccount": "your AWS 账户 ID" } } } ] }
aws:SourceArn 条件:
注意

如果要将一个 IAM 角色用于多个实例集,我们建议使用带通配符(*)的 aws:SourceArn 全局条件上下文键来匹配多个 AppStream 2.0 实例集资源。

{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "Service": [ "appstream.amazonaws.com" ] }, "Action": "sts:AssumeRole", "Condition": { "ArnLike": { "aws:SourceArn": "arn:{aws partition}:appstream:{your region name}:{your AWS 账户 ID}:fleet/{your fleet name}" } } } ] }