本文属于机器翻译版本。若本译文内容与英语原文存在差异,则一律以英文原文为准。
示例: AppStream 2.0 舰队机器角色跨服务混淆副手预防
例 aws:SourceAccount
条件:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "Service": [ "appstream.amazonaws.com" ] }, "Action": "sts:AssumeRole", "Condition": { "StringEquals": { "aws:SourceAccount": "
your AWS 账户 ID
" } } } ] }
例 aws:SourceArn
条件:
注意
如果您想将一个IAM角色用于多个舰队,我们建议使用带通配符 (*) 的aws:SourceArn
全局上下文条件键来匹配多个 AppStream 2.0 舰队资源。
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "Service": [ "appstream.amazonaws.com" ] }, "Action": "sts:AssumeRole", "Condition": { "ArnLike": { "aws:SourceArn": "arn:{aws partition}:appstream:{
your region name
}:{your AWS 账户 ID
}:fleet/{your fleet name
}" } } } ] }