本文属于机器翻译版本。若本译文内容与英语原文存在差异,则一律以英文原文为准。
AwsGlueSessionUserRestrictedPolicy
描述:提供允许用户仅创建和使用与用户关联的交互式会话的权限。此策略还包括明确允许用户传递受限 Glue 会话角色的权限。
AwsGlueSessionUserRestrictedPolicy
是一项 AWS 托管式策略。
使用此策略
您可以将 AwsGlueSessionUserRestrictedPolicy
附加到您的用户、组和角色。
策略详细信息
-
类型: AWS 托管策略
-
创建时间:2022 年 4 月 14 日 21:31 UTC
-
编辑时间:2024 年 8 月 5 日 23:06 UTC
-
ARN:
arn:aws:iam::aws:policy/AwsGlueSessionUserRestrictedPolicy
策略版本
策略版本:v3 (默认值)
此策略的默认版本是定义策略权限的版本。当使用该策略的用户或角色请求访问 AWS 资源时, AWS 会检查策略的默认版本以确定是否允许该请求。
JSON 策略文档
{
"Version" : "2012-10-17",
"Statement" : [
{
"Sid" : "AllowSessionActions",
"Effect" : "Allow",
"Action" : [
"glue:CreateSession"
],
"Resource" : [
"arn:aws:glue:*:*:session/*"
],
"Condition" : {
"StringEquals" : {
"aws:RequestTag/owner" : "${aws:userid}"
},
"ForAnyValue:StringEquals" : {
"aws:TagKeys" : [
"owner"
]
}
}
},
{
"Sid" : "AllowGlueTaggingAction",
"Effect" : "Allow",
"Action" : [
"glue:TagResource"
],
"Resource" : "arn:aws:glue:*:*:session/*",
"Condition" : {
"StringEquals" : {
"aws:ResourceTag/owner" : "${aws:userid}",
"aws:RequestTag/owner" : "${aws:userid}"
}
}
},
{
"Sid" : "AllowCompletionActions",
"Effect" : "Allow",
"Action" : [
"glue:StartCompletion",
"glue:GetCompletion"
],
"Resource" : [
"arn:aws:glue:*:*:completion/*"
]
},
{
"Sid" : "AllowGlueActions",
"Effect" : "Allow",
"Action" : [
"glue:RunStatement",
"glue:GetStatement",
"glue:ListStatements",
"glue:CancelStatement",
"glue:StopSession",
"glue:DeleteSession",
"glue:GetSession"
],
"Resource" : [
"arn:aws:glue:*:*:session/*"
],
"Condition" : {
"StringEquals" : {
"aws:ResourceTag/owner" : "${aws:userid}"
}
}
},
{
"Sid" : "AllowListSessions",
"Effect" : "Allow",
"Action" : [
"glue:ListSessions"
],
"Resource" : [
"*"
]
},
{
"Sid" : "DenyTagActions",
"Effect" : "Deny",
"Action" : [
"glue:UntagResource",
"tag:TagResources",
"tag:UntagResources"
],
"Resource" : [
"arn:aws:glue:*:*:session/*"
],
"Condition" : {
"ForAnyValue:StringEquals" : {
"aws:TagKeys" : [
"owner"
]
}
}
},
{
"Sid" : "AllowPassRoleActions",
"Effect" : "Allow",
"Action" : [
"iam:PassRole"
],
"Resource" : [
"arn:aws:iam::*:role/service-role/AwsGlueSessionServiceRoleUserRestricted*"
],
"Condition" : {
"StringLike" : {
"iam:PassedToService" : [
"glue.amazonaws.com"
]
}
}
}
]
}