View a markdown version of this page

範例 1:使用 aws:ResourceTag 允許串流讀取存取 - Amazon DynamoDB

本文為英文版的機器翻譯版本,如內容有任何歧義或不一致之處,概以英文版為準。

範例 1:使用 aws:ResourceTag 允許串流讀取存取

使用 aws:ResourceTag/tag-key條件金鑰,您可以將 IAM 政策中指定的標籤鍵值對與連接至 DynamoDB 串流的鍵值對進行比較。例如,如果標籤條件相符,您可以允許串流GetRecords操作。

使用 AWS CLI

  1. 建立已啟用串流的資料表並新增標籤。

    aws dynamodb create-table \ --table-name myMusicTable \ --attribute-definitions AttributeName=id,AttributeType=S \ --key-schema AttributeName=id,KeyType=HASH \ --provisioned-throughput ReadCapacityUnits=5,WriteCapacityUnits=5 \ --stream-specification StreamEnabled=true,StreamViewType=NEW_AND_OLD_IMAGES \ --region us-east-1
  2. 將標籤新增至串流。首先,從資料表描述取得串流 ARN。

    STREAM_ARN=$(aws dynamodb describe-table \ --table-name myMusicTable \ --query "Table.LatestStreamArn" \ --output text \ --region us-east-1) aws dynamodb tag-resource \ --resource-arn $STREAM_ARN \ --tags Key=Team,Value=Analytics \ --region us-east-1
  3. 建立內嵌政策並將其新增至角色,如下列範例所示。

    { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "dynamodb:DescribeStream", "dynamodb:GetRecords" ], "Resource": "arn:aws:dynamodb:*:*:table/*/stream/*", "Condition": { "StringEquals": { "aws:ResourceTag/Team": "Analytics" } } } ] }

    當串流的標籤符合政策中指定的金鑰 "Team" 和值 "Analytics" 時,此政策允許 DescribeStream和 GetRecords操作。

  4. 使用步驟 3 中所述的政策來擔任角色。

  5. 在串流上使用 describe-stream AWS CLI 命令。

    aws dynamodb describe-stream \ --stream-arn $STREAM_ARN \ --region us-east-1

使用和不使用 Streams ABAC 的行為

沒有 Streams ABAC

如果您的 未啟用 Streams ABAC AWS 帳戶,則 IAM 政策和 DynamoDB 串流中的標籤條件不相符。DescribeStream 動作會傳回 ,AccessDeniedException因為沒有任何政策允許動作沒有相符的標籤條件。

使用 Streams ABAC

如果您的 已啟用 Streams ABAC AWS 帳戶,則DescribeStream動作會成功完成。這是因為內嵌政策允許在 IAM 政策和串流中的標籤條件相符時執行 動作。