本文為英文版的機器翻譯版本,如內容有任何歧義或不一致之處,概以英文版為準。
範例 1:使用 aws:ResourceTag 允許串流讀取存取
使用 aws:ResourceTag/tag-key條件金鑰,您可以將 IAM 政策中指定的標籤鍵值對與連接至 DynamoDB 串流的鍵值對進行比較。例如,如果標籤條件相符,您可以允許串流GetRecords操作。
使用 AWS CLI
-
建立已啟用串流的資料表並新增標籤。
aws dynamodb create-table \ --table-name myMusicTable \ --attribute-definitions AttributeName=id,AttributeType=S \ --key-schema AttributeName=id,KeyType=HASH \ --provisioned-throughput ReadCapacityUnits=5,WriteCapacityUnits=5 \ --stream-specification StreamEnabled=true,StreamViewType=NEW_AND_OLD_IMAGES \ --region us-east-1 -
將標籤新增至串流。首先,從資料表描述取得串流 ARN。
STREAM_ARN=$(aws dynamodb describe-table \ --table-name myMusicTable \ --query "Table.LatestStreamArn" \ --output text \ --region us-east-1) aws dynamodb tag-resource \ --resource-arn $STREAM_ARN \ --tags Key=Team,Value=Analytics \ --region us-east-1 -
建立內嵌政策並將其新增至角色,如下列範例所示。
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "dynamodb:DescribeStream", "dynamodb:GetRecords" ], "Resource": "arn:aws:dynamodb:*:*:table/*/stream/*", "Condition": { "StringEquals": { "aws:ResourceTag/Team": "Analytics" } } } ] }當串流的標籤符合政策中指定的金鑰 "Team" 和值 "Analytics" 時,此政策允許
DescribeStream和GetRecords操作。 -
使用步驟 3 中所述的政策來擔任角色。
-
在串流上使用
describe-streamAWS CLI 命令。aws dynamodb describe-stream \ --stream-arn $STREAM_ARN \ --region us-east-1
使用和不使用 Streams ABAC 的行為
- 沒有 Streams ABAC
-
如果您的 未啟用 Streams ABAC AWS 帳戶,則 IAM 政策和 DynamoDB 串流中的標籤條件不相符。
DescribeStream動作會傳回 ,AccessDeniedException因為沒有任何政策允許動作沒有相符的標籤條件。 - 使用 Streams ABAC
-
如果您的 已啟用 Streams ABAC AWS 帳戶,則
DescribeStream動作會成功完成。這是因為內嵌政策允許在 IAM 政策和串流中的標籤條件相符時執行 動作。