我得到了以下错误。
IAM资源路径必须为"*“或以user/、联合用户/、角色/、组/、实例配置文件/、mfa/、服务器证书/、策略/、sms-mfa/、saml-provider/、oidc-provider/、report/、access-report/开头。
请帮帮我。
这是我的代码。
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"ssm:StartSession"
],
"Resource": [
"arn:aws:iam::197709948620:instance/*"
],
"Condition": {
"StringLike": {
"ssm:resourceTag/Finance": [
"Web Server"
]
}
}
},
{
"Effect": "Allow",
"Action": [
"ssm:TerminateSession"
],
"Resource": [
"arn:aws:ssm:*:*:session/${aws:username}-*"
]
}
]
}发布于 2021-02-13 15:43:57
以下资源不正确:
arn:aws:iam::197709948620:instance/*instance是ec2,不是iam。它应该是:
arn:aws:ec2::197709948620:instance/*https://stackoverflow.com/questions/66182818
复制相似问题