Amazon Web Services Bootcamp
上QQ阅读APP看书,第一时间看更新

Adding a group policy – Inline

Add an inline policy under the group. If the same policy name is available under the group, it will update it:

    aws iam put-group-policy ^
    --group-name "Developer" ^
    --policy-name "S3FullAccessOnMyBucket2" ^
    --policy-document file://NewPolicyDocument.json  

The following is the policy document used to create the inline group policy NewPolicyDocument.json:

{ 
  "Version": "2012-10-17", 
  "Statement": [{ 
    "Effect": "Allow", 
    "Action": [ 
      "s3:*" 
    ], 
    "Resource": "arn:aws:s3:::my-bucket-2" 
  }] 
}

The following are the options, which can be used with put-group-policy:

Parameters

Optional

Descriptions

--group-name

False

This is the name of the group

--policy-name

False

This is the name of the policy that needs to be created

--policy-document

False

This is the policy JSON document that defines permissions to AWS services