阿里云RAM权限策略限制指定账号只能访问某个固定的OSS云存储Bucket


在RAM权限策略管理里面新增自定义策略,输入一下内容,记得将“你的Bucket名字”替换成你自己的Bucket名字

然后新建用户后去添加权限,选择自定义策略即可找到。

{
    "Version": "1",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": [
                "oss:ListBuckets",
                "oss:GetBucketStat",
                "oss:GetBucketInfo"
            ],
            "Resource": "acs:oss:*:*:*"
        },
        {
            "Effect": "Allow",
            "Action": [
                "oss:ListObjects",
                "oss:GetBucketAcl",
                "oss:PutBucketAcl"
            ],
            "Resource": "acs:oss:*:*:你的Bucket名字"
        },
        {
            "Effect": "Allow",
            "Action": [
                "oss:ListObjects",
                "oss:GetObject",
                "oss:GetObjectAcl",
                "oss:DeleteObject",
                "oss:DeleteObjectAcl",
                "oss:PutObject",
                "oss:PutObjectAcl"
            ],
            "Resource": "acs:oss:*:*:你的Bucket名字/*"
        }
    ]
}