Creating an S3 bucket policy that allows access to Cloudfront but restricts access to anyone else

后端 未结 2 1646
太阳男子
太阳男子 2021-02-01 18:29

I have the following policy:

{
        \"Version\": \"2008-10-17\",
        \"Id\": \"PolicyForCloudFrontPrivateContent\",
        \"Statement\": [
                  


        
2条回答
  •  走了就别回头了
    2021-02-01 18:53

    The S3 policy will look like something like this:

    {
    "Version": "2008-10-17",
    "Id": "PolicyForCloudFrontPrivateContent",
    "Statement": [
        {
            "Sid": "1",
            "Effect": "Allow",
            "Principal": {
                "AWS": "arn:aws:iam::cloudfront:user/CloudFront Origin Access Identity XXXXXXXXXXX"
            },
            "Action": "s3:GetObject",
            "Resource": "arn:aws:s3:::YYYYYYYYYYYYY.com/*"
        }
     ]
    }
    

    But, I didnt manually generate this. When you add an origin (S3) in cloudfront, you have an option to "Restrict Bucket Access" - tell "Yes" here and move forward. Cloudfront configuration will do the rest automatically for you.

    Details here: Using an Origin Access Identity to Restrict Access to Your Amazon S3 Content - Amazon CloudFront.

提交回复
热议问题