<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Storage :: Ay Docs</title>
    <link>https://ops.docs.72602.space/using/storage/index.html</link>
    <description>User Based Policy</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Thu, 14 Mar 2024 15:00:59 +0800</lastBuildDate>
    <atom:link href="https://ops.docs.72602.space/using/storage/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>User Based Policy</title>
      <link>https://ops.docs.72602.space/using/storage/user_based_policy/index.html</link>
      <pubDate>Thu, 14 Mar 2024 15:00:59 +0800</pubDate>
      <guid>https://ops.docs.72602.space/using/storage/user_based_policy/index.html</guid>
      <description>User Based Policy you can change &lt;$bucket&gt; to control the permission&#xA;App: minio oss ${aws:username} is a build-in variable, indicating the logined user name. { &#34;Version&#34;: &#34;2012-10-17&#34;, &#34;Statement&#34;: [ { &#34;Sid&#34;: &#34;AllowUserToSeeBucketListInTheConsole&#34;, &#34;Action&#34;: [ &#34;s3:ListAllMyBuckets&#34;, &#34;s3:GetBucketLocation&#34; ], &#34;Effect&#34;: &#34;Allow&#34;, &#34;Resource&#34;: [ &#34;arn:aws:s3:::*&#34; ] }, { &#34;Sid&#34;: &#34;AllowRootAndHomeListingOfCompanyBucket&#34;, &#34;Action&#34;: [ &#34;s3:ListBucket&#34; ], &#34;Effect&#34;: &#34;Allow&#34;, &#34;Resource&#34;: [ &#34;arn:aws:s3:::&lt;$bucket&gt;&#34; ], &#34;Condition&#34;: { &#34;StringEquals&#34;: { &#34;s3:prefix&#34;: [ &#34;&#34;, &#34;&lt;$path&gt;/&#34;, &#34;&lt;$path&gt;/${aws:username}&#34; ], &#34;s3:delimiter&#34;: [ &#34;/&#34; ] } } }, { &#34;Sid&#34;: &#34;AllowListingOfUserFolder&#34;, &#34;Action&#34;: [ &#34;s3:ListBucket&#34; ], &#34;Effect&#34;: &#34;Allow&#34;, &#34;Resource&#34;: [ &#34;arn:aws:s3:::&lt;$bucket&gt;&#34; ], &#34;Condition&#34;: { &#34;StringLike&#34;: { &#34;s3:prefix&#34;: [ &#34;&lt;$path&gt;/${aws:username}/*&#34; ] } } }, { &#34;Sid&#34;: &#34;AllowAllS3ActionsInUserFolder&#34;, &#34;Effect&#34;: &#34;Allow&#34;, &#34;Action&#34;: [ &#34;s3:*&#34; ], &#34;Resource&#34;: [ &#34;arn:aws:s3:::&lt;$bucket&gt;/&lt;$path&gt;/${aws:username}/*&#34; ] } ] } &lt;$uid&gt; is Aliyun UID { &#34;Version&#34;: &#34;1&#34;, &#34;Statement&#34;: [{ &#34;Effect&#34;: &#34;Allow&#34;, &#34;Action&#34;: [ &#34;oss:*&#34; ], &#34;Principal&#34;: [ &#34;&lt;$uid&gt;&#34; ], &#34;Resource&#34;: [ &#34;acs:oss:*:&lt;$oss_id&gt;:&lt;$bucket&gt;/&lt;$path&gt;/*&#34; ] }, { &#34;Effect&#34;: &#34;Allow&#34;, &#34;Action&#34;: [ &#34;oss:ListObjects&#34;, &#34;oss:GetObject&#34; ], &#34;Principal&#34;: [ &#34;&lt;$uid&gt;&#34; ], &#34;Resource&#34;: [ &#34;acs:oss:*:&lt;$oss_id&gt;:&lt;$bucket&gt;&#34; ], &#34;Condition&#34;: { &#34;StringLike&#34;: { &#34;oss:Prefix&#34;: [ &#34;&lt;$path&gt;/*&#34; ] } } }] } Example: { &#34;Version&#34;: &#34;1&#34;, &#34;Statement&#34;: [{ &#34;Effect&#34;: &#34;Allow&#34;, &#34;Action&#34;: [ &#34;oss:*&#34; ], &#34;Principal&#34;: [ &#34;203415213249511533&#34; ], &#34;Resource&#34;: [ &#34;acs:oss:*:1007296819402486:conti-csst/test/*&#34; ] }, { &#34;Effect&#34;: &#34;Allow&#34;, &#34;Action&#34;: [ &#34;oss:ListObjects&#34;, &#34;oss:GetObject&#34; ], &#34;Principal&#34;: [ &#34;203415213249511533&#34; ], &#34;Resource&#34;: [ &#34;acs:oss:*:1007296819402486:conti-csst&#34; ], &#34;Condition&#34;: { &#34;StringLike&#34;: { &#34;oss:Prefix&#34;: [ &#34;test/*&#34; ] } } }] }</description>
    </item>
  </channel>
</rss>