I have a policy:
{ "Version": "2012-10-17", "Statement": [ { "Sid": "Stmt1429817158000", "Effect": "Allow", "Action": [ "ec2:*" ], "Resource": [ "arn:aws:ec2:*" ] } ] }
This is tied to a group. This group has one user. When I enter myloginthing.signin.aws.amazon.com with these user credentials, I cannot do anything with EC2. This gives me messages such as "You are not authorized to describe Running Instances" for each activity on the page.
The IAM policy simulator tells me that any action is rejected because
Implicitly rejected (no matching claims found).
What am I missing?
It really took some time to understand.
, ( , ec2:*) ( arn:aws:ec2:*).
ec2:*
arn:aws:ec2:*
, - , RunInstances, DescribeInstances *.
(: , a) , b) , , .
ec2:* , "arn:aws:ec2:*" Amazon.
"arn:aws:ec2:*"
"arn:aws:ec2:*" "arn:aws:ec2:::*" "*" .
"arn:aws:ec2:::*"
"*"
. Amazon (ARN) AWS
Source: https://habr.com/ru/post/1584370/More articles:Как добавить другой EditText, когда я нажимаю и заполняю другой (Android) - javahttps://translate.googleusercontent.com/translate_c?depth=1&pto=aue&rurl=translate.google.com&sl=ru&sp=nmt4&tl=en&u=https://fooobar.com/questions/1584366/use-pythonpandas-to-match-sample-pairs-yearly-data&usg=ALkJrhg7d5JFdrJzOnFa2C4lS4F3t757RgIs Shiro DefaultPasswordService thread safe? - javaPandas: how to compile annual data on top of each other - pythonRuby Perl Translation - Modules Versus Classes - ruby | fooobar.comEsentVersionStoreOutOfMemoryAndCleanupTimedOutException when creating a new TFS 2013 build machine - tfsHow to create a tree table using AJAX that load 1 level at a time? - jqueryHow to use CriteriaQuery for ElementCollection and CollectionTable - javaWhat is the easiest way to turn a known-length list into nested pairs in Haskell? - listЗначки JWT всегда должны отправляться через заголовок авторизации - jwtAll Articles