Example S3 Bucket Policies
Limiting Access to Specific IP Addresses
{
"Version": "2012-10-17",
"Id": "S3PolicyId1",
"Statement": [
{
"Sid": "IPAllow",
"Effect": "Deny",
"Principal": "*",
"Action": "s3:*",
"Resource": [
"arn:aws:s3:::DOC-EXAMPLE-BUCKET",
"arn:aws:s3:::DOC-EXAMPLE-BUCKET/*"
],
"Condition": {
"NotIpAddress": {"aws:SourceIp": "54.240.143.0/24"}
}
}
]
}Adding a Bucket Policy to Require MFA
Granting Read-Only Permission to an Anonymous User
PreviousTrusts in Active DirectoryNextCross-account access to S3 buckets using Resource-based policies and IAM policies
Last updated