DOCS InstallGet StartedUser GuideRelease Notes

How To Grant Access To Only One S3 Bucket Using AWS IAM Policy

This guide gives an overview on how to restrict an IAM user's access to a single S3 bucket.

Open the IAM console, select "Policies" under "Access management", and click "Create policy".
IAM // ACCESS MANAGEMENTUSER GROUPSUSERSROLESPOLICIESCREATE POLICY
In the policy editor, select the "JSON" tab.
CREATE POLICY // POLICY EDITORVISUALJSON{"Version": "2012-10-17","Statement": [ ... ]}
Paste the policy below, replacing <your bucket> with your bucket name.

Note: The "s3:ListAllMyBuckets" is used to list all buckets owned by you, so that tools that list buckets will work.
The "s3:GetBucketLocation" is needed so that ObjectiveFS can select the right S3 endpoint to talk with.

Example policy:

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": [
                        "s3:GetBucketLocation",
                        "s3:ListAllMyBuckets"
                      ],
            "Resource": "arn:aws:s3:::*"
        },
        {
            "Effect": "Allow",
            "Action": "s3:*",
            "Resource": [
                "arn:aws:s3:::<your bucket>",
                "arn:aws:s3:::<your bucket>/*"
            ]
        }
    ]
}
Click "Next", enter a policy name, e.g. single-bucket-access, and click "Create policy".
CREATE POLICY // REVIEW AND CREATEPOLICY NAMEsingle-bucket-accessDESCRIPTIONOne S3 bucket + bucket listCREATE POLICY
Attach the policy to your IAM user: select "Users", choose your user, and on the "Permissions" tab click "Add permissions". Choose "Attach policies directly", select your new policy, and confirm with "Add permissions".
IAM // USER: OBJECTIVEFS · ADD PERMISSIONSADD USER TO GROUPATTACH POLICIES DIRECTLYsingle-bucket-accessCUSTOMER MANAGEDADD PERMISSIONS

Note: To grant the same access to several users, attach the policy to a user group instead and add the users to the group.

You can now use your "Access Key ID" and "Secret Access Key" to run ObjectiveFS restricted to a single bucket.

Last updated ObjectiveFS staff

ObjectiveFS is a shared file system for macOS and Linux that automatically scales and gives you scalable cloud storage. If you have questions or article idea suggestions, please email us at support@objectivefs.com