How To Grant Access To Only One S3 Bucket Using AWS IAM Policy
This guide gives an overview on how to restrict an IAM user's access to a single S3 bucket.
Open the IAM console, select "Policies" under "Access management", and click "Create policy".
In the policy editor, select the "JSON" tab.
Paste the policy below, replacing <your bucket> with your bucket name.
Note: The "s3:ListAllMyBuckets" is used to list all buckets owned by you, so that tools that list buckets will work.
The "s3:GetBucketLocation" is needed so that ObjectiveFS can select the right S3 endpoint to talk with.
Example policy:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"s3:GetBucketLocation",
"s3:ListAllMyBuckets"
],
"Resource": "arn:aws:s3:::*"
},
{
"Effect": "Allow",
"Action": "s3:*",
"Resource": [
"arn:aws:s3:::<your bucket>",
"arn:aws:s3:::<your bucket>/*"
]
}
]
}
Click "Next", enter a policy name, e.g. single-bucket-access, and click "Create policy".
Attach the policy to your IAM user: select "Users", choose your user, and on the "Permissions" tab click "Add permissions". Choose "Attach policies directly", select your new policy, and confirm with "Add permissions".
Note: To grant the same access to several users, attach the policy to a user group instead and add the users to the group.
You can now use your "Access Key ID" and "Secret Access Key" to run ObjectiveFS restricted to a single bucket.
Useful Links
Last updated ObjectiveFS staff
ObjectiveFS is a shared file system for macOS and Linux that automatically scales and gives you scalable cloud storage. If you have questions or article idea suggestions, please email us at support@objectivefs.com