AWS IoT Core通用设备策略配置疑问:仅访问自身主题及子主题缺什么?
AWS IoT Core通用策略遗漏内容分析
你的当前策略存在两处关键遗漏:
未覆盖设备自身的根主题
原策略中所有主题相关资源都使用/*后缀,仅能匹配${iot:Connection.Thing.ThingName}/xxx这类子主题,但无法匹配设备的根主题(比如示例中的myclient),这会导致设备无法直接发布、接收或订阅自身根主题的消息。Subscribe操作的TopicFilter未包含根主题
原策略里iot:Subscribe的权限仅开放了topicfilter/${iot:Connection.Thing.ThingName}/*,如果设备需要订阅自身根主题,必须补充topicfilter/${iot:Connection.Thing.ThingName}的权限。
修正后的完整策略
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "iot:Connect", "Resource": "arn:aws:iot:eu-central-1:11111111:client/${iot:Connection.Thing.ThingName}" }, { "Effect": "Allow", "Action": "iot:Publish", "Resource": [ "arn:aws:iot:eu-central-1:11111111:topic/${iot:Connection.Thing.ThingName}", "arn:aws:iot:eu-central-1:11111111:topic/${iot:Connection.Thing.ThingName}/*" ] }, { "Effect": "Allow", "Action": "iot:Receive", "Resource": [ "arn:aws:iot:eu-central-1:11111111:topic/${iot:Connection.Thing.ThingName}", "arn:aws:iot:eu-central-1:11111111:topic/${iot:Connection.Thing.ThingName}/*" ] }, { "Effect": "Allow", "Action": "iot:Subscribe", "Resource": [ "arn:aws:iot:eu-central-1:11111111:topicfilter/${iot:Connection.Thing.ThingName}", "arn:aws:iot:eu-central-1:11111111:topicfilter/${iot:Connection.Thing.ThingName}/*" ] } ] }
内容的提问来源于stack exchange,提问作者code123
相关产品推荐
相关产品推荐

