You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为Amazon EC2 Ubuntu实例创建仅访问project_1目录的IAM用户?

How to Restrict a Developer to Only Access /var/www/html/project_1 on an Ubuntu EC2 Instance via SSH/SFTP

Hey there, let's break this down clearly—first, a key clarification: IAM users manage access to AWS services, not directly file system permissions on your EC2 instance. To get the setup you want (a developer who can only access /var/www/html/project_1 via SSH/SFTP), we'll need to create a dedicated system user on your Ubuntu instance, lock them into that directory with a chroot jail, and optionally link this system user to an IAM user if you prefer IAM-based authentication.

Step 1: Create a dedicated system user for the developer

First, make a system user (we'll name them dev_project1) and tie their home directory to your project folder. We'll temporarily disable their shell to prevent full SSH access until we lock down permissions:

sudo useradd -d /var/www/html/project_1 -s /usr/sbin/nologin dev_project1
sudo passwd dev_project1  # Skip this if you'll use SSH keys instead of password-based SFTP

Step 2: Set secure permissions for the project directory

Chroot requires strict permissions to work safely: the root directory of the jail must be owned by root and not writable by the user. Run these commands:

sudo chown root:root /var/www/html/project_1
sudo chmod 755 /var/www/html/project_1

Then, give the developer write access to files inside the folder. If you have existing project files, adjust their ownership; otherwise, create a writable subdirectory:

# Create a writable workspace for the developer
sudo mkdir -p /var/www/html/project_1/workspace
sudo chown dev_project1:dev_project1 /var/www/html/project_1/workspace
sudo chmod 775 /var/www/html/project_1/workspace

# If you have existing files in project_1, run this to let the dev edit them
sudo chown -R dev_project1:dev_project1 /var/www/html/project_1/*

Step 3: Configure SSH/SFTP to enforce the chroot jail

Edit the SSH daemon config to lock the user into the project folder:

sudo nano /etc/ssh/sshd_config

Add these lines at the bottom of the file:

Match User dev_project1
    ForceCommand internal-sftp
    ChrootDirectory /var/www/html/project_1
    PermitTunnel no
    AllowAgentForwarding no
    AllowTcpForwarding no
    X11Forwarding no

Save the file and restart the SSH service to apply changes:

sudo systemctl restart sshd

If you want the developer to use their IAM credentials to connect (instead of a regular SSH key), set up IAM-based SSH authentication:

  1. Ensure the AWS Systems Manager (SSM) Agent is installed on your EC2 instance (most official Ubuntu AMIs have it pre-installed).
  2. Attach this IAM policy to your target IAM user (replace REGION, ACCOUNT_ID, and INSTANCE_ID with your values):
    {
        "Version": "2012-10-17",
        "Statement": [
            {
                "Effect": "Allow",
                "Action": [
                    "ssm:StartSession",
                    "ssm:TerminateSession",
                    "ssm:DescribeSessions",
                    "ssm:GetConnectionStatus"
                ],
                "Resource": [
                    "arn:aws:ec2:REGION:ACCOUNT_ID:instance/INSTANCE_ID",
                    "arn:aws:ssm:REGION::document/AWS-StartSSHSession"
                ]
            }
        ]
    }
    
  3. Update your SSH config to use IAM for authorized keys:
    sudo nano /etc/ssh/sshd_config
    
    Add these lines:
    PubkeyAuthentication yes
    AuthorizedKeysCommand /usr/bin/aws ssm get-parameter --name /ec2/instance/INSTANCE_ID/authorized_keys --query Parameter.Value --output text
    AuthorizedKeysCommandUser root
    
  4. Link the IAM user to the dev_project1 system user by storing their public key in SSM:
    aws ssm put-parameter --name /ec2/instance/INSTANCE_ID/authorized_keys --type String --value "$(ssh-keyscan -t rsa localhost | head -1) $(aws iam get-user --user-name YOUR_IAM_USER --query User.Arn --output text)"
    

Step 5: Test the connection

  • SFTP (FileZilla): Use dev_project1 as the username, either the password you set or the developer's SSH key. They'll land directly in /var/www/html/project_1 and won't be able to navigate outside of it.
  • SSH: If you want to allow limited shell access, change the user's shell to /bin/bash (run sudo usermod -s /bin/bash dev_project1), then test the connection—they'll be locked into the project folder and can't access other directories.

Critical Notes

  • Never make the chroot directory writable by the user—this breaks chroot security.
  • If you need the developer to run specific commands via SSH (not just SFTP), replace ForceCommand internal-sftp with a command that restricts them to allowed actions (e.g., ForceCommand /usr/local/bin/allowed-commands.sh).
  • Always test the setup with a non-privileged account first to confirm restrictions work as expected.

内容的提问来源于stack exchange,提问作者h4kl0rd

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.13 07:57:31