如何为Amazon EC2 Ubuntu实例创建仅访问project_1目录的IAM用户?
/var/www/html/project_1 on an Ubuntu EC2 Instance via SSH/SFTP Hey there, let's break this down clearly—first, a key clarification: IAM users manage access to AWS services, not directly file system permissions on your EC2 instance. To get the setup you want (a developer who can only access /var/www/html/project_1 via SSH/SFTP), we'll need to create a dedicated system user on your Ubuntu instance, lock them into that directory with a chroot jail, and optionally link this system user to an IAM user if you prefer IAM-based authentication.
Step 1: Create a dedicated system user for the developer
First, make a system user (we'll name them dev_project1) and tie their home directory to your project folder. We'll temporarily disable their shell to prevent full SSH access until we lock down permissions:
sudo useradd -d /var/www/html/project_1 -s /usr/sbin/nologin dev_project1 sudo passwd dev_project1 # Skip this if you'll use SSH keys instead of password-based SFTP
Step 2: Set secure permissions for the project directory
Chroot requires strict permissions to work safely: the root directory of the jail must be owned by root and not writable by the user. Run these commands:
sudo chown root:root /var/www/html/project_1 sudo chmod 755 /var/www/html/project_1
Then, give the developer write access to files inside the folder. If you have existing project files, adjust their ownership; otherwise, create a writable subdirectory:
# Create a writable workspace for the developer sudo mkdir -p /var/www/html/project_1/workspace sudo chown dev_project1:dev_project1 /var/www/html/project_1/workspace sudo chmod 775 /var/www/html/project_1/workspace # If you have existing files in project_1, run this to let the dev edit them sudo chown -R dev_project1:dev_project1 /var/www/html/project_1/*
Step 3: Configure SSH/SFTP to enforce the chroot jail
Edit the SSH daemon config to lock the user into the project folder:
sudo nano /etc/ssh/sshd_config
Add these lines at the bottom of the file:
Match User dev_project1 ForceCommand internal-sftp ChrootDirectory /var/www/html/project_1 PermitTunnel no AllowAgentForwarding no AllowTcpForwarding no X11Forwarding no
Save the file and restart the SSH service to apply changes:
sudo systemctl restart sshd
Step 4: Link to an IAM User (Optional, for IAM-based SSH access)
If you want the developer to use their IAM credentials to connect (instead of a regular SSH key), set up IAM-based SSH authentication:
- Ensure the AWS Systems Manager (SSM) Agent is installed on your EC2 instance (most official Ubuntu AMIs have it pre-installed).
- Attach this IAM policy to your target IAM user (replace
REGION,ACCOUNT_ID, andINSTANCE_IDwith your values):{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "ssm:StartSession", "ssm:TerminateSession", "ssm:DescribeSessions", "ssm:GetConnectionStatus" ], "Resource": [ "arn:aws:ec2:REGION:ACCOUNT_ID:instance/INSTANCE_ID", "arn:aws:ssm:REGION::document/AWS-StartSSHSession" ] } ] } - Update your SSH config to use IAM for authorized keys:
Add these lines:sudo nano /etc/ssh/sshd_configPubkeyAuthentication yes AuthorizedKeysCommand /usr/bin/aws ssm get-parameter --name /ec2/instance/INSTANCE_ID/authorized_keys --query Parameter.Value --output text AuthorizedKeysCommandUser root - Link the IAM user to the
dev_project1system user by storing their public key in SSM:aws ssm put-parameter --name /ec2/instance/INSTANCE_ID/authorized_keys --type String --value "$(ssh-keyscan -t rsa localhost | head -1) $(aws iam get-user --user-name YOUR_IAM_USER --query User.Arn --output text)"
Step 5: Test the connection
- SFTP (FileZilla): Use
dev_project1as the username, either the password you set or the developer's SSH key. They'll land directly in/var/www/html/project_1and won't be able to navigate outside of it. - SSH: If you want to allow limited shell access, change the user's shell to
/bin/bash(runsudo usermod -s /bin/bash dev_project1), then test the connection—they'll be locked into the project folder and can't access other directories.
Critical Notes
- Never make the chroot directory writable by the user—this breaks chroot security.
- If you need the developer to run specific commands via SSH (not just SFTP), replace
ForceCommand internal-sftpwith a command that restricts them to allowed actions (e.g.,ForceCommand /usr/local/bin/allowed-commands.sh). - Always test the setup with a non-privileged account first to confirm restrictions work as expected.
内容的提问来源于stack exchange,提问作者h4kl0rd

