You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何配置策略实现Lightsail实例访问受限S3桶?咨询指定权限及替代方案

针对跨账户Lightsail实例的S3权限方案

Great question! Let's break this down step by step—first with a targeted S3 bucket policy, then a more robust alternative approach that's often better for cross-account access.

一、合适的S3桶策略实现

If you want to use a bucket policy directly, you first need to set up an IAM role in the dedicated AWS account hosting your Lightsail instance (let's call it LightsailS3LimitedAccess). This role must have a trust policy that allows the Lightsail service to assume it (principal: lightsail.amazonaws.com).

Next, add this bucket policy to your target S3 bucket (in your main AWS account):

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Principal": {
                "AWS": "arn:aws:iam::LIGHTSAIL_ACCOUNT_ID:role/LightsailS3LimitedAccess"
            },
            "Action": [
                "s3:ListBucket",
                "s3:PutObject"
            ],
            "Resource": [
                "arn:aws:s3:::YOUR_TARGET_BUCKET_NAME",
                "arn:aws:s3:::YOUR_TARGET_BUCKET_NAME/*"
            ],
            "Condition": {
                "StringEquals": {
                    "aws:PrincipalArn": "arn:aws:iam::LIGHTSAIL_ACCOUNT_ID:role/LightsailS3LimitedAccess"
                }
            }
        }
    ]
}

Key Notes:

  • Replace LIGHTSAIL_ACCOUNT_ID with the ID of the dedicated AWS account running your Lightsail instance, and YOUR_TARGET_BUCKET_NAME with your bucket's name.
  • The Condition clause ensures permissions are only granted to the specific IAM role, not the entire account—this follows the least privilege principle and prevents accidental access from other roles in the dedicated account.
  • Don't forget to associate the LightsailS3LimitedAccess role with your Lightsail instance via the Lightsail console (under the instance's "Permissions" tab).

二、更优的权限方案:跨账户IAM角色信任

While bucket policies work, cross-account IAM role trust is almost always a better choice for this scenario. Here's why:

  • Centralized permission management: All access logic lives in IAM roles, not split between bucket policies and role policies.
  • Better security: You can add extra safeguards like MFA requirements or IP restrictions, and you have tighter control over who can assume the role.
  • Greater flexibility: Adjusting permissions later only requires updating the cross-account role's policy, not touching the bucket policy.

Step-by-Step Implementation:

  1. Create a cross-account role in your main (bucket) AWS account

    • Name it something like CrossAccountLightsailS3Access, and set its trust policy to allow the Lightsail instance's role to assume it:
      {
          "Version": "2012-10-17",
          "Statement": [
              {
                  "Effect": "Allow",
                  "Principal": {
                      "AWS": "arn:aws:iam::LIGHTSAIL_ACCOUNT_ID:role/LightsailS3LimitedAccess"
                  },
                  "Action": "sts:AssumeRole"
              }
          ]
      }
      
    • Attach a permission policy to this role that grants only the required S3 access:
      {
          "Version": "2012-10-17",
          "Statement": [
              {
                  "Effect": "Allow",
                  "Action": [
                      "s3:ListBucket",
                      "s3:PutObject"
                  ],
                  "Resource": [
                      "arn:aws:s3:::YOUR_TARGET_BUCKET_NAME",
                      "arn:aws:s3:::YOUR_TARGET_BUCKET_NAME/*"
                  ]
              }
          ]
      }
      
  2. Update the Lightsail instance's role in the dedicated account
    Add a policy to LightsailS3LimitedAccess that allows it to assume the cross-account role:

    {
        "Version": "2012-10-17",
        "Statement": [
            {
                "Effect": "Allow",
                "Action": "sts:AssumeRole",
                "Resource": "arn:aws:iam::TARGET_BUCKET_ACCOUNT_ID:role/CrossAccountLightsailS3Access"
            }
        ]
    }
    
  3. Use the role in the Lightsail instance
    Configure your AWS SDK/CLI to call sts:AssumeRole and use the temporary credentials to access S3. Most SDKs can automatically handle role assumption with minimal configuration.

Extra Best Practices

  • Stick to the least privilege principle: Never grant more permissions than the instance needs to do its job.
  • For extra security, add an aws:SourceIp condition to restrict access to your Lightsail instance's static IP (you'll need to assign a static IP to the instance first).
  • Periodically audit your IAM roles and bucket policies to remove any outdated or unnecessary permissions.

内容的提问来源于stack exchange,提问作者texdc

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 07:33:42