{ } [ ] " , :
= < > ( ) |
[<resource_string>, < resource_string>, ...]<principal_map> = { <principal_map_entry>, <principal_map_entry>, ... }
"resource": [<resource_string>]"resource": <resource_string>
<condition_block?>
("allow" | "deny")
<version_block> = "version" : "2.0"
policy = {<version_block><principal_block?>,<statement_block>}<version_block> = "version" : "2.0"<statement_block> = "statement" : [ <statement>, <statement>, ... ]<statement> = {<effect_block>,<action_block>,<resource_block>,<condition_block?>}<effect_block> = "effect" : ("allow" | "deny")<principal_block> = "principal": ("*" | <principal_map>)<principal_map> = { <principal_map_entry>, <principal_map_entry>, ... }<principal_map_entry> = "qcs":[<principal_id_string>, <principal_id_string>, ...]<action_block> = "action":("*" | [<action_string>, <action_string>, ...])<resource_block> = "resource":("*" | [<resource_string>, <resource_string>, ...])<condition_block> = "condition" : { <condition_map> }<condition_map> {<condition_type_string> : { <condition_key_string> : <condition_value_list> },<condition_type_string> : { <condition_key_string> : <condition_value_list> }, ...}<condition_value_list> = [<condition_value>, <condition_value>, ...]<condition_value> = ("string" | "number")
//所有产品所有操作"action":"*""action":"*:*"// COS 产品所有操作"action":"cos:*"// COS 产品的名为 GetBucketPolicy 的操作"action":"cos:GetBucketPolicy"// COS 产品部分匹配 Bucket 的操作"action":"cos:*Bucket*"// cos 产品,名为 GetBucketPolicy\\PutBucketPolicy\\DeleteBucketPolicy 的操作列表"action":["cos:GetBucketPolicy","cos:PutBucketPolicy","cos: DeleteBucketPolicy"]
qcs: project :serviceType:region:account:resource
// COS 产品的 object 资源,上海地域,资源拥有者的 uid 是10001234,资源名是 bucket1/object2qcs::cos:sh:uid/10001234:prefix//10001234/bucket1/object2// CMQ 产品的队列,上海地域,资源拥有者的 uin 是12345678,资源名是12345678/queueName1,资源前缀是 queueNameqcs::cmqqueue:sh:uin/12345678:queueName/12345678/queueName1// CVM 产品的云服务器,上海地域,资源拥有者的 uin 是12345678,资源名是 ins-abcdefg,资源前缀是 instanceqcs::cvm:sh:uin/12345678:instance/ins-abcdefg
"condition":{"string_equal":{"cvm:region":["sh","gz"]},"ip_equal":{"qcs:ip":"10.131.12.12/24"}}
"principal": {"qcs":["qcs::cam::uin/1238423:uin/3232","qcs::cam::uin/1238423:groupid/13"]}
本页内容是否解决了您的问题?