© 2021 Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Policy分为以下六种:
Policy与身份或资源相关联时来定义它们的权限。在某个 IAM 主体(用户或角色)发出请求时,AWS 将评估这些Policy。
它的Json结构如下:
Principal字段仅在Resource-based policies中有,在Identity based policy中没有
Resource-based policies
Identity based policy