[英]Can I use existing AWS IAM role to create S3 bucket via Cloudformation template?
I want to create a S3 Bucket via CloudFormation template. 我想通过CloudFormation模板创建一个S3存储桶。 I found there is a way to do it for EC2 instance on this link . 我发现在此链接上有一种针对EC2实例的方法。
Do we have a way to create S3 bucket using existing IAM role via cloudformation? 我们是否有办法通过cloudformation使用现有的IAM角色创建S3存储桶?
It looks like what you're looking for is a service role . 看起来您正在寻找的是服务角色 。 From AWS: 从AWS:
A service role is an AWS Identity and Access Management (IAM) role that allows AWS CloudFormation to make calls to resources in a stack on your behalf. 服务角色是一个AWS Identity and Access Management(IAM)角色,它允许AWS CloudFormation代表您对堆栈中的资源进行调用。 You can specify an IAM role that allows AWS CloudFormation to create, update, or delete your stack resources. 您可以指定一个IAM角色,该角色允许AWS CloudFormation创建,更新或删除您的堆栈资源。 By default, AWS CloudFormation uses a temporary session that it generates from your user credentials for stack operations. 默认情况下,AWS CloudFormation使用从您的用户凭证生成的临时会话进行堆栈操作。 If you specify a service role, AWS CloudFormation uses the role's credentials. 如果您指定服务角色,则AWS CloudFormation使用角色的凭证。
For more information, you might want to take a look at this , specifically the permission part to find out how to use an existing IAM role for creating a Cloudformation stack. 欲了解更多信息,你可能想看看这个 ,特别是允许部分以了解如何使用现有IAM角色创建Cloudformation堆栈。
By the way: Unfortunately the link that you've provided doesn't seem to be accessible anymore. 顺便说一句:不幸的是,您提供的链接似乎不再可用。
When deploying infrastructure using creating Cloudformation template, you can have 2 ways to do it: 使用创建Cloudformation模板部署基础结构时,您可以通过以下两种方法进行:
声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.