The bucket owner (root account) or other accounts and IAM users, who have the permission to set bucket policies, can configure bucket policies to grant the bucket operation permissions to other accounts or IAM users under other accounts.
The following is an example about how to authorize other accounts with the bucket access and object upload permissions.
To grant permissions to IAM users under other accounts, you need to configure a bucket policy and also IAM policies.
Only permissions that are allowed by both the bucket policy and IAM policies can take effect.
Parameter |
Value |
---|---|
Policy Mode |
Customized |
Effect |
Allow |
Principal |
|
Resources |
|
Actions |
|
Before authorizing the user with the permission to operate objects, ensure that the user has the permission to access the bucket.
Parameter |
Value |
---|---|
Policy Mode |
Customized |
Effect |
Allow |
Principal |
|
Resources |
|
Actions |
|