要创建网关端点,请配置以下设置:
对于 Region(区域),选择要在其中创建端点的 Region code(区域代码)。例如,要在 us-east-1 中创建端点,请选择 com.amazonaws.us-east-1.s3。
对于 VPC,为您的实例选择 VPC ID。
对于 Configure route tables(配置路由表),为您的实例选择路由表 ID。
对于 Policy(策略),选择 Full Access(完全访问)以允许完全访问 Amazon S3。如果您选择 Custom(自定义),则必须允许在 Amazon Linux 存储库存储桶上进行 s3:GetObject API 调用。
**注意:**在以下示例策略中,将 us-east-1 替换为您的端点区域。
AL2023:
{ "Statement": [
{
"Principal": "*",
"Action": [
"s3:GetObject"
],
"Effect": "Allow",
"Resource": [
"arn:aws:s3:::al2023-repos-us-east-1-de612dc2/*"
]
}
]
}
AL2:
{ "Statement": [
{
"Principal": "*",
"Action": [
"s3:GetObject"
],
"Effect": "Allow",
"Resource": [
"arn:aws:s3:::amazonlinux.us-east-1.amazonaws.com/*",
"arn:aws:s3:::amazonlinux-2-repos-us-east-1/*"
]
}
]
}
AL1:
{ "Statement": [
{
"Principal": "*",
"Action": [
"s3:GetObject"
],
"Effect": "Allow",
"Resource": [
"arn:aws:s3:::packages.us-east-1.amazonaws.com/*",
"arn:aws:s3:::repo.us-east-1.amazonaws.com/*"
]
}
]
}
**注意:**在前面的 AL1 和 AL2 策略中,arn:aws:s3:::amazonlinux.us-east-1.amazonaws.com/* 和 arn:aws:s3:::amazonlinux-2-repos-us-east-1/* 存储桶托管存储库。