{"id":1957,"date":"2024-12-24T14:33:29","date_gmt":"2024-12-24T06:33:29","guid":{"rendered":"https:\/\/aws-oncloudai.com\/?p=1957"},"modified":"2024-12-24T14:33:29","modified_gmt":"2024-12-24T06:33:29","slug":"aws-basics-iam-beginners-guide","status":"publish","type":"post","link":"https:\/\/aws-oncloudai.com\/zh_hk\/aws-basics-iam-beginners-guide\/","title":{"rendered":"AWS \u57fa\u790e\u2013 IAM \u521d\u5b78\u8005\u6307\u5357"},"content":{"rendered":"<p>Amazon Web Services\uff08AWS\uff09\u4f5c\u70ba\u5168\u7403\u9818\u5148\u7684\u96f2\u7aef\u670d\u52d9\u5e73\u53f0\uff0c\u70ba\u4f7f\u7528\u8005\u63d0\u4f9b\u4e86\u9748\u6d3b\u7684\u8cc7\u6e90\u7ba1\u7406\u5de5\u5177\u3002 AWS Identity and Access Management\uff08IAM\uff09\u662f\u5176\u4e2d\u81f3\u95dc\u91cd\u8981\u7684\u4e00\u90e8\u5206\uff0c\u5b83\u70ba\u4f7f\u7528\u8005\u63d0\u4f9b\u4e86\u5b89\u5168\u4e14\u6709\u6548\u7387\u7684\u5b58\u53d6\u63a7\u5236\u529f\u80fd\u3002\u7121\u8ad6\u662f\u500b\u4eba\u958b\u767c\u8005\u6216\u4f01\u696d\u5718\u968a\uff0c\u77ad\u89e3IAM \u7684\u57fa\u672c\u6982\u5ff5\u3001\u7b56\u7565\u548c\u6700\u4f73\u5be6\u8e10\u90fd\u662f\u78ba\u4fdd\u5e33\u6236\u548c\u8cc7\u6e90\u5b89\u5168\u7684\u95dc\u9375\u3002\u672c\u6587\u5c07\u5e36\u4f60\u5feb\u901f\u4e0a\u624bIAM\uff0c\u5e6b\u52a9\u4f60\u70ba\u96f2\u7aef\u8cc7\u6e90\u5efa\u7f6e\u4e00\u500b\u5b89\u5168\u4e14\u53ef\u63a7\u5236\u7684\u5b58\u53d6\u74b0\u5883\u3002<\/p>\n<p>&nbsp;<\/p>\n<h3>IAM\uff08\u8eab\u5206\u5b58\u53d6\u7ba1\u7406\uff09<\/h3>\n<p><strong>IAM<\/strong>\u5141\u8a31\u60a8\u7ba1\u7406\u4f7f\u7528\u8005\u3001\u7fa4\u7d44\u3001\u89d2\u8272\u53ca\u5176\u5c0dAWS \u5e73\u53f0\u7684\u76f8\u61c9\u5b58\u53d6\u7b49\u7d1a\u3002<\/p>\n<p>IAM \u662f<strong>\u901a\u7528\u7684<\/strong>\u3002\u76ee\u524d\u4e0d\u9069\u7528\u65bc\u5730\u5340\u3002<\/p>\n<p>&nbsp;<\/p>\n<h3><a href=\"https:\/\/dev.to\/manojpatra1991\/aws-basics-beginners-guide-to-iam-53a4#root-account-vs-iam-user\" name=\"root-account-vs-iam-user\" rel=\"nofollow noopener\" target=\"_blank\"><\/a>\u6839\u5e33\u6236\u8207IAM \u7528\u6236<\/h3>\n<p><strong>\u6839\u5e33\u6236<\/strong>\u5177\u6709\u5b8c\u5168\u7ba1\u7406\u54e1\u6b0a\u9650\uff0c\u4e0d\u61c9\u6bcf\u5929\u4f7f\u7528\u3002\u76f8\u53cd\uff0c\u61c9\u4f7f\u7528IAM \u4f7f\u7528\u8005\u5e33\u6236\u4f86\u57f7\u884c\u65e5\u5e38\u4efb\u52d9\u3002<\/p>\n<blockquote><p>\u958b\u59cb\u4f7f\u7528AWS \u6642\uff0c\u8acb\u52d9\u5fc5\u9078\u64c7\u8ddd\u96e2\u60a8\u6700\u8fd1\u7684<strong><em>\u5340\u57df\u3002<\/em><\/strong><\/p>\n<p>&nbsp;<\/p><\/blockquote>\n<h3><a href=\"https:\/\/dev.to\/manojpatra1991\/aws-basics-beginners-guide-to-iam-53a4#adding-a-user-to-iam\" name=\"adding-a-user-to-iam\" rel=\"nofollow noopener\" target=\"_blank\"><\/a>\u5411IAM \u65b0\u589e\u7528\u6236<\/h3>\n<ol>\n<li>\u8f49\u81f3<code>IAM Dashboard<\/code><\/li>\n<li>\u9ede\u9078<code>Add user<\/code><\/li>\n<li>\u6dfb\u52a0<code>User name<\/code>\u548c<code>Access type: Programmatic access \/ AWS Management Console access<\/code><\/li>\n<li>\u6dfb\u52a0<code>group<\/code><\/li>\n<li>\u6dfb\u52a0<code>tags<\/code>\uff08\u53ef\u9078\uff09<\/li>\n<li>\u5275\u9020<code>user<\/code><\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p><img fetchpriority=\"high\" decoding=\"async\" class=\"alignnone size-large wp-image-1973\" src=\"http:\/\/aws-oncloudai.com\/wp-content\/uploads\/2024\/12\/ouwylrtb3vumr08exvel-1024x796.jpg\" alt=\"\" width=\"800\" height=\"622\" srcset=\"https:\/\/aws-oncloudai.com\/wp-content\/uploads\/2024\/12\/ouwylrtb3vumr08exvel-1024x796.jpg 1024w, https:\/\/aws-oncloudai.com\/wp-content\/uploads\/2024\/12\/ouwylrtb3vumr08exvel-300x233.jpg 300w, https:\/\/aws-oncloudai.com\/wp-content\/uploads\/2024\/12\/ouwylrtb3vumr08exvel-768x597.jpg 768w, https:\/\/aws-oncloudai.com\/wp-content\/uploads\/2024\/12\/ouwylrtb3vumr08exvel-15x12.jpg 15w, https:\/\/aws-oncloudai.com\/wp-content\/uploads\/2024\/12\/ouwylrtb3vumr08exvel.jpg 1152w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p>&nbsp;<\/p>\n<h3><a href=\"https:\/\/dev.to\/manojpatra1991\/aws-basics-beginners-guide-to-iam-53a4#sign-in-as-an-iam-user\" name=\"sign-in-as-an-iam-user\" rel=\"nofollow noopener\" target=\"_blank\"><\/a><\/h3>\n<h3><a href=\"https:\/\/dev.to\/manojpatra1991\/aws-basics-beginners-guide-to-iam-53a4#aws-access-types\" name=\"aws-access-types\" rel=\"nofollow noopener\" target=\"_blank\"><\/a>AWS \u5b58\u53d6\u985e\u578b<\/h3>\n<p>\u65b0\u589e\u4f7f\u7528\u8005\u6642\u555f\u7528AWS \u5b58\u53d6\u7684\u53ef\u7528\u65b9\u6cd5\uff1a<\/p>\n<ol>\n<li><strong>\u7de8\u7a0b\u8a2a\u554f<\/strong>\uff1a\u70ba\u958b\u767c\u4eba\u54e1\u555f\u7528\u5b58\u53d6\u91d1\u9470ID \u548c\u79d8\u5bc6\u5b58\u53d6\u91d1\u9470\uff1b\u79d8\u5bc6\u5b58\u53d6\u91d1\u9470\u50c5\u5728\u6211\u5011\u9996\u6b21\u5efa\u7acb\u4f7f\u7528\u8005\u6642\u53ef\u7528<\/li>\n<li><strong>AWS \u7ba1\u7406\u4e3b\u63a7\u53f0\u5b58\u53d6<\/strong>\uff1a\u555f\u7528\u5bc6\u78bc\u4ee5\u53ca\u4f7f\u7528\u8005\u540d\u7a31\u5f9eAWS \u7ba1\u7406\u63a7\u5236\u53f0\u767b\u5165\u3002<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<h3><a href=\"https:\/\/dev.to\/manojpatra1991\/aws-basics-beginners-guide-to-iam-53a4#security-best-practices-in-iam\" name=\"security-best-practices-in-iam\" rel=\"nofollow noopener\" target=\"_blank\"><\/a>IAM \u4e2d\u7684\u5b89\u5168\u6700\u4f73\u5be6\u8e10<\/h3>\n<ol>\n<li>\u522a\u9664\u60a8\u7684\u6839\u8a2a\u554f\u5bc6\u9470<\/li>\n<li>\u5728\u60a8\u7684\u6839\u5e33\u6236\u4e0a\u555f\u52d5MFA<\/li>\n<li>\u5efa\u7acb\u55ae\u7368\u7684IAM \u7528\u6236<\/li>\n<li>\u4f7f\u7528\u7fa4\u7d44\u5206\u914d\u6b0a\u9650<\/li>\n<li><strong>\u61c9\u7528IAM \u5bc6\u78bc\u7b56\u7565<\/strong>\u9032\u884c\u5bc6\u78bc\u8907\u96dc\u6027\u8207\u751f\u547d\u9031\u671f\u7ba1\u7406\u2013<u>\u5b9a\u7fa9IAM \u4f7f\u7528\u8005\u5728\u8a2d\u5b9a\u5bc6\u78bc\u6642\u61c9\u9075\u5faa\u7684\u4e00\u7d44\u898f\u5247<\/u>\u3002<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p><img decoding=\"async\" class=\"alignnone size-large wp-image-1970\" src=\"http:\/\/aws-oncloudai.com\/wp-content\/uploads\/2024\/12\/ahjuadyenmfyg1hb8f8v-1024x796.jpg\" alt=\"\" width=\"800\" height=\"622\" srcset=\"https:\/\/aws-oncloudai.com\/wp-content\/uploads\/2024\/12\/ahjuadyenmfyg1hb8f8v-1024x796.jpg 1024w, https:\/\/aws-oncloudai.com\/wp-content\/uploads\/2024\/12\/ahjuadyenmfyg1hb8f8v-300x233.jpg 300w, https:\/\/aws-oncloudai.com\/wp-content\/uploads\/2024\/12\/ahjuadyenmfyg1hb8f8v-768x597.jpg 768w, https:\/\/aws-oncloudai.com\/wp-content\/uploads\/2024\/12\/ahjuadyenmfyg1hb8f8v-15x12.jpg 15w, https:\/\/aws-oncloudai.com\/wp-content\/uploads\/2024\/12\/ahjuadyenmfyg1hb8f8v.jpg 1152w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p>&nbsp;<\/p>\n<h3><a href=\"https:\/\/dev.to\/manojpatra1991\/aws-basics-beginners-guide-to-iam-53a4#setting-permissions-for-a-user\" name=\"setting-permissions-for-a-user\" rel=\"nofollow noopener\" target=\"_blank\"><\/a>\u70ba\u4f7f\u7528\u8005\u8a2d\u5b9a\u6b0a\u9650<\/h3>\n<p>\u70ba\u65b0\u4f7f\u7528\u8005\u8a2d\u5b9a\u6b0a\u9650\u7684\u4e0d\u540c\u65b9\u6cd5\u5982\u4e0b\uff1a<\/p>\n<ol>\n<li>\u5c07\u4f7f\u7528\u8005\u65b0\u589e\u81f3\u7fa4\u7d44<\/li>\n<li>\u5f9e\u73fe\u6709\u4f7f\u7528\u8005\u8907\u88fd\u6b0a\u9650<\/li>\n<li>\u76f4\u63a5\u9644\u52a0\u73fe\u6709\u653f\u7b56<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<h3><a href=\"https:\/\/dev.to\/manojpatra1991\/aws-basics-beginners-guide-to-iam-53a4#iam-roles\" name=\"iam-roles\" rel=\"nofollow noopener\" target=\"_blank\"><\/a>IAM \u89d2\u8272<\/h3>\n<p><strong>IAM \u89d2\u8272<\/strong>\u662f\u5411\u60a8\u4fe1\u4efb\u7684\u5be6\u9ad4\u6388\u4e88\u6b0a\u9650\u7684\u5b89\u5168\u65b9\u5f0f\u3002<\/p>\n<p>\u5be6\u9ad4\u7684\u7bc4\u4f8b\u5305\u62ec\uff1a<\/p>\n<ul>\n<li>\u53e6\u4e00\u500b\u5e33\u6236\u4e2d\u7684IAM \u7528\u6236<\/li>\n<li>\u5728EC2 \u57f7\u884c\u500b\u9ad4\u4e0a\u57f7\u884c\u7684\u9700\u8981\u5c0dAWS \u8cc7\u6e90\u57f7\u884c\u4f5c\u696d\u7684\u61c9\u7528\u7a0b\u5f0f\u7a0b\u5f0f\u78bc<\/li>\n<li>\u9700\u8981\u5c0d\u60a8\u5e33\u6236\u4e2d\u7684\u8cc7\u6e90\u63a1\u53d6\u884c\u52d5\u4ee5\u63d0\u4f9b\u5176\u529f\u80fd\u7684AWS \u670d\u52d9<\/li>\n<li>\u4f86\u81ea\u516c\u53f8\u76ee\u9304\u4e26\u4f7f\u7528<strong>SAML<\/strong>\uff08\u5b89\u5168\u65b7\u8a00\u6a19\u8a18\u8a9e\u8a002.0\uff09\u9032\u884c\u8eab\u4efd\u806f\u5408\u7684\u7528\u6236<\/li>\n<\/ul>\n<blockquote><p>IAM \u89d2\u8272\u9812\u767c\u5728\u77ed\u6642\u9593\u5167\u6709\u6548\u7684\u91d1\u9470\uff0c\u4f7f\u5176\u6210\u70ba\u66f4\u5b89\u5168\u7684\u6388\u4e88\u5b58\u53d6\u6b0a\u9650\u7684\u65b9\u5f0f\u3002<\/p><\/blockquote>\n<blockquote><p><img decoding=\"async\" class=\"alignnone size-large wp-image-1972\" src=\"http:\/\/aws-oncloudai.com\/wp-content\/uploads\/2024\/12\/pfgyyjyv2553jwereivf-1024x796.jpg\" alt=\"\" width=\"800\" height=\"622\" srcset=\"https:\/\/aws-oncloudai.com\/wp-content\/uploads\/2024\/12\/pfgyyjyv2553jwereivf-1024x796.jpg 1024w, https:\/\/aws-oncloudai.com\/wp-content\/uploads\/2024\/12\/pfgyyjyv2553jwereivf-300x233.jpg 300w, https:\/\/aws-oncloudai.com\/wp-content\/uploads\/2024\/12\/pfgyyjyv2553jwereivf-768x597.jpg 768w, https:\/\/aws-oncloudai.com\/wp-content\/uploads\/2024\/12\/pfgyyjyv2553jwereivf-15x12.jpg 15w, https:\/\/aws-oncloudai.com\/wp-content\/uploads\/2024\/12\/pfgyyjyv2553jwereivf.jpg 1152w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p>&nbsp;<\/p><\/blockquote>\n<h3><a href=\"https:\/\/dev.to\/manojpatra1991\/aws-basics-beginners-guide-to-iam-53a4#iam-policy\" name=\"iam-policy\" rel=\"nofollow noopener\" target=\"_blank\"><\/a>IAM \u7b56\u7565<\/h3>\n<p><strong>IAM \u7b56\u7565<\/strong>\u662f\u5b9a\u7fa9\u4e00\u500b\u6216\u591a\u500b\u6b0a\u9650\u7684JSON \u6587\u4ef6\u3002<\/p>\n<p>&nbsp;<\/p>\n<h3><a href=\"https:\/\/dev.to\/manojpatra1991\/aws-basics-beginners-guide-to-iam-53a4#testing-iam-permissions\" name=\"testing-iam-permissions\" rel=\"nofollow noopener\" target=\"_blank\"><\/a>\u6e2c\u8a66IAM \u6b0a\u9650<\/h3>\n<p>IAM \u7b56\u7565\u6a21\u64ec\u5668\u53ef\u7528\u65bc\u57f7\u884c\u4e0b\u5217\u64cd\u4f5c\uff1a<\/p>\n<ol>\n<li>\u5728\u5c07IAM \u6b0a\u9650\u6295\u5165\u751f\u7522\u4e4b\u524d\u9032\u884c\u6e2c\u8a66<\/li>\n<li>\u9a57\u8b49\u7b56\u7565\u662f\u5426\u5982\u9810\u671f\u904b\u884c<\/li>\n<li>\u6e2c\u8a66\u5df2\u9644\u52a0\u5230\u73fe\u6709\u7528\u6236\u7684\u7b56\u7565<\/li>\n<\/ol>\n<p>IAM \u662fAWS \u5b89\u5168\u7cfb\u7d71\u7684\u6838\u5fc3\u5143\u4ef6\uff0c\u70ba\u4f7f\u7528\u8005\u548c\u8cc7\u6e90\u63d0\u4f9b\u4e86\u9748\u6d3b\u7684\u8eab\u4efd\u9a57\u8b49\u8207\u6b0a\u9650\u7ba1\u7406\u80fd\u529b\u3002\u900f\u904e\u5efa\u7acb\u4f7f\u7528\u8005\u3001\u7fa4\u7d44\u3001\u89d2\u8272\u548c\u7b56\u7565\uff0c\u60a8\u53ef\u4ee5\u7cbe\u78ba\u5730\u63a7\u5236\u8cc7\u6e90\u5b58\u53d6\u6b0a\u9650\uff0c\u907f\u514d\u5b89\u5168\u96b1\u60a3\u3002\u638c\u63e1IAM \u7684\u57fa\u672c\u64cd\u4f5c\u548c\u6700\u4f73\u5be6\u8e10\uff0c\u4e0d\u50c5\u80fd\u589e\u5f37\u7cfb\u7d71\u7684\u5b89\u5168\u6027\uff0c\u9084\u80fd\u63d0\u5347\u7ba1\u7406\u6548\u7387\u3002<\/p>","protected":false},"excerpt":{"rendered":"<p>Amazon Web Services\uff08AWS\uff09\u4f5c\u70ba\u5168\u7403\u9818\u5148\u7684\u96f2\u7aef\u670d\u52d9\u5e73\u53f0\uff0c\u70ba\u4f7f\u7528\u8005\u63d0\u4f9b\u4e86\u9748\u6d3b\u7684\u8cc7\u6e90\u7ba1\u7406\u5de5\u5177\u3002 AWS Identity and Access Management\uff08IAM\uff09\u662f\u5176\u4e2d\u81f3\u95dc\u91cd\u8981\u7684\u4e00\u90e8\u5206\uff0c\u5b83\u70ba\u4f7f\u7528\u8005\u63d0\u4f9b\u4e86\u5b89\u5168\u4e14\u6709\u6548\u7387\u7684\u5b58\u53d6\u63a7\u5236\u529f\u80fd\u3002\u7121\u8ad6\u662f\u500b\u4eba\u958b\u767c\u8005\u6216\u4f01\u696d\u5718\u968a\uff0c\u77ad\u89e3IAM \u7684\u57fa\u672c\u6982\u5ff5\u3001\u7b56\u7565\u548c\u6700\u4f73\u5be6\u8e10\u90fd\u662f\u78ba\u4fdd\u5e33\u6236\u548c\u8cc7\u6e90\u5b89\u5168\u7684\u95dc\u9375\u3002\u672c\u6587\u5c07\u5e36\u4f60\u5feb\u901f\u4e0a\u624bIAM\uff0c\u5e6b\u52a9\u4f60\u70ba\u96f2\u7aef\u8cc7\u6e90\u5efa\u7f6e\u4e00\u500b\u5b89\u5168\u4e14\u53ef\u63a7\u5236\u7684\u5b58\u53d6\u74b0\u5883\u3002<\/p>","protected":false},"author":1,"featured_media":1958,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[65],"tags":[],"class_list":["post-1957","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technical-sharing"],"_links":{"self":[{"href":"https:\/\/aws-oncloudai.com\/zh_hk\/wp-json\/wp\/v2\/posts\/1957","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/aws-oncloudai.com\/zh_hk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/aws-oncloudai.com\/zh_hk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/aws-oncloudai.com\/zh_hk\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/aws-oncloudai.com\/zh_hk\/wp-json\/wp\/v2\/comments?post=1957"}],"version-history":[{"count":0,"href":"https:\/\/aws-oncloudai.com\/zh_hk\/wp-json\/wp\/v2\/posts\/1957\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/aws-oncloudai.com\/zh_hk\/wp-json\/wp\/v2\/media\/1958"}],"wp:attachment":[{"href":"https:\/\/aws-oncloudai.com\/zh_hk\/wp-json\/wp\/v2\/media?parent=1957"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/aws-oncloudai.com\/zh_hk\/wp-json\/wp\/v2\/categories?post=1957"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/aws-oncloudai.com\/zh_hk\/wp-json\/wp\/v2\/tags?post=1957"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}