Help us understand the problem. What is going on with this article?

s3にCloudFrontからはアクセスさせて、開発拠点、開発VPC以外からアクセスさせないパケットポリシー

More than 1 year has passed since last update.

s3のバケットに

CloudFrontからはアクセスさせる。
S3への直接アクセスは、開発拠点からのみアクセスできる
S3にアップロードするEC2の所属するVPCからのみアクセスできる
というポリシーが必要になった。

NotPrincipalの存在に気付かなかったので少しハマった。
別途VPCのエンドポイントを作成して、使用するVPCからのアクセスを限定する必要がある。

qiita.rb
{
    "Version": "2012-10-17",
    "Id": "IP-VPC-CloudFront-Policy",
    "Statement": [
        {
            "Sid": "2",
            "Effect": "Allow",
            "Principal": {
                "AWS": "arn:aws:iam::cloudfront:user/CloudFront Origin Access Identity E233333eee"
            },
            "Action": "s3:GetObject",
            "Resource": "arn:aws:s3:::production-s3/*"
        },
        {
            "Sid": "Allow-from-specific-IP-and-VPC-only",
            "Effect": "Deny",
            "NotPrincipal": {
                "AWS": "arn:aws:iam::cloudfront:user/CloudFront Origin Access Identity E233333eee"
            },
            "Action": "s3:*",
            "Resource": "arn:aws:s3:::production-s3/*",
            "Condition": {
                "NotIpAddress": {
                    "aws:SourceIp": [
                        "<IPアドレス>",
                        "<IPアドレス>",
                        "<IPアドレス>",
                        "<IPアドレス>
                    ]
                },
                "StringNotEquals": {
                    "aws:sourceVpc": "vpc-<vpcid>"
                }
            }
        }
    ]
}
Why not register and get more from Qiita?
  1. We will deliver articles that match you
    By following users and tags, you can catch up information on technical fields that you are interested in as a whole
  2. you can read useful information later efficiently
    By "stocking" the articles you like, you can search right away
Comments
No comments
Sign up for free and join this conversation.
If you already have a Qiita account
Why do not you register as a user and use Qiita more conveniently?
You need to log in to use this function. Qiita can be used more conveniently after logging in.
You seem to be reading articles frequently this month. Qiita can be used more conveniently after logging in.
  1. We will deliver articles that match you
    By following users and tags, you can catch up information on technical fields that you are interested in as a whole
  2. you can read useful information later efficiently
    By "stocking" the articles you like, you can search right away
ユーザーは見つかりませんでした