-
Notifications
You must be signed in to change notification settings - Fork 5.8k
Expand file tree
/
Copy pathput-bucket-policy.js
More file actions
92 lines (86 loc) · 2.46 KB
/
put-bucket-policy.js
File metadata and controls
92 lines (86 loc) · 2.46 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.
// SPDX-License-Identifier: Apache-2.0
// snippet-start:[s3.JavaScript.policy.putBucketPolicyV3]
import {
PutBucketPolicyCommand,
S3Client,
S3ServiceException,
} from "@aws-sdk/client-s3";
/**
* Grant an IAM role GetObject access to all of the objects
* in the provided bucket.
* @param {{ bucketName: string, iamRoleArn: string }}
*/
export const main = async ({ bucketName, iamRoleArn }) => {
const client = new S3Client({});
const command = new PutBucketPolicyCommand({
// This is a resource-based policy. For more information on resource-based policies,
// see https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies.html#policies_resource-based.
Policy: JSON.stringify({
Version: "2012-10-17",
Statement: [
{
Effect: "Allow",
Principal: {
AWS: iamRoleArn,
},
Action: "s3:GetObject",
Resource: `arn:aws:s3:::${bucketName}/*`,
},
],
}),
// Apply the preceding policy to this bucket.
Bucket: bucketName,
});
try {
await client.send(command);
console.log(
`GetObject access to the bucket "${bucketName}" was granted to the provided IAM role.`,
);
} catch (caught) {
if (
caught instanceof S3ServiceException &&
caught.name === "MalformedPolicy"
) {
console.error(
`Error from S3 while setting the bucket policy for the bucket "${bucketName}". The policy was malformed.`,
);
} else if (caught instanceof S3ServiceException) {
console.error(
`Error from S3 while setting the bucket policy for the bucket "${bucketName}". ${caught.name}: ${caught.message}`,
);
} else {
throw caught;
}
}
};
// snippet-end:[s3.JavaScript.policy.putBucketPolicyV3]
// Call function if run directly
import { parseArgs } from "node:util";
import {
isMain,
validateArgs,
} from "@aws-doc-sdk-examples/lib/utils/util-node.js";
const loadArgs = () => {
const options = {
bucketName: {
type: "string",
required: true,
},
iamRoleArn: {
type: "string",
required: true,
},
};
const results = parseArgs({ options });
const { errors } = validateArgs({ options }, results);
return { errors, results };
};
if (isMain(import.meta.url)) {
const { errors, results } = loadArgs();
if (!errors) {
main(results.values);
} else {
console.error(errors.join("\n"));
}
}