Amazon ECS 서비스 배포를 조회하는 데 필요한 권한

Amazon ECS 서비스 배포를 조회하는 데 필요한 권한

최소 권한(least privilege)을 부여하는 모범 사례를 따를 때 콘솔에서 서비스 배포를 보려면 추가 권한을 부여해야 해요. 필요한 액션과 리소스 권한을 이 문서에서 확인해 보아요.

출처: 문서

본문

최소 권한을 부여하는 모범 사례를 따르면 콘솔에서 서비스 배포를 보기 위해 추가 권한을 부여해야 해요. 다음 액션에 대한 액세스 권한이 필요해요.

  • ListServiceDeployments
  • DescribeServiceDeployments
  • DescribeServiceRevisions

다음 리소스에 대한 액세스 권한이 필요해요.

  • Service
  • Service deployment
  • Service revision

다음 예제 정책에는 필요한 권한이 포함되어 있고 액션이 지정된 서비스로 제한돼 있어요. account , cluster-name , service-name 을 내 값으로 바꿔 주세요.

{
    "Statement": [
        {
            "Effect": "Allow",
            "Action": [
                "ecs:ListServiceDeployments",
                "ecs:DescribeServiceDeployments",
                "ecs:DescribeServiceRevisions"
            ],
            "Resource": [
                "arn:aws:ecs:us-east-1:123456789012:service/cluster-name/service-name",
                "arn:aws:ecs:us-east-1:123456789012:service-deployment/cluster-name/service-name/*",
                "arn:aws:ecs:us-east-1:123456789012:service-revision/cluster-name/service-name/*"
            ]
        }
   ]
}

더 알아보기 (Learn more)