S3 Storage Lens 신뢰 액세스 비활성화

S3 Storage Lens 신뢰 액세스 비활성화

계정을 위임 관리자에서 제거하거나 신뢰 액세스를 비활성화하면 계정 소유자의 S3 Storage Lens 대시보드 지표가 계정 수준에서만 작동하도록 제한돼요. 그러면 각 계정 보유자는 조직 전체가 아니라 자신의 계정으로 제한된 범위에서만 S3 Storage Lens의 이점을 볼 수 있게 돼요.

출처: Disabling trusted access for S3 Storage Lens

S3 Storage Lens에서 신뢰 액세스를 비활성화하면 신뢰 액세스가 필요한 모든 대시보드가 더 이상 업데이트되지 않아요. 생성된 조직 수준 대시보드도 더 이상 업데이트되지 않아요. 대신 데이터가 계속 사용 가능한 동안 S3 Storage Lens 대시보드의 과거 데이터만 쿼리할 수 있어요.

참고:

  • S3 Storage Lens의 신뢰 액세스를 비활성화하면 모든 조직 수준 대시보드가 스토리지 지표 수집·집계를 자동으로 중단해요. 이는 S3 Storage Lens가 더 이상 조직 계정에 대한 신뢰 액세스를 갖지 못하기 때문이에요.
  • 관리 계정과 위임 관리자 계정은 비활성화된 대시보드의 과거 데이터를 계속 볼 수 있어요. 데이터가 계속 사용 가능한 동안 이 과거 데이터를 쿼리할 수도 있어요.

S3 Storage Lens의 신뢰 액세스를 비활성화하려면

  1. AWS Management Console에 로그인하고 https://console.aws.amazon.com/s3/ 에서 Amazon S3 콘솔을 엽니다.
  2. 왼쪽 탐색 창에서 Storage Lens로 이동합니다.
  3. AWS Organizations settings를 선택합니다. Storage Lens용 AWS Organizations 액세스 페이지가 표시됩니다.
  4. AWS Organizations trusted access 아래에서 Edit을 선택합니다. AWS Organizations 액세스 페이지가 표시됩니다.
  5. Disable을 선택해 S3 Storage Lens 대시보드의 신뢰 액세스를 비활성화합니다.
  6. Save changes를 선택합니다.

예시

다음 예시는 AWS CLI를 사용해 S3 Storage Lens의 신뢰 액세스를 비활성화해요.

aws organizations disable-aws-service-access --service-principal storage-lens.s3.amazonaws.com

예시 - S3 Storage Lens용 AWS Organizations 신뢰 액세스 비활성화

다음 예시는 Java용 SDK에서 S3 Storage Lens용 AWS Organizations 신뢰 액세스를 비활성화하는 방법을 보여줘요. 이 예시를 사용하려면 입력 자리 표시자(user input placeholders)를 자신의 정보로 바꿔주세요.

import com.amazonaws.AmazonServiceException;
import com.amazonaws.SdkClientException;
import com.amazonaws.auth.profile.ProfileCredentialsProvider;
import com.amazonaws.regions.Regions;
import com.amazonaws.services.organizations.AWSOrganizations;
import com.amazonaws.services.organizations.AWSOrganizationsClient;
import com.amazonaws.services.organizations.model.DisableAWSServiceAccessRequest;

public class DisableOrganizationsTrustedAccess {
	private static final String S3_STORAGE_LENS_SERVICE_PRINCIPAL = "storage-lens.s3.amazonaws.com";

	public static void main(String[] args) {
		try {
            AWSOrganizations organizationsClient = AWSOrganizationsClient.builder()
                .withCredentials(new ProfileCredentialsProvider())
                .withRegion(Regions.US_EAST_1)
                .build();

            // Make sure to remove any existing delegated administrator for S3 Storage Lens 
            // before disabling access; otherwise, the request will fail.
            organizationsClient.disableAWSServiceAccess(new DisableAWSServiceAccessRequest()
                .withServicePrincipal(S3_STORAGE_LENS_SERVICE_PRINCIPAL));
        } catch (AmazonServiceException e) {
            // The call was transmitted successfully, but AWS Organizations couldn't process
            // it and returned an error response.
            e.printStackTrace();
        } catch (SdkClientException e) {
            // AWS Organizations couldn't be contacted for a response, or the client
            // couldn't parse the response from AWS Organizations.
            e.printStackTrace();
        }
	}
}

더 알아보기

  • S3 Storage Lens 신뢰 액세스 활성화하기
  • S3 Storage Lens 위임 관리자 등록 해제하기