S3 Storage Lens 신뢰 액세스 활성화
S3 Storage Lens 신뢰 액세스 활성화
신뢰 액세스를 활성화하면 Amazon S3 Storage Lens가 AWS Organizations API 작업을 통해 AWS Organizations 계층 구조, 멤버십, 구성을 액세스하도록 허용해요. 그러면 S3 Storage Lens는 조직 전체 구조에 대한 신뢰할 수 있는 서비스가 돼요.
대시보드 구성을 만들 때마다 S3 Storage Lens는 조직의 관리 또는 위임 관리자 계정에 서비스 연결 역할(service-linked role)을 만들어요. 서비스 연결 역할은 S3 Storage Lens가 다음 작업을 수행하도록 권한을 부여해요.
- 조직 설명
- 계정 나열
- 조직의 AWS 서비스 액세스 목록 확인
- 조직의 위임 관리자 가져오기
그러면 S3 Storage Lens는 조직의 계정에 대한 교차 계정 지표를 수집할 수 있는 액세스 권한을 확보할 수 있어요. 자세한 내용은 Amazon S3 Storage Lens용 서비스 연결 역할 사용을 참조해 주세요.
신뢰 액세스를 활성화한 후에는 조직의 계정에 위임 관리자 액세스를 할당할 수 있어요. 계정이 서비스의 위임 관리자로 지정되면 해당 계정은 모든 읽기 전용 조직 API 작업에 액세스할 권한을 받아요. 이 액세스는 위임 관리자가 조직의 멤버와 구조를 볼 수 있게 해줘서 그들도 S3 Storage Lens 대시보드를 만들 수 있게 해줘요.
참고:
- 신뢰 액세스는 관리 계정에서만 활성화할 수 있어요.
- 조직의 S3 Storage Lens 대시보드나 구성을 만들 수 있는 것은 관리 계정과 위임 관리자뿐이에요.
S3 Storage Lens에 AWS Organizations 신뢰 액세스를 활성화하려면
- AWS Management Console에 로그인하고 https://console.aws.amazon.com/s3/ 에서 Amazon S3 콘솔을 엽니다.
- 왼쪽 탐색 창에서 Storage Lens로 이동합니다.
- AWS Organizations settings를 선택합니다. Storage Lens용 AWS Organizations 액세스 페이지가 표시됩니다.
- AWS Organizations trusted access 아래에서 Edit을 선택합니다. AWS Organizations 액세스 페이지가 표시됩니다.
- Enable을 선택해 S3 Storage Lens 대시보드의 신뢰 액세스를 활성화합니다.
- Save changes를 선택합니다.
예시
다음 예시는 AWS CLI에서 S3 Storage Lens용 AWS Organizations 신뢰 액세스를 활성화하는 방법을 보여줘요.
aws organizations enable-aws-service-access --service-principal storage-lens.s3.amazonaws.com
예시 - Java용 SDK로 S3 Storage Lens용 AWS Organizations 신뢰 액세스 활성화
다음 예시는 Java용 SDK에서 S3 Storage Lens 신뢰 액세스를 활성화하는 방법을 보여줘요. 이 예시를 사용하려면 입력 자리 표시자(user input placeholders)를 자신의 정보로 바꿔주세요.
import com.amazonaws.AmazonServiceException;
import com.amazonaws.SdkClientException;
import com.amazonaws.auth.profile.ProfileCredentialsProvider;
import com.amazonaws.regions.Regions;
import com.amazonaws.services.organizations.AWSOrganizations;
import com.amazonaws.services.organizations.AWSOrganizationsClient;
import com.amazonaws.services.organizations.model.EnableAWSServiceAccessRequest;
public class EnableOrganizationsTrustedAccess {
private static final String S3_STORAGE_LENS_SERVICE_PRINCIPAL = "storage-lens.s3.amazonaws.com";
public static void main(String[] args) {
try {
AWSOrganizations organizationsClient = AWSOrganizationsClient.builder()
.withCredentials(new ProfileCredentialsProvider())
.withRegion(Regions.US_EAST_1)
.build();
organizationsClient.enableAWSServiceAccess(new EnableAWSServiceAccessRequest()
.withServicePrincipal(S3_STORAGE_LENS_SERVICE_PRINCIPAL));
} catch (AmazonServiceException e) {
// The call was transmitted successfully, but AWS Organizations couldn't process
// it and returned an error response.
e.printStackTrace();
} catch (SdkClientException e) {
// AWS Organizations couldn't be contacted for a response, or the client
// couldn't parse the response from AWS Organizations.
e.printStackTrace();
}
}
}
더 알아보기
- S3 Storage Lens 신뢰 액세스 비활성화하기
- S3 Storage Lens 위임 관리자 등록하기