Example bucket policies for directory buckets
This section provides example directory bucket policies. To use these policies, replace
the with your own
information.user input placeholders
The following example bucket policy allows Amazon Web Services account ID
to use the
111122223333CreateSession API operation for the specified directory bucket. When no session
mode is specified, the session will be created with the maximum allowable privilege
(attempting ReadWrite first, then ReadOnly if not permitted).
This policy grants access to the Zonal endpoint (object level) API operations.
Example– Bucket policy to allow CreateSession calls
Example– Bucket policy to allow CreateSession calls with a
ReadOnly session
The following example bucket policy allows Amazon Web Services account ID
to use the
111122223333CreateSession API operation. This policy uses the
s3express:SessionMode condition key with the ReadOnly
value to set a read-only session.
Example– Bucket policy to allow cross-account access for CreateSession
calls
The following example bucket policy allows Amazon Web Services account ID
to use the
111122223333CreateSession API operation for the specified directory bucket that's
owned by Amazon Web Services account ID
.444455556666