Skip to main content
NetApp Knowledge Base

CONTAP-760202: RFE: Request functionality to set the value arn:s3::$[aws:username]/* in the resource field when editing S3 policy

Views:
7
Visibility:
Public
Votes:
0
Category:
ontap-9
Specialty:
core
Last Updated:

Issue

Can it be specified in an S3 policy that a “Allow all” rule applies to all buckets that have the same name as the user, e.g., user “example,” bucket “example”? -resource arn:s3::$[aws:username]/*
When this is tested follow error is displayed from CLI and GUI:
 
::> vserver object-store-server policy statement create -vserver svm_name -policy policy_name -effect allow -action object_store_actions -resource arn:s3::$[aws:username]/*
 
The value /${aws:username}/" is not valid for field "-resource". Valid ways to specify a resource are "*", "<bucket-name>", "<bucket-name>/.../...".".
 
Error seen when editing a policy statement 
Failed to modify policy statement for policy "test". Reason: "The value "/${aws:username}/" is not valid for field "-resource". Valid ways to specify a resource are "*", "<bucket-name>", "<bucket-name>/.../...".".
 

Sign in to view the entire content of this KB article.

New to NetApp?

Learn more about our award-winning Support

NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.