Working with Vault Access Policy. Access Policy Examples. How to manage Glacier Vault Access.
FastGlacier
Free Windows Client for Amazon Glacier
Follow:
Like:
Share:

Working with Vault Access Policy

Glacier Vault Access Policy allows you to control access to your vaults, for instance, grant access to your vaults to another users, protect your data from accidental deletion, etc.

To Edit Vault Access Policy

1. Start FastGlacier and navigate to the vault you want to work with.

2. Click Vaults, Advanced, Access Policy

vaults-advanced-access-policy

Click Vaults, Advanced, Access Policy to open Access Policy Editor

Vault Access Policy Editor will open:

vault-policy-editor-dialog

Vault Access Policy Editor

3. Enter the policy document and click Apply:

Vault Access Policy Examples


{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "cross-account-upload",
      "Effect": "Allow",
      "Principal": {
        "AWS": "arn:aws:iam::111111111111:root"
      },
      "Action": [
        "glacier:InitiateMultipartUpload",
        "glacier:ListParts",
        "glacier:UploadArchive",
        "glacier:UploadMultipartPart",
        "glacier:AbortMultipartUpload",
        "glacier:CompleteMultipartUpload"
      ],
      "Resource": "arn:aws:glacier:us-west-2:777777777777:vaults/DailyBackup"
    }
  ]
}
Allow uploads to the vault DailyBackup in US-West Oregon region for user with account id 111111111111

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "deny-delete",
      "Effect": "Deny",
      "Principal": {
        "AWS": "*"
      },
      "Action": [
        "glacier:DeleteVaultAccessPolicy",
        "glacier:DeleteVault",
        "glacier:DeleteArchive",
        "glacier:SetVaultAccessPolicy"
      ],
      "Resource": "arn:aws:glacier:us-east-1:777777777777:vaults/sample-vault"
    }
  ]
}
Deny data deletion and access policy change for all users on the vault sample-vault

{
    "Version":"2012-10-17",
    "Statement":[
       {
          "Sid": "read-only-for-everyone",
          "Principal": "*",
          "Effect": "Allow",
          "Action": [
             "glacier:InitiateJob",
             "glacier:GetJobOutput"
          ],
          "Resource": [
             "arn:aws:glacier:us-west-2:777777777777:vaults/shared-vault"
          ]
       }
    ]
}
Grant Read-Only Permission to all AWS Accounts for the vault shared-vault

You can find more information about vault access policy language and policy examples in AWS Documentation.


Related articles

How to share the vault with another Glacier User using Vault Access Policy

FastGlacier 3.4.7 Freeware
Powered by Amazon Web Services
Social Connection
Glacier Client Logo
 
People like FastGlacier!
Our customers say

"Your client software has been wonderful to use and has made working with the Glacier service a pleasant experience. What I like most about FastGlacier is that it's extremely easy to use, even for non-technical/IT people." - Rob Costello, Pro User

"Your product recently saved me after I deleted everything I had locally. But with FG, I restored all our video and photos from AWS. Phew! Divorce averted!!" - Jamie C., USA

"Spending ~$40 on @FastGlacier was one of my best software purchases." - J Biggert (Twitter)

Related Products
Copyright © 2012-2017 NetSDK Software, LLC. All rights reserved.  Terms of Use.  Privacy Policy.