Change Bucket Policy
When modifying a policy, you can add new rules, edit or delete existing ones. You can also add and delete conditions in rules.
Edit rule
When editing rules, you can change all settings, as well as add, modify, and delete conditions.
-
In the Control Panel, in the top menu, click Products and select S3.
-
Go to Buckets.
-
Open the bucket page → Access policy tab.
-
Click Edit.
-
Open the rule card.
-
Change the rule name.
-
In the Access field, select the rule type.
-
Specify the principal: select the users to whom the rule will apply:
- all — to users with any role and unauthorized users who accessed the bucket;
- authorized — for individual project users.
-
If you selected access for authorized users, add users from the list.
-
Select the set of actions applied in the rule:
- reader — a set of rights to view the bucket and objects in it;
- editor — a set of rights to edit the bucket and objects in it;
- custom — an empty set to which you can add any actions;
- all — a set of all actions.
-
If you selected the Custom set, add actions to it.
-
Optional: if you selected another set, add new actions or remove pre-filled ones if necessary. When editing a set, its type will change to Custom.
-
Specify the bucket resources to which the rule will apply. You cannot specify resources of another bucket:
- all bucket objects:
<bucket_name>/* - objects with a specific prefix:
<bucket_name>/<prefix>/* - object:
<bucket_name>/<prefix>/<object_name>
- all bucket objects:
-
Optional: to add a condition that determines when the rule will apply, click Add condition. You can add any number of conditions. For the condition, specify:
- key — the parameter to which the condition will apply;
- operator — checks whether the value in the request matches the key value;
- value — the key value; you can add multiple values;
- optional: select the Apply if field exists checkbox (equivalent to the
IfExistsoperator). If the checkbox is selected and the field with such a key exists, the condition will be applied. If the field does not exist, it will be created with the specified value.changes to the rule.
-
Click Save.
Delete rule
- In the Control Panel, in the top menu, click Products and select S3.
- Go to Buckets.
- Open the bucket page → Access policy tab.
- Click Edit.
- In the menu of the rule, click Delete rule → Delete.