Within IAM, can I restrict a group of users to access/launch/terminate only certain EC2 AMIs or instances?
问题 What the title says. Within the master AWS account, I have several personal accounts, i.e. AWS Identity and Access Management (IAM) users. I would like to assign certain IAM users to groups and prevent them from terminating certain Amazon EC2 instances, de-registering certain Amazon Machine Images (AMIs), etc. I don't mind if they're playing with their own stuff, but I don't want them to touch my stuff. Is that possible? 回答1: Update AWS has just announced Resource-Level Permissions for Amazon