image.png

image.png

image.png

image.png

image.png

image.png

"Condition": {
    "Bool": {
        "elasticfilesystem:AccessedViaMountTarget": "true"
    }
}

권한 설정 후 re-mount가 필요하다.

{
    "Version": "2012-10-17",
    "Id": "efs-policy-wizard-67384a9c-0873-47c8-9efe-eebe4de8e355",
    "Statement": [
        {
            "Effect": "Deny",
            "Principal": {
                "AWS": "*"
            },
            "Action": "*",
            "Resource": "arn:aws:elasticfilesystem:ap-northeast-2:362708816803:file-system/fs-0e74e865ada055dc7",
            "Condition": {
                "Bool": {
                    "elasticfilesystem:AccessedViaMountTarget": "false"
                }
            }
        },
        {
            "Effect": "Deny",
            "Principal": {
                "AWS": "*"
            },
            "Action": "*",
            "Resource": "arn:aws:elasticfilesystem:ap-northeast-2:362708816803:file-system/fs-0e74e865ada055dc7",
            "Condition": {
                "Bool": {
                    "aws:SecureTransport": "false"
                }
            }
        },
        {
            "Effect": "Allow",
            "Principal": {
                "AWS": "arn:aws:iam::362708816803:role/efs-attach-ec2-role"
            },
            "Action": [
                "elasticfilesystem:ClientRootAccess",
                "elasticfilesystem:ClientWrite",
                "elasticfilesystem:ClientMount"
            ],
            "Resource": "arn:aws:elasticfilesystem:ap-northeast-2:362708816803:file-system/fs-0e74e865ada055dc7"
        }
    ]
}