场景: 限制仅能通过IAM角色sso-admin来访问NAT网关。策略示例:
{ "Statement": [ { "Effect": "Allow", "Action": [ "natgateway:*" ], "Resource": [ "*" ], "Condition":{ "StringEquals":{ "volc:PrincipalTrn":"trn:iam::20000123**:role/sso-admin" } } } ] }