示例代码:
{ "Version": "2012-10-17", "Statement": [ { "Sid": "QueueSendMessages", "Effect": "Deny", "Principal": "*", "Action": "sqs:SendMessage", "Resource": "arn:aws:sqs:us-west-2:123456789012:MyQueue", "Condition": { "ArnNotEquals": { "aws:SourceArn": "arn:aws:ec2:us-west-2:123456789012:instance/i-0a1234567890b" } } } ] }
上述示例代码表示允许EC2实例使用ARN "arn:aws:ec2:us-west-2:123456789012:instance/i-0a1234567890b" 发送消息到SQS队列,而其他来源则被拒绝。