IAM(Identity and Access Management,身份和访问管理)控制 AWS 中的谁可以做什么 — 管理用户、组、角色和权限。这是 AWS 安全的基础:每项操作都通过 IAM 授权,因此理解它是必不可少的。
IAM 管理什么
IAM controls AUTHENTICATION (who you are) and AUTHORIZATION (what you can do):
USERS → individual identities (people or applications) with credentials
GROUPS → collections of users (assign permissions to a group → all its users get them)
ROLES → identities ASSUMED temporarily (by users, services, or AWS resources)
— no permanent credentials; key for services/cross-account access
POLICIES → JSON documents defining PERMISSIONS (what actions on what resources)
