---
格式版本: 2
标题: "Amazon DynamoDB Streams now supports attribute-based access control"
原文链接: "https://aws.amazon.com/cn/about-aws/whats-new/2026/08/amazon-dynamodb-streams-abac/"
发布日期: "2026-08-19"
发布时间校准状态: "found"
发布时间需复核: "否"
发布时间来源: "llm:local:original_script_field"
发布时间证据: "postDateTime: 2026-08-19T21:03:00Z"
发布时间校准原因: "候选日期为文章元数据中的发布时间，且位于脚本字段，符合发布时间判定优先级。"
发布时间校准置信度: "1"
发布时间候选数量: 1
发布时间严格候选数量: 0
发布时间原页读取状态: "source template page reused from URL open"
发布时间未找到原因: ""
发布时间校准时间: "2026-08-21T09:55:42+08:00"
发布时间仲裁状态: "confirmed"
发布时间仲裁尝试次数: 1
发布时间仲裁耗时毫秒: 6522
发现时间: "2026-08-21T09:50:45+08:00"
入库时间: "2026-08-21T01:55:51.003Z"
来源平台: "固定入口"
搜索渠道: "fixed_url"
搜索词: "https://aws.amazon.com/new"
匹配关键词:
  []
相关厂家:
  - "AWS"
相关专家:
  []
内容类型: "网页"
抓取工具: "Free Fetch + Defuddle"
清洗工具: "Defuddle Markdown + Defuddle/Readability 正文提取"
原始附件:
  []
AI优质: "否"
AI打分: 5
AI分档: "非优质"
AI质检状态: "不通过"
AI打分理由: "内容为AWS DynamoDB Streams的ABAC功能，属于数据库流访问控制，与超节点、AI Rack、机柜级AI基础设施、供电散热互连等完全无关。"
AI质检模型: "ali-deepseek-v4-flash"
AI质检时间: "2026-08-21T09:56:36+08:00"
AI主题相关性: 0
AI来源权威性: 5
AI新颖性: 0
AI技术细节: 0
AI商业部署信号: 0
AI完整性: 0
AI摘要: "Amazon DynamoDB Streams 现支持基于属性的访问控制（ABAC），允许在 IAM 策略中使用标签条件管理数据流访问权限。每个数据流最多可附加 50 个标签，该功能已覆盖所有商业及 GovCloud 区域，且无需额外费用。"
AI摘要模型: "ali-deepseek-v4-flash"
AI摘要时间: "2026-09-07T02:13:32.966Z"
采集批次: "2026年8月21日9点50分40秒"
采集批次ID: "20260821-095040-035"
去重键: "https://aws.amazon.com/cn/about-aws/whats-new/2026/08/amazon-dynamodb-streams-abac"
---

Amazon DynamoDB Streams now supports attribute-based access control (ABAC), enabling you to use tag-based conditions in your Identity and Access Management (IAM) policies to control access to your data streams. ABAC is an authorization strategy that simplifies access management by allowing you to enforce different access levels for multiple teams and applications using fewer IAM policies. This capability is built for teams that manage DynamoDB Streams access across multiple applications and environments and need finer-grained, scalable access control.

With ABAC for DynamoDB Streams, you can attach up to 50 tags to each stream and use these tags in IAM policy conditions to grant or deny access to specific actions. For example, you can allow users to read records only from streams tagged with "environment:production" while restricting access to other environments. Stream tags are managed independently from their parent table tags, giving you flexibility to implement environment segregation, team-based isolation, and compliance requirements without creating numerous individual IAM policies.

ABAC for DynamoDB Streams is in all commercial AWS Regions and AWS GovCloud (US) Regions where Amazon DynamoDB Streams is available. There is no additional cost to use ABAC for DynamoDB Streams. To learn more, visit the [Amazon DynamoDB](https://aws.amazon.com/dynamodb) page and see the [Amazon DynamoDB Streams ABAC](https://docs.aws.amazon.com/amazondynamodb/latest/developerguide/abac-streams.html).
