VAST Data s3policies API
Identity policies comprise statements that grant or deny permissions for any combination of specific actions on any combination of specified resources. They are the primary access control method available with the VAST Cluster S3 service. Identity policies are manageable exclusively through VMS. They are written in JSON document structure. Multiple identity policies can be attached to multiple users and to multiple groups. Permissions denied by identity policies override permissions allowed by identity policies. Permissions allowed or denied by identity policies override S3 ACLs.