<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Iam on TinyChen's Blog</title><link>https://tinychen.com/tags/iam/</link><description>Recent content in Iam on TinyChen's Blog</description><generator>Hugo</generator><language>zh-cn</language><lastBuildDate>Thu, 23 Jul 2026 12:00:00 +0800</lastBuildDate><atom:link href="https://tinychen.com/tags/iam/index.xml" rel="self" type="application/rss+xml"/><item><title>Octans-媒体库图片访问与签名URL</title><link>https://tinychen.com/20260416-octans-image-access-architecture/</link><pubDate>Thu, 16 Apr 2026 12:00:00 +0800</pubDate><guid>https://tinychen.com/20260416-octans-image-access-architecture/</guid><description>&lt;p&gt;本文主要说明自托管媒体库（以 Octans 为例）在&lt;strong&gt;媒体图片访问&lt;/strong&gt;上的架构边界：谁推导 URL、谁做鉴权、HTTP 缓存与权限变更如何共处，以及 Signed URL 与「三层资产模型」相比为何更匹配家用 / 小团队私有化场景。重点是 &lt;strong&gt;CDN / 鉴权 / 缓存&lt;/strong&gt; 的分层口径，而不是接口字段或迁移 runbook。&lt;/p&gt;</description></item><item><title>Octans-媒体库用户角色与权限分层</title><link>https://tinychen.com/20260412-octans-user-role-iam-principles/</link><pubDate>Sun, 12 Apr 2026 12:00:00 +0800</pubDate><guid>https://tinychen.com/20260412-octans-user-role-iam-principles/</guid><description>&lt;p&gt;本文主要说明一类自托管媒体库（以 Octans 为例）在**身份与访问管理（IAM）**上应先固定哪些原则：全局角色只管系统级能力，媒体库访问另用 &lt;code&gt;R/W&lt;/code&gt; 表达；再通过三类库集合与资源范围解析，把列表过滤、详情隐藏、写操作拒绝和播放 / 图片等边角资源收进同一套语义。重点是分层与边界，不是登录配置、迁移步骤或排障命令。&lt;/p&gt;</description></item><item><title>MinIO公开读与指定用户写策略</title><link>https://tinychen.com/20251114-minio-access-policy/</link><pubDate>Fri, 14 Nov 2025 18:42:58 +0800</pubDate><guid>https://tinychen.com/20251114-minio-access-policy/</guid><description>&lt;p&gt;本文主要记录在 MinIO 上实现「匿名可读、指定 Access Key 可写/管理」的 IAM 策略写法，以及用 &lt;code&gt;mc&lt;/code&gt; 附加用户策略与桶策略的步骤。&lt;/p&gt;</description></item></channel></rss>