<BUCKET_NAME> は S3 のバケット名、<SOURCE_IPADRESS> は制限したいIPアドレスとします。
{ "Version": "2008-10-17", "Id": "PolicyAccessCtrl", "Statement": [ { "Sid": "StmtAccessCtrl", "Effect": "Deny", "Principal": { "AWS": "*" }, "Action": "s3:*", "Resource": "arn:aws:s3:::<BUCKET_NAME>/*", "Condition": { "NotIpAddress": { "aws:SourceIp": [ "<SOURCE_IPADDRESS>" ] } } }, { "Sid": "StmtAccessCtrl", "Effect": "Allow", "Principal": { "AWS": "*" }, "Action": "s3:GetObject", "Resource": "arn:aws:s3:::<BUCKET_NAME>/*", "Condition": { "IpAddress": { "aws:SourceIp": [ "<SOURCE_IPADDRESS>" ] } } } ] }