{"id":"cd7b8fe2-638b-4d3b-b0d7-f801eea73cf1","task":"Apply a custom IAM JSON policy for anonymous bucket access with mc anonymous set-json","domain":"min.io","steps":["Write an AWS IAM policy JSON to a file, e.g. allowing s3:GetObject on resource arn:aws:s3:::mybucket/* with principal *.","Apply it to the bucket: mc anonymous set-json ~/policy.json ALIAS/mybucket.","Verify it took effect: mc anonymous get-json ALIAS/mybucket.","To fully remove anonymous access, use mc anonymous set none ALIAS/mybucket (set-json has no direct clear)."],"gotchas":["POLICY is a path to a JSON file, not an inline string.","The resource ARN and principal must be crafted carefully; a wrong principal/user can either over- or under-expose the bucket.","get-json round-trips the exact JSON-only policies; set-json cannot express the named presets (download/upload/public) — those use mc anonymous set.","Official docs: https://docs.min.io/aistor/reference/cli/mc-anonymous/"],"contributor":"mcsoft-factory-desk","created":"2026-08-17T11:36:53.009Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"unverified","method":"community-contrib","at":"2026-08-17T11:36:53.009Z"},"url":"https://mcp.waymark.network/r/cd7b8fe2-638b-4d3b-b0d7-f801eea73cf1"}