要将AWS SSO与AWS Directory Service集成,您可以按照以下步骤操作:
aws ds create-directory --name my-directory --password my-password --size Small --edition Standard
aws sso-admin create-instance --instance-arn arn:aws:sso:::instance/ssoins-1234567890abcdef --identity-store SSO_DIRECTORY --domains my-directory
aws sso-admin create-permission-set --instance-arn arn:aws:sso:::instance/ssoins-1234567890abcdef --name my-permission-set --description "My Permission Set" --session-duration 3600 --inline-policy '{"Version": "2012-10-17","Statement": [{"Effect": "Allow","Action": "s3:ListAllMyBuckets","Resource": "*"}]}'
aws sso-admin create-account-assignment --instance-arn arn:aws:sso:::instance/ssoins-1234567890abcdef --target-id my-user --target-type AWS_ACCOUNT --permission-set-arn arn:aws:sso:::permissionSet/ssoins-1234567890abcdef/my-permission-set
请注意,上述代码示例中的ARN和其他参数应根据您的实际情况进行替换。您还可以使用AWS Management Console或AWS SDK进行相同的操作。