Skip to content

Commit

Permalink
upd: update policy minimal IAM permissions file for a number of policies
Browse files Browse the repository at this point in the history
  • Loading branch information
anna-shcherbak committed Jun 21, 2024
1 parent 008c472 commit 333602e
Show file tree
Hide file tree
Showing 72 changed files with 304 additions and 325 deletions.
1 change: 0 additions & 1 deletion iam/All-permissions_1.json
Original file line number Diff line number Diff line change
Expand Up @@ -214,7 +214,6 @@
"states:DescribeStateMachine",
"states:ListStateMachine",
"tag:GetResources",
"tagging:GetResources",
"waf-regional:ListResourcesForWebACL",
"waf-regional:ListWebACLs",
"waf-regional:GetWebACL",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,8 +4,7 @@
{
"Effect": "Allow",
"Action": [
"iam:ListMFADevices",
"iam:GetAccountPasswordPolicy",
"iam:GetCredentialReport",
"iam:ListUsers",
"iam:GetUser"
],
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,8 @@
"Effect": "Allow",
"Action": [
"iam:ListUsers",
"iam:GetUser"
"iam:GetUser",
"iam:GetCredentialReport"
],
"Resource": "*"
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,6 @@
"s3:GetBucketWebsite",
"s3:GetBucketNotification",
"s3:GetBucketVersioning",
"s3:GetBucketLifecycle",
"s3:GetLifecycleConfiguration",
"s3:GetReplicationConfiguration",
"s3:GetBucketPolicy"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,8 +4,7 @@
{
"Effect": "Allow",
"Action": [
"rds:DescribeDBInstances",
"tag:GetResources"
"rds:DescribeDBInstances"
],
"Resource": "*"
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,8 +4,7 @@
{
"Effect": "Allow",
"Action": [
"rds:DescribeDBInstances",
"tag:GetResources"
"rds:DescribeDBInstances"
],
"Resource": "*"
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,8 @@
"iam:ListAccountAliases",
"iam:ListMFADevices",
"iam:ListVirtualMFADevices",
"iam:GetCredentialReport"
"iam:GetCredentialReport",
"iam:GenerateCredentialReport"
],
"Resource": "*"
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,6 @@
"Effect": "Allow",
"Action": [
"iam:GenerateCredentialReport",
"iam:ListAccountAliases",
"iam:ListUsers",
"iam:GetUser",
"iam:GetCredentialReport"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,8 +4,7 @@
{
"Effect": "Allow",
"Action": [
"tag:GetResources",
"rds:DescribeDBInstances"
"tag:GetResources"
],
"Resource": "*"
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,6 @@
{
"Effect": "Allow",
"Action": [
"tag:GetResources",
"rds:DescribeDBInstances"
],
"Resource": "*"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,6 @@
"s3:GetBucketWebsite",
"s3:GetBucketNotification",
"s3:GetBucketVersioning",
"s3:GetBucketLifecycle",
"s3:GetLifecycleConfiguration",
"s3:GetReplicationConfiguration",
"s3:GetBucketPolicy",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,6 @@
"s3:GetBucketWebsite",
"s3:GetBucketNotification",
"s3:GetBucketVersioning",
"s3:GetBucketLifecycle",
"s3:GetLifecycleConfiguration",
"s3:GetReplicationConfiguration",
"s3:GetBucketPolicy",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,6 @@
"s3:GetBucketWebsite",
"s3:GetBucketNotification",
"s3:GetBucketVersioning",
"s3:GetBucketLifecycle",
"s3:GetLifecycleConfiguration",
"s3:GetReplicationConfiguration",
"s3:GetBucketPolicy",
Expand Down
Original file line number Diff line number Diff line change
@@ -1,14 +1,13 @@
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"cloudtrail:DescribeTrails",
"cloudtrail:GetTrailStatus",
"iam:ListAccountAliases"
],
"Resource": "*"
}
]
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"tag:GetResources",
"cloudtrail:DescribeTrails"
],
"Resource": "*"
}
]
}
Original file line number Diff line number Diff line change
@@ -1,15 +1,16 @@
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"kms:DescribeKey",
"kms:ListKeys",
"kms:GetKeyRotationStatus",
"tagging:GetResources"
],
"Resource": "*"
}
]
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"kms:DescribeKey",
"kms:ListKeys",
"kms:GetKeyRotationStatus",
"tag:GetResources",
"kms:ListAliases"
],
"Resource": "*"
}
]
}
Original file line number Diff line number Diff line change
@@ -1,14 +1,14 @@
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"es:ListDomainNames",
"es:DescribeElasticsearchDomains",
"es:ListTags"
],
"Resource": "*"
}
]
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"es:DescribeDomains",
"es:ListDomainNames",
"es:ListTags"
],
"Resource": "*"
}
]
}
Original file line number Diff line number Diff line change
@@ -1,14 +1,14 @@
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"es:ListDomainNames",
"es:DescribeElasticsearchDomains",
"es:ListTags"
],
"Resource": "*"
}
]
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"es:DescribeDomains",
"es:ListDomainNames",
"es:ListTags"
],
"Resource": "*"
}
]
}
Original file line number Diff line number Diff line change
Expand Up @@ -12,11 +12,9 @@
"s3:GetBucketWebsite",
"s3:GetBucketNotification",
"s3:GetBucketVersioning",
"s3:GetBucketLifecycle",
"s3:GetLifecycleConfiguration",
"s3:GetReplicationConfiguration",
"s3:GetBucketPolicy",
"s3:GetEncryptionConfiguration"
"s3:GetBucketPolicy"
],
"Resource": "*"
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,7 @@
"Effect": "Allow",
"Action": [
"iam:ListUsers",
"iam:GetUser",
"iam:ListUserPolicies"
],
"Resource": "*"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,8 +4,7 @@
{
"Effect": "Allow",
"Action": [
"rds:DescribeDBClusters",
"tag:GetResources"
"rds:DescribeDBClusters"
],
"Resource": "*"
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,10 @@
{
"Sid": "VisualEditor0",
"Effect": "Allow",
"Action": "access-analyzer:ListAnalyzers",
"Action": [
"access-analyzer:ListAnalyzers",
"iam:ListAccountAliases"
],
"Resource": "*"
}
]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,8 @@
{
"Effect": "Allow",
"Action": [
"iam:ListAccessKeys",
"iam:GetUser",
"iam:ListAccessKeys"
],
"Resource": "*"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,12 +12,10 @@
"s3:GetBucketWebsite",
"s3:GetBucketNotification",
"s3:GetBucketVersioning",
"s3:GetBucketLifecycle",
"s3:GetLifecycleConfiguration",
"s3:GetReplicationConfiguration",
"s3:GetBucketPolicy",
"s3:GetBucketPublicAccessBlock",
"s3:GetEncryptionConfiguration"
"s3:GetBucketPublicAccessBlock"
],
"Resource": "*"
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,11 +12,9 @@
"s3:GetBucketWebsite",
"s3:GetBucketNotification",
"s3:GetBucketVersioning",
"s3:GetBucketLifecycle",
"s3:GetLifecycleConfiguration",
"s3:GetReplicationConfiguration",
"s3:GetBucketPolicy",
"s3:GetEncryptionConfiguration"
"s3:GetBucketPolicy"
],
"Resource": "*"
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,8 +4,7 @@
{
"Effect": "Allow",
"Action": [
"rds:DescribeDBClusters",
"tag:GetResources"
"rds:DescribeDBInstances"
],
"Resource": "*"
}
Expand Down
4 changes: 2 additions & 2 deletions terraform/ecc-aws-149-rds_public_access_disabled/red/rds.tf
Original file line number Diff line number Diff line change
Expand Up @@ -7,8 +7,8 @@ resource "random_password" "this" {

resource "aws_db_instance" "this" {
engine = "mysql"
engine_version = "5.7"
instance_class = "db.t2.micro"
engine_version = "8.0.35"
instance_class = "db.t3.micro"
allocated_storage = 10
storage_type = "gp2"
db_name = "database149red"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -77,7 +77,9 @@ resource "aws_kms_key" "this" {

resource "random_password" "this" {
length = 12
special = true
numeric = true
min_lower = 1
min_numeric = 1
min_special = 1
min_upper = 1
override_special = "!#$%*()-_=+[]{}:?"
}
Original file line number Diff line number Diff line change
@@ -1,12 +1,14 @@
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"es:DescribeElasticsearchDomain"
],
"Resource": "*"
}
]
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"es:DescribeDomains",
"es:ListDomainNames",
"es:ListTags"
],
"Resource": "*"
}
]
}
Original file line number Diff line number Diff line change
@@ -1,12 +1,14 @@
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"es:DescribeElasticsearchDomains"
],
"Resource": "*"
}
]
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"es:DescribeDomains",
"es:ListDomainNames",
"es:ListTags"
],
"Resource": "*"
}
]
}
Loading

0 comments on commit 333602e

Please sign in to comment.