Skip to content

Commit

Permalink
skip: Merge remote-tracking branch 'origin/update_iam_per_policy' int…
Browse files Browse the repository at this point in the history
…o feature/policy_testing_v2
  • Loading branch information
anna-shcherbak committed Jun 21, 2024
2 parents 3163f11 + 079e10b commit 7b1d832
Show file tree
Hide file tree
Showing 70 changed files with 576 additions and 573 deletions.
433 changes: 206 additions & 227 deletions iam/All-permissions_1.json

Large diffs are not rendered by default.

94 changes: 69 additions & 25 deletions iam/All-permissions_2.json
Original file line number Diff line number Diff line change
@@ -1,27 +1,71 @@
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"batch:DescribeComputeEnvironments",
"cloudformation:ListStacks",
"cloudwatch:DescribeAlarmsForMetric",
"events:ListRules",
"events:ListTargetsByRule",
"guardduty:GetDetector",
"guardduty:GetMasterAccount",
"iam:ListVirtualMFADevices",
"iam:ListAttachedRolePolicies",
"kafka:ListClustersV2",
"lambda:GetFunctionConfiguration",
"wafv2:ListWebACLs",
"workspaces:DescribeWorkspaceImages",
"workspaces:DescribeWorkspaces",
"workspaces:DescribeWorkspacesConnectionStatus",
"xray:GetEncryptionConfig"
],
"Resource": "*"
}
]
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"route53:ListHostedZones",
"route53:ListQueryLoggingConfigs",
"route53:ListResourceRecordSets",
"route53:ListTagsForResources",
"route53domains:ListDomains",
"route53domains:ListTagsForDomain",
"s3:GetBucketAcl",
"s3:GetBucketLifecycle",
"s3:GetBucketLocation",
"s3:GetBucketLogging",
"s3:GetBucketNotification",
"s3:GetBucketObjectLockConfiguration",
"s3:GetBucketOwnershipControls",
"s3:GetBucketPolicy",
"s3:GetBucketPublicAccessBlock",
"s3:GetBucketReplication",
"s3:GetBucketTagging",
"s3:GetBucketVersioning",
"s3:GetBucketWebsite",
"s3:GetEncryptionConfiguration",
"s3:GetLifecycleConfiguration",
"s3:GetObject",
"s3:GetReplicationConfiguration",
"s3:ListAllMyBuckets",
"s3:ListBucket",
"sagemaker:DescribeEndpointConfig",
"sagemaker:DescribeModel",
"sagemaker:DescribeNotebookInstance",
"sagemaker:ListEndpointConfigs",
"sagemaker:ListModels",
"sagemaker:ListNotebookInstances",
"sagemaker:ListTags",
"secretsmanager:DescribeSecret",
"secretsmanager:ListSecrets",
"securityhub:DescribeHub",
"sns:GetTopicAttributes",
"sns:ListTagsForResource",
"sns:ListTopics",
"sqs:GetQueueAttributes",
"sqs:ListQueues",
"ssm:DescribeInstanceInformation",
"ssm:ListResourceComplianceSummaries",
"states:DescribeStateMachine",
"states:ListStateMachine",
"tag:GetResources",
"waf-regional:GetWebACL",
"waf-regional:ListResourcesForWebACL",
"waf-regional:ListWebACLs",
"waf:GetRule",
"waf:GetWebACL",
"waf:ListActivatedRulesInRuleGroup",
"waf:ListRuleGroups",
"waf:ListRules",
"waf:ListWebACLs",
"wafv2:ListWebACLs",
"workspaces:DescribeWorkspaceDirectories",
"workspaces:DescribeWorkspaceImages",
"workspaces:DescribeWorkspaces",
"workspaces:DescribeWorkspacesConnectionStatus",
"xray:GetEncryptionConfig"
],
"Resource": "*"
}
]
}
Original file line number Diff line number Diff line change
Expand Up @@ -4,8 +4,7 @@
{
"Effect": "Allow",
"Action": [
"iam:ListMFADevices",
"iam:GetAccountPasswordPolicy",
"iam:GetCredentialReport",
"iam:ListUsers",
"iam:GetUser"
],
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,8 @@
"Effect": "Allow",
"Action": [
"iam:ListUsers",
"iam:GetUser"
"iam:GetUser",
"iam:GetCredentialReport"
],
"Resource": "*"
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,6 @@
"s3:GetBucketWebsite",
"s3:GetBucketNotification",
"s3:GetBucketVersioning",
"s3:GetBucketLifecycle",
"s3:GetLifecycleConfiguration",
"s3:GetReplicationConfiguration",
"s3:GetBucketPolicy"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,8 +4,7 @@
{
"Effect": "Allow",
"Action": [
"rds:DescribeDBInstances",
"tag:GetResources"
"rds:DescribeDBInstances"
],
"Resource": "*"
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,8 +4,7 @@
{
"Effect": "Allow",
"Action": [
"rds:DescribeDBInstances",
"tag:GetResources"
"rds:DescribeDBInstances"
],
"Resource": "*"
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,8 @@
"iam:ListAccountAliases",
"iam:ListMFADevices",
"iam:ListVirtualMFADevices",
"iam:GetCredentialReport"
"iam:GetCredentialReport",
"iam:GenerateCredentialReport"
],
"Resource": "*"
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,6 @@
"Effect": "Allow",
"Action": [
"iam:GenerateCredentialReport",
"iam:ListAccountAliases",
"iam:ListUsers",
"iam:GetUser",
"iam:GetCredentialReport"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,8 +4,7 @@
{
"Effect": "Allow",
"Action": [
"tag:GetResources",
"rds:DescribeDBInstances"
"tag:GetResources"
],
"Resource": "*"
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,6 @@
{
"Effect": "Allow",
"Action": [
"tag:GetResources",
"rds:DescribeDBInstances"
],
"Resource": "*"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,6 @@
"s3:GetBucketWebsite",
"s3:GetBucketNotification",
"s3:GetBucketVersioning",
"s3:GetBucketLifecycle",
"s3:GetLifecycleConfiguration",
"s3:GetReplicationConfiguration",
"s3:GetBucketPolicy",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,6 @@
"s3:GetBucketWebsite",
"s3:GetBucketNotification",
"s3:GetBucketVersioning",
"s3:GetBucketLifecycle",
"s3:GetLifecycleConfiguration",
"s3:GetReplicationConfiguration",
"s3:GetBucketPolicy",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,6 @@
"s3:GetBucketWebsite",
"s3:GetBucketNotification",
"s3:GetBucketVersioning",
"s3:GetBucketLifecycle",
"s3:GetLifecycleConfiguration",
"s3:GetReplicationConfiguration",
"s3:GetBucketPolicy",
Expand Down
Original file line number Diff line number Diff line change
@@ -1,14 +1,13 @@
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"cloudtrail:DescribeTrails",
"cloudtrail:GetTrailStatus",
"iam:ListAccountAliases"
],
"Resource": "*"
}
]
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"tag:GetResources",
"cloudtrail:DescribeTrails"
],
"Resource": "*"
}
]
}
Original file line number Diff line number Diff line change
@@ -1,15 +1,16 @@
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"kms:DescribeKey",
"kms:ListKeys",
"kms:GetKeyRotationStatus",
"tag:GetResources"
],
"Resource": "*"
}
]
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"kms:DescribeKey",
"kms:ListKeys",
"kms:GetKeyRotationStatus",
"tag:GetResources",
"kms:ListAliases"
],
"Resource": "*"
}
]
}
Original file line number Diff line number Diff line change
@@ -1,14 +1,14 @@
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"es:ListDomainNames",
"es:DescribeElasticsearchDomains",
"es:ListTags"
],
"Resource": "*"
}
]
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"es:DescribeDomains",
"es:ListDomainNames",
"es:ListTags"
],
"Resource": "*"
}
]
}
Original file line number Diff line number Diff line change
@@ -1,14 +1,14 @@
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"es:ListDomainNames",
"es:DescribeElasticsearchDomains",
"es:ListTags"
],
"Resource": "*"
}
]
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"es:DescribeDomains",
"es:ListDomainNames",
"es:ListTags"
],
"Resource": "*"
}
]
}
Original file line number Diff line number Diff line change
Expand Up @@ -12,11 +12,9 @@
"s3:GetBucketWebsite",
"s3:GetBucketNotification",
"s3:GetBucketVersioning",
"s3:GetBucketLifecycle",
"s3:GetLifecycleConfiguration",
"s3:GetReplicationConfiguration",
"s3:GetBucketPolicy",
"s3:GetEncryptionConfiguration"
"s3:GetBucketPolicy"
],
"Resource": "*"
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,7 @@
"Effect": "Allow",
"Action": [
"iam:ListUsers",
"iam:GetUser",
"iam:ListUserPolicies"
],
"Resource": "*"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,8 +4,7 @@
{
"Effect": "Allow",
"Action": [
"rds:DescribeDBClusters",
"tag:GetResources"
"rds:DescribeDBClusters"
],
"Resource": "*"
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,10 @@
{
"Sid": "VisualEditor0",
"Effect": "Allow",
"Action": "access-analyzer:ListAnalyzers",
"Action": [
"access-analyzer:ListAnalyzers",
"iam:ListAccountAliases"
],
"Resource": "*"
}
]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,8 @@
{
"Effect": "Allow",
"Action": [
"iam:ListAccessKeys",
"iam:GetUser",
"iam:ListAccessKeys"
],
"Resource": "*"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,12 +12,10 @@
"s3:GetBucketWebsite",
"s3:GetBucketNotification",
"s3:GetBucketVersioning",
"s3:GetBucketLifecycle",
"s3:GetLifecycleConfiguration",
"s3:GetReplicationConfiguration",
"s3:GetBucketPolicy",
"s3:GetBucketPublicAccessBlock",
"s3:GetEncryptionConfiguration"
"s3:GetBucketPublicAccessBlock"
],
"Resource": "*"
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,11 +12,9 @@
"s3:GetBucketWebsite",
"s3:GetBucketNotification",
"s3:GetBucketVersioning",
"s3:GetBucketLifecycle",
"s3:GetLifecycleConfiguration",
"s3:GetReplicationConfiguration",
"s3:GetBucketPolicy",
"s3:GetEncryptionConfiguration"
"s3:GetBucketPolicy"
],
"Resource": "*"
}
Expand Down
Loading

0 comments on commit 7b1d832

Please sign in to comment.