Skip to content

Commit 6c3bd88

Browse files
authored
Merge pull request #56 from aws-samples/Swara-changes
Add new services as supported by RCPs and VPCEOrgID.
2 parents 61d7f4f + a2a4f71 commit 6c3bd88

File tree

4 files changed

+59
-23
lines changed

4 files changed

+59
-23
lines changed

resource_control_policies/identity_perimeter_rcp.json

Lines changed: 19 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -7,18 +7,23 @@
77
"Principal": "*",
88
"Action": [
99
"s3:*",
10-
"sqs:*",
11-
"kms:*",
12-
"secretsmanager:*",
1310
"sts:AssumeRole",
1411
"sts:DecodeAuthorizationMessage",
1512
"sts:GetAccessKeyInfo",
1613
"sts:GetFederationToken",
1714
"sts:GetServiceBearerToken",
1815
"sts:GetSessionToken",
1916
"sts:SetContext",
20-
"aoss:*",
21-
"ecr:*"
17+
"kms:*",
18+
"sqs:*",
19+
"secretsmanager:*",
20+
"cognito-identity:*",
21+
"cognito-idp:*",
22+
"cognito-sync:*",
23+
"logs:*",
24+
"dynamodb:*",
25+
"ecr:*",
26+
"aoss:*"
2227
],
2328
"Resource": "*",
2429
"Condition": {
@@ -72,12 +77,17 @@
7277
"Principal": "*",
7378
"Action": [
7479
"s3:*",
75-
"sqs:*",
80+
"sts:*",
7681
"kms:*",
82+
"sqs:*",
7783
"secretsmanager:*",
78-
"sts:*",
79-
"aoss:*",
80-
"ecr:*"
84+
"cognito-identity:*",
85+
"cognito-idp:*",
86+
"cognito-sync:*",
87+
"logs:*",
88+
"dynamodb:*",
89+
"ecr:*",
90+
"aoss:*"
8191
],
8292
"Resource": "*",
8393
"Condition": {

resource_control_policies/network_perimeter_sourcevpc_rcp.json

Lines changed: 18 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -6,17 +6,19 @@
66
"Effect": "Deny",
77
"Principal": "*",
88
"Action": [
9-
"sqs:*",
9+
"aoss:*",
10+
"cognito-idp:*",
11+
"cognito-sync:*",
12+
"dynamodb:*",
13+
"logs:*",
1014
"secretsmanager:*",
1115
"sts:AssumeRole",
1216
"sts:DecodeAuthorizationMessage",
1317
"sts:GetAccessKeyInfo",
1418
"sts:GetFederationToken",
1519
"sts:GetServiceBearerToken",
1620
"sts:GetSessionToken",
17-
"sts:SetContext",
18-
"aoss:*",
19-
"ecr:*"
21+
"sts:SetContext"
2022
],
2123
"Resource": "*",
2224
"Condition": {
@@ -53,17 +55,19 @@
5355
"Effect": "Deny",
5456
"Principal": "*",
5557
"Action": [
56-
"sqs:*",
58+
"aoss:*",
59+
"cognito-idp:*",
60+
"cognito-sync:*",
61+
"dynamodb:*",
62+
"logs:*",
5763
"secretsmanager:*",
5864
"sts:AssumeRole",
5965
"sts:DecodeAuthorizationMessage",
6066
"sts:GetAccessKeyInfo",
6167
"sts:GetFederationToken",
6268
"sts:GetServiceBearerToken",
6369
"sts:GetSessionToken",
64-
"sts:SetContext",
65-
"aoss:*",
66-
"ecr:*"
70+
"sts:SetContext"
6771
],
6872
"Resource": "*",
6973
"Condition": {
@@ -80,17 +84,19 @@
8084
"Effect": "Deny",
8185
"Principal": "*",
8286
"Action": [
83-
"sqs:*",
87+
"aoss:*",
88+
"cognito-idp:*",
89+
"cognito-sync:*",
90+
"dynamodb:*",
91+
"logs:*",
8492
"secretsmanager:*",
8593
"sts:AssumeRole",
8694
"sts:DecodeAuthorizationMessage",
8795
"sts:GetAccessKeyInfo",
8896
"sts:GetFederationToken",
8997
"sts:GetServiceBearerToken",
9098
"sts:GetSessionToken",
91-
"sts:SetContext",
92-
"aoss:*",
93-
"ecr:*"
99+
"sts:SetContext"
94100
],
95101
"Resource": "*",
96102
"Condition": {

resource_control_policies/network_perimeter_vpceorgid_rcp.json

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,8 +6,11 @@
66
"Effect": "Deny",
77
"Principal": "*",
88
"Action": [
9+
"cognito-identity:*",
10+
"ecr:*",
11+
"kms:*",
912
"s3:*",
10-
"kms:*"
13+
"sqs:*"
1114
],
1215
"Resource": "*",
1316
"Condition": {

service_control_policies/network_perimeter_vpceorgid_scp.json

Lines changed: 18 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,33 +9,50 @@
99
"applicationinsights:*",
1010
"apprunner:*",
1111
"athena:*",
12+
"b2bi:*",
13+
"cassandra:*",
1214
"cloudformation:*",
15+
"cognito-identity:*",
1316
"comprehendmedical:*",
1417
"compute-optimizer:*",
1518
"datasync:*",
1619
"discovery:*",
20+
"dms:*",
21+
"ds-data:*",
1722
"ebs:*",
23+
"ecr:*",
24+
"ecs:*",
1825
"firehose:*",
1926
"healthlake:*",
27+
"identitystore:*",
2028
"iotfleetwise:*",
29+
"iottwinmaker:*",
2130
"iotwireless:*",
31+
"kinesisanalytics:*",
2232
"kms:*",
2333
"lambda:*",
2434
"medical-imaging:*",
35+
"network-firewall:*",
2536
"omics:*",
2637
"payment-cryptography:*",
2738
"polly:*",
39+
"pricing:*",
2840
"rbin:*",
2941
"rekognition:*",
42+
"route53:*",
3043
"s3:*",
3144
"scheduler:*",
3245
"servicediscovery:*",
3346
"servicequotas:*",
47+
"ses:*",
48+
"sms-voice:*",
49+
"sqs:*",
3450
"ssm-contacts:*",
3551
"storagegateway:*",
3652
"textract:*",
3753
"transcribe:*",
38-
"transfer:*"
54+
"transfer:*",
55+
"workmail:*"
3956
],
4057
"Resource":"*",
4158
"Condition":{

0 commit comments

Comments
 (0)