Skip to content

Commit 141d854

Browse files
Scppatches (#1155)
* Incorporated SCP changes from closed PRs * Added SCP changes re private marketplace
1 parent 10a2bb3 commit 141d854

File tree

5 files changed

+16
-5
lines changed

5 files changed

+16
-5
lines changed

reference-artifacts/SCPs/ASEA-Guardrails-Part0-CoreOUs.json

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -78,10 +78,13 @@
7878
"kms:PutKeyPolicy",
7979
"kms:ScheduleKeyDeletion"
8080
],
81-
"Resource": "arn:aws:kms:::alias/${ACCELERATOR_PREFIX_ND}*",
81+
"Resource": "*",
8282
"Condition": {
8383
"ArnNotLike": {
8484
"aws:PrincipalARN": ["arn:aws:iam::*:role/${ACCELERATOR_PREFIX}*"]
85+
},
86+
"ForAnyValue:StringLike": {
87+
"kms:ResourceAliases": "alias/${ACCELERATOR_PREFIX_ND}*"
8588
}
8689
}
8790
},

reference-artifacts/SCPs/ASEA-Guardrails-Part0-WkldOUs.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -78,13 +78,17 @@
7878
"kms:PutKeyPolicy",
7979
"kms:ScheduleKeyDeletion"
8080
],
81-
"Resource": "arn:aws:kms:::alias/${ACCELERATOR_PREFIX_ND}*",
81+
"Resource": "*",
8282
"Condition": {
8383
"ArnNotLike": {
8484
"aws:PrincipalARN": ["arn:aws:iam::*:role/${ACCELERATOR_PREFIX}*"]
85+
},
86+
"ForAnyValue:StringLike": {
87+
"kms:ResourceAliases": "alias/${ACCELERATOR_PREFIX_ND}*"
8588
}
8689
}
8790
},
91+
8892
{
8993
"Sid": "IAM",
9094
"Effect": "Deny",

reference-artifacts/SCPs/ASEA-Guardrails-Sandbox.json

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,8 @@
99
"aws-marketplace:AssociateProductsWithPrivate*",
1010
"aws-marketplace:DescribePrivate*",
1111
"aws-marketplace:DisassociateProducts*",
12-
"aws-marketplace:ListPrivate*"
12+
"aws-marketplace:ListPrivate*",
13+
"aws-marketplace:StartChangeSet"
1314
],
1415
"Resource": "*"
1516
},

reference-artifacts/SCPs/ASEA-Guardrails-Sensitive.json

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,8 @@
99
"aws-marketplace:AssociateProductsWithPrivate*",
1010
"aws-marketplace:DescribePrivate*",
1111
"aws-marketplace:DisassociateProducts*",
12-
"aws-marketplace:ListPrivate*"
12+
"aws-marketplace:ListPrivate*",
13+
"aws-marketplace:StartChangeSet"
1314
],
1415
"Resource": "*"
1516
},
@@ -257,6 +258,7 @@
257258
"s3:GetMultiR*",
258259
"s3:ListMultiR*",
259260
"s3:PutMultiR*",
261+
"sso:DescribeRegisteredRegions",
260262
"sns:Publish",
261263
"tag:GetResources"
262264
],

reference-artifacts/SCPs/ASEA-Guardrails-Unclass.json

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,8 @@
99
"aws-marketplace:AssociateProductsWithPrivate*",
1010
"aws-marketplace:DescribePrivate*",
1111
"aws-marketplace:DisassociateProducts*",
12-
"aws-marketplace:ListPrivate*"
12+
"aws-marketplace:ListPrivate*",
13+
"aws-marketplace:StartChangeSet"
1314
],
1415
"Resource": "*"
1516
},

0 commit comments

Comments
 (0)