Skip to content

Commit 6c37079

Browse files
update Sensitive SCP to include ClientVPN (#725)
* update Sensitive SCP to include ClientVPN * block additional clientvpn action Co-authored-by: Brian969 <56414362+Brian969@users.noreply.github.com>
1 parent ac42992 commit 6c37079

File tree

1 file changed

+6
-0
lines changed

1 file changed

+6
-0
lines changed

reference-artifacts/SCPs/ASEA-Guardrails-Sensitive.json

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,8 +6,11 @@
66
"Effect": "Deny",
77
"Action": [
88
"ec2:AcceptVpcPeeringConnection",
9+
"ec2:AssociateClientVpnTargetNetwork",
10+
"ec2:AuthorizeClientVpnIngress",
911
"ec2:AttachEgressOnlyInternetGateway",
1012
"ec2:AttachInternetGateway",
13+
"ec2:CreateClientVpnEndpoint",
1114
"ec2:CreateEgressOnlyInternetGateway",
1215
"ec2:CreateInternetGateway",
1316
"ec2:CreateNatGateway",
@@ -18,6 +21,7 @@
1821
"ec2:CreateVpc",
1922
"ec2:CreateVpcEndpoint",
2023
"ec2:CreateVpcPeeringConnection",
24+
"ec2:DeleteClientVpnEndpoint",
2125
"ec2:DeleteNatGateway",
2226
"ec2:DeleteTransitGatewayRoute",
2327
"ec2:DeleteTransitGatewayRouteTable",
@@ -38,8 +42,10 @@
3842
"ec2:DisassociateRouteTable",
3943
"ec2:AllocateAddress",
4044
"ec2:AssociateAddress",
45+
"ec2:ModifyClientVpnEndpoint",
4146
"ec2:ModifyImageAttribute",
4247
"ec2:ModifySnapshotAttribute",
48+
"ec2:RevokeClientVpnIngress",
4349
"rds:ModifyDBSnapshotAttribute",
4450
"rds:ModifyDBClusterSnapshotAttribute",
4551
"globalaccelerator:Create*",

0 commit comments

Comments
 (0)