boundary.json 661 B

123456789101112131415161718192021222324252627282930313233
  1. {
  2. "Version": "2012-10-17",
  3. "Statement": [
  4. {
  5. "Sid": "ServiceBoundaries",
  6. "Effect": "Allow",
  7. "Action": [
  8. "s3:*",
  9. "ec2:*",
  10. "lambda:*",
  11. "logs:*",
  12. "sqs:*",
  13. "resource-groups:*",
  14. "ssm:*",
  15. "ssmmessages:*",
  16. "ec2messages:*"
  17. ],
  18. "Resource": "*"
  19. },
  20. {
  21. "Sid": "RoleInNamespace",
  22. "Effect": "Allow",
  23. "Action": ["iam:PassRole"],
  24. "Resource": "arn:${aws_partition}:iam::${account_id}:role/${role_namespace}/*"
  25. },
  26. {
  27. "Sid": "Decrypt",
  28. "Effect": "Allow",
  29. "Action": ["kms:Decrypt"],
  30. "Resource": "*"
  31. }
  32. ]
  33. }