File tree Expand file tree Collapse file tree 3 files changed +18
-12
lines changed
cloudformation/iam-cloudformation-detailed Expand file tree Collapse file tree 3 files changed +18
-12
lines changed Original file line number Diff line number Diff line change 146
146
" ec2:DescribeTransitGatewayVpcAttachments" ,
147
147
" ec2:DescribeVolumes" ,
148
148
" ec2:DescribeVpcEndpoints" ,
149
+ " ec2:DescribeVpcEndpointServicePermissions" ,
150
+ " ec2:DescribeVpcEndpointServices" ,
149
151
" ec2:DescribeVpcPeeringConnections" ,
150
152
" ec2:DescribeVpcs" ,
151
153
" ec2:DescribeVpnConnections" ,
243
245
" iam:ListAccessKeys" ,
244
246
" iam:ListAccountAliases" ,
245
247
" iam:ListEntitiesForPolicy" ,
246
- " iam:ListGroupPolicies" ,
247
- " iam:ListGroups" ,
248
- " iam:ListInstanceProfiles" ,
249
- " iam:ListMFADevices"
248
+ " iam:ListGroupPolicies"
250
249
]
251
250
}
252
251
]
266
265
"Effect" : " Allow" ,
267
266
"Resource" : " *" ,
268
267
"Action" : [
268
+ " iam:ListGroups" ,
269
+ " iam:ListInstanceProfiles" ,
270
+ " iam:ListMFADevices" ,
269
271
" iam:ListOpenIDConnectProviders" ,
270
272
" iam:ListOpenIDConnectProviderTags" ,
271
273
" iam:ListPolicies" ,
Original file line number Diff line number Diff line change 109
109
" ec2:DescribeTransitGatewayVpcAttachments" ,
110
110
" ec2:DescribeVolumes" ,
111
111
" ec2:DescribeVpcEndpoints" ,
112
+ " ec2:DescribeVpcEndpointServicePermissions" ,
113
+ " ec2:DescribeVpcEndpointServices" ,
112
114
" ec2:DescribeVpcPeeringConnections" ,
113
115
" ec2:DescribeVpcs" ,
114
116
" ec2:DescribeVpnConnections" ,
206
208
" iam:ListAccessKeys" ,
207
209
" iam:ListAccountAliases" ,
208
210
" iam:ListEntitiesForPolicy" ,
209
- " iam:ListGroupPolicies" ,
210
- " iam:ListGroups" ,
211
- " iam:ListInstanceProfiles" ,
212
- " iam:ListMFADevices"
211
+ " iam:ListGroupPolicies"
213
212
]
214
213
}
215
214
]
226
225
"Effect" : " Allow" ,
227
226
"Resource" : " *" ,
228
227
"Action" : [
228
+ " iam:ListGroups" ,
229
+ " iam:ListInstanceProfiles" ,
230
+ " iam:ListMFADevices" ,
229
231
" iam:ListOpenIDConnectProviders" ,
230
232
" iam:ListOpenIDConnectProviderTags" ,
231
233
" iam:ListPolicies" ,
Original file line number Diff line number Diff line change @@ -135,6 +135,8 @@ resource "aws_iam_policy" "jupiterone_security_audit_policy" {
135
135
"ec2:DescribeTransitGatewayVpcAttachments",
136
136
"ec2:DescribeVolumes",
137
137
"ec2:DescribeVpcEndpoints",
138
+ "ec2:DescribeVpcEndpointServicePermissions",
139
+ "ec2:DescribeVpcEndpointServices",
138
140
"ec2:DescribeVpcPeeringConnections",
139
141
"ec2:DescribeVpcs",
140
142
"ec2:DescribeVpnConnections",
@@ -232,10 +234,7 @@ resource "aws_iam_policy" "jupiterone_security_audit_policy" {
232
234
"iam:ListAccessKeys",
233
235
"iam:ListAccountAliases",
234
236
"iam:ListEntitiesForPolicy",
235
- "iam:ListGroupPolicies",
236
- "iam:ListGroups",
237
- "iam:ListInstanceProfiles",
238
- "iam:ListMFADevices"
237
+ "iam:ListGroupPolicies"
239
238
]
240
239
}
241
240
]
@@ -257,6 +256,9 @@ resource "aws_iam_policy" "jupiterone_security_audit_policy_2" {
257
256
"Effect": "Allow",
258
257
"Resource": "*",
259
258
"Action": [
259
+ "iam:ListGroups",
260
+ "iam:ListInstanceProfiles",
261
+ "iam:ListMFADevices",
260
262
"iam:ListOpenIDConnectProviders",
261
263
"iam:ListOpenIDConnectProviderTags",
262
264
"iam:ListPolicies",
You can’t perform that action at this time.
0 commit comments