Skip to content

Commit 861cfc1

Browse files
authored
Merge pull request #187 from JupiterOne/update-documentation-1.319.0
2 parents 45afd27 + d67691d commit 861cfc1

File tree

3 files changed

+18
-12
lines changed

3 files changed

+18
-12
lines changed

cloudformation/iam-cloudformation-detailed/cloudformation-template.json

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -146,6 +146,8 @@
146146
"ec2:DescribeTransitGatewayVpcAttachments",
147147
"ec2:DescribeVolumes",
148148
"ec2:DescribeVpcEndpoints",
149+
"ec2:DescribeVpcEndpointServicePermissions",
150+
"ec2:DescribeVpcEndpointServices",
149151
"ec2:DescribeVpcPeeringConnections",
150152
"ec2:DescribeVpcs",
151153
"ec2:DescribeVpnConnections",
@@ -243,10 +245,7 @@
243245
"iam:ListAccessKeys",
244246
"iam:ListAccountAliases",
245247
"iam:ListEntitiesForPolicy",
246-
"iam:ListGroupPolicies",
247-
"iam:ListGroups",
248-
"iam:ListInstanceProfiles",
249-
"iam:ListMFADevices"
248+
"iam:ListGroupPolicies"
250249
]
251250
}
252251
]
@@ -266,6 +265,9 @@
266265
"Effect": "Allow",
267266
"Resource": "*",
268267
"Action": [
268+
"iam:ListGroups",
269+
"iam:ListInstanceProfiles",
270+
"iam:ListMFADevices",
269271
"iam:ListOpenIDConnectProviders",
270272
"iam:ListOpenIDConnectProviderTags",
271273
"iam:ListPolicies",

cloudformation/iam-cloudformation-detailed/managed-policy.md

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -109,6 +109,8 @@
109109
"ec2:DescribeTransitGatewayVpcAttachments",
110110
"ec2:DescribeVolumes",
111111
"ec2:DescribeVpcEndpoints",
112+
"ec2:DescribeVpcEndpointServicePermissions",
113+
"ec2:DescribeVpcEndpointServices",
112114
"ec2:DescribeVpcPeeringConnections",
113115
"ec2:DescribeVpcs",
114116
"ec2:DescribeVpnConnections",
@@ -206,10 +208,7 @@
206208
"iam:ListAccessKeys",
207209
"iam:ListAccountAliases",
208210
"iam:ListEntitiesForPolicy",
209-
"iam:ListGroupPolicies",
210-
"iam:ListGroups",
211-
"iam:ListInstanceProfiles",
212-
"iam:ListMFADevices"
211+
"iam:ListGroupPolicies"
213212
]
214213
}
215214
]
@@ -226,6 +225,9 @@
226225
"Effect": "Allow",
227226
"Resource": "*",
228227
"Action": [
228+
"iam:ListGroups",
229+
"iam:ListInstanceProfiles",
230+
"iam:ListMFADevices",
229231
"iam:ListOpenIDConnectProviders",
230232
"iam:ListOpenIDConnectProviderTags",
231233
"iam:ListPolicies",

cloudformation/iam-cloudformation-detailed/terraform.tf

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -135,6 +135,8 @@ resource "aws_iam_policy" "jupiterone_security_audit_policy" {
135135
"ec2:DescribeTransitGatewayVpcAttachments",
136136
"ec2:DescribeVolumes",
137137
"ec2:DescribeVpcEndpoints",
138+
"ec2:DescribeVpcEndpointServicePermissions",
139+
"ec2:DescribeVpcEndpointServices",
138140
"ec2:DescribeVpcPeeringConnections",
139141
"ec2:DescribeVpcs",
140142
"ec2:DescribeVpnConnections",
@@ -232,10 +234,7 @@ resource "aws_iam_policy" "jupiterone_security_audit_policy" {
232234
"iam:ListAccessKeys",
233235
"iam:ListAccountAliases",
234236
"iam:ListEntitiesForPolicy",
235-
"iam:ListGroupPolicies",
236-
"iam:ListGroups",
237-
"iam:ListInstanceProfiles",
238-
"iam:ListMFADevices"
237+
"iam:ListGroupPolicies"
239238
]
240239
}
241240
]
@@ -257,6 +256,9 @@ resource "aws_iam_policy" "jupiterone_security_audit_policy_2" {
257256
"Effect": "Allow",
258257
"Resource": "*",
259258
"Action": [
259+
"iam:ListGroups",
260+
"iam:ListInstanceProfiles",
261+
"iam:ListMFADevices",
260262
"iam:ListOpenIDConnectProviders",
261263
"iam:ListOpenIDConnectProviderTags",
262264
"iam:ListPolicies",

0 commit comments

Comments
 (0)