Skip to content
This repository has been archived by the owner on Jun 13, 2024. It is now read-only.

Question on AWSLambdaVPCAccessExecutionRole #11

Closed
ahusmc opened this issue Feb 7, 2019 · 1 comment
Closed

Question on AWSLambdaVPCAccessExecutionRole #11

ahusmc opened this issue Feb 7, 2019 · 1 comment

Comments

@ahusmc
Copy link

ahusmc commented Feb 7, 2019

Is this really necessary or is there a more restrictive permission set that could accomplish the same?

"arn:aws:iam::aws:policy/service-role/AWSLambdaVPCAccessExecutionRole" It seems to me that GuardDuty doesn't need to do anything with the VPC. It should just receive the guard duty message as JSON and then post it on to slack. Thoughts?

@ryanholland
Copy link
Contributor

You are correct that is not needed, I have removed it from the template.
thanks
ryan

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants