-
Notifications
You must be signed in to change notification settings - Fork 220
Closed
Labels
pending-releaseThis issue will be fixed by an approved PR that hasn't been released yet.This issue will be fixed by an approved PR that hasn't been released yet.
Description
Confirm by changing [ ] to [x] below to ensure that it's a bug:
- I've searched for previous similar issues and didn't find any solution
Describe the bug
The policy documented as sample policy in README.MD for fleet provisioning sample is wrong. For the subscribe policy it should be topicfilter and not topic.
Expected behavior
The correct policy should be as follows:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"iot:Connect"
],
"Resource": "arn:aws:iot:us-west-2:478068371121:client/*"
},
{
"Effect": "Allow",
"Action": [
"iot:Receive"
],
"Resource": [
"arn:aws:iot:us-west-2:478068371121:topic/$aws/certificates/create/*",
"arn:aws:iot:us-west-2:478068371121:topic/$aws/certificates/create-from-csr/*",
"arn:aws:iot:us-west-2:478068371121:topic/$aws/provisioning-templates/mb3-sensor-fleet-provision-template/provision/*"
]
},
{
"Effect": "Allow",
"Action": "iot:Publish",
"Resource": [
"arn:aws:iot:us-west-2:478068371121:topic/$aws/certificates/create/*",
"arn:aws:iot:us-west-2:478068371121:topic/$aws/certificates/create-from-csr/*",
"arn:aws:iot:us-west-2:478068371121:topic/$aws/provisioning-templates/mb3-sensor-fleet-provision-template/provision/*"
]
},
{
"Effect": "Allow",
"Action": ["iot:Subscribe"],
"Resource": [
"arn:aws:iot:us-west-2:478068371121:topicfilter/$aws/certificates/create/*",
"arn:aws:iot:us-west-2:478068371121:topicfilter/$aws/certificates/create-from-csr/*",
"arn:aws:iot:us-west-2:478068371121:topicfilter/$aws/provisioning-templates/mb3-sensor-fleet-provision-template/provision/*"
]
}
]
}
Metadata
Metadata
Assignees
Labels
pending-releaseThis issue will be fixed by an approved PR that hasn't been released yet.This issue will be fixed by an approved PR that hasn't been released yet.