-
Notifications
You must be signed in to change notification settings - Fork 0
/
Katonic-platform-installation--iam-policy .txt
141 lines (141 loc) · 5.8 KB
/
Katonic-platform-installation--iam-policy .txt
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "VisualEditor0",
"Effect": "Allow",
"Action": [
"iam:GetPolicyVersion",
"iam:DeactivateMFADevice",
"iam:CreateServiceSpecificCredential",
"iam:ListRoleTags",
"iam:GenerateServiceLastAccessedDetails",
"iam:UpdateOpenIDConnectProviderThumbprint",
"iam:RemoveRoleFromInstanceProfile",
"iam:CreateRole",
"iam:TagMFADevice",
"iam:AttachRolePolicy",
"iam:ListServiceSpecificCredentials",
"iam:PutRolePolicy",
"iam:TagSAMLProvider",
"iam:ListSigningCertificates",
"iam:AddRoleToInstanceProfile",
"iam:ListSSHPublicKeys",
"iam:DetachRolePolicy",
"iam:SimulatePrincipalPolicy",
"iam:ListAttachedRolePolicies",
"iam:ListOpenIDConnectProviderTags",
"iam:ListSAMLProviderTags",
"iam:ListRolePolicies",
"iam:DeleteOpenIDConnectProvider",
"iam:UpdateServiceSpecificCredential",
"iam:GetServerCertificate",
"iam:GetRole",
"iam:UntagSAMLProvider",
"iam:GetPolicy",
"iam:RemoveClientIDFromOpenIDConnectProvider",
"iam:GetAccessKeyLastUsed",
"iam:ListEntitiesForPolicy",
"iam:DeleteRole",
"iam:UpdateRoleDescription",
"iam:TagPolicy",
"iam:GetUserPolicy",
"iam:ListGroupsForUser",
"iam:GetGroupPolicy",
"iam:GetOpenIDConnectProvider",
"iam:GetRolePolicy",
"iam:CreateInstanceProfile",
"iam:UntagRole",
"iam:TagRole",
"iam:ListPoliciesGrantingServiceAccess",
"iam:ResetServiceSpecificCredential",
"iam:DeletePolicy",
"iam:ListInstanceProfileTags",
"iam:CreateVirtualMFADevice",
"iam:ListMFADevices",
"iam:GetGroup",
"iam:GetContextKeysForPrincipalPolicy",
"iam:GetServiceLinkedRoleDeletionStatus",
"iam:ListInstanceProfilesForRole",
"iam:PassRole",
"iam:GenerateOrganizationsAccessReport",
"iam:DeleteRolePolicy",
"iam:EnableMFADevice",
"iam:ResyncMFADevice",
"iam:ListAttachedUserPolicies",
"iam:ListAttachedGroupPolicies",
"iam:ListPolicyTags",
"iam:CreatePolicyVersion",
"iam:GetSAMLProvider",
"iam:ListAccessKeys",
"iam:DeleteInstanceProfile",
"iam:GetInstanceProfile",
"iam:ListGroupPolicies",
"iam:GetSSHPublicKey",
"iam:UntagServerCertificate",
"iam:ListUserPolicies",
"iam:ListInstanceProfiles",
"iam:TagUser",
"iam:CreateOpenIDConnectProvider",
"iam:CreatePolicy",
"iam:UntagUser",
"iam:CreateServiceLinkedRole",
"iam:ListPolicyVersions",
"iam:UntagMFADevice",
"iam:ListServerCertificateTags",
"iam:TagServerCertificate",
"iam:UntagPolicy",
"iam:UpdateRole",
"iam:GetUser",
"iam:UntagOpenIDConnectProvider",
"iam:AddClientIDToOpenIDConnectProvider",
"iam:ListMFADeviceTags",
"iam:UntagInstanceProfile",
"iam:DeleteServiceSpecificCredential",
"iam:TagOpenIDConnectProvider",
"iam:GetLoginProfile",
"iam:DeletePolicyVersion",
"iam:TagInstanceProfile",
"iam:ListUserTags"
],
"Resource": [
"arn:aws:iam::407050727951:oidc-provider/*",
"arn:aws:iam::407050727951:saml-provider/*",
"arn:aws:iam::407050727951:role/*",
"arn:aws:iam::407050727951:server-certificate/*",
"arn:aws:iam::407050727951:access-report/*",
"arn:aws:iam::407050727951:group/*",
"arn:aws:iam::407050727951:user/*",
"arn:aws:iam::407050727951:instance-profile/*",
"arn:aws:iam::407050727951:mfa/*",
"arn:aws:iam::407050727951:policy/*"
]
},
{
"Sid": "VisualEditor1",
"Effect": "Allow",
"Action": [
"iam:ListPolicies",
"iam:GenerateCredentialReport",
"iam:GetAccountPasswordPolicy",
"iam:ListSAMLProviders",
"iam:GetServiceLastAccessedDetailsWithEntities",
"iam:ListServerCertificates",
"iam:ListRoles",
"iam:GetServiceLastAccessedDetails",
"iam:ListVirtualMFADevices",
"iam:GetOrganizationsAccessReport",
"iam:GetContextKeysForCustomPolicy",
"iam:SimulateCustomPolicy",
"iam:ListOpenIDConnectProviders",
"iam:ListAccountAliases",
"iam:ListUsers",
"iam:ListGroups",
"iam:GetAccountAuthorizationDetails",
"iam:GetCredentialReport",
"iam:GetAccountSummary"
],
"Resource": "*"
}
]
}