Skip to content

feat: Add internal access analyzer support to aws_accessanalyzer_analyzer #43138

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Conversation

acwwat
Copy link
Contributor

@acwwat acwwat commented Jun 23, 2025

Rollback Plan

If a change needs to be reverted, we will publish an updated version of the library.

Changes to Security Controls

n/a

Description

This PR adds internal access analyzer support to the aws_accessanalyzer_analyzer resource.

Relations

Closes #43083

References

Referred to AnalyzerSummary for specs and wordings.

Output from Acceptance Testing

Account analyzer tests:

$ make testacc TESTS="TestAccAccessAnalyzer_serial/Analyzer/" PKG=accessanalyzer
make: Verifying source code with gofmt...
==> Checking that code complies with gofmt requirements...
TF_ACC=1 go1.24.4 test ./internal/service/accessanalyzer/... -v -count 1 -parallel 20 -run='TestAccAccessAnalyzer_serial/Analyzer/'  -timeout 360m -vet=off
2025/06/22 20:24:46 Creating Terraform AWS Provider (SDKv2-style)...
2025/06/22 20:24:46 Initializing Terraform AWS Provider (SDKv2-style)...
=== RUN   TestAccAccessAnalyzer_serial
=== PAUSE TestAccAccessAnalyzer_serial
=== CONT  TestAccAccessAnalyzer_serial
=== RUN   TestAccAccessAnalyzer_serial/Analyzer
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/accountUnusedAccess
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_providerOnly
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_updateToProviderOnly
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_emptyResourceTag
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/ComputedTag_OnUpdate_Add
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/IgnoreTags_Overlap_DefaultTag
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/EmptyMap
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/AddOnUpdate
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/EmptyTag_OnUpdate_Replace
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_overlapping
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/basic
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/null
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/EmptyTag_OnUpdate_Add
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_updateToResourceOnly
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_nullOverlappingResourceTag
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_nullNonOverlappingResourceTag
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/ComputedTag_OnCreate
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/IgnoreTags_Overlap_ResourceTag
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/EmptyTag_OnCreate
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_nonOverlapping
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/ComputedTag_OnUpdate_Replace
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/type_Organization
    analyzer_test.go:89: skipping tests; this AWS account must not be an existing member of an AWS Organization
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/upgradeV5_95_0
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/basic
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/accountInternalAccess
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/organizationInternalAccess
    analyzer_test.go:213: skipping tests; this AWS account must not be an existing member of an AWS Organization
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/organizationUnusedAccess
    analyzer_test.go:281: skipping tests; this AWS account must not be an existing member of an AWS Organization
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/disappears
--- PASS: TestAccAccessAnalyzer_serial (805.26s)
    --- PASS: TestAccAccessAnalyzer_serial/Analyzer (805.26s)
        --- PASS: TestAccAccessAnalyzer_serial/Analyzer/accountUnusedAccess (17.42s)
        --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags (677.43s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_providerOnly (62.95s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_updateToProviderOnly (29.44s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_emptyResourceTag (17.98s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/ComputedTag_OnUpdate_Add (32.26s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/IgnoreTags_Overlap_DefaultTag (36.46s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/EmptyMap (22.19s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/AddOnUpdate (28.82s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/EmptyTag_OnUpdate_Replace (28.91s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_overlapping (48.21s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/basic (62.17s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/null (22.32s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/EmptyTag_OnUpdate_Add (43.39s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_updateToResourceOnly (27.97s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_nullOverlappingResourceTag (18.16s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_nullNonOverlappingResourceTag (18.27s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/ComputedTag_OnCreate (20.96s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/IgnoreTags_Overlap_ResourceTag (42.61s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/EmptyTag_OnCreate (31.67s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_nonOverlapping (47.52s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/ComputedTag_OnUpdate_Replace (35.16s)
        --- SKIP: TestAccAccessAnalyzer_serial/Analyzer/type_Organization (0.55s)
        --- PASS: TestAccAccessAnalyzer_serial/Analyzer/upgradeV5_95_0 (42.39s)
        --- PASS: TestAccAccessAnalyzer_serial/Analyzer/basic (16.19s)
        --- PASS: TestAccAccessAnalyzer_serial/Analyzer/accountInternalAccess (36.39s)
        --- SKIP: TestAccAccessAnalyzer_serial/Analyzer/organizationInternalAccess (0.45s)
        --- SKIP: TestAccAccessAnalyzer_serial/Analyzer/organizationUnusedAccess (0.25s)
        --- PASS: TestAccAccessAnalyzer_serial/Analyzer/disappears (14.19s)
PASS
ok      github.com/hashicorp/terraform-provider-aws/internal/service/accessanalyzer     805.544s

$

Organization analyzer tests (had to run them in a separate account):

$ make testacc TESTS="TestAccAccessAnalyzer_serial/Analyzer/organization|TestAccAccessAnalyzer_serial/Analyzer/type_Organization" PKG=accessanalyzer
make: Verifying source code with gofmt...
==> Checking that code complies with gofmt requirements...
TF_ACC=1 go1.24.4 test ./internal/service/accessanalyzer/... -v -count 1 -parallel 20 -run='TestAccAccessAnalyzer_serial/Analyzer/organization|TestAccAccessAnalyzer_serial/Analyzer/type_Organization'  -timeout 360m -vet=off
2025/06/22 20:21:53 Creating Terraform AWS Provider (SDKv2-style)...
2025/06/22 20:21:53 Initializing Terraform AWS Provider (SDKv2-style)...
=== RUN   TestAccAccessAnalyzer_serial
=== PAUSE TestAccAccessAnalyzer_serial
=== CONT  TestAccAccessAnalyzer_serial
=== RUN   TestAccAccessAnalyzer_serial/Analyzer
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/organizationUnusedAccess
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/type_Organization
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/organizationInternalAccess
--- PASS: TestAccAccessAnalyzer_serial (83.05s)
    --- PASS: TestAccAccessAnalyzer_serial/Analyzer (83.05s)
        --- PASS: TestAccAccessAnalyzer_serial/Analyzer/organizationUnusedAccess (20.28s)
        --- PASS: TestAccAccessAnalyzer_serial/Analyzer/type_Organization (20.99s)
        --- PASS: TestAccAccessAnalyzer_serial/Analyzer/organizationInternalAccess (41.79s)
PASS
ok      github.com/hashicorp/terraform-provider-aws/internal/service/accessanalyzer     83.310s

$

@acwwat acwwat requested a review from a team as a code owner June 23, 2025 00:52
Copy link

Community Guidelines

This comment is added to every new Pull Request to provide quick reference to how the Terraform AWS Provider is maintained. Please review the information below, and thank you for contributing to the community that keeps the provider thriving! 🚀

Voting for Prioritization

  • Please vote on this Pull Request by adding a 👍 reaction to the original post to help the community and maintainers prioritize it.
  • Please see our prioritization guide for additional information on how the maintainers handle prioritization.
  • Please do not leave +1 or other comments that do not add relevant new information or questions; they generate extra noise for others following the Pull Request and do not help prioritize the request.

Pull Request Authors

  • Review the contribution guide relating to the type of change you are making to ensure all of the necessary steps have been taken.
  • Whether or not the branch has been rebased will not impact prioritization, but doing so is always a welcome surprise.

Copy link

github-actions bot commented Jun 23, 2025

✅ Thank you for correcting the previously detected issues! The maintainers appreciate your efforts to make the review process as smooth as possible.

@github-actions github-actions bot added needs-triage Waiting for first response or review from a maintainer. documentation Introduces or discusses updates to documentation. tests PRs: expanded test coverage. Issues: expanded coverage, enhancements to test infrastructure. service/accessanalyzer Issues and PRs that pertain to the accessanalyzer service. size/XL Managed by automation to categorize the size of a PR. external-maintainer Contribution from a trusted external contributor. labels Jun 23, 2025
@acwwat acwwat force-pushed the f-aws_accessanalyzer_analyzer-add_internal_access_analyzer_support branch 2 times, most recently from e99d6a7 to cb09c3c Compare June 23, 2025 01:00
@acwwat acwwat force-pushed the f-aws_accessanalyzer_analyzer-add_internal_access_analyzer_support branch from cb09c3c to e5a9a51 Compare June 23, 2025 01:38
@github-actions github-actions bot added the linter Pertains to changes to or issues with the various linters. label Jun 23, 2025
@justinretzolk justinretzolk added enhancement Requests to existing resources that expand the functionality or scope. and removed needs-triage Waiting for first response or review from a maintainer. labels Jun 23, 2025
@ewbankkit ewbankkit self-assigned this Jun 25, 2025
@github-actions github-actions bot added the prioritized Part of the maintainer teams immediate focus. To be addressed within the current quarter. label Jun 25, 2025
Copy link
Contributor

@ewbankkit ewbankkit left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM 🚀.

% make testacc TESTARGS='-run=TestAccAccessAnalyzer_serial/^Analyzer$$' PKG=accessanalyzer
make: Verifying source code with gofmt...
==> Checking that code complies with gofmt requirements...
TF_ACC=1 go1.24.4 test ./internal/service/accessanalyzer/... -v -count 1 -parallel 20  -run=TestAccAccessAnalyzer_serial/^Analyzer$ -timeout 360m -vet=off
2025/06/25 12:22:13 Creating Terraform AWS Provider (SDKv2-style)...
2025/06/25 12:22:13 Initializing Terraform AWS Provider (SDKv2-style)...
=== RUN   TestAccAccessAnalyzer_serial
=== PAUSE TestAccAccessAnalyzer_serial
=== CONT  TestAccAccessAnalyzer_serial
=== RUN   TestAccAccessAnalyzer_serial/Analyzer
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/organizationInternalAccess
    analyzer_test.go:213: skipping tests; this AWS account must not be an existing member of an AWS Organization
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/organizationUnusedAccess
    analyzer_test.go:281: skipping tests; this AWS account must not be an existing member of an AWS Organization
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/type_Organization
    analyzer_test.go:89: skipping tests; this AWS account must not be an existing member of an AWS Organization
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/basic
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/accountUnusedAccess
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/disappears
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/EmptyTag_OnUpdate_Replace
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_providerOnly
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_nonOverlapping
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_updateToResourceOnly
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_nullOverlappingResourceTag
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/EmptyMap
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/EmptyTag_OnCreate
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/EmptyTag_OnUpdate_Add
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_emptyResourceTag
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/ComputedTag_OnCreate
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/basic
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/IgnoreTags_Overlap_ResourceTag
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_overlapping
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_updateToProviderOnly
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_nullNonOverlappingResourceTag
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/ComputedTag_OnUpdate_Add
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/ComputedTag_OnUpdate_Replace
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/IgnoreTags_Overlap_DefaultTag
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/null
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/tags/AddOnUpdate
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/upgradeV5_95_0
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/accountInternalAccess
--- PASS: TestAccAccessAnalyzer_serial (661.29s)
    --- PASS: TestAccAccessAnalyzer_serial/Analyzer (661.29s)
        --- SKIP: TestAccAccessAnalyzer_serial/Analyzer/organizationInternalAccess (1.09s)
        --- SKIP: TestAccAccessAnalyzer_serial/Analyzer/organizationUnusedAccess (0.26s)
        --- SKIP: TestAccAccessAnalyzer_serial/Analyzer/type_Organization (2.02s)
        --- PASS: TestAccAccessAnalyzer_serial/Analyzer/basic (13.12s)
        --- PASS: TestAccAccessAnalyzer_serial/Analyzer/accountUnusedAccess (13.36s)
        --- PASS: TestAccAccessAnalyzer_serial/Analyzer/disappears (11.30s)
        --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags (543.71s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/EmptyTag_OnUpdate_Replace (23.21s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_providerOnly (49.48s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_nonOverlapping (37.87s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_updateToResourceOnly (22.59s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_nullOverlappingResourceTag (14.39s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/EmptyMap (17.57s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/EmptyTag_OnCreate (25.77s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/EmptyTag_OnUpdate_Add (35.00s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_emptyResourceTag (14.55s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/ComputedTag_OnCreate (17.96s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/basic (48.96s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/IgnoreTags_Overlap_ResourceTag (34.14s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_overlapping (38.47s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_updateToProviderOnly (23.27s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_nullNonOverlappingResourceTag (14.42s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/ComputedTag_OnUpdate_Add (27.57s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/ComputedTag_OnUpdate_Replace (27.35s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/IgnoreTags_Overlap_DefaultTag (29.79s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/null (18.06s)
            --- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/AddOnUpdate (23.28s)
        --- PASS: TestAccAccessAnalyzer_serial/Analyzer/upgradeV5_95_0 (45.36s)
        --- PASS: TestAccAccessAnalyzer_serial/Analyzer/accountInternalAccess (31.07s)
PASS
ok  	github.com/hashicorp/terraform-provider-aws/internal/service/accessanalyzer	666.140s
% make testacc TESTARGS='-run=TestAccAccessAnalyzer_serial/^Analyzer$$/organization\|TestAccAccessAnalyzer_serial/^Analyzer$$/type_Organization' PKG=accessanalyzer
make: Verifying source code with gofmt...
==> Checking that code complies with gofmt requirements...
TF_ACC=1 go1.24.4 test ./internal/service/accessanalyzer/... -v -count 1 -parallel 20  -run=TestAccAccessAnalyzer_serial/^Analyzer$/organization\|TestAccAccessAnalyzer_serial/^Analyzer$/type_Organization -timeout 360m -vet=off
2025/06/25 13:02:22 Creating Terraform AWS Provider (SDKv2-style)...
2025/06/25 13:02:22 Initializing Terraform AWS Provider (SDKv2-style)...
=== RUN   TestAccAccessAnalyzer_serial
=== PAUSE TestAccAccessAnalyzer_serial
=== CONT  TestAccAccessAnalyzer_serial
=== RUN   TestAccAccessAnalyzer_serial/Analyzer
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/organizationInternalAccess
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/organizationUnusedAccess
=== RUN   TestAccAccessAnalyzer_serial/Analyzer/type_Organization
--- PASS: TestAccAccessAnalyzer_serial (71.21s)
    --- PASS: TestAccAccessAnalyzer_serial/Analyzer (71.21s)
        --- PASS: TestAccAccessAnalyzer_serial/Analyzer/organizationInternalAccess (39.44s)
        --- PASS: TestAccAccessAnalyzer_serial/Analyzer/organizationUnusedAccess (15.66s)
        --- PASS: TestAccAccessAnalyzer_serial/Analyzer/type_Organization (16.10s)
PASS
ok  	github.com/hashicorp/terraform-provider-aws/internal/service/accessanalyzer	75.973s

Copy link
Contributor

@johnsonaj johnsonaj left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM 🚀

@ewbankkit
Copy link
Contributor

@acwwat Thanks for the contribution 🎉 👏.

@ewbankkit ewbankkit merged commit d90a76e into hashicorp:main Jun 26, 2025
52 of 53 checks passed
Copy link

Warning

This Issue has been closed, meaning that any additional comments are much easier for the maintainers to miss. Please assume that the maintainers will not see them.

Ongoing conversations amongst community members are welcome, however, the issue will be locked after 30 days. Moving conversations to another venue, such as the AWS Provider forum, is recommended. If you have additional concerns, please open a new issue, referencing this one where needed.

@github-actions github-actions bot added this to the v6.1.0 milestone Jun 26, 2025
Copy link

This functionality has been released in v6.1.0 of the Terraform AWS Provider. Please see the Terraform documentation on provider versioning or reach out if you need any assistance upgrading.

For further feature requests or bug reports with this functionality, please create a new GitHub issue following the template. Thank you!

@github-actions github-actions bot removed the prioritized Part of the maintainer teams immediate focus. To be addressed within the current quarter. label Jun 26, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
documentation Introduces or discusses updates to documentation. enhancement Requests to existing resources that expand the functionality or scope. external-maintainer Contribution from a trusted external contributor. linter Pertains to changes to or issues with the various linters. service/accessanalyzer Issues and PRs that pertain to the accessanalyzer service. size/XL Managed by automation to categorize the size of a PR. tests PRs: expanded test coverage. Issues: expanded coverage, enhancements to test infrastructure.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

IAM Access Analyzer internal analyzer
4 participants