forked from jonrau1/ElectricEye
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Instance_Profile_IAM_Policy.json
260 lines (260 loc) · 10.7 KB
/
Instance_Profile_IAM_Policy.json
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "VisualEditor0",
"Effect": "Allow",
"Action": [
"ec2:AuthorizeSecurityGroupIngress",
"ec2:ReplaceRouteTableAssociation",
"ec2:AttachInternetGateway",
"iam:PutRolePolicy",
"iam:AddRoleToInstanceProfile",
"ec2:CreateNetworkInterfacePermission",
"ec2:CreateRoute",
"events:RemoveTargets",
"iam:ListRolePolicies",
"ecs:TagResource",
"iam:ListPolicies",
"ec2:DeleteVpcEndpointConnectionNotifications",
"ec2:CreateVpcEndpointConnectionNotification",
"ec2:AcceptVpcEndpointConnections",
"ec2:DeleteVpcEndpoints",
"ec2:CreateVpcEndpoint",
"ec2:DescribeVpcEndpoints",
"ec2:DescribeVpcEndpointConnections",
"ec2:ModifyVpcEndpointConnectionNotification",
"ec2:RejectVpcEndpointConnections",
"ec2:DescribeVpcEndpointConnectionNotifications",
"ec2:ModifyVpcEndpoint",
"iam:GetRole",
"events:DescribeRule",
"ecr:SetRepositoryPolicy",
"ecr:DeleteRepositoryPolicy",
"ec2:DescribeVpcClassicLinkDnsSupport",
"ecr:PutImageScanningConfiguration",
"ecr:GetAuthorizationToken",
"s3:GetBucketNotification",
"ec2:CreateNetworkInterface",
"s3:PutObjectVersionAcl",
"logs:ListTagsLogGroup",
"ecr:PutImageTagMutability",
"s3:GetLifecycleConfiguration",
"s3:GetBucketTagging",
"iam:UntagRole",
"iam:TagRole",
"ec2:DescribeRegions",
"ec2:DescribeFlowLogs",
"events:PutRule",
"ec2:CreateVpc",
"s3:ReplicateTags",
"logs:DeleteLogStream",
"ec2:ModifySubnetAttribute",
"iam:ListInstanceProfilesForRole",
"iam:PassRole",
"iam:DeleteRolePolicy",
"ssm:GetMaintenanceWindow",
"ecs:DescribeTasks",
"s3:PutBucketVersioning",
"ec2:AssociateDhcpOptions",
"iam:ListRoles",
"events:DescribeEventSource",
"ec2:DescribeSecurityGroups",
"ecs:ListTagsForResource",
"s3:ListAllMyBuckets",
"iam:UpdateRole",
"ec2:ModifyVpcTenancy",
"ecs:PutAttributes",
"iam:UpdateAssumeRolePolicy",
"iam:GetPolicyVersion",
"ec2:DeleteSubnet",
"events:EnableRule",
"events:DeactivateEventSource",
"iam:RemoveRoleFromInstanceProfile",
"securityhub:CreateInsight",
"ec2:AssociateVpcCidrBlock",
"ec2:DisassociateVpcCidrBlock",
"s3:GetBucketObjectLockConfiguration",
"ssm:DeleteParameter",
"logs:CreateLogStream",
"events:ListRuleNamesByTarget",
"ssm:AddTagsToResource",
"ecs:RegisterTaskDefinition",
"ec2:DescribeNetworkInterfacePermissions",
"events:ListTargetsByRule",
"ecr:BatchCheckLayerAvailability",
"ec2:UpdateSecurityGroupRuleDescriptionsEgress",
"ecr:CreateRepository",
"ecr:GetDownloadUrlForLayer",
"ec2:DeleteNetworkInterface",
"s3:PutBucketCORS",
"ec2:DeleteVpc",
"s3:GetBucketLogging",
"s3:GetAccelerateConfiguration",
"ecr:UploadLayerPart",
"s3:GetBucketPolicy",
"s3:PutEncryptionConfiguration",
"s3:GetEncryptionConfiguration",
"ec2:DeleteNetworkInterfacePermission",
"s3:GetBucketRequestPayment",
"ecr:CompleteLayerUpload",
"ecr:DescribeRepositories",
"ecs:UntagResource",
"ecs:ListClusters",
"iam:GetInstanceProfile",
"events:TagResource",
"events:PutTargets",
"iam:ListPolicyVersions",
"ec2:DescribeSecurityGroupReferences",
"ec2:DeleteSecurityGroup",
"events:UntagResource",
"iam:ListRoleTags",
"ecs:DescribeTaskDefinition",
"ec2:UpdateSecurityGroupRuleDescriptionsIngress",
"ec2:DeleteRouteTable",
"ssm:GetMaintenanceWindowTask",
"ssm:RemoveTagsFromResource",
"ec2:RevokeSecurityGroupEgress",
"ec2:CreateInternetGateway",
"ec2:DeleteInternetGateway",
"ecs:ListTaskDefinitions",
"securityhub:UpdateInsight",
"s3:PutAccountPublicAccessBlock",
"iam:GetPolicy",
"s3:GetBucketWebsite",
"ec2:CreateTags",
"ec2:ModifyNetworkInterfaceAttribute",
"iam:ListEntitiesForPolicy",
"ecs:DeleteCluster",
"iam:DeleteRole",
"ec2:DisassociateRouteTable",
"s3:DeleteBucketPolicy",
"s3:GetReplicationConfiguration",
"ec2:RevokeSecurityGroupIngress",
"ssm:UpdateMaintenanceWindow",
"s3:PutObject",
"ssm:DescribeMaintenanceWindows",
"events:ListTagsForResource",
"events:RemovePermission",
"ec2:CreateSubnet",
"ec2:DescribeSubnets",
"iam:GetRolePolicy",
"ecr:InitiateLayerUpload",
"iam:CreateInstanceProfile",
"s3:GetInventoryConfiguration",
"ecr:ListTagsForResource",
"s3:ListBucket",
"ecr:ListImages",
"ec2:DescribeVpcAttribute",
"ecs:DeregisterTaskDefinition",
"ec2:DescribeAvailabilityZones",
"s3:PutBucketTagging",
"ecs:ListTasks",
"ec2:DescribeNetworkInterfaceAttribute",
"ssm:GetParametersByPath",
"logs:DeleteLogDelivery",
"s3:DeleteBucket",
"events:DisableRule",
"iam:DeleteInstanceProfile",
"ec2:AssignIpv6Addresses",
"s3:GetBucketVersioning",
"ec2:DisassociateSubnetCidrBlock",
"events:DeleteRule",
"s3:ObjectOwnerOverrideToBucketOwner",
"ssm:ListTagsForResource",
"ec2:DescribeVpcs",
"ec2:DisableVpcClassicLink",
"s3:GetBucketCORS",
"ec2:DescribeStaleSecurityGroups",
"ssm:LabelParameterVersion",
"ec2:DeleteFlowLogs",
"ec2:DetachClassicLinkVpc",
"iam:CreateRole",
"s3:CreateBucket",
"iam:AttachRolePolicy",
"ssm:GetParameter",
"ec2:ReplaceRoute",
"ec2:AssociateRouteTable",
"ec2:DescribeInternetGateways",
"iam:DetachRolePolicy",
"ssm:DescribeParameters",
"iam:ListAttachedRolePolicies",
"ec2:DescribeAccountAttributes",
"s3:PutBucketAcl",
"events:ListRules",
"s3:HeadBucket",
"ec2:DescribeNetworkAcls",
"ec2:DescribeRouteTables",
"ec2:EnableVpcClassicLink",
"s3:GetBucketPolicyStatus",
"events:PutEvents",
"ecs:CreateCluster",
"ec2:ResetNetworkInterfaceAttribute",
"ec2:CreateRouteTable",
"ssm:GetParameters",
"ec2:DetachInternetGateway",
"logs:CreateLogGroup",
"ssm:DeleteParameters",
"ec2:DescribeVpcClassicLink",
"ecs:DescribeClusters",
"ecr:PutImage",
"ssm:PutParameter",
"ec2:CreateFlowLogs",
"ec2:AssociateSubnetCidrBlock",
"ecr:DescribeImages",
"s3:GetAnalyticsConfiguration",
"ec2:DeleteTags",
"logs:DescribeLogStreams",
"s3:ListBucketVersions",
"iam:ListPoliciesGrantingServiceAccess",
"ec2:DescribeDhcpOptions",
"ec2:DescribeNetworkInterfaces",
"ec2:CreateSecurityGroup",
"ec2:ModifyVpcAttribute",
"s3:GetMetricsConfiguration",
"s3:PutObjectAcl",
"s3:GetBucketPublicAccessBlock",
"ec2:AuthorizeSecurityGroupEgress",
"ec2:DetachNetworkInterface",
"s3:PutBucketPublicAccessBlock",
"logs:DescribeLogGroups",
"logs:DeleteLogGroup",
"ssm:GetParameterHistory",
"ec2:DescribeTags",
"ec2:DeleteRoute",
"events:ActivateEventSource",
"iam:ListInstanceProfiles",
"s3:GetBucketAcl",
"events:PutPermission",
"s3:PutBucketPolicy",
"ec2:AttachNetworkInterface",
"s3:GetBucketLocation",
"ecr:GetRepositoryPolicy",
"lambda:ListFunctions",
"cloudwatch:GetMetricData",
"sns:GetTopicAttributes",
"kms:ListAliases",
"kms:GetKeyPolicy",
"kms:ListKeys",
"kms:GetKeyRotationStatus",
"qldb:ListLedgers",
"qldb:DescribeLedger",
"qldb:ListJournalS3Exports",
"globalaccelerator:ListAccelerators",
"globalaccelerator:ListListeners",
"globalaccelerator:ListEndpointGroups",
"globalaccelerator:DescribeAcceleratorAttributes",
"ram:GetResourceShares",
"kinesisanalyticsv2:ListApplications",
"kinesisanalyticsv2:DescribeApplication",
"imagebuilder:ListImagePipelines",
"imagebuilder:GetImagePipeline",
"imagebuilder:ListImageRecipes",
"imagebuilder:GetImageRecipe",
"cloudfront:ListDistributions",
"cloudfront:GetDistribution"
],
"Resource": "*"
}
]
}