2017-12-15 14:15:01 +01:00
|
|
|
{
|
|
|
|
"Version": "2012-10-17",
|
|
|
|
"Statement": [
|
|
|
|
{
|
|
|
|
"Action": [
|
2018-09-18 01:53:44 +02:00
|
|
|
"iam:GetGroup",
|
2018-08-24 03:04:18 +02:00
|
|
|
"iam:GetInstanceProfile",
|
2019-06-12 16:25:54 +02:00
|
|
|
"iam:CreateInstanceProfile",
|
2017-12-15 14:15:01 +01:00
|
|
|
"iam:GetPolicy",
|
|
|
|
"iam:GetPolicyVersion",
|
|
|
|
"iam:GetRole",
|
2018-08-24 03:04:18 +02:00
|
|
|
"iam:GetRolePolicy",
|
2018-09-18 01:53:44 +02:00
|
|
|
"iam:GetUser",
|
|
|
|
"iam:ListAttachedGroupPolicies",
|
2017-12-15 14:15:01 +01:00
|
|
|
"iam:ListAttachedRolePolicies",
|
2018-09-18 01:53:44 +02:00
|
|
|
"iam:ListAttachedUserPolicies",
|
2017-12-15 14:15:01 +01:00
|
|
|
"iam:ListGroups",
|
2018-08-24 03:04:18 +02:00
|
|
|
"iam:ListInstanceProfiles",
|
2017-12-15 14:15:01 +01:00
|
|
|
"iam:ListInstanceProfilesForRole",
|
|
|
|
"iam:ListPolicies",
|
|
|
|
"iam:ListRoles",
|
|
|
|
"iam:ListRolePolicies",
|
2018-08-22 23:21:12 +02:00
|
|
|
"iam:ListUsers",
|
|
|
|
"iam:ListAccountAliases"
|
2017-12-15 14:15:01 +01:00
|
|
|
],
|
|
|
|
"Resource": "*",
|
|
|
|
"Effect": "Allow",
|
|
|
|
"Sid": "AllowReadOnlyIAMUse"
|
2018-02-02 00:16:27 +01:00
|
|
|
},
|
2019-03-06 13:46:37 +01:00
|
|
|
{
|
|
|
|
"Action": [
|
|
|
|
"iam:AttachRolePolicy",
|
|
|
|
"iam:CreateRole",
|
|
|
|
"iam:DeleteRole",
|
|
|
|
"iam:DetachRolePolicy",
|
|
|
|
"iam:PassRole"
|
|
|
|
],
|
|
|
|
"Resource": "arn:aws:iam::{{ aws_account }}:role/ansible-test-*",
|
|
|
|
"Effect": "Allow",
|
|
|
|
"Sid": "AllowUpdateOfSpecificRoles"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"Action": [
|
|
|
|
"iam:CreateInstanceProfile",
|
|
|
|
"iam:DeleteInstanceProfile",
|
|
|
|
"iam:AddRoleToInstanceProfile",
|
|
|
|
"iam:RemoveRoleFromInstanceProfile"
|
|
|
|
],
|
|
|
|
"Resource": "arn:aws:iam::{{ aws_account }}:instance-profile/ansible-test-*",
|
|
|
|
"Effect": "Allow",
|
|
|
|
"Sid": "AllowUpdateOfSpecificInstanceProfiles"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"Action": [
|
|
|
|
"ec2:ReplaceIamInstanceProfileAssociation"
|
|
|
|
],
|
|
|
|
"Resource": "*",
|
|
|
|
"Condition": {
|
|
|
|
"ArnEquals": {
|
|
|
|
"ec2:InstanceProfile": "arn:aws:iam::{{ aws_account }}:instance-profile/ansible-test-*"
|
|
|
|
}
|
|
|
|
},
|
|
|
|
"Effect": "Allow",
|
|
|
|
"Sid": "AllowReplacementOfSpecificInstanceProfiles"
|
|
|
|
},
|
2018-02-02 00:16:27 +01:00
|
|
|
{
|
|
|
|
"Sid": "AllowWAFusage",
|
|
|
|
"Action": "waf:*",
|
|
|
|
"Effect": "Allow",
|
|
|
|
"Resource": "*"
|
2018-11-14 18:15:24 +01:00
|
|
|
},
|
|
|
|
{
|
|
|
|
"Sid": "AllowListingCloudwatchLogs",
|
|
|
|
"Effect": "Allow",
|
|
|
|
"Action": [
|
|
|
|
"logs:DescribeLogGroups"
|
|
|
|
],
|
|
|
|
"Resource": [
|
|
|
|
"arn:aws:logs:{{aws_region}}:{{aws_account}}:log-group:*"
|
|
|
|
]
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"Sid": "AllowModifyingCloudwatchLogs",
|
|
|
|
"Effect": "Allow",
|
|
|
|
"Action": [
|
|
|
|
"logs:CreateLogGroup",
|
|
|
|
"logs:PutRetentionPolicy",
|
|
|
|
"logs:DeleteLogGroup"
|
|
|
|
],
|
|
|
|
"Resource": [
|
|
|
|
"arn:aws:logs:{{aws_region}}:{{aws_account}}:log-group:ansible-testing*"
|
|
|
|
]
|
2019-05-17 02:36:14 +02:00
|
|
|
},
|
|
|
|
{
|
2019-06-17 20:41:20 +02:00
|
|
|
"Sid": "AllowSTSAnsibleTests",
|
|
|
|
"Action": [
|
|
|
|
"iam:CreateRole",
|
|
|
|
"iam:DeleteRole",
|
|
|
|
"iam:DetachRolePolicy",
|
|
|
|
"sts:AssumeRole",
|
|
|
|
"iam:AttachRolePolicy",
|
|
|
|
"iam:CreateInstanceProfile"
|
|
|
|
],
|
2019-05-17 02:36:14 +02:00
|
|
|
"Effect": "Allow",
|
2019-06-17 20:41:20 +02:00
|
|
|
"Resource": [
|
|
|
|
"arn:aws:iam::{{aws_account}}:role/ansible-test-sts-*",
|
|
|
|
"arn:aws:iam::{{aws_account}}:instance-profile/ansible-test-sts-*"
|
|
|
|
]
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"Sid": "AllowAccessToUnspecifiedKMSResources",
|
|
|
|
"Effect": "Allow",
|
|
|
|
"Action": [
|
|
|
|
"kms:CancelKeyDeletion",
|
|
|
|
"kms:CreateAlias",
|
|
|
|
"kms:CreateGrant",
|
|
|
|
"kms:CreateKey",
|
|
|
|
"kms:DeleteAlias",
|
|
|
|
"kms:Describe*",
|
|
|
|
"kms:DisableKey",
|
|
|
|
"kms:EnableKey",
|
|
|
|
"kms:GenerateRandom",
|
|
|
|
"kms:Get*",
|
|
|
|
"kms:List*",
|
|
|
|
"kms:RetireGrant",
|
|
|
|
"kms:ScheduleKeyDeletion",
|
|
|
|
"kms:TagResource",
|
|
|
|
"kms:UntagResource",
|
|
|
|
"kms:UpdateGrant",
|
|
|
|
"kms:UpdateKeyDescription"
|
|
|
|
],
|
2019-05-17 02:36:14 +02:00
|
|
|
"Resource": "*"
|
2019-06-17 20:41:20 +02:00
|
|
|
},
|
|
|
|
{
|
|
|
|
"Sid": "AllowAccessToSpecifiedIAMResources",
|
|
|
|
"Effect": "Allow",
|
|
|
|
"Action": [
|
|
|
|
"iam:CreateRole",
|
|
|
|
"iam:DeleteRole",
|
|
|
|
"iam:GetRole",
|
|
|
|
"iam:PassRole",
|
|
|
|
"iam:UpdateAssumeRolePolicy"
|
|
|
|
],
|
|
|
|
"Resource": "arn:aws:iam::{{aws_account}}:role/ansible-test-*"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"Sid": "AllowInstanceProfileCreation",
|
|
|
|
"Effect": "Allow",
|
|
|
|
"Action": [
|
|
|
|
"iam:AddRoleToInstanceProfile",
|
|
|
|
"iam:CreateInstanceProfile",
|
|
|
|
"iam:RemoveRoleFromInstanceProfile"
|
|
|
|
],
|
|
|
|
"Resource": "arn:aws:iam::{{aws_account}}:instance-profile/ansible-test-*"
|
2017-12-15 14:15:01 +01:00
|
|
|
}
|
|
|
|
]
|
|
|
|
}
|