Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update control-tower-integration.template.yaml #3

Open
wants to merge 2 commits into
base: master
Choose a base branch
from

Conversation

J-C-B
Copy link

@J-C-B J-C-B commented Jun 26, 2023

Due to customer feedback around Lacework broad permissions requests - limit the Sid "StackSetInstanceDelete" permissions to "lacework-*" prefixed resources only.

Also break "StackSetInstanceDescribeStackSetOperation" out into its own Sid without the limitation

Due to customer feedback around Lacework broad permissions requests - limit the Sid "StackSetInstanceDelete" permissions to "lacework-*" prefixed resources only. 

Also break "StackSetInstanceDescribeStackSetOperation" out into its own Sid without the limitation
Added missing space to appease the yaml gods
@jvogt
Copy link

jvogt commented Jul 5, 2023

@jefferyfry @davymcaleer can you review & approve? This change is on behalf of a customer who asked for additional regulation over what resources can be deleted by the lambda (to prevent any future bugs from deleting non-lw stacksets).

This filtering by prefix is tested, and similar to other restrictions by name, which are found elsewhere in the IAM role.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants