Advertisement
Guest User

Untitled

a guest
Jun 24th, 2019
90
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 6.95 KB | None | 0 0
  1. {
  2. "Version": "2012-10-17",
  3. "Statement": [
  4. {
  5. "Sid": "FullAccessToMostServices",
  6. "Effect": "Allow",
  7. "Action": [
  8. "a4b:*",
  9. "apigateway:*",
  10. "application-autoscaling:*",
  11. "discovery:*",
  12. "appstream:*",
  13. "appsync:*",
  14. "artifact:*",
  15. "athena:*",
  16. "autoscaling-plans:*",
  17. "batch:*",
  18. "aws-portal:*",
  19. "budgets:*",
  20. "acm:*",
  21. "acm-pca:*",
  22. "chime:*",
  23. "cloud9:*",
  24. "clouddirectory:*",
  25. "cloudformation:*",
  26. "cloudfront:*",
  27. "cloudhsm:*",
  28. "servicediscovery:*",
  29. "cloudsearch:*",
  30. "cloudtrail:*",
  31. "cloudwatch:*",
  32. "events:*",
  33. "logs:*",
  34. "codebuild:*",
  35. "codecommit:*",
  36. "codedeploy:*",
  37. "codepipeline:*",
  38. "signer:*",
  39. "codestar:*",
  40. "cognito-idp:*",
  41. "cognito-identity:*",
  42. "cognito-sync:*",
  43. "comprehend:*",
  44. "config:*",
  45. "connect:*",
  46. "cur:*",
  47. "ce:*",
  48. "datapipeline:*",
  49. "dms:*",
  50. "devicefarm:*",
  51. "directconnect:*",
  52. "ds:*",
  53. "rds:*",
  54. "dynamodb:*",
  55. "dax:*",
  56. "autoscaling:*",
  57. "ec2:*",
  58. "ecr:*",
  59. "ecs:*",
  60. "eks:*",
  61. "elasticbeanstalk:*",
  62. "elasticfilesystem:*",
  63. "elasticloadbalancing:*",
  64. "elasticmapreduce:*",
  65. "elastictranscoder:*",
  66. "elasticache:*",
  67. "es:*",
  68. "fms:*",
  69. "freertos:*",
  70. "gamelift:*",
  71. "glacier:*",
  72. "globalaccelerator:*",
  73. "glue:*",
  74. "greengrass:*",
  75. "groundstation:*",
  76. "guardduty:*",
  77. "health:*",
  78. "importexport:*",
  79. "inspector:*",
  80. "iot:*",
  81. "iotanalytics:*",
  82. "iot1click:*",
  83. "kms:*",
  84. "kinesisanalytics:*",
  85. "firehose:*",
  86. "kinesis:*",
  87. "kinesisvideo:*",
  88. "lambda:*",
  89. "lex:*",
  90. "lightsail:*",
  91. "macie:*",
  92. "machinelearning:*",
  93. "aws-marketplace:*",
  94. "aws-marketplace-management:*",
  95. "mechanicalturk:*",
  96. "crowd:*",
  97. "mediaconnect:*",
  98. "mediaconvert:*",
  99. "medialive:*",
  100. "mediapackage:*",
  101. "mediastore:*",
  102. "mediatailor:*",
  103. "ec2message:*",
  104. "mgh:*",
  105. "mobileanalytics:*",
  106. "mobilehub:*",
  107. "mq:*",
  108. "opsworks:*",
  109. "opsworks-cm:*",
  110. "organizations:*",
  111. "personalize:*",
  112. "mobiletargeting:*",
  113. "polly:*",
  114. "pricing:*",
  115. "quicksight:*",
  116. "redshift:*",
  117. "rekognition:*",
  118. "rds:*",
  119. "resource-groups:*",
  120. "tag:*",
  121. "sagemaker:*",
  122. "secretsmanager:*",
  123. "sts:*",
  124. "serverlessrepo:*",
  125. "servicecatalog:*",
  126. "shield:*",
  127. "shield:*",
  128. "transfer:*",
  129. "ses:*",
  130. "sns:*",
  131. "sqs:*",
  132. "s3:*",
  133. "swf:*",
  134. "sdb:*",
  135. "sso:*",
  136. "snowball:*",
  137. "states:*",
  138. "storagegateway:*",
  139. "sumerian:*",
  140. "support:*",
  141. "ssm:*",
  142. "textract:*",
  143. "transcribe:*",
  144. "translate:*",
  145. "trustedadvisor:*",
  146. "ec2:*",
  147. "waf:*",
  148. "waf-regional:*",
  149. "workdocs:*",
  150. "worklink:*",
  151. "workmail:*",
  152. "workspaces:*",
  153. "wam:*",
  154. "xray:*"
  155. ],
  156. "Resource": "*"
  157. },
  158. {
  159. "Sid": "LimitedReadAccessRoute53",
  160. "Effect": "Allow",
  161. "Action": [
  162. "route53:Get*",
  163. "route53:List*",
  164. "route53:Test*",
  165. "route53resolver:Get*",
  166. "route53resolver:List*",
  167. "route53domains:Get*",
  168. "route53domains:List*",
  169. "route53domains:Check*",
  170. "route53domains:View*"
  171. ],
  172. "Resource": "*"
  173. },
  174. {
  175. "Sid": "CreateOrChangeOnlyWithBoundary",
  176. "Effect": "Allow",
  177. "Action": [
  178. "iam:CreateUser",
  179. "iam:DeleteUserPolicy",
  180. "iam:AttachUserPolicy",
  181. "iam:DetachUserPolicy",
  182. "iam:PutUserPermissionsBoundary"
  183. ],
  184. "Resource": "*",
  185. "Condition": {
  186. "StringEquals": {
  187. "iam:PermissionsBoundary": "arn:aws:iam::polishop-aws:policy/PolishopBoundaries"
  188. }
  189. }
  190. },
  191. {
  192. "Sid": "OtherIamTasks",
  193. "Effect": "Allow",
  194. "Action": [
  195. "iam:Get*",
  196. "iam:List*",
  197. "iam:Generate*",
  198. "iam:Simulate*",
  199. "iam:*Group*",
  200. "iam:*MFA*",
  201. "iam:UpdateUser",
  202. "iam:CreateAccessKey",
  203. "iam:CreateLoginProfile",
  204. "iam:CreatePolicy",
  205. "iam:DeletePolicy",
  206. "iam:DeletePolicyVersion",
  207. "iam:PutUserPolicy",
  208. "iam:SetDefaultPolicyVersion"
  209. ],
  210. "Resource": "*"
  211. },
  212. {
  213. "Sid": "NoBoundaryPolicyEdit",
  214. "Effect": "Deny",
  215. "Action": [
  216. "iam:CreatePolicyVersion",
  217. "iam:DeletePolicy",
  218. "iam:DeletePolicyVersion",
  219. "iam:SetDefaultPolicyVersion"
  220. ],
  221. "Resource": [
  222. "arn:aws:iam::polishop-aws:policy/PolishopBoundaries",
  223. "arn:aws:iam::polishop-aws:policy/ManagerBoundaries"
  224. ]
  225. },
  226. {
  227. "Sid": "NoBoundaryUserDelete",
  228. "Effect": "Deny",
  229. "Action": "iam:DeleteUserPermissionsBoundary",
  230. "Resource": "*"
  231. }
  232. ]
  233. }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement