Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- {
- "SSid" : "DenegarManipulacionDeBoundaries",
- "Effect" : "Deny",
- "Action" : [
- "iam:PutRolePermissionsBoundary",
- "iam:PutUserPermissionsBoundary",
- "iam:DeleteRolePermissionsBoundary",
- "iam:DeleteUserPermissionsBoundary"
- ],
- "Resource" : "*"
- },
- {
- "SSid" : "PermitirOpercionesIAMVarias",
- "Effect" : "Allow",
- "Action" : [
- "iam:Get*",
- "iam:List*",
- "iam:AddUserToGroup",
- "iam:ChangePassword",
- "iam:CreateAccessKey",
- "iam:CreateGroup",
- "iam:DeleteAccessKey",
- "iam:DeleteGroup",
- "iam:DeleteInstanceProfile",
- "iam:DeleteLoginProfile",
- "iam:GetAccessKeyLastUsed",
- "iam:RemoveRoleFromInstanceProfile",
- "iam:RemoveUserFromGroup",
- "iam:SetDefaultPolicyVersion",
- "iam:SimulateCustomPolicy",
- "iam:SimulatePrincipalPolicy",
- "iam:TagRole",
- "iam:TagUser",
- "iam:UntagRole",
- "iam:UntagUser",
- "iam:UpdateAccessKey",
- "iam:UpdateAssumeRolePolicy",
- "iam:UpdateRoleDescription"
- ],
- "Resource" : "*"
- },
- {
- "SSid" : "PermitirOperacionesIAMPeroObligandoBoundary"
- "Effect" : "Allow",
- "Action" : [
- "iam:AttachGroupPolicy",
- "iam:AttachRolePolicy",
- "iam:AttachUserPolicy",
- "iam:CreateInstanceProfile",
- "iam:CreateLoginProfile",
- "iam:CreatePolicy",
- "iam:CreatePolicyVersion",
- "iam:CreateRole",
- "iam:CreateUser",
- "iam:DeleteGroupPolicy",
- "iam:DeletePolicyVersion",
- "iam:DeleteRole",
- "iam:DeleteRolePolicy",
- "iam:DeleteUser",
- "iam:DeleteUserPolicy",
- "iam:DetachGroupPolicy",
- "iam:DetachRolePolicy",
- "iam:DetachUserPolicy",
- "iam:PutGroupPolicy",
- "iam:PutRolePolicy",
- "iam:PutUserPolicy",
- "iam:UpdateGroup",
- "iam:UpdateLoginProfile",
- "iam:UpdateRole",
- "iam:UpdateUser"
- ],
- "Resource": "arn:aws:iam::12345678:user/prefijodelnombredemisusuarios-*",
- "Condition" {
- "StringEquals" : {
- "iam:PermissionBoundary" : "arn:aws:iam::12345678:policy/MiBoundaryLimitada"
- }
- }
- },
- {
- "SSid" : ""
- "Effect" : "Allow",
- "Action" : [
- "iam:PassRole",
- "iam:AddRoleToInstanceProfile"
- ]
- "Resource" : "arn:aws:iam::12345678:user/prefijodelnombredemisusuarios-*"
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement