Scp Tag enforcement is not working on Ec2.

0

I have created an SCP to deny ec2 resource creation if there is no tag. The instance is only get created if it has an environment tag key mentioned in it.

Here is my policy :

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "Scp1",
      "Effect": "Deny",
      "Action": [
        "ec2:CreateTags",
        "ec2:RunInstances"
      ],
      "Resource": [
        "arn:aws:ec2:*:*:instance/*",
        "arn:aws:ec2:*:*:volume/*"
      ],
      "Condition": {
        "ForAllValues:StringEquals": {
          "aws:RequestTag/environment": "true"
        }
      }
    }
  ]
}
Shubham
gefragt vor 2 Jahren1021 Aufrufe
2 Antworten
0

Yes I am trying to achieve this thing but I want to achieve this by using AWS SCP. All post which I have seen they all have same json file as mine. But while implementation it is not working.

Shubham
beantwortet vor 2 Jahren
  • So what condition type you are using?

    ForAllValues:StringEquals? Or StringNotLike?

  • I have used Both but no luck.

  • Can you also post the policy you use with StringNotLike to see if there is any other issue?

  • {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Sid": "Scp1",
          "Effect": "Deny",
          "Action": [
            "ec2:RunInstances"
          ],
          "Resource": [
            "arn:aws:ec2:*:*:instance/*",
            "arn:aws:ec2:*:*:volume/*"
          ],
          "Condition": {
            "ForAllValues:StringEquals": {
              "aws:RequestTag/environment": "true"
            }
          }
        }
      ]
    }
    
    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Sid": "Scp1",
          "Effect": "Deny",
          "Action": [
            "ec2:RunInstances"
          ],
          "Resource": [
            "arn:aws:ec2:*:*:instance/*",
            "arn:aws:ec2:*:*:volume/*"
          ],
          "Condition": {
            "ForAllValues:StringNotLike": {
              "aws:RequestTag/environment": "true"
            }
          }
        }
      ]
    }
    
  • Your policy with

    "ForAllValues:StringNotLike": {
              "aws:RequestTag/environment": "true"
            }
    

    means all your new EC2 instances need to have a tag environment and the tag value must be exactly true

    Is this what you expect and what you get?

0

I guess you are trying to achieve something like this: https://aws.amazon.com/premiumsupport/knowledge-center/iam-policy-tags-deny/ (Sid: AllowRunInstancesWithRestrictions1)

Your policy can be modified as follow:

{
    "Effect": "Deny",
    "Action": [
        "ec2: CreateTags",
        "ec2: RunInstances"
    ],
    "Resource": [
        "arn:aws:ec2:*:*:instance/*",
        "arn:aws:ec2:*:*:volume/*"
    ],
    "Condition": {
        "StringNotLike": {
            "aws:RequestTag/cost_center": "?*"
        }
    }
}
beantwortet vor 2 Jahren

Du bist nicht angemeldet. Anmelden um eine Antwort zu veröffentlichen.

Eine gute Antwort beantwortet die Frage klar, gibt konstruktives Feedback und fördert die berufliche Weiterentwicklung des Fragenstellers.

Richtlinien für die Beantwortung von Fragen