Questions tagged with IAM Policies
Content language: English
Select up to 5 tags to filter
Sort by most recent
Browse through the questions and answers listed below or filter and sort to narrow down your results.
Hi AWS, I need to create aws SCP that denies creation of EC2 that does not have tags, and allows EC2 creation with specific tag keys pre-defined. We are doing it as part of the FinOps management as we...
1
answers
0
votes
228
views
asked 2 months agolg...
I have a lambda function that can read secrets just fine, but fails to update the secret with the newer token data. The error returns that the assumed execution role does not have the necessary rights...
1
answers
0
votes
145
views
asked 2 months agolg...
im trying to turn on aws config using an account with limited permissions.
For the IAM role for AWS Config I used the option 'Use an existing AWS Config service-linked role' and then I manually...
2
answers
0
votes
202
views
asked 2 months agolg...
Hi all,
We have service hosted on ECS Fargate & we have an OpenSearch Domain that has fine-grained access enabled[user].
On Service side we have enabled the OpenSearchServiceReadOnlyAccess since...
1
answers
0
votes
262
views
asked 2 months agolg...
There is a SCP to Deny access to Block Public Access settings in S3. The policy was later updated to Allow a specific lambda function to perform this action. The updated policy is given below. The...
3
answers
0
votes
584
views
asked 2 months agolg...
We are trying to restore an RDS MySQL database from a backfile on an S3 instance. However, our request to create DB Instance fails with the following error message: "IAM role ARN value is invalid or...
2
answers
0
votes
275
views
asked 2 months agolg...
Hello,
we're using Salesforce Service Cloud Voice with Amazon Connect and we're in the development phase atm.
Inbound calls are working fine but the outbound calls only working to the standard...
3
answers
0
votes
194
views
asked 2 months agolg...
I created a first APIGateway A (sub1.custom-domain.com) with a couple of apis and I have another APIGateway B (sub2.custom-domain.com) within the same account.
I have an API /items in ApiGateway A...
1
answers
0
votes
255
views
asked 2 months agolg...
I am looking a way to scope ec2:RunInstance and enable user to launch instances if they a particular tag on it, how can i achieve this?
2
answers
0
votes
159
views
asked 2 months agolg...
we use control tower, organizations, and iam identity center, for all of our accounts. in the management account, we have one prod OU that has an service control policies pre-attached by CT (the name...
1
answers
0
votes
195
views
asked 2 months agolg...
Hey!
I have a policy statement for allowing an assumed role via web identity. It works fine. I have a role which this policy is attached to with permissions to invoke a lambda function. I can invoke...
1
answers
0
votes
124
views
asked 2 months agolg...
Currently, I return this
```
{
"principalId": "user",
"policyDocument": {
"Version": "2012-10-17",
"Statement": [
{
"Action":...
1
answers
0
votes
250
views
asked 2 months agolg...