Questions tagged with IAM Policies
Content language: English
Select up to 5 tags to filter
Sort by most recent
Browse through the questions and answers listed below or filter and sort to narrow down your results.
Hi AWS, I need to create aws SCP that denies creation of EC2 that does not have tags, and allows EC2 creation with specific tag keys pre-defined. We are doing it as part of the FinOps management as we...
1
answers
0
votes
207
views
asked 2 months agolg...
I have a lambda function that can read secrets just fine, but fails to update the secret with the newer token data. The error returns that the assumed execution role does not have the necessary rights...
1
answers
0
votes
132
views
asked 2 months agolg...
im trying to turn on aws config using an account with limited permissions.
For the IAM role for AWS Config I used the option 'Use an existing AWS Config service-linked role' and then I manually...
2
answers
0
votes
180
views
asked 2 months agolg...
Hi all,
We have service hosted on ECS Fargate & we have an OpenSearch Domain that has fine-grained access enabled[user].
On Service side we have enabled the OpenSearchServiceReadOnlyAccess since...
1
answers
0
votes
231
views
asked 2 months agolg...
There is a SCP to Deny access to Block Public Access settings in S3. The policy was later updated to Allow a specific lambda function to perform this action. The updated policy is given below. The...
3
answers
0
votes
547
views
asked 2 months agolg...
We are trying to restore an RDS MySQL database from a backfile on an S3 instance. However, our request to create DB Instance fails with the following error message: "IAM role ARN value is invalid or...
2
answers
0
votes
224
views
asked 2 months agolg...
Hello,
we're using Salesforce Service Cloud Voice with Amazon Connect and we're in the development phase atm.
Inbound calls are working fine but the outbound calls only working to the standard...
3
answers
0
votes
177
views
asked 2 months agolg...
I created a first APIGateway A (sub1.custom-domain.com) with a couple of apis and I have another APIGateway B (sub2.custom-domain.com) within the same account.
I have an API /items in ApiGateway A...
1
answers
0
votes
245
views
asked 2 months agolg...
I am looking a way to scope ec2:RunInstance and enable user to launch instances if they a particular tag on it, how can i achieve this?
2
answers
0
votes
143
views
asked 2 months agolg...
we use control tower, organizations, and iam identity center, for all of our accounts. in the management account, we have one prod OU that has an service control policies pre-attached by CT (the name...
1
answers
0
votes
168
views
asked 2 months agolg...
Hey!
I have a policy statement for allowing an assumed role via web identity. It works fine. I have a role which this policy is attached to with permissions to invoke a lambda function. I can invoke...
1
answers
0
votes
113
views
asked 2 months agolg...
Currently, I return this
```
{
"principalId": "user",
"policyDocument": {
"Version": "2012-10-17",
"Statement": [
{
"Action":...
1
answers
0
votes
235
views
asked 2 months agolg...