Scp Tag enforcement is not working on Ec2.

0

I have created an SCP to deny ec2 resource creation if there is no tag. The instance is only get created if it has an environment tag key mentioned in it.

Here is my policy :

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "Scp1",
      "Effect": "Deny",
      "Action": [
        "ec2:CreateTags",
        "ec2:RunInstances"
      ],
      "Resource": [
        "arn:aws:ec2:*:*:instance/*",
        "arn:aws:ec2:*:*:volume/*"
      ],
      "Condition": {
        "ForAllValues:StringEquals": {
          "aws:RequestTag/environment": "true"
        }
      }
    }
  ]
}
Shubham
已提问 2 年前1021 查看次数
2 回答
0

Yes I am trying to achieve this thing but I want to achieve this by using AWS SCP. All post which I have seen they all have same json file as mine. But while implementation it is not working.

Shubham
已回答 2 年前
  • So what condition type you are using?

    ForAllValues:StringEquals? Or StringNotLike?

  • I have used Both but no luck.

  • Can you also post the policy you use with StringNotLike to see if there is any other issue?

  • {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Sid": "Scp1",
          "Effect": "Deny",
          "Action": [
            "ec2:RunInstances"
          ],
          "Resource": [
            "arn:aws:ec2:*:*:instance/*",
            "arn:aws:ec2:*:*:volume/*"
          ],
          "Condition": {
            "ForAllValues:StringEquals": {
              "aws:RequestTag/environment": "true"
            }
          }
        }
      ]
    }
    
    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Sid": "Scp1",
          "Effect": "Deny",
          "Action": [
            "ec2:RunInstances"
          ],
          "Resource": [
            "arn:aws:ec2:*:*:instance/*",
            "arn:aws:ec2:*:*:volume/*"
          ],
          "Condition": {
            "ForAllValues:StringNotLike": {
              "aws:RequestTag/environment": "true"
            }
          }
        }
      ]
    }
    
  • Your policy with

    "ForAllValues:StringNotLike": {
              "aws:RequestTag/environment": "true"
            }
    

    means all your new EC2 instances need to have a tag environment and the tag value must be exactly true

    Is this what you expect and what you get?

0

I guess you are trying to achieve something like this: https://aws.amazon.com/premiumsupport/knowledge-center/iam-policy-tags-deny/ (Sid: AllowRunInstancesWithRestrictions1)

Your policy can be modified as follow:

{
    "Effect": "Deny",
    "Action": [
        "ec2: CreateTags",
        "ec2: RunInstances"
    ],
    "Resource": [
        "arn:aws:ec2:*:*:instance/*",
        "arn:aws:ec2:*:*:volume/*"
    ],
    "Condition": {
        "StringNotLike": {
            "aws:RequestTag/cost_center": "?*"
        }
    }
}
已回答 2 年前

您未登录。 登录 发布回答。

一个好的回答可以清楚地解答问题和提供建设性反馈,并能促进提问者的职业发展。

回答问题的准则