Description
CloudFormation AWS::IAM::Policy attaches an inline policy to roles, users, or groups. At least one target is required, but all three are not. A policy name alone does not select an AWS managed policy.
Potential impact
Without an attachment target, policy deployment can fail and intended support permissions cannot be granted.
Remediation
Specify the appropriate Roles, Users, or Groups responsible for support work, and allow only required actions. Remove unused policies.
Examples
The examples attach a policy allowing only support-case queries to an existing myexistinggroup1 group. The first example, without a target, cannot be deployed.
Before
yaml
Resources:
noGroups:
Type: AWS::IAM::Policy
Properties:
PolicyName: AWSSupportAccess
PolicyDocument:
Version: '2012-10-17'
Statement:
- Effect: Allow
Action: ["support:DescribeCases"]
Resource: "*"
After
yaml
Resources:
MyPolicy:
Type: AWS::IAM::Policy
Properties:
PolicyName: mygrouppolicy
PolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action:
- support:DescribeCases
Resource: "*"
Groups:
- myexistinggroup1