Description
A resource-based allow statement uses Principal to identify the account, role, user, or service receiving permissions. IAM identity-based policies do not use Principal; the attached identity is the principal.
Potential impact
A resource policy missing a required principal may be invalid or fail to grant the intended permissions.
Remediation
Specify the required Principal in each resource-based allow statement and limit its scope. The IAM JSON key is Principal, not Principals.
Examples
The examples compare part of a KMS key policy’s allow statements. Use actual account IDs and users, and retain key-policy administration permissions in the complete policy.
Before
hcl
resource "aws_kms_key" "example" {
description = "KMS key + secure_policy"
deletion_window_in_days = 7
policy = <<EOF
{
"Version": "2008-10-17",
"Statement": [
{
"Sid": "Secure Policy",
"Effect": "Allow",
"Resource": "*",
"Action": [
"kms:Create*",
"kms:Describe*",
"kms:Enable*"
]
}
]
}
EOF
}
After
hcl
resource "aws_kms_key" "example" {
description = "KMS key + secure_policy"
deletion_window_in_days = 7
policy = <<EOF
{
"Version": "2008-10-17",
"Statement": [
{
"Sid": "Secure Policy",
"Effect": "Allow",
"Resource": "*",
"Action": [
"kms:Create*",
"kms:Describe*",
"kms:Enable*"
],
"Principal": {
"AWS": [
"arn:aws:iam::123456789012:user/user-name-1",
"arn:aws:iam::123456789012:user/UserName2"
]
}
}
]
}
EOF
}