Resource-based policy has no Principal

Specify the principal in resource-based allow statements.

Description

A resource-based allow statement uses Principal to identify the account, role, user, or service receiving permissions. IAM identity-based policies do not use Principal; the attached identity is the principal.

Potential impact

A resource policy missing a required principal may be invalid or fail to grant the intended permissions.

Remediation

Specify the required Principal in each resource-based allow statement and limit its scope. The IAM JSON key is Principal, not Principals.

Examples

The examples compare part of a KMS key policy’s allow statements. Use actual account IDs and users, and retain key-policy administration permissions in the complete policy.

Before

hcl
resource "aws_kms_key" "example" {
  description             = "KMS key + secure_policy"
  deletion_window_in_days = 7

  policy = <<EOF
{
    "Version": "2008-10-17",
    "Statement": [
        {
            "Sid": "Secure Policy",
            "Effect": "Allow",
            "Resource": "*",
            "Action": [
              "kms:Create*",
              "kms:Describe*",
              "kms:Enable*"
            ]
        }
    ]
}
EOF
}

After

hcl
resource "aws_kms_key" "example" {
  description             = "KMS key + secure_policy"
  deletion_window_in_days = 7

  policy = <<EOF
{
    "Version": "2008-10-17",
    "Statement": [
        {
            "Sid": "Secure Policy",
            "Effect": "Allow",
            "Resource": "*",
            "Action": [
              "kms:Create*",
              "kms:Describe*",
              "kms:Enable*"
            ],
            "Principal": {
              "AWS": [
                "arn:aws:iam::123456789012:user/user-name-1",
                "arn:aws:iam::123456789012:user/UserName2"
              ]
            }
        }
    ]
}
EOF
}

References