aws.artifact-domain

Filters

cross-account

Check a resource’s embedded iam policy for cross account access.

Supports a whitelist_patterns option to skip principals whose identifier matches any of the provided fnmatch patterns. This is useful for ignoring unique identifiers left behind by deleted IAM principals (e.g. AIDA* for deleted IAM users, AROA* for deleted IAM roles) which AWS substitutes into resource policies when the original principal is removed. See IAM unique identifiers for the full list of prefixes.

- type: cross-account
  whitelist_patterns:
    - "AIDA*"
    - "AROA*"

Supports a whitelist_org_units option for trusting principals via aws:PrincipalOrgPaths conditions. Each entry must be a full OU path starting with the org ID and ending with the OU ID to trust:

- type: cross-account
  whitelist_org_units:
    - "o-abc1234567/r-ab12/ou-ab12-prod"

Wildcards (*, ?) are not permitted in whitelist entries. The org ID prefix is required because OU IDs are only unique within an organization. A whitelist matches a policy path when the path’s leading segment equals the whitelist’s org ID and the whitelist’s leaf OU ID appears as a literal segment in the path; this means a parent-OU whitelist will not implicitly cover policies that only name a descendant OU. List each OU level you actually want to trust. aws:PrincipalOrgPaths matching also respects whitelist_orgids. Any policy path whose leading segment matches a whitelisted org ID is accepted regardless of the OU whitelist.

properties:
  actions:
    items:
      type: string
    type: array
  everyone_only:
    type: boolean
  return_allowed:
    type: boolean
  type:
    enum:
    - cross-account
  whitelist:
    items:
      type: string
    type: array
  whitelist_conditions:
    items:
      type: string
    type: array
  whitelist_from:
    additionalProperties: 'False'
    properties:
      expr:
        oneOf:
        - type: integer
        - type: string
      format:
        enum:
        - csv
        - json
        - txt
        - csv2dict
      headers:
        patternProperties:
          ? ''
          : type: string
        type: object
      query:
        type: string
      url:
        type: string
    required:
    - url
    type: object
  whitelist_org_units:
    items:
      type: string
    type: array
  whitelist_org_units_from:
    additionalProperties: 'False'
    properties:
      expr:
        oneOf:
        - type: integer
        - type: string
      format:
        enum:
        - csv
        - json
        - txt
        - csv2dict
      headers:
        patternProperties:
          ? ''
          : type: string
        type: object
      query:
        type: string
      url:
        type: string
    required:
    - url
    type: object
  whitelist_orgids:
    items:
      type: string
    type: array
  whitelist_orgids_from:
    additionalProperties: 'False'
    properties:
      expr:
        oneOf:
        - type: integer
        - type: string
      format:
        enum:
        - csv
        - json
        - txt
        - csv2dict
      headers:
        patternProperties:
          ? ''
          : type: string
        type: object
      query:
        type: string
      url:
        type: string
    required:
    - url
    type: object
  whitelist_patterns:
    items:
      type: string
    type: array
  whitelist_patterns_from:
    additionalProperties: 'False'
    properties:
      expr:
        oneOf:
        - type: integer
        - type: string
      format:
        enum:
        - csv
        - json
        - txt
        - csv2dict
      headers:
        patternProperties:
          ? ''
          : type: string
        type: object
      query:
        type: string
      url:
        type: string
    required:
    - url
    type: object
  whitelist_vpc:
    items:
      type: string
    type: array
  whitelist_vpc_from:
    additionalProperties: 'False'
    properties:
      expr:
        oneOf:
        - type: integer
        - type: string
      format:
        enum:
        - csv
        - json
        - txt
        - csv2dict
      headers:
        patternProperties:
          ? ''
          : type: string
        type: object
      query:
        type: string
      url:
        type: string
    required:
    - url
    type: object
  whitelist_vpce:
    items:
      type: string
    type: array
  whitelist_vpce_from:
    additionalProperties: 'False'
    properties:
      expr:
        oneOf:
        - type: integer
        - type: string
      format:
        enum:
        - csv
        - json
        - txt
        - csv2dict
      headers:
        patternProperties:
          ? ''
          : type: string
        type: object
      query:
        type: string
      url:
        type: string
    required:
    - url
    type: object
required:
- type

Permissions - codeartifact:GetDomainPermissionsPolicy

json-diff

Compute the diff from the current resource to a previous version.

A resource matches the filter if a diff exists between the current resource and the selected revision.

Utilizes config as a resource revision database.

Revisions can be selected by date, against the previous version, and against a locked version (requires use of is-locked filter).

properties:
  selector:
    enum:
    - previous
    - date
    - locked
  selector_value:
    type: string
  type:
    enum:
    - json-diff
required:
- type

Permissions - config:GetResourceConfigHistory

Actions

delete

example:

Delete empty domains older than 30 days.

policies:
  - name: empty-delete
    resource: artifact-domain
    filters:
       - type: value
         key: createdTime
         value_type: age
         op: greater-than
         value: 30
       - assetSizeBytes: 0
    actions:
       - delete
properties:
  force:
    type: boolean
  type:
    enum:
    - delete
required:
- type

Permissions - codeartifact:DeleteDomain, codeartifact:DeleteRepository, codeartifact:ListRepositoriesInDomain