aws.event-rule-target

Filters

cross-account

Check a resource’s embedded iam policy for cross account access.

Supports a whitelist_patterns option to skip principals whose identifier matches any of the provided fnmatch patterns. This is useful for ignoring unique identifiers left behind by deleted IAM principals (e.g. AIDA* for deleted IAM users, AROA* for deleted IAM roles) which AWS substitutes into resource policies when the original principal is removed. See IAM unique identifiers for the full list of prefixes.

- type: cross-account
  whitelist_patterns:
    - "AIDA*"
    - "AROA*"

Supports a whitelist_org_units option for trusting principals via aws:PrincipalOrgPaths conditions. Each entry must be a full OU path starting with the org ID and ending with the OU ID to trust:

- type: cross-account
  whitelist_org_units:
    - "o-abc1234567/r-ab12/ou-ab12-prod"

Wildcards (*, ?) are not permitted in whitelist entries. The org ID prefix is required because OU IDs are only unique within an organization. A whitelist matches a policy path when the path’s leading segment equals the whitelist’s org ID and the whitelist’s leaf OU ID appears as a literal segment in the path; this means a parent-OU whitelist will not implicitly cover policies that only name a descendant OU. List each OU level you actually want to trust. aws:PrincipalOrgPaths matching also respects whitelist_orgids. Any policy path whose leading segment matches a whitelisted org ID is accepted regardless of the OU whitelist.

properties:
  type:
    enum:
    - cross-account
  whitelist:
    items:
      type: string
    type: array
  whitelist_from:
    additionalProperties: 'False'
    properties:
      expr:
        oneOf:
        - type: integer
        - type: string
      format:
        enum:
        - csv
        - json
        - txt
        - csv2dict
      headers:
        patternProperties:
          ? ''
          : type: string
        type: object
      query:
        type: string
      url:
        type: string
    required:
    - url
    type: object
required:
- type

Permissions - events:ListTargetsByRule

Actions

delete

Parent base class for filters and actions.

properties:
  force:
    type: boolean
  type:
    enum:
    - delete
required:
- type

Permissions - events:RemoveTargets