aws.iam-certificate
Filters
json-diff
Compute the diff from the current resource to a previous version.
A resource matches the filter if a diff exists between the current resource and the selected revision.
Utilizes config as a resource revision database.
Revisions can be selected by date, against the previous version, and against a locked version (requires use of is-locked filter).
properties:
selector:
enum:
- previous
- date
- locked
selector_value:
type: string
type:
enum:
- json-diff
required:
- type
Permissions - config:GetResourceConfigHistory
Actions
delete
Delete an IAM Certificate
For example, if you want to automatically delete an unused IAM certificate.
- example:
- name: aws-iam-certificate-delete-expired resource: iam-certificate filters: - type: value key: Expiration value_type: expiration op: greater-than value: 0 actions: - type: delete
properties:
type:
enum:
- delete
required:
- type
Permissions - iam:DeleteServerCertificate