aws.iam-certificate¶
Filters¶
json-diff¶
Compute the diff from the current resource to a previous version.
A resource matches the filter if a diff exists between the current resource and the selected revision.
Utilizes config as a resource revision database.
Revisions can be selected by date, against the previous version, and against a locked version (requires use of is-locked filter).
properties:
selector:
enum:
- previous
- date
- locked
selector_value:
type: string
type:
enum:
- json-diff
required:
- type
Permissions - config:GetResourceConfigHistory
Actions¶
delete¶
Delete an IAM Certificate
For example, if you want to automatically delete an unused IAM certificate.
- example:
- name: aws-iam-certificate-delete-expired resource: iam-certificate filters: - type: value key: Expiration value_type: expiration op: greater-than value: 0 actions: - type: delete
properties:
type:
enum:
- delete
required:
- type
Permissions - iam:DeleteServerCertificate