aws.iot-policy
AWS IoT policy.
Filters
attached
Filter IoT policies by whether they are attached to any target.
- example:
policies:
- name: iot-policy-orphaned
resource: aws.iot-policy
filters:
- type: attached
state: false
properties:
state:
type: boolean
type:
enum:
- attached
required:
- type
Permissions - iot:ListTargetsForPolicy
has-statement
Find resources with matching access policy statements.
If you want to return resource statements that include the listed key, e.g. Action, you can use PartialMatch instead of an exact match.
- example:
policies:
- name: sns-check-statement-id
resource: sns
filters:
- type: has-statement
statement_ids:
- BlockNonSSL
policies:
- name: sns-check-block-non-ssl
resource: sns
filters:
- type: has-statement
statements:
- Effect: Deny
Action: 'SNS:Publish'
Principal: '*'
Condition:
Bool:
"aws:SecureTransport": "false"
PartialMatch: 'Action'
properties:
statement_ids:
items:
type: string
type: array
statements:
items:
properties:
Action:
anyOf:
- type: string
- type: array
Condition:
type: object
Effect:
enum:
- Allow
- Deny
type: string
NotAction:
anyOf:
- type: string
- type: array
NotPrincipal:
anyOf:
- type: object
- type: array
NotResource:
anyOf:
- type: string
- type: array
PartialMatch:
anyOf:
- enum:
- Action
- NotAction
- Principal
- NotPrincipal
- Resource
- NotResource
- Condition
type: string
- items:
- enum:
- Action
- NotAction
- Principal
- NotPrincipal
- Resource
- NotResource
- Condition
type: string
type: array
Principal:
anyOf:
- type: string
- type: object
- type: array
Resource:
anyOf:
- type: string
- type: array
Sid:
type: string
required:
- Effect
type: object
type: array
type:
enum:
- has-statement
required:
- type
Actions
delete
Delete an IoT policy.
Non-default versions are deleted and targets detached first, as required
by the API. Set force to detach targets; without it an attached policy
is skipped.
- example:
policies:
- name: iot-policy-delete-orphaned
resource: aws.iot-policy
filters:
- type: attached
state: false
actions:
- delete
properties:
force:
type: boolean
type:
enum:
- delete
required:
- type
Permissions - iot:DeletePolicy, iot:DeletePolicyVersion, iot:ListPolicyVersions, iot:ListTargetsForPolicy, iot:DetachPolicy