aws.workspaces-image
Filters
cross-account
Check a resource’s embedded iam policy for cross account access.
Supports a whitelist_patterns option to skip principals whose identifier
matches any of the provided fnmatch patterns. This is
useful for ignoring unique identifiers left behind by deleted IAM principals
(e.g. AIDA* for deleted IAM users, AROA* for deleted IAM roles)
which AWS substitutes into resource policies when the original principal is
removed. See IAM unique identifiers
for the full list of prefixes.
- type: cross-account
whitelist_patterns:
- "AIDA*"
- "AROA*"
Supports a whitelist_org_units option for trusting principals via
aws:PrincipalOrgPaths conditions. Each entry must be a full OU path
starting with the org ID and ending with the OU ID to trust:
- type: cross-account
whitelist_org_units:
- "o-abc1234567/r-ab12/ou-ab12-prod"
Wildcards (*, ?) are not permitted in whitelist entries. The org
ID prefix is required because OU IDs are only unique within an
organization. A whitelist matches a policy path when the path’s leading
segment equals the whitelist’s org ID and the whitelist’s leaf OU ID
appears as a literal segment in the path; this means a parent-OU whitelist
will not implicitly cover policies that only name a descendant OU. List
each OU level you actually want to trust. aws:PrincipalOrgPaths matching
also respects whitelist_orgids. Any policy path whose leading segment
matches a whitelisted org ID is accepted regardless of the OU whitelist.
properties:
type:
enum:
- cross-account
whitelist:
items:
type: string
type: array
whitelist_from:
additionalProperties: 'False'
properties:
expr:
oneOf:
- type: integer
- type: string
format:
enum:
- csv
- json
- txt
- csv2dict
headers:
patternProperties:
? ''
: type: string
type: object
query:
type: string
url:
type: string
required:
- url
type: object
required:
- type
Permissions - workspaces:DescribeWorkspaceImagePermissions
Actions
delete
Deletes a Workspace Image
- example:
policies:
- name: delete-workspace-img
resource: workspaces-image
filters:
- "tag:DeleteMe": present
actions:
- delete
properties:
type:
enum:
- delete
required:
- type
Permissions - workspaces:DeleteWorkspaceImage
rename-tag
Rename an existing tag key to a new value.
- example:
rename Application, and Bap to App, if a resource has both of the old keys then we’ll use the value specified by Application, which is based on the order of values of old_keys.
policies: - name: rename-tags-example resource: aws.log-group filters: - or: - "tag:Bap": present - "tag:Application": present actions: - type: rename-tag old_keys: [Application, Bap] new_key: App
properties:
new_key:
type: string
old_key:
type: string
old_keys:
items:
type: string
type: array
type:
enum:
- rename-tag
required:
- type
Permissions - tag:TagResources, tag:UntagResources