Skip to content

Commit c854c8d

Browse files
committed
troubleshooting policy conditions
1 parent fcc913e commit c854c8d

File tree

1 file changed

+6
-7
lines changed

1 file changed

+6
-7
lines changed

aws_sra_examples/solutions/guardduty/guardduty_org/templates/sra-guardduty-org-delivery-s3-bucket.yaml

Lines changed: 6 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -166,8 +166,8 @@ Resources:
166166
Condition:
167167
StringLike:
168168
aws:PrincipalServiceName: guardduty.*.amazonaws.com
169-
StringEquals:
170-
s3:x-amz-acl: bucket-owner-full-control
169+
# StringEquals:
170+
# s3:x-amz-acl: bucket-owner-full-control
171171

172172
- Sid: DenyUnencryptedObjectUploads
173173
Effect: Deny
@@ -189,8 +189,8 @@ Resources:
189189
Condition:
190190
StringLike:
191191
aws:PrincipalServiceName: guardduty.*.amazonaws.com
192-
StringNotEquals:
193-
s3:x-amz-server-side-encryption: aws:kms
192+
# StringNotEquals:
193+
# s3:x-amz-server-side-encryption: aws:kms
194194

195195
- Sid: DenyIncorrectEncryptionHeader
196196
Effect: Deny
@@ -207,14 +207,13 @@ Resources:
207207
- Sid: DenyIncorrectEncryptionHeaderOptinRegions
208208
Effect: Deny
209209
Action: s3:PutObject
210-
Condition:
211-
StringNotEquals:
212-
s3:x-amz-server-side-encryption-aws-kms-key-id: !Sub ${pGuardDutyOrgDeliveryKMSKeyArn}
213210
Resource: !Sub arn:aws:s3:::${rGuardDutyDeliveryS3Bucket}/*
214211
Principal: '*'
215212
Condition:
216213
StringLike:
217214
aws:PrincipalServiceName: guardduty.*.amazonaws.com
215+
# StringNotEquals:
216+
# s3:x-amz-server-side-encryption-aws-kms-key-id: !Sub ${pGuardDutyOrgDeliveryKMSKeyArn}
218217

219218

220219
Outputs:

0 commit comments

Comments
 (0)