File tree 2 files changed +26
-9
lines changed
aws_sra_examples/solutions/inspector/inspector_org/templates
2 files changed +26
-9
lines changed Original file line number Diff line number Diff line change @@ -126,18 +126,27 @@ Resources:
126
126
Action : iam:CreateServiceLinkedRole
127
127
Condition :
128
128
StringLike :
129
- iam:AWSServiceName : inspector2.amazonaws.com
130
- Resource : !Sub arn:${AWS::Partition}:iam::${AWS::AccountId}:role/aws-service-role/inspector2.amazonaws.com/AWSServiceRoleForAmazonInspector2
129
+ iam:AWSServiceName :
130
+ - inspector2.amazonaws.com
131
+ - agentless.inspector2.amazonaws.com
132
+ Resource :
133
+ - !Sub arn:${AWS::Partition}:iam::${AWS::AccountId}:role/aws-service-role/inspector2.amazonaws.com/AWSServiceRoleForAmazonInspector2
134
+ - !Sub arn:${AWS::Partition}:iam::${AWS::AccountId}:role/aws-service-role/agentless.inspector2.amazonaws.com/AWSServiceRoleForAmazonInspector2Agentless
131
135
132
136
- Sid : AllowPolicyActions
133
137
Effect : Allow
134
138
Action : iam:PutRolePolicy
135
- Resource : !Sub arn:${AWS::Partition}:iam::${AWS::AccountId}:role/aws-service-role/inspector2.amazonaws.com/AWSServiceRoleForAmazonInspector2
139
+ Resource :
140
+ - !Sub arn:${AWS::Partition}:iam::${AWS::AccountId}:role/aws-service-role/inspector2.amazonaws.com/AWSServiceRoleForAmazonInspector2
141
+ - !Sub arn:${AWS::Partition}:iam::${AWS::AccountId}:role/aws-service-role/agentless.inspector2.amazonaws.com/AWSServiceRoleForAmazonInspector2Agentless
136
142
137
- - Sid : AllowDeleteServiceLinkRole
143
+ - Sid : AllowDeleteServiceLinkedRole
138
144
Effect : Allow
139
145
Action : iam:DeleteServiceLinkedRole
140
- Resource : !Sub arn:${AWS::Partition}:iam::${AWS::AccountId}:role/aws-service-role/inspector2.amazonaws.com/AWSServiceRoleForAmazonInspector2
146
+ Resource :
147
+ - !Sub arn:${AWS::Partition}:iam::${AWS::AccountId}:role/aws-service-role/inspector2.amazonaws.com/AWSServiceRoleForAmazonInspector2
148
+ - !Sub arn:${AWS::Partition}:iam::${AWS::AccountId}:role/aws-service-role/agentless.inspector2.amazonaws.com/AWSServiceRoleForAmazonInspector2Agentless
149
+
141
150
Tags :
142
151
- Key : sra-solution
143
152
Value : !Ref pSRASolutionName
Original file line number Diff line number Diff line change @@ -320,18 +320,26 @@ Resources:
320
320
Action : iam:CreateServiceLinkedRole
321
321
Condition :
322
322
StringLike :
323
- iam:AWSServiceName : inspector2.amazonaws.com
324
- Resource : !Sub arn:${AWS::Partition}:iam::${AWS::AccountId}:role/aws-service-role/inspector2.amazonaws.com/AWSServiceRoleForAmazonInspector2
323
+ iam:AWSServiceName :
324
+ - inspector2.amazonaws.com
325
+ - agentless.inspector2.amazonaws.com
326
+ Resource :
327
+ - !Sub arn:${AWS::Partition}:iam::${AWS::AccountId}:role/aws-service-role/inspector2.amazonaws.com/AWSServiceRoleForAmazonInspector2
328
+ - !Sub arn:${AWS::Partition}:iam::${AWS::AccountId}:role/aws-service-role/agentless.inspector2.amazonaws.com/AWSServiceRoleForAmazonInspector2Agentless
325
329
326
330
- Sid : AllowPolicyActions
327
331
Effect : Allow
328
332
Action : iam:PutRolePolicy
329
- Resource : !Sub arn:${AWS::Partition}:iam::${AWS::AccountId}:role/aws-service-role/inspector2.amazonaws.com/AWSServiceRoleForAmazonInspector2
333
+ Resource :
334
+ - !Sub arn:${AWS::Partition}:iam::${AWS::AccountId}:role/aws-service-role/inspector2.amazonaws.com/AWSServiceRoleForAmazonInspector2
335
+ - !Sub arn:${AWS::Partition}:iam::${AWS::AccountId}:role/aws-service-role/agentless.inspector2.amazonaws.com/AWSServiceRoleForAmazonInspector2Agentless
330
336
331
337
- Sid : AllowDeleteServiceLinkedRole
332
338
Effect : Allow
333
339
Action : iam:DeleteServiceLinkedRole
334
- Resource : !Sub arn:${AWS::Partition}:iam::${AWS::AccountId}:role/aws-service-role/inspector2.amazonaws.com/AWSServiceRoleForAmazonInspector2
340
+ Resource :
341
+ - !Sub arn:${AWS::Partition}:iam::${AWS::AccountId}:role/aws-service-role/inspector2.amazonaws.com/AWSServiceRoleForAmazonInspector2
342
+ - !Sub arn:${AWS::Partition}:iam::${AWS::AccountId}:role/aws-service-role/agentless.inspector2.amazonaws.com/AWSServiceRoleForAmazonInspector2Agentless
335
343
336
344
- PolicyName : sra-inspector-org-policy-logs
337
345
PolicyDocument :
You can’t perform that action at this time.
0 commit comments