SCP to restrict create resource

0

Dear Team - I have gone through https://aws.amazon.com/blogs/mt/implement-aws-resource-tagging-strategy-using-aws-tag-policies-and-service-control-policies-scps/ . As per this we can create the SCP tag policy to prevent creating new resources if no pre-defined tags are there.

In above link, example given is for EC2:runinstance. Which means, existing EC2 resources with non-compliance tags will not be impacted, right ?

If yes, i am looking for similar functionality for all the AWS resources. For example, if i create new RDS/EC2/S3 without tags "costcenter=0890", it should not let user to create those resources. At the same time, it should also not impact any existing resources without the same tag name and value.

To achieve this, do i need to add separate action for individual resource type like ec2:runinstance to stop creating that resources ? Do we have any documents for the same. i have 16 linked account under organization.

1개 답변
1
수락된 답변

Could you simply add additional resource types to sample tag policy from your link? Tag policy enforcement doesn't work with all the resources but I think the list covers the most important ones.

https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_supported-resources-enforcement.html

profile picture
전문가
Kallu
답변함 3달 전
profile picture
전문가
검토됨 2달 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠