Scp Tag enforcement is not working on Ec2.

0

I have created an SCP to deny ec2 resource creation if there is no tag. The instance is only get created if it has an environment tag key mentioned in it.

Here is my policy :

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "Scp1",
      "Effect": "Deny",
      "Action": [
        "ec2:CreateTags",
        "ec2:RunInstances"
      ],
      "Resource": [
        "arn:aws:ec2:*:*:instance/*",
        "arn:aws:ec2:*:*:volume/*"
      ],
      "Condition": {
        "ForAllValues:StringEquals": {
          "aws:RequestTag/environment": "true"
        }
      }
    }
  ]
}
Shubham
feita há 2 anos1021 visualizações
2 Respostas
0

Yes I am trying to achieve this thing but I want to achieve this by using AWS SCP. All post which I have seen they all have same json file as mine. But while implementation it is not working.

Shubham
respondido há 2 anos
  • So what condition type you are using?

    ForAllValues:StringEquals? Or StringNotLike?

  • I have used Both but no luck.

  • Can you also post the policy you use with StringNotLike to see if there is any other issue?

  • {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Sid": "Scp1",
          "Effect": "Deny",
          "Action": [
            "ec2:RunInstances"
          ],
          "Resource": [
            "arn:aws:ec2:*:*:instance/*",
            "arn:aws:ec2:*:*:volume/*"
          ],
          "Condition": {
            "ForAllValues:StringEquals": {
              "aws:RequestTag/environment": "true"
            }
          }
        }
      ]
    }
    
    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Sid": "Scp1",
          "Effect": "Deny",
          "Action": [
            "ec2:RunInstances"
          ],
          "Resource": [
            "arn:aws:ec2:*:*:instance/*",
            "arn:aws:ec2:*:*:volume/*"
          ],
          "Condition": {
            "ForAllValues:StringNotLike": {
              "aws:RequestTag/environment": "true"
            }
          }
        }
      ]
    }
    
  • Your policy with

    "ForAllValues:StringNotLike": {
              "aws:RequestTag/environment": "true"
            }
    

    means all your new EC2 instances need to have a tag environment and the tag value must be exactly true

    Is this what you expect and what you get?

0

I guess you are trying to achieve something like this: https://aws.amazon.com/premiumsupport/knowledge-center/iam-policy-tags-deny/ (Sid: AllowRunInstancesWithRestrictions1)

Your policy can be modified as follow:

{
    "Effect": "Deny",
    "Action": [
        "ec2: CreateTags",
        "ec2: RunInstances"
    ],
    "Resource": [
        "arn:aws:ec2:*:*:instance/*",
        "arn:aws:ec2:*:*:volume/*"
    ],
    "Condition": {
        "StringNotLike": {
            "aws:RequestTag/cost_center": "?*"
        }
    }
}
respondido há 2 anos

Você não está conectado. Fazer login para postar uma resposta.

Uma boa resposta responde claramente à pergunta, dá feedback construtivo e incentiva o crescimento profissional de quem perguntou.

Diretrizes para responder a perguntas