SCP to restrict create resource

0

Dear Team - I have gone through https://aws.amazon.com/blogs/mt/implement-aws-resource-tagging-strategy-using-aws-tag-policies-and-service-control-policies-scps/ . As per this we can create the SCP tag policy to prevent creating new resources if no pre-defined tags are there.

In above link, example given is for EC2:runinstance. Which means, existing EC2 resources with non-compliance tags will not be impacted, right ?

If yes, i am looking for similar functionality for all the AWS resources. For example, if i create new RDS/EC2/S3 without tags "costcenter=0890", it should not let user to create those resources. At the same time, it should also not impact any existing resources without the same tag name and value.

To achieve this, do i need to add separate action for individual resource type like ec2:runinstance to stop creating that resources ? Do we have any documents for the same. i have 16 linked account under organization.

1 回答
1
已接受的回答

Could you simply add additional resource types to sample tag policy from your link? Tag policy enforcement doesn't work with all the resources but I think the list covers the most important ones.

https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_supported-resources-enforcement.html

profile picture
专家
Kallu
已回答 3 个月前
profile picture
专家
已审核 2 个月前

您未登录。 登录 发布回答。

一个好的回答可以清楚地解答问题和提供建设性反馈,并能促进提问者的职业发展。

回答问题的准则