Skip to content

Commit

Permalink
Browse files Browse the repository at this point in the history
fixed scp for region limit
ericstraavaldsen committed Oct 28, 2019
1 parent fcab2ba commit a54f079
Showing 2 changed files with 39 additions and 0 deletions.
2 changes: 2 additions & 0 deletions docker-container-scan.sh
@@ -0,0 +1,2 @@
#!/bin/bash
docker ps -ef
37 changes: 37 additions & 0 deletions us-regions-only-group-exception.policy
@@ -0,0 +1,37 @@
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "DenyAllOutsideUS",
"Effect": "Deny",
"NotAction": [
"iam:*",
"organizations:*",
"route53:*",
"budgets:*",
"waf:*",
"cloudfront:*",
"globalaccelerator:*",
"importexport:*",
"support:*",
"sts:*"
],
"Resource": "*",
"Condition": {
"StringNotEquals": {
"aws:RequestedRegion": [
"us-east-1",
"us-east-2",
"us-west-1",
"us-west-2"
]
},
"StringNotLike": {
"aws:PrincipalArn": [
"arn:aws:iam::*:role/NetIDSuperAdmistratorAccess",
"arn:aws:iam::*:role/NetIDCloudTeamAccess"]
}
}
}
]
}

0 comments on commit a54f079

Please sign in to comment.