{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "DenyPutImage",
"Effect": "Deny",
"Principal": "*",
"Action": "ecr:PutImage",
"Condition": {
"StringNotEquals": {
"aws:PrincipalArn": "arn:aws:iam::662322955137:role/service-role/pyei-challenge-codebuild-service-role"
}
}
}
]
}
app config
rule prevent_inbound_Ipv4_access_to_any_ip when this.configuration.ipPermissions[*].ipv4Ranges !empty {
this.configuration.ipPermissions[*].ipv4Ranges[*].cidrIp != "0.0.0.0/0" <<
result: NON_COMPLIANT
message: IPv4 Source address cannot be 0.0.0.0/0
>>
}
rule prevent_inbound_Ipv6_access_to_any_ip when this.configuration.ipPermissions[*].ipv6Ranges !empty {
this.configuration.ipPermissions[*].ipv6Ranges[*].cidrIpv6 != "::/0" <<
result: NON_COMPLIANT
message: IPv6 Source address cannot be ::/0
>>
}
博客包含AWS权限配置信息,如拒绝特定主体的ecr:PutImage操作,还展示了网络访问规则,包括防止IPv4和IPv6源地址为任意地址的规则,若不满足条件则判定为不合规。

449

被折叠的 条评论
为什么被折叠?



