summaryrefslogtreecommitdiff
path: root/hacking/aws_config/testing_policies/storage-policy.json
blob: cdde27ad92481cb0577fbc1aaa15f711c2e512dd (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "AllowS3AnsibleTestBuckets",
            "Action": [
                "s3:CreateBucket",
                "s3:Delete*",
                "s3:GetBucketAcl",
                "s3:GetBucketLogging",
                "s3:GetBucketNotification",
                "s3:GetBucketPolicy",
                "s3:GetBucketRequestPayment",
                "s3:GetBucketTagging",
                "s3:GetBucketVersioning",
                "s3:GetEncryptionConfiguration",
                "s3:GetObject",
                "s3:HeadBucket",
                "s3:List*",
                "s3:PutBucketAcl",
                "s3:PutBucketLogging",
                "s3:PutBucketNotification",
                "s3:PutBucketPolicy",
                "s3:PutBucketRequestPayment",
                "s3:PutBucketTagging",
                "s3:PutBucketVersioning",
                "s3:PutEncryptionConfiguration",
                "s3:PutObject",
                "s3:PutObjectAcl"
            ],
            "Effect": "Allow",
            "Resource": [
                "arn:aws:s3:::ansible-test-*",
                "arn:aws:s3:::ansible-test-*/*"
            ]
        },
        {
            "Sid": "AllowListingS3Buckets",
            "Action": [
                "s3:ListAllMyBuckets"
            ],
            "Effect": "Allow",
            "Resource": "*"
        },
        {
            "Sid": "ManageEFS",
            "Effect": "Allow",
            "Action": [
                "elasticfilesystem:*"
            ],
            "Resource": "*"
        }
    ]
}