Skip to content

Commit 4d52aa3

Browse files
authored
Update data_perimeter_governance_policy_1.json
Added APIs that neither use resource-based policies nor AWS RAM for external sharing to the governance policy
1 parent 8725524 commit 4d52aa3

1 file changed

Lines changed: 13 additions & 1 deletion

File tree

service_control_policies/data_perimeter_governance_policy_1.json

Lines changed: 13 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,14 +24,19 @@
2424
"Action": [
2525
"ec2:ModifyImageAttribute",
2626
"ec2:ModifyFPGAImageAttribute",
27+
"ec2:CreateNetworkInterfacePermission",
28+
"ec2:EnableAddressTransfer",
2729
"ec2:ModifySnapshotAttribute",
2830
"ec2:ModifyVpcEndpointServicePermissions",
2931
"ssm:ModifyDocumentPermission",
3032
"rds:ModifyDBSnapshotAttribute",
3133
"rds:ModifyDBClusterSnapshotAttribute",
3234
"redshift:AuthorizeDataShare",
3335
"redshift:AuthorizeSnapshotAccess",
36+
"redshift:AuthorizeEndpointAccess",
3437
"ds:ShareDirectory",
38+
"directconnect:CreateDirectConnectGatewayAssociationProposal",
39+
"detective:CreateMembers",
3540
"logs:PutSubscriptionFilter",
3641
"lakeformation:GrantPermissions",
3742
"lakeformation:BatchGrantPermissions",
@@ -42,7 +47,14 @@
4247
"guardduty:CreateMembers",
4348
"guardduty:InviteMembers",
4449
"auditmanager:StartAssessmentFrameworkShare",
45-
"docdb:ModifyDBClusterSnapshots"
50+
"docdb:ModifyDBClusterSnapshots",
51+
"workspaces:UpdateWorkspaceImagePermission",
52+
"oam:CreateLink",
53+
"servicecatalog:CreatePortfolioShare",
54+
"config:PutConfigurationAggregator",
55+
"fis:CreateTargetAccountConfiguration",
56+
"globalaccelerator:CreateCrossAccountAttachment",
57+
"cloud9:CreateEnvironmentMembership"
4658
],
4759
"Resource": "*",
4860
"Condition": {

0 commit comments

Comments
 (0)