Skip to content

Commit e175dac

Browse files
authored
Update resource_perimeter_scp.json
1 parent b66ff1e commit e175dac

1 file changed

Lines changed: 2 additions & 2 deletions

File tree

service_control_policies/resource_perimeter_scp.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,6 @@
1212
"arn:aws:ssm:*::automation-definition/*",
1313
"arn:aws:imagebuilder:*:aws:component/*",
1414
"arn:aws:imagebuilder:*:aws:image/*",
15-
"arn:aws:ec2:*::image/*",
1615
"arn:aws:ec2:*:aws:prefix-list/*",
1716
"arn:aws:lambda:*:<service-account-id>:layer:*",
1817
"arn:aws:ecr:*:<service-account-id>:repository/*",
@@ -36,6 +35,7 @@
3635
"Condition":{
3736
"StringNotEqualsIfExists":{
3837
"aws:ResourceOrgID":"<my-org-id>",
38+
"ec2:Owner": "amazon",
3939
"aws:PrincipalTag/dp:exclude:resource": "true"
4040
}
4141
}
@@ -79,4 +79,4 @@
7979
}
8080
}
8181
]
82-
}
82+
}

0 commit comments

Comments
 (0)