Authored FILES (not applied to AWS — provisioning gated behind the mandatory
GPT-4.1 IAM cross-review + Adam, design §7 B3) for the aws-posture checker's
read-only AWS identity. Decision D5: box stays read-only, auths via IAM Roles
Anywhere short-lived leaf certs from a new internal step-ca; NO long-lived AWS key.
- aws-posture-readonly-policy.json least-privilege read-only (ce:Get*,
cloudwatch:GetMetric*/DescribeAlarms, ec2/elb/rds:Describe*, lambda list +
GetFunctionConfiguration, s3:ListAllMyBuckets/GetBucketLocation). No write,
no iam:* mutation, no s3:GetObject/secrets/kms/logs data reads, no wildcard
actions. Resource:* only where AWS has no resource-level support.
- aws-posture-readonly-policy.rationale.md per-statement least-privilege rationale.
- aws-posture-trust-policy.json pins Roles Anywhere principal + leaf subject CN +
issuer CN + trust-anchor SourceArn (three conditions, all required).
- roles-anywhere-config.json trust anchor (pins step-ca root) + profile (1h session).
- step-ca-config-sketch.md internal CA config + systemd-timer leaf auto-renewal.
- CROSS-REVIEW-PACKET.md end-to-end trust model, blast radius, EXERCISED rollback,
reviewer scrutiny list.
Does NOT build aws-posture.sh, touch checker_coordinator.sh, or requirements.txt.
72 lines
1.8 KiB
JSON
72 lines
1.8 KiB
JSON
{
|
|
"Version": "2012-10-17",
|
|
"Statement": [
|
|
{
|
|
"Sid": "CostAndUsageReadOnly",
|
|
"Effect": "Allow",
|
|
"Action": [
|
|
"ce:GetCostAndUsage",
|
|
"ce:GetCostAndUsageWithResources",
|
|
"ce:GetCostForecast",
|
|
"ce:GetDimensionValues",
|
|
"ce:GetTags",
|
|
"ce:GetReservationUtilization",
|
|
"ce:GetSavingsPlansUtilization",
|
|
"ce:GetAnomalies",
|
|
"ce:GetAnomalyMonitors",
|
|
"ce:GetAnomalySubscriptions"
|
|
],
|
|
"Resource": "*"
|
|
},
|
|
{
|
|
"Sid": "CloudWatchMetricsReadOnly",
|
|
"Effect": "Allow",
|
|
"Action": [
|
|
"cloudwatch:GetMetricData",
|
|
"cloudwatch:GetMetricStatistics",
|
|
"cloudwatch:ListMetrics",
|
|
"cloudwatch:DescribeAlarms",
|
|
"cloudwatch:DescribeAlarmsForMetric"
|
|
],
|
|
"Resource": "*"
|
|
},
|
|
{
|
|
"Sid": "Ec2DescribeReadOnly",
|
|
"Effect": "Allow",
|
|
"Action": [
|
|
"ec2:DescribeInstances",
|
|
"ec2:DescribeInstanceStatus",
|
|
"ec2:DescribeVolumes",
|
|
"ec2:DescribeAddresses",
|
|
"ec2:DescribeNatGateways",
|
|
"ec2:DescribeSnapshots",
|
|
"ec2:DescribeImages",
|
|
"ec2:DescribeRegions"
|
|
],
|
|
"Resource": "*"
|
|
},
|
|
{
|
|
"Sid": "ElbAndRdsDescribeReadOnly",
|
|
"Effect": "Allow",
|
|
"Action": [
|
|
"elasticloadbalancing:DescribeLoadBalancers",
|
|
"elasticloadbalancing:DescribeTargetGroups",
|
|
"elasticloadbalancing:DescribeTargetHealth",
|
|
"rds:DescribeDBInstances",
|
|
"rds:DescribeDBClusters"
|
|
],
|
|
"Resource": "*"
|
|
},
|
|
{
|
|
"Sid": "LambdaAndStorageInventoryReadOnly",
|
|
"Effect": "Allow",
|
|
"Action": [
|
|
"lambda:ListFunctions",
|
|
"lambda:GetFunctionConfiguration",
|
|
"s3:ListAllMyBuckets",
|
|
"s3:GetBucketLocation"
|
|
],
|
|
"Resource": "*"
|
|
}
|
|
]
|
|
}
|