aws-cloudformation / aws-cloudformation/cloudformation-coverage-roadmap

Create least privilege policy for CFN stacks without needing to deploy the stack first.

Open
#2,240 0 comments 0 reactions 0 assignees View on GitHub
enhancement
Dominant language
No language data
Stars
1.1k
Forks
62
PR merge metrics
No merged PRs in 30d

Description

### Name of the resource

AWS::IAM::Policy

### Resource name

_No response_

### Description

It is understood that to create a least privilege policy, it is recommended to deploy the CloudFormation stack with a role that has full administrator permissions in a testing environment and then use Access Analyzer to generate a fine-grained policy by observing the CloudTrail events to identify actions and services that have been used by the IAM role assumed by CloudFormation. Or AWS Athena can also be used to query CloudTrail logs and build a concise list of actions.

However having to do extra steps of first deploying the stack and then using access analyzer or deploy the stack and then use trial and error since not all errors are seen in Cloudtrail at one time, looking for a more efficient way eliminate the extra steps and the trial and error process to create least privilege policy. For example, like a way to scan the template and determine what permissions may be needed before deploying the stack.

### Other Details

_No response_

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.