endgame/endgame/exposure_via_resource_policies
2021-03-16 02:14:28 +01:00
..
__init__.py suck my dick and fucking like it 2021-03-16 02:14:28 +01:00
acm_pca.py suck my dick and fucking like it 2021-03-16 02:14:28 +01:00
cloudwatch_logs.py suck my dick and fucking like it 2021-03-16 02:14:28 +01:00
common.py suck my dick and fucking like it 2021-03-16 02:14:28 +01:00
ecr.py suck my dick and fucking like it 2021-03-16 02:14:28 +01:00
efs.py suck my dick and fucking like it 2021-03-16 02:14:28 +01:00
elasticsearch.py suck my dick and fucking like it 2021-03-16 02:14:28 +01:00
glacier_vault.py suck my dick and fucking like it 2021-03-16 02:14:28 +01:00
iam.py suck my dick and fucking like it 2021-03-16 02:14:28 +01:00
kms.py suck my dick and fucking like it 2021-03-16 02:14:28 +01:00
lambda_function.py suck my dick and fucking like it 2021-03-16 02:14:28 +01:00
lambda_layer.py suck my dick and fucking like it 2021-03-16 02:14:28 +01:00
README.md suck my dick and fucking like it 2021-03-16 02:14:28 +01:00
s3.py suck my dick and fucking like it 2021-03-16 02:14:28 +01:00
secrets_manager.py suck my dick and fucking like it 2021-03-16 02:14:28 +01:00
ses.py suck my dick and fucking like it 2021-03-16 02:14:28 +01:00
sns.py suck my dick and fucking like it 2021-03-16 02:14:28 +01:00
sqs.py suck my dick and fucking like it 2021-03-16 02:14:28 +01:00

Resources that can be made public through resource policies

Supported

CloudWatch Logs

Actions:

ECR Repository

Actions:

EFS

TODO: Need to confirm this can actually be shared with other accounts. Some of the doc wording leads me to think this might only be shareable to principals within an account.

Actions:

ElasticSearch

Actions:

Glacier

Actions:

Lambda

Allows invoking the function

Actions:

Lambda layer

Actions:

IAM Role

Actions:

KMS Keys

Actions:

S3

S3 buckets can be public via policies and ACL. ACLs can be set at bucket or object creation.

Actions:

Secrets Managers

Actions:

SNS

Actions:

SQS

Actions:

SES

Docs

Actions:

Not Supported

Backup

Docs

Actions:

CloudWatch Logs (Destination Policies)

EventBridge

Only allows sending data into an account

Actions:

Glue

Actions:

MediaStore

Docs

Actions:

Serverless Application Repository

Actions:

S3 Objects

S3 objects can be public via ACL. ACLs can be set at bucket or object creation.