Intro
data:image/s3,"s3://crabby-images/c384b/c384be3d2a5caafe8f23555999c7ce659dd50c11" alt=""
There are three different "Actions" we want to allow our feature tu use:
- AuthorizeSecurityGroupIngress
- RevokeSecurityGroupIngress
- DescribeSecurityGroups
Code
First create a new policy with the name: CanDo_SecurityGroup
Within the policy paste the following piece of code:
As you can see in the snippet above, with the "Condition" module we can define our own restrictions. In this case our feature will only create or remove security groups with a particular tag value ("yourSecurityGroupTagValue").
0 comments:
Post a Comment