aws.iot-policy

AWS IoT policy.

Filters

attached

Filter IoT policies by whether they are attached to any target.

example:

policies:
  - name: iot-policy-orphaned
    resource: aws.iot-policy
    filters:
      - type: attached
        state: false
properties:
  state:
    type: boolean
  type:
    enum:
    - attached
required:
- type

Permissions - iot:ListTargetsForPolicy

has-statement

Find resources with matching access policy statements.

If you want to return resource statements that include the listed key, e.g. Action, you can use PartialMatch instead of an exact match.

example:

policies:
  - name: sns-check-statement-id
    resource: sns
    filters:
      - type: has-statement
        statement_ids:
          - BlockNonSSL
policies:
  - name: sns-check-block-non-ssl
    resource: sns
    filters:
      - type: has-statement
        statements:
          - Effect: Deny
            Action: 'SNS:Publish'
            Principal: '*'
            Condition:
                Bool:
                    "aws:SecureTransport": "false"
            PartialMatch: 'Action'
properties:
  statement_ids:
    items:
      type: string
    type: array
  statements:
    items:
      properties:
        Action:
          anyOf:
          - type: string
          - type: array
        Condition:
          type: object
        Effect:
          enum:
          - Allow
          - Deny
          type: string
        NotAction:
          anyOf:
          - type: string
          - type: array
        NotPrincipal:
          anyOf:
          - type: object
          - type: array
        NotResource:
          anyOf:
          - type: string
          - type: array
        PartialMatch:
          anyOf:
          - enum:
            - Action
            - NotAction
            - Principal
            - NotPrincipal
            - Resource
            - NotResource
            - Condition
            type: string
          - items:
            - enum:
              - Action
              - NotAction
              - Principal
              - NotPrincipal
              - Resource
              - NotResource
              - Condition
              type: string
            type: array
        Principal:
          anyOf:
          - type: string
          - type: object
          - type: array
        Resource:
          anyOf:
          - type: string
          - type: array
        Sid:
          type: string
      required:
      - Effect
      type: object
    type: array
  type:
    enum:
    - has-statement
required:
- type

Actions

delete

Delete an IoT policy.

Non-default versions are deleted and targets detached first, as required by the API. Set force to detach targets; without it an attached policy is skipped.

example:

policies:
  - name: iot-policy-delete-orphaned
    resource: aws.iot-policy
    filters:
      - type: attached
        state: false
    actions:
      - delete
properties:
  force:
    type: boolean
  type:
    enum:
    - delete
required:
- type

Permissions - iot:DeletePolicy, iot:DeletePolicyVersion, iot:ListPolicyVersions, iot:ListTargetsForPolicy, iot:DetachPolicy