admin管理员组

文章数量:1279090

We have a corporate policy that all IAM IaC must be approved by the IAM team. For our Terraform solutions we keep the IAM code in a IAM module, and any time that is changed it triggers a review by the IAM team. Is there a way to do something similar with AWS SAM? I see there are policy templates but they are managed by Amazon so our IAM team would not know if there were changed without constantly checking. Inline policy would not work because then the IAM team would have to review the whole template every time it is changed, even if it is not an IAM change.

本文标签: aws samPartitioned Policy FileStack Overflow