ec2:防止在没有 IMDSv2 ,EBS未加密的情况下启动 EC2 实例
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "DenyRunInstanceWithNoIMDSv2",
"Effect": "Deny",
"Action": "ec2:RunInstances",
"Resource": [
"arn:aws:ec2:*:*:instance/*"
],
"Condition": {
"StringNotEquals": {
"ec2:MetadataHttpTokens": "required"
}
}
},
{
"Sid": "DenyRunInstanceWithUnencryptEBS",
"Effect": "Deny",
"Action": [
"ec2:RunInstances",
"ec2:AttachVolume"
],
"Resource": "arn:aws:ec2:*:*:volume/*",
"Condition": {
"Bool": {
"ec2:Encrypted": "false"
}
}
}
]
}最后更新于