pulumi

{
    "Version": "2012-10-17",
    "Statement": [
      {
        "Sid": "EnforceTrustedOIDCTenantPulumi",
        "Effect": "Deny",
        "Principal": "*",
        "Action": "sts:AssumeRoleWithWebIdentity",
        "Resource": "*",
        "Condition": {
          "StringNotLikeIfExists": {
            "api.pulumi.com:sub": "pulumi:*:org:<organization>:*"
          },
          "Null": {
            "api.pulumi.com:sub": "false"
          }
        }
      }
    ]
  }

最后更新于