This policy is great, very clear, and objective but EC2 doesn't implement the Global Condition aws:ViaAWSService. So this policy cause problems to launch EC2 instances based on encrypted EBS.
It would be great to have a new version of this policy to work as expected or at least add a disclaimer explaining that some services such as EC2, OpsWorks, Glue, and LakeFormation could have problems to perform some actions if this policy is applied.
This policy is great, very clear, and objective but EC2 doesn't implement the Global Condition aws:ViaAWSService. So this policy cause problems to launch EC2 instances based on encrypted EBS.
It would be great to have a new version of this policy to work as expected or at least add a disclaimer explaining that some services such as EC2, OpsWorks, Glue, and LakeFormation could have problems to perform some actions if this policy is applied.
Doc: Denies Access to AWS Based on the Source IP