hashicorp / terraform-provider-aws

The AWS Provider enables Terraform to manage AWS resources.
https://registry.terraform.io/providers/hashicorp/aws
Mozilla Public License 2.0
9.76k stars 9.12k forks source link

Restrict backup example policy #39490

Closed MarkCBell closed 1 day ago

MarkCBell commented 2 days ago

Description

The current example of an AWS Backup vault policy allows any user to put a new policy (since it uses Principal "*"). Therefore deploying the provided example would allow anyone to replace this policy with one in which they had full control over the backup vault. This would include taking copies of the data in there or deleting snapshots.

AWS "strongly recommend that you do not use a wildcard (*) in the Principal element of a resource-based policy with an Allow effect". Following this, this PR replaces the Principal with the account id, therefore giving this power only to roles already within this account, which is much less dangerous.

Relations

None

References

https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_elements_principal.html#principal-anonymous

github-actions[bot] commented 2 days ago

Community Note

Voting for Prioritization

For Submitters

jar-b commented 1 day ago

Thanks for your contribution, @MarkCBell! 👍

github-actions[bot] commented 1 day ago

This functionality has been released in v5.69.0 of the Terraform AWS Provider. Please see the Terraform documentation on provider versioning or reach out if you need any assistance upgrading.

For further feature requests or bug reports with this functionality, please create a new GitHub issue following the template. Thank you!