Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Overly permissive service permission #30

Open
dmurvihill opened this issue Sep 30, 2023 · 0 comments
Open

Overly permissive service permission #30

dmurvihill opened this issue Sep 30, 2023 · 0 comments
Labels
bug Something isn't working

Comments

@dmurvihill
Copy link

The AWS S3 console for the generated log bucket shows the following security warning:

Ln 15, Col 15 | Restrict Access To Service Principal: Granting  access to a service principal without specifying a source is overly  permissive. Use aws:SourceArn or aws:SourceAccount condition key to  grant fine-grained access.
-- | --

Referring to the getBucketAcl action for ELB log delivery. I agree, adding a variable for sourceArn or sourceAccount would be best.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
Development

No branches or pull requests

2 participants