I want to have a logical or between AWS policy which I then need to attach to SCP. The motivation is to add a policy which applies in case one of 2 conditions are met.
{
"sid": "OnlyT1T2Micro",
"Effect": "Deny",
"Action": ["ec2:RunInstances"],
"Resource": ["arn:aws:ec2:us-east-1:accountid:instance/*"],
"Condition": {
"StringEquals": {
"ec2:InstanceType": ["t1.micro","t2.micro"]
},
"StringEquals": {
"ec2:Region": "us-east-1"
}
}
}
In this case, I would like to deny Ec2 run instance API in case type is one of t1 or t2 micro or the region is us-east-1. But in this snippet, it's a logical "and" between conditions which mean the policy would apply in case it's a (t1.micro or t2.micro) and (us-east-1 region), which I'm looking to add "or"
In order to save the text in the SCP (due to limit), I was looking for shrinking together in 1 policy 2 conditions with "or", in case there is an option
Hope this example is clear