AWS IAM Policy to Enforce Multiple Tags

Viewed 242

Is it possible to write this more succinctly I have tried a number of ways but all seem to fail. I have Tried adding all 3 conditions to one deny with ForAllValues or ForAnyValues but although the statements create the rules are not enforced entirely unless it is written like this.

{"Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "Statement1",
      "Effect": "Deny",
      "Action": [
        "ec2:RunInstances"
      ],
      "Resource": [
        "arn:aws:ec2:*:*:instance/*"
      ],
      "Condition": {
        "Null": {
          "aws:RequestTag/Name": "true"
        }
      }
    },
    {
      "Sid": "Statement2",
      "Effect": "Deny",
      "Action": [
        "ec2:RunInstances"
      ],
      "Resource": [
        "arn:aws:ec2:*:*:instance/*"
      ],
      "Condition": {
        "Null": {
          "aws:RequestTag/Dept": "true"
        }
      }
    },
    {
      "Sid": "Statement3",
      "Effect": "Deny",
      "Action": [
        "ec2:RunInstances"
      ],
      "Resource": [
        "arn:aws:ec2:*:*:instance/*"
      ],
      "Condition": {
        "Null": {
          "aws:RequestTag/Owner": "true"
        }
      }
    }
  ]
}
1 Answers

I also ran into same scenario where i needed to enforce multiple tags on a single resource type and tried the below methods all of which failed.

ForAllValue is not suitable as it will allow resource creation if no tag keys are passed. Thus failing the scp purpose ForAnyValue will not work as it will work like an OR operator between tag keys aws:TagKeys don’t work as it also works as OR operator.

We can’t use same condition key like StringNotEquals multiple times in one condition operator.

So i also followed the same approach as suggested by you. If anyone has a suggestion please suggest or i think it’s a feature miss at aws side

Related