-
-
Notifications
You must be signed in to change notification settings - Fork 38
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
AWS Service Role IAM Policies and IAM Policy Attachments Are Being Removed #465
Comments
Did you add the setting to include the roles by chance in your config? I added a resource setting to allow the removal of service roles but its disable by default. I suppose it could be bugged, although I haven't seen it myself. I should create a way to have configs shared securely ... |
Not that I know of, but it's possible I did. Let me know how best to send over the config and I will! Thanks so much. |
Email works for now |
Sent. Thank you. |
This is expected behavior, Service Linked Roles vs Service Roles. The tool only ever blocked the deletion of Service Linked Roles which were under the path |
Understood. I'll add the following going forward:
|
Version:
3.29.1
Platform:
Aarch64
It's totally possible I'm missing something, but I was testing an updated version of our config and I'm seeing AWS Service Role's IAM Policies and Policy Attachments being deleted. I haven't experienced when testing previously.
Is this expected behavior? Happy to send my config privately.
The IAM Policy Attachment /IAM Role for
Amazon_EventBridge_Scheduler_LAMBDA_fbb2554175
may be part of a separate non-default resource that I expect to be deleted, but included it for completeness.The text was updated successfully, but these errors were encountered: