资源治理中心 RGC-必选控制策略:RGC-GR_CT_AUDIT_BUCKET_ENCRYPTION_CHANGES_PROHIBITED

时间:2024-05-11 17:30:08

RGC-GR_CT_AUDIT_BUCKET_ENCRYPTION_CHANGES_PROHIBITED

实现:SCP

类型:Preventive

功能:防止对RGC创建的OBS桶的加密配置进行更改。

{
	"Version": "5.0",
	"Statement": [{
		"Sid": "AUDIT_BUCKET_ENCRYPTION_CHANGES_PROHIBITED",
		"Effect": "Deny",
		"Action": [
			"obs:bucket:PutEncryptionConfiguration"
		],
		"Resource": [
			"obs:*::bucket:rgcservice-managed-*-logs-*"
		],
		"Condition": {
			"StringNotMatch": {
				"g:PrincipalUrn": "sts::*:assumed-agency:RG CS erviceExecutionAgency/*"
			}
		}
	}]
}
support.huaweicloud.com/usermanual-rgc/rgc_01_0035.html