资源治理中心 RGC-必选控制策略:RGC-GR_CES_CHANGE_PROHIBITED

时间:2024-05-11 17:30:08

RGC-GR_ CES _CHANGE_PROHIBITED

实现:SCP

类型:Preventive

功能:防止更改RGC为监控环境而设置的CES配置。

{
	"Version": "5.0",
	"Statement": [{
			"Sid": "CES_CHANGE_PROHIBITED",
			"Effect": "Deny",
			"Action": [
				"ces:alarms:put*",
				"ces:alarms:delete*",
				"ces:alarms:addResources"
			],
			"Resource": [
				"*"
			],
			"Condition": {
				"StringNotMatch": {
					"g:PrincipalUrn": "sts::*:assumed-agency:RG CS erviceExecutionAgency/*"
				},
				"StringMatch": {
					"g:ResourceTag/rgcservice-managed": "RGC-ConfigComplianceChangeEventRule"
				}
			}
		},
		{
			"Sid": "CES_TAG_CHANGE_PROHIBITED",
			"Effect": "Deny",
			"Action": [
				"ces:tags:create"
			],
			"Resource": [
				"*"
			],
			"Condition": {
				"StringNotMatch": {
					"g:PrincipalUrn": "sts::*:assumed-agency:RGCServiceExecutionAgency/*"
				},
				"ForAnyValue:StringMatch": {
					"g:TagKeys": "rgcservice-managed"
				}
			}
		}
	]
}

support.huaweicloud.com/usermanual-rgc/rgc_01_0035.html