🔌 AWS IAM Group Policy - object.extracts.yaml
- Contextual name: 🔌 object.extracts.yaml
- ID:
/types/CA10__CaAwsGroupPolicy__c/object.extracts.yaml
Used In
| Logic | Policy | Flags |
|---|---|---|
| 🧠 prod.logic.yaml🟢 | 🛡️ AWS IAM Group Inline Policy allows KMS decryption actions on all KMS keys🟢 | 🟢 x3 |
Content
# yaml-language-server: $schema=../../schema/Extracts.schema.json
---
extracts:
- name: "CA10__policyDocument__c"
value:
FIELD:
path: "CA10__policyDocument__c"
returnType: BYTES
undeterminedIf:
noAccessDelegate:
path: "CA10__policyDocument__c"
currentStateMessage: "Unable to determine the Policy Document. Possible permission issue with iam:GetGroupPolicy"
- name: "caJsonFrom_policyDocument__c"
value:
JSON_FROM:
arg:
EXTRACT: "CA10__policyDocument__c"
undeterminedIf:
isInvalid: "IAM policy document JSON is invalid."