2019-06-30 13:47:17 +02:00 
										
									 
								 
							 
							
								
							 
							
								 
							
							
								import  json  
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								import  boto3  
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								from  botocore . exceptions  import  ClientError  
						 
					
						
							
								
									
										
										
										
											2020-10-06 07:54:49 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								import  pytest  
						 
					
						
							
								
									
										
										
										
											2022-03-11 20:28:45 -01:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								import  sure   # noqa # pylint: disable=unused-import  
						 
					
						
							
								
									
										
										
										
											2019-06-30 13:47:17 +02:00 
										
									 
								 
							 
							
								
							 
							
								 
							
							
								
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								from  moto  import  mock_iam  
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								invalid_policy_document_test_cases  =  [  
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  " This is not a json document " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Syntax errors in policy. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            } 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Policy document must be version 2012-10-17 or greater. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2008-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Policy document must be version 2012-10-17 or greater. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2013-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Syntax errors in policy. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " document " :  { " Version " :  " 2012-10-17 " } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " error_message " :  " Syntax errors in policy. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " document " :  { " Version " :  " 2012-10-17 " ,  " Statement " :  [ " afd " ] } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " error_message " :  " Syntax errors in policy. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Extra field " :  " value " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Syntax errors in policy. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Extra field " :  " value " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Syntax errors in policy. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Id " :  [ " cd3a324d2343d942772346-34234234423404-4c2242343242349d1642ee " ] , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Syntax errors in policy. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Id " :  { } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Syntax errors in policy. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " invalid " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Syntax errors in policy. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " invalid " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Actions/Conditions must be prefaced by a vendor, e.g., iam, sdb, ec2, etc. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 20:33:17 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " NotAction " :  " " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 20:33:17 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Actions/Conditions must be prefaced by a vendor, e.g., iam, sdb, ec2, etc. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 20:33:17 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 18:48:27 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " a a:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 18:48:27 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Vendor a a is not valid " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 18:48:27 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:List:Bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 18:48:27 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Actions/Condition can contain only one colon. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 18:48:27 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 20:33:17 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Statement " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " Action " :  " s3s:ListBucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                    " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 20:33:17 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " Action " :  " s:3s:ListBucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                    " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 20:33:17 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Actions/Condition can contain only one colon. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 20:33:17 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  " invalid resource " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  ' Resource invalid resource must be in ARN format or  " * " . ' , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Statement " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " Sid " :  " EnableDisableHongKong " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " Effect " :  " Allow " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                    " Action " :  [ " account:EnableRegion " ,  " account:DisableRegion " ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                    " Resource " :  " " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " Condition " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                        " StringEquals " :  { " account:TargetRegion " :  " ap-east-1 " } 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                    } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " Sid " :  " ViewConsole " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " Effect " :  " Allow " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                    " Action " :  [ " aws-portal:ViewAccount " ,  " account:ListRegions " ] , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " Resource " :  " " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  ' Resource  must be in ARN format or  " * " . ' , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 20:33:17 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s:3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " sdfsadf " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 20:33:17 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  ' Resource sdfsadf must be in ARN format or  " * " . ' , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 20:33:17 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  [ " adf " ] , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  ' Resource adf must be in ARN format or  " * " . ' , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 18:48:27 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Statement " :  { " Effect " :  " Allow " ,  " Action " :  " s3:ListBucket " ,  " Resource " :  " " } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 18:48:27 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  ' Resource  must be in ARN format or  " * " . ' , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 18:48:27 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 20:33:17 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " NotAction " :  " s3s:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " a:bsdfdsafsad " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 20:33:17 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  ' Partition  " bsdfdsafsad "  is not valid for resource  " arn:bsdfdsafsad:*:*:*:* " . ' , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 20:33:17 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " NotAction " :  " s3s:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " a:b:cadfsdf " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 20:33:17 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  ' Partition  " b "  is not valid for resource  " arn:b:cadfsdf:*:*:* " . ' , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 20:33:17 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " NotAction " :  " s3s:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " a:b:c:d:e:f:g:h " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 20:33:17 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  ' Partition  " b "  is not valid for resource  " arn:b:c:d:e:f:g:h " . ' , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 20:33:17 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 17:30:59 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  " aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 17:30:59 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  ' Partition  " s3 "  is not valid for resource  " arn:s3:::example_bucket:* " . ' , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 17:30:59 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " arn:error:s3:::example_bucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                    " arn:error:s3::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                ] , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 17:30:59 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  ' Partition  " error "  is not valid for resource  " arn:error:s3:::example_bucket " . ' , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 17:30:59 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " document " :  { " Version " :  " 2012-10-17 " ,  " Statement " :  [ ] } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " error_message " :  " Syntax errors in policy. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Statement " :  { " Effect " :  " Allow " ,  " Action " :  " s3:ListBucket " } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Policy statement must contain resources. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Statement " :  { " Effect " :  " Allow " ,  " Action " :  " s3:ListBucket " ,  " Resource " :  [ ] } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Policy statement must contain resources. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 18:48:27 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Statement " :  { " Effect " :  " Allow " ,  " Action " :  " invalid " } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 18:48:27 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2022-07-29 23:25:56 -04:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Actions/Conditions must be prefaced by a vendor, e.g., iam, sdb, ec2, etc. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 18:48:27 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Statement " :  { " Effect " :  " Allow " ,  " Resource " :  " arn:aws:s3:::example_bucket " } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Policy statement must contain actions. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Syntax errors in policy. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " document " :  { " Version " :  " 2012-10-17 " ,  " Statement " :  { " Effect " :  " Allow " } } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " error_message " :  " Policy statement must contain actions. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 18:48:27 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  [ ] , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 18:48:27 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Policy statement must contain actions. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 18:48:27 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Statement " :  [ 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                { " Effect " :  " Deny " } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                { 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 13:47:17 +02:00 
										
									 
								 
							 
							
								
							 
							
								 
							
							
								                    " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                    " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Policy statement must contain actions. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:iam:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 13:47:17 +02:00 
										
									 
								 
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  ' IAM resource path must either be  " * "  or start with user/, federated-user/, role/, group/, instance-profile/, mfa/, server-certificate/, policy/, sms-mfa/, saml-provider/, oidc-provider/, report/, access-report/. ' , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 16:36:49 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " The policy failed legacy parsing " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 17:30:59 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Statement " :  { " Effect " :  " Allow " ,  " Resource " :  " arn:aws:s3::example_bucket " } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 17:30:59 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " The policy failed legacy parsing " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 17:30:59 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 13:47:17 +02:00 
										
									 
								 
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Resource vendor must be fully qualified and cannot contain regexes. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  { " a " :  " arn:aws:s3:::example_bucket " } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 13:47:17 +02:00 
										
									 
								 
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Syntax errors in policy. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Deny " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  [ " adfdf " ,  { } ] , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Syntax errors in policy. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 20:33:17 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " NotAction " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " NotResource " :  [ ] , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 20:33:17 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Syntax errors in policy. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 20:33:17 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 18:48:27 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Deny " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  [ [ ] ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 18:48:27 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Syntax errors in policy. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 18:48:27 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 20:33:17 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " NotAction " :  " s3s:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  [ ] , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 20:33:17 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Syntax errors in policy. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 20:33:17 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 18:48:27 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  { } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 18:48:27 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Syntax errors in policy. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 18:48:27 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Condition " :  [ ] , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 13:47:17 +02:00 
										
									 
								 
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Syntax errors in policy. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Condition " :  " a " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 13:47:17 +02:00 
										
									 
								 
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Syntax errors in policy. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Condition " :  { " a " :  " b " } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 13:47:17 +02:00 
										
									 
								 
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Syntax errors in policy. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Condition " :  { " DateGreaterThan " :  " b " } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 13:47:17 +02:00 
										
									 
								 
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Syntax errors in policy. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Condition " :  { " DateGreaterThan " :  [ ] } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 13:47:17 +02:00 
										
									 
								 
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Syntax errors in policy. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Condition " :  { " DateGreaterThan " :  { " a " :  { } } } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 13:47:17 +02:00 
										
									 
								 
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Syntax errors in policy. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Condition " :  { " DateGreaterThan " :  { " a " :  { } } } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 13:47:17 +02:00 
										
									 
								 
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Syntax errors in policy. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 17:30:59 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Condition " :  { " x " :  { " a " :  " 1 " } } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 17:30:59 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Syntax errors in policy. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 17:30:59 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Condition " :  { " ForAnyValue::StringEqualsIfExists " :  { " a " :  " asf " } } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 17:30:59 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Syntax errors in policy. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 17:30:59 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Condition " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    { " ForAllValues:StringEquals " :  { " aws:TagKeys " :  " Department " } } 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                ] , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 16:36:49 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Syntax errors in policy. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:iam:us-east-1::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 13:47:17 +02:00 
										
									 
								 
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " IAM resource arn:aws:iam:us-east-1::example_bucket cannot contain region information. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:us-east-1::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 13:47:17 +02:00 
										
									 
								 
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Resource arn:aws:s3:us-east-1::example_bucket can not contain region information. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Sid " :  { } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 13:47:17 +02:00 
										
									 
								 
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Syntax errors in policy. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Sid " :  [ ] , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 14:03:18 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Syntax errors in policy. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Statement " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " Sid " :  " sdf " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 14:03:18 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                    " Effect " :  " Allow " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                    " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                    " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                { " Sid " :  " sdf " ,  " Effect " :  " Allow " } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Statement IDs (SID) in a single policy must be unique. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 20:33:17 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Statement " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " Sid " :  " sdf " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                    " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 20:33:17 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                { " Sid " :  " sdf " ,  " Effect " :  " Allow " } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 20:33:17 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            ] 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Policy document must be version 2012-10-17 or greater. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 20:33:17 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " NotAction " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " iam:dsf " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Syntax errors in policy. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " NotResource " :  " * " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Syntax errors in policy. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " denY " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " The policy failed legacy parsing " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Condition " :  { " DateGreaterThan " :  { " a " :  " sdfdsf " } } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 16:36:49 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " The policy failed legacy parsing " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Condition " :  { " DateGreaterThan " :  { " a " :  " sdfdsf " } } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Policy document must be version 2012-10-17 or greater. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 17:30:59 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " denY " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 17:30:59 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            } 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " Policy document must be version 2012-10-17 or greater. " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 17:30:59 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Condition " :  { " DateGreaterThan " :  { " a " :  " sdfdsf " } } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " The policy failed legacy parsing " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 20:33:17 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " NotAction " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws::::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 20:33:17 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " The policy failed legacy parsing " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 20:33:17 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:us-east-1::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 20:33:17 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " The policy failed legacy parsing " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 17:30:59 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Statement " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " Sid " :  " sdf " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " Effect " :  " aLLow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                    " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 17:30:59 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                { " Sid " :  " sdf " ,  " Effect " :  " Allow " } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 17:30:59 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " The policy failed legacy parsing " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 17:30:59 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " NotResource " :  " arn:aws:s3::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 17:30:59 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " The policy failed legacy parsing " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 17:30:59 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Condition " :  { " DateLessThanEquals " :  { " a " :  " 234-13 " } } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 17:30:59 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " The policy failed legacy parsing " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 17:30:59 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Condition " :  { 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                    " DateLessThanEquals " :  { " a " :  " 2016-12-13t2:00:00.593194+1 " } 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 17:30:59 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " The policy failed legacy parsing " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 17:30:59 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Condition " :  { 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                    " DateLessThanEquals " :  { " a " :  " 2016-12-13t2:00:00.1999999999+10:59 " } 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 17:30:59 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " The policy failed legacy parsing " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 17:30:59 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Condition " :  { " DateLessThan " :  { " a " :  " 9223372036854775808 " } } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 17:30:59 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " The policy failed legacy parsing " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 17:30:59 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:error:s3:::example_bucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Condition " :  { " DateGreaterThan " :  { " a " :  " sdfdsf " } } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 17:30:59 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " The policy failed legacy parsing " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " document " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws::fdsasf " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " error_message " :  " The policy failed legacy parsing " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								]  
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								valid_policy_documents  =  [  
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Resource " :  [ " arn:aws:s3:::example_bucket " ] , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Action " :  " iam: asdf safdsf af  " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Resource " :  [ " arn:aws:s3:::example_bucket " ,  " * " ] , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Action " :  " * " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Statement " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            } 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Action " :  " service-prefix:action-name " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Resource " :  " * " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Condition " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " DateGreaterThan " :  { " aws:CurrentTime " :  " 2017-07-01T00:00:00Z " } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " DateLessThan " :  { " aws:CurrentTime " :  " 2017-12-31T23:59:59Z " } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Action " :  " fsx:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Resource " :  " arn:aws:iam:::user/example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Resource " :  " arn:aws:s33:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Resource " :  " arn:aws:fdsasf " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Condition " :  { } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Condition " :  { " ForAllValues:StringEquals " :  { " aws:TagKeys " :  " Department " } } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Resource " :  " arn:aws:cloudwatch:us-east-1::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Resource " :  " arn:aws:ec2:us-east-1::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Resource " :  " arn:aws:invalid-service:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Resource " :  " arn:aws:invalid-service:us-east-1::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Condition " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " DateGreaterThan " :  { " aws:CurrentTime " :  " 2017-07-01T00:00:00Z " } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " DateLessThan " :  { " aws:CurrentTime " :  " 2017-12-31T23:59:59Z " } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Condition " :  { " DateGreaterThan " :  { } } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Condition " :  { " DateGreaterThan " :  { " a " :  [ ] } } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Condition " :  { " a " :  { } } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Sid " :  " dsfsdfsdfsdfsdfsadfsd " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Statement " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Sid " :  " ConsoleDisplay " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:GetRole " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:GetUser " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:ListRoles " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:ListRoleTags " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:ListUsers " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                    " iam:ListUserTags " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  " * " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Sid " :  " AddTag " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Action " :  [ " iam:TagUser " ,  " iam:TagRole " ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  " * " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Condition " :  { 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                    " StringEquals " :  { " aws:RequestTag/CostCenter " :  [ " A-123 " ,  " B-456 " ] } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " ForAllValues:StringEquals " :  { " aws:TagKeys " :  " CostCenter " } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " NotAction " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Effect " :  " Deny " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Action " :  " s3:* " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " NotResource " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " arn:aws:s3:::HRBucket/Payroll " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " arn:aws:s3:::HRBucket/Payroll/* " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            ] , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Id " :  " sdfsdfsdf " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " NotAction " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Action " :  " aaaaaadsfdsafsadfsadfaaaaa:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Action " :  " s3-s:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Action " :  " s3.s:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " NotAction " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " NotResource " :  " * " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Statement " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Sid " :  " sdf " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Condition " :  { " DateGreaterThan " :  { " a " :  " 01T " } } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Condition " :  { " x " :  { } ,  " y " :  { } } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Condition " :  { " StringEqualsIfExists " :  { " a " :  " asf " } } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Condition " :  { " ForAnyValue:StringEqualsIfExists " :  { " a " :  " asf " } } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Condition " :  { " DateLessThanEquals " :  { " a " :  " 2019-07-01T13:20:15Z " } } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Condition " :  { 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " DateLessThanEquals " :  { " a " :  " 2016-12-13T21:20:37.593194+00:00 " } 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Condition " :  { " DateLessThanEquals " :  { " a " :  " 2016-12-13t2:00:00.593194+23 " } } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Statement " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            " Resource " :  " arn:aws:s3:::example_bucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            " Condition " :  { " DateLessThan " :  { " a " :  " -292275054 " } } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Statement " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Sid " :  " AllowViewAccountInfo " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:GetAccountPasswordPolicy " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:GetAccountSummary " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                    " iam:ListVirtualMFADevices " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  " * " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Sid " :  " AllowManageOwnPasswords " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Action " :  [ " iam:ChangePassword " ,  " iam:GetUser " ] , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:iam::*:user/$ { aws:username} " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Sid " :  " AllowManageOwnAccessKeys " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:CreateAccessKey " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:DeleteAccessKey " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:ListAccessKeys " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                    " iam:UpdateAccessKey " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:iam::*:user/$ { aws:username} " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Sid " :  " AllowManageOwnSigningCertificates " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:DeleteSigningCertificate " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:ListSigningCertificates " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:UpdateSigningCertificate " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                    " iam:UploadSigningCertificate " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:iam::*:user/$ { aws:username} " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Sid " :  " AllowManageOwnSSHPublicKeys " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:DeleteSSHPublicKey " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:GetSSHPublicKey " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:ListSSHPublicKeys " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:UpdateSSHPublicKey " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                    " iam:UploadSSHPublicKey " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:iam::*:user/$ { aws:username} " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Sid " :  " AllowManageOwnGitCredentials " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:CreateServiceSpecificCredential " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:DeleteServiceSpecificCredential " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:ListServiceSpecificCredentials " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:ResetServiceSpecificCredential " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                    " iam:UpdateServiceSpecificCredential " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:iam::*:user/$ { aws:username} " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Sid " :  " AllowManageOwnVirtualMFADevice " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Action " :  [ " iam:CreateVirtualMFADevice " ,  " iam:DeleteVirtualMFADevice " ] , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:iam::*:mfa/$ { aws:username} " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Sid " :  " AllowManageOwnUserMFA " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:DeactivateMFADevice " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:EnableMFADevice " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:ListMFADevices " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                    " iam:ResyncMFADevice " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:iam::*:user/$ { aws:username} " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Sid " :  " DenyAllExceptListedIfNoMFA " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Deny " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " NotAction " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:CreateVirtualMFADevice " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:EnableMFADevice " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:GetUser " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:ListMFADevices " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:ListVirtualMFADevices " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:ResyncMFADevice " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                    " sts:GetSessionToken " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                ] , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " * " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Condition " :  { " BoolIfExists " :  { " aws:MultiFactorAuthPresent " :  " false " } } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Statement " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Sid " :  " ListAndDescribe " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " dynamodb:List* " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " dynamodb:DescribeReservedCapacity* " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " dynamodb:DescribeLimits " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                    " dynamodb:DescribeTimeToLive " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  " * " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Sid " :  " SpecificTable " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " dynamodb:BatchGet* " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " dynamodb:DescribeStream " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " dynamodb:DescribeTable " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " dynamodb:Get* " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " dynamodb:Query " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " dynamodb:Scan " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " dynamodb:BatchWrite* " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " dynamodb:CreateTable " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " dynamodb:Delete* " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " dynamodb:Update* " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                    " dynamodb:PutItem " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:dynamodb:*:*:table/MyTable " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Statement " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Action " :  [ " ec2:AttachVolume " ,  " ec2:DetachVolume " ] , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  [ " arn:aws:ec2:*:*:volume/* " ,  " arn:aws:ec2:*:*:instance/* " ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Condition " :  { 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                    " ArnEquals " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                        " ec2:SourceInstanceARN " :  " arn:aws:ec2:*:*:instance/instance-id " 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    } 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            } 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Statement " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Action " :  [ " ec2:AttachVolume " ,  " ec2:DetachVolume " ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:ec2:*:*:instance/* " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Condition " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " StringEquals " :  { " ec2:ResourceTag/Department " :  " Development " } 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Action " :  [ " ec2:AttachVolume " ,  " ec2:DetachVolume " ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:ec2:*:*:volume/* " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Condition " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " StringEquals " :  { " ec2:ResourceTag/VolumeUser " :  " $ { aws:username} " } 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Statement " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Sid " :  " StartStopIfTags " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " ec2:StartInstances " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " ec2:StopInstances " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                    " ec2:DescribeTags " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                ] , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:ec2:region:account-id:instance/* " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Condition " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " StringEquals " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                        " ec2:ResourceTag/Project " :  " DataAnalytics " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                        " aws:PrincipalTag/Department " :  " Data " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                    } 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            } 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Statement " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Sid " :  " ListYourObjects " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  [ " arn:aws:s3:::bucket-name " ] , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Condition " :  { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " StringLike " :  { 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                        " s3:prefix " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                            " cognito/application-name/$ { cognito-identity.amazonaws.com:sub} " 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                        ] 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                    } 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Sid " :  " ReadWriteDeleteYourObjects " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Action " :  [ " s3:GetObject " ,  " s3:PutObject " ,  " s3:DeleteObject " ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " arn:aws:s3:::bucket-name/cognito/application-name/$ { cognito-identity.amazonaws.com:sub} " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                    " arn:aws:s3:::bucket-name/cognito/application-name/$ { cognito-identity.amazonaws.com:sub}/* " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                ] , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Statement " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Action " :  [ " s3:ListAllMyBuckets " ,  " s3:GetBucketLocation " ] , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " * " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:s3:::bucket-name " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Condition " :  { 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                    " StringLike " :  { " s3:prefix " :  [ " " ,  " home/ " ,  " home/$ { aws:userid}/* " ] } 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:* " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " arn:aws:s3:::bucket-name/home/$ { aws:userid} " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                    " arn:aws:s3:::bucket-name/home/$ { aws:userid}/* " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                ] , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Statement " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Sid " :  " ConsoleAccess " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " s3:GetAccountPublicAccessBlock " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " s3:GetBucketAcl " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " s3:GetBucketLocation " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " s3:GetBucketPolicyStatus " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " s3:GetBucketPublicAccessBlock " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                    " s3:ListAllMyBuckets " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  " * " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Sid " :  " ListObjectsInBucket " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:ListBucket " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  [ " arn:aws:s3:::bucket-name " ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Sid " :  " AllObjectActions " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " s3:*Object " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  [ " arn:aws:s3:::bucket-name/* " ] , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Statement " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Sid " :  " AllowViewAccountInfo " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Action " :  [ " iam:GetAccountPasswordPolicy " ,  " iam:GetAccountSummary " ] , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " * " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Sid " :  " AllowManageOwnPasswords " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Action " :  [ " iam:ChangePassword " ,  " iam:GetUser " ] , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:iam::*:user/$ { aws:username} " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Sid " :  " AllowManageOwnAccessKeys " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:CreateAccessKey " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:DeleteAccessKey " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:ListAccessKeys " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                    " iam:UpdateAccessKey " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:iam::*:user/$ { aws:username} " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Sid " :  " AllowManageOwnSigningCertificates " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:DeleteSigningCertificate " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:ListSigningCertificates " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:UpdateSigningCertificate " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                    " iam:UploadSigningCertificate " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:iam::*:user/$ { aws:username} " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Sid " :  " AllowManageOwnSSHPublicKeys " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:DeleteSSHPublicKey " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:GetSSHPublicKey " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:ListSSHPublicKeys " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:UpdateSSHPublicKey " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                    " iam:UploadSSHPublicKey " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:iam::*:user/$ { aws:username} " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Sid " :  " AllowManageOwnGitCredentials " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:CreateServiceSpecificCredential " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:DeleteServiceSpecificCredential " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:ListServiceSpecificCredentials " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                    " iam:ResetServiceSpecificCredential " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                    " iam:UpdateServiceSpecificCredential " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  " arn:aws:iam::*:user/$ { aws:username} " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Statement " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " ec2:* " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Resource " :  " * " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Condition " :  { " StringEquals " :  { " ec2:Region " :  " region " } } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            } 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Statement " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " rds:* " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  [ " arn:aws:rds:region:*:* " ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            { " Effect " :  " Allow " ,  " Action " :  [ " rds:Describe* " ] ,  " Resource " :  [ " * " ] } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-09-10 23:43:50 -03:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Version " :  " 2012-10-17 " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        " Statement " :  [ 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Sid " :  " " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  " rds:* " , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  [ " arn:aws:rds:region:*:* " ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-09-10 23:43:50 -03:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            { 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Sid " :  " " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Effect " :  " Allow " , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								                " Action " :  [ " rds:Describe* " ] , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								                " Resource " :  [ " * " ] , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            } , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        ] , 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    } , 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								]  
						 
					
						
							
								
									
										
										
										
											2019-06-30 13:47:17 +02:00 
										
									 
								 
							 
							
								
							 
							
								 
							
							
								
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								
							 
						 
					
						
							
								
									
										
										
										
											2020-11-25 02:48:05 -08:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								@pytest.mark.parametrize ( " invalid_policy_document " ,  invalid_policy_document_test_cases )  
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								@mock_iam  
						 
					
						
							
								
									
										
										
										
											2020-11-25 02:48:05 -08:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								def  test_create_policy_with_invalid_policy_document ( invalid_policy_document ) :  
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    conn  =  boto3 . client ( " iam " ,  region_name = " us-east-1 " ) 
							 
						 
					
						
							
								
									
										
										
										
											2020-10-06 07:54:49 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    with  pytest . raises ( ClientError )  as  ex : 
							 
						 
					
						
							
								
									
										
										
										
											2019-06-30 17:04:02 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        conn . create_policy ( 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								            PolicyName = " TestCreatePolicy " , 
							 
						 
					
						
							
								
									
										
										
										
											2020-11-25 02:48:05 -08:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								            PolicyDocument = json . dumps ( invalid_policy_document [ " document " ] ) , 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        ) 
							 
						 
					
						
							
								
									
										
										
										
											2020-10-06 08:04:09 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    ex . value . response [ " Error " ] [ " Code " ] . should . equal ( " MalformedPolicyDocument " ) 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    ex . value . response [ " ResponseMetadata " ] [ " HTTPStatusCode " ] . should . equal ( 400 ) 
							 
						 
					
						
							
								
									
										
										
										
											2020-11-25 02:48:05 -08:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    ex . value . response [ " Error " ] [ " Message " ] . should . equal ( 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								        invalid_policy_document [ " error_message " ] 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    ) 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								
							 
						 
					
						
							
								
									
										
										
										
											2020-11-25 02:48:05 -08:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								@pytest.mark.parametrize ( " valid_policy_document " ,  valid_policy_documents )  
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								@mock_iam  
						 
					
						
							
								
									
										
										
										
											2020-11-25 02:48:05 -08:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								def  test_create_policy_with_valid_policy_document ( valid_policy_document ) :  
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    conn  =  boto3 . client ( " iam " ,  region_name = " us-east-1 " ) 
							 
						 
					
						
							
								
									
										
										
										
											2019-07-01 18:21:54 +02:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								    conn . create_policy ( 
							 
						 
					
						
							
								
									
										
										
										
											2019-10-31 08:44:26 -07:00 
										
									 
								 
							 
							
								
									
										 
								
							 
							
								 
							
							
								        PolicyName = " TestCreatePolicy " ,  PolicyDocument = json . dumps ( valid_policy_document ) 
							 
						 
					
						
							
								
							 
							
								
							 
							
								 
							
							
								    )