Skip to main content

resource_policy

Gets an individual resource_policy resource

Overview

Nameresource_policy
TypeResource
Descriptionresource_policy
Idawscc.cloudtrail.resource_policy

Fields

NameDatatypeDescription
resource_arnstringThe ARN of the AWS CloudTrail resource to which the policy applies.
resource_policyobjectA policy document containing permissions to add to the specified resource. In IAM, you must provide policy documents in JSON format. However, in CloudFormation you can provide the policy in JSON or YAML format because CloudFormation converts YAML to JSON before submitting it to IAM.
regionstringAWS region.

Methods

Currently only SELECT is supported for this resource resource.

Example

SELECT
region,
resource_arn,
resource_policy
FROM awscc.cloudtrail.resource_policy
WHERE data__Identifier = '<ResourceArn>';

Permissions

To operate on the resource_policy resource, the following permissions are required:

Read

CloudTrail:GetResourcePolicy

Update

CloudTrail:PutResourcePolicy,
CloudTrail:GetResourcePolicy

Delete

CloudTrail:DeleteResourcePolicy