-
Notifications
You must be signed in to change notification settings - Fork 22
/
Copy pathdashboard-crossaccount-kinesis-role.yaml
74 lines (68 loc) · 2.38 KB
/
dashboard-crossaccount-kinesis-role.yaml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
#
# Copyright Amazon.com, Inc. and its affiliates. All Rights Reserved.
# SPDX-License-Identifier: MIT
#
# Licensed under the MIT License. See the LICENSE accompanying this file
# for the specific language governing permissions and limitations under
# the License.
#
AWSTemplateFormatVersion: "2010-09-09"
Description: Kinesis deployment Role for AWS WAF Dashboard build
Parameters:
S3Bucket:
Type: String
Description: Name of the destinatio S3 bucket
Resources:
DeliveryStreamRole:
Type: AWS::IAM::Role
Properties:
RoleName: kinesis-delivery-role
AssumeRolePolicyDocument:
Version: 2012-10-17
Statement:
- Effect: Allow
Action: sts:AssumeRole
Principal:
Service: firehose.amazonaws.com
Policies:
- PolicyName: DeliveryStreamRolePolicy
PolicyDocument:
Version: 2012-10-17
Statement:
- Effect: Allow
Action:
- s3:AbortMultipartUpload
- s3:GetBucketLocation
- s3:GetObject
- s3:ListBucket
- s3:ListBucketMultipartUploads
- s3:PutObject
- s3:PutObjectAcl
Resource:
- !Sub arn:aws:s3:::${S3Bucket}
- !Sub arn:aws:s3:::${S3Bucket}/*
- Effect: Allow
Action:
- logs:PutLogEvents
Resource: "*"
- Effect: Allow
Action:
- kinesis:DescribeStream
- kinesis:GetShardIterator
- kinesis:GetRecords
- kinesis:ListShards
Resource: !Sub arn:aws:kinesis:${AWS::Region}:${AWS::AccountId}:stream/%FIREHOSE_STREAM_NAME%
#- Effect: Allow
# Action:
# - kms:Decrypt
# - kms:GenerateDataKey
# Resource: !Sub arn:aws:kms:${AWS::Region}:${AWS::AccountId}-id:key/key-id
# Condition:
# StringEquals:
# "kms:ViaService": !Ref s3.region.amazonaws.com
# StringLike:
# "kms:EncryptionContext:aws:s3:arn": "arn:aws:s3:::bucket-name/prefix*"
Outputs:
KinesisFirehoseDeliveryRoleArn:
Description: kenesis Firehose
Value: !GetAtt DeliveryStreamRole.Arn