主に誤操作防止用に。 注意 RDSのはIAM Policy Simulatorでは通るにも関わらず、何故かManaged Policyにすると動かないという謎の挙動。Inline Policyだと動く。バグ?(2015/7/3現在) EC2 起動はvpc-abcd1234でVPC IDを指定して限定可能 停止等はec2:Vpcのresource level permissionが使えないので Vpc: myvpc等のタグで限定(ec2:CreateTagsはそもそも制限不可能なのであまり厳密ではないが) { "Version": "2012-10-17", "Statement": [ { "Sid": "UnsupportedResourceLevelPermissions", "Effect": "Allow", "Action": [ "ec2:Describe*", "ec2:*T
![AWSで特定のVPC下での操作の許可するIAM Policy - Qiita](https://cdn-ak-scissors.b.st-hatena.com/image/square/cf4979f546c7cf66d49bda72b9c7ef7f7fee973b/height=288;version=1;width=512/https%3A%2F%2Fqiita-user-contents.imgix.net%2Fhttps%253A%252F%252Fcdn.qiita.com%252Fassets%252Fpublic%252Farticle-ogp-background-9f5428127621718a910c8b63951390ad.png%3Fixlib%3Drb-4.0.0%26w%3D1200%26mark64%3DaHR0cHM6Ly9xaWl0YS11c2VyLWNvbnRlbnRzLmltZ2l4Lm5ldC9-dGV4dD9peGxpYj1yYi00LjAuMCZ3PTkxNiZoPTMzNiZ0eHQ9QVdTJUUzJTgxJUE3JUU3JTg5JUI5JUU1JUFFJTlBJUUzJTgxJUFFVlBDJUU0JUI4JThCJUUzJTgxJUE3JUUzJTgxJUFFJUU2JTkzJThEJUU0JUJEJTlDJUUzJTgxJUFFJUU4JUE4JUIxJUU1JThGJUFGJUUzJTgxJTk5JUUzJTgyJThCSUFNJTIwUG9saWN5JnR4dC1jb2xvcj0lMjMyMTIxMjEmdHh0LWZvbnQ9SGlyYWdpbm8lMjBTYW5zJTIwVzYmdHh0LXNpemU9NTYmdHh0LWNsaXA9ZWxsaXBzaXMmdHh0LWFsaWduPWxlZnQlMkN0b3Amcz0zNWU5YzkxYWI5MzYxNmFjYjNjYzhlY2E1NGZiN2Q2NA%26mark-x%3D142%26mark-y%3D112%26blend64%3DaHR0cHM6Ly9xaWl0YS11c2VyLWNvbnRlbnRzLmltZ2l4Lm5ldC9-dGV4dD9peGxpYj1yYi00LjAuMCZ3PTYxNiZ0eHQ9JTQwaWppbiZ0eHQtY29sb3I9JTIzMjEyMTIxJnR4dC1mb250PUhpcmFnaW5vJTIwU2FucyUyMFc2JnR4dC1zaXplPTM2JnR4dC1hbGlnbj1sZWZ0JTJDdG9wJnM9MGQ5ZGQ2MmIwYzBlNjRhODlkMzBhZDgxMWFlMDJhMmQ%26blend-x%3D142%26blend-y%3D491%26blend-mode%3Dnormal%26s%3Df97077fcf4c5265542ddbbd365e2937a)