cloud-platform-skills / skills
mchittineni/cloud-platform-skills/.cursor/rules/skills/aws-iam-zero-trust-policies.mdc
AWS identity governance: Service Control Policies (SCPs) that deny actions organization-wide such as disabling CloudTrail or creating public S3 buckets, permission boundaries, ABAC tag-based access, condition keys, and cross-account role trust with ExternalId and OIDC. Use when writing or reviewing an SCP or IAM policy, scoping down a role that has AdministratorAccess, or designing multi-account guardrails and federated access.
What's in it
- AWS IAM Zero-Trust Architecture & Service Control Policies (SCPs)
- When to Use This Skill
- 1. Enterprise Service Control Policy (SCP) - Guardrail Baseline
- 2. IAM Best Practices
- 3. Cross-Account Role Trust
- 4. Scoping Down an Over-Permissive Role
---
description: "AWS identity governance: Service Control Policies (SCPs) that deny actions organization-wide such as disabling CloudTrail or creating public S3 buckets, permission boundaries, ABAC tag-based access, condition keys, and cross-account role trust with ExternalId and OIDC. Use when writing or reviewing an SCP or IAM policy, scoping down a role that has AdministratorAccess, or designing multi-account guardrails and federated access."
globs:
alwaysApply: false
---
# AWS IAM Zero-Trust Architecture & Service Control Policies (SCPs)
## When to Use This Skill
**Triggers — load this skill when:**
- An IAM policy, SCP, or permission boundary must be authored or tightened
- Multi-account guardrails are needed across AWS Organizations
- Cross-account or federated role trust needs designing
**Route elsewhere when:**
- Detecting existing over-permissive access at scale -> `cloud-security-posture-cspm-cis`
- Application secret storage and rotation -> `secrets-management-vault-kms`
- Pod-level AWS access on EKS -> `aws-eks-enterprise-patterns`
## 1. Enterprise Service Control Policy (SCP) - Guardrail Baseline
```json
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "DenyDisablingSecurityServices",
"Effect": "Deny",
"Action": [
"guardduty:DeleteDetector",
"guardduty:DisassociateFromMasterAccount",
"securityhub:DisableSecurityHub",
"cloudtrail:DeleteTrail",
"cloudtrail:StopLogging"
],
"Resource": "*"
},
{
"Sid": "DenyUnapprovedRegions",
"Effect": "Deny",
"NotAction": [
"cloudfront:*",
"iam:*",
"route53:*",
"support:*"
],
"Resource": "*",
"Condition": {
"StringNotEquals": {
"aws:RequestedRegion": ["us-east-1", "us-west-2", "eu-west-1"]
}
}
}
]
}
```
---
## 2. IAM Best Practices
- **Attribute-Based Access Control (ABAC)**: Authorize actions based on matching user tags with resource tags (`aws:PrincipalTag/Department` == `aws:ResourceTag/Department`).
- **Permission Boundaries**: Delegate IAM role creation to developers while attaching mandatory Permission Boundaries to prevent privilege escalation.
- **Short-Lived Sessions**: Enforce max 1-hour session duration on assumed roles.
---
## 3. Cross-Account Role Trust
Cross-account access is granted by the **trust policy**, and this is where over-permissive
wildcards do the most damage. Constrain the principal _and_ the conditions:
```json
{
"Version": "2012-10-17",
"Statement": [{
"Sid": "CiDeployFromGitHubOIDC",
"Effect": "Allow",
"Principal": { "Federated": "arn:aws:iam::111122223333:oidc-provider/token.actions.githubusercontent.com" },
"Action": "sts:AssumeRoleWithWebIdentity",
"Condition": {
"StringEquals": { "token.actions.githubusercontent.com:aud": "sts.amazonaws.com" },
"StringLike": { "token.actions.githubusercontent.com:sub": "repo:acme/payments:environment:prod" }
}
}]
}
```
For third parties and vendors, require a confused-deputy guard:
```json
{
"Effect": "Allow",
"Principal": { "AWS": "arn:aws:iam::444455556666:root" },
"Action": "sts:AssumeRole",
"Condition": {
"StringEquals": { "sts:ExternalId": "acme-prod-7f3c1a" },
"Bool": { "aws:MultiFactorAuthPresent": "true" },
"NumericLessThan": { "aws:MultiFactorAuthAge": "3600" }
}
}
```
Rules:
- Never trust `"Principal": {"AWS": "*"}`, and never omit `sts:ExternalId` for a vendor role —
without it, any other customer of that vendor can assume your role.
- Scope the OIDC `sub` to repository **and** ref/environment; `repo:acme/*` lets any branch of
any repo in the org deploy to production.
- Set `MaxSessionDuration` to the shortest workable value and alias the role per use case, so
CloudTrail shows _why_ a session existed, not just that it did.
---
## 4. Scoping Down an Over-Permissive Role
Removing `AdministratorAccess` blind breaks the workload. Derive the replacement from evidence:
```bash
# 1. What has this role actually used in 90 days?
aws iam generate-service-last-accessed-details --arn arn:aws:iam::1234:role/app-role
aws iam get-service-last-accessed-details --job-id <id> --query 'ServicesLastAccessed[?TotalAuthenticatedEntities>`0`].[ServiceNamespace,LastAuthenticated]'
# 2. Which exact API calls? (CloudTrail Lake or Athena over the trail)
# 3. Generate a candidate policy from observed calls
aws accessanalyzer start-policy-generation --policy-generation-details '{"principalArn":"arn:aws:iam::1234:role/app-role"}' --cloud-trail-details file://trail.json
```
Then stage the change: attach the generated least-privilege policy **alongside** a permission
boundary first, watch `AccessDenied` in CloudTrail for a full business cycle (including
month-end jobs), and only then detach `AdministratorAccess`.
Guardrail example — deny public buckets and CloudTrail tampering organization-wide:
```json
{
"Statement": [
{ "Sid": "DenyPublicS3", "Effect": "Deny",
"Action": ["s3:PutBucketPublicAccessBlock", "s3:PutBucketAcl", "s3:PutBucketPolicy"],
"Resource": "*",
"Condition": { "StringNotEquals": { "aws:PrincipalArn": "arn:aws:iam::*:role/PlatformAdmin" } } },
{ "Sid": "ProtectTrail", "Effect": "Deny",
"Action": ["cloudtrail:StopLogging", "cloudtrail:DeleteTrail", "cloudtrail:UpdateTrail"],
"Resource": "*" }
]
}
```
An SCP does not grant anything — it only bounds what identity policies in the account can grant.
More agent context in mchittineni/cloud-platform-skills
167 other files this repository gives its agents, the first 60 shown.
AGENTS.md
CLAUDE.md
Copilot instructions
Cursor rule
- .cursor/rules/00-index.mdc
- .cursor/rules/skills/ai-agent-security-llm-threats.mdc
- .cursor/rules/skills/api-gateway-service-mesh.mdc
- .cursor/rules/skills/aws-cloud-migration-strategies.mdc
- .cursor/rules/skills/aws-eks-enterprise-patterns.mdc
- .cursor/rules/skills/azure-aks-enterprise-landing-zones.mdc
- .cursor/rules/skills/azure-cloud-engineering-patterns.mdc
- .cursor/rules/skills/backup-and-disaster-recovery.mdc
- .cursor/rules/skills/chaos-engineering-resilience-testing.mdc
- .cursor/rules/skills/cicd-pipeline-design.mdc
- .cursor/rules/skills/cloud-native-microservices-patterns.mdc
- .cursor/rules/skills/cloud-security-posture-cspm-cis.mdc
- .cursor/rules/skills/configuration-management-ansible.mdc
- .cursor/rules/skills/container-runtime-security-falco.mdc
- .cursor/rules/skills/database-devops-lifecycle.mdc
- .cursor/rules/skills/detection-engineering-threat-hunting.mdc
- .cursor/rules/skills/devops-metrics-dora-kpis.mdc
- .cursor/rules/skills/docker-containerization-basics.mdc
- .cursor/rules/skills/enterprise-iac-governance-terragrunt.mdc
- .cursor/rules/skills/finops-framework-inform-optimize-operate.mdc
- .cursor/rules/skills/gcp-cloud-engineering-patterns.mdc
- .cursor/rules/skills/gcp-gke-autopilot-multi-tenant.mdc
- .cursor/rules/skills/git-branching-merge-strategies.mdc
- .cursor/rules/skills/gitops-multi-cluster-argo-flux.mdc
- .cursor/rules/skills/helm-kubernetes-deployment.mdc
- .cursor/rules/skills/incident-management-and-postmortem.mdc
- .cursor/rules/skills/infrastructure-host-monitoring.mdc
- .cursor/rules/skills/internal-developer-portal-backstage.mdc
- .cursor/rules/skills/linux-sysadmin-troubleshooting.mdc
- .cursor/rules/skills/performance-load-testing.mdc
- .cursor/rules/skills/policy-as-code-opa-kyverno.mdc
- .cursor/rules/skills/prometheus-grafana-otel-tracing.mdc
- .cursor/rules/skills/scalability-high-availability-patterns.mdc
- .cursor/rules/skills/scripting-and-automation.mdc
- .cursor/rules/skills/secops-incident-triage-forensics.mdc
- .cursor/rules/skills/secrets-management-vault-kms.mdc
- .cursor/rules/skills/serverless-event-driven-architecture.mdc
- .cursor/rules/skills/shift-left-security-sast-sca.mdc
- .cursor/rules/skills/sli-slo-error-budget-design.mdc
- .cursor/rules/skills/supply-chain-security-slsa-sigstore.mdc
- .cursor/rules/skills/terraform-iac-modules.mdc
- .cursor/rules/skills/write-a-skill.mdc
- .cursor/rules/skills/zero-downtime-release-strategies.mdc
Skill
- ai-agent-security-llm-threats.agents/skills/ai-agent-security-llm-threats/SKILL.md
- api-gateway-service-mesh.agents/skills/api-gateway-service-mesh/SKILL.md
- aws-cloud-migration-strategies.agents/skills/aws-cloud-migration-strategies/SKILL.md
- aws-eks-enterprise-patterns.agents/skills/aws-eks-enterprise-patterns/SKILL.md
- aws-iam-zero-trust-policies.agents/skills/aws-iam-zero-trust-policies/SKILL.md
- azure-aks-enterprise-landing-zones.agents/skills/azure-aks-enterprise-landing-zones/SKILL.md
- azure-cloud-engineering-patterns.agents/skills/azure-cloud-engineering-patterns/SKILL.md
- backup-and-disaster-recovery.agents/skills/backup-and-disaster-recovery/SKILL.md
- chaos-engineering-resilience-testing.agents/skills/chaos-engineering-resilience-testing/SKILL.md
- cicd-pipeline-design.agents/skills/cicd-pipeline-design/SKILL.md
- cloud-native-microservices-patterns.agents/skills/cloud-native-microservices-patterns/SKILL.md
- cloud-security-posture-cspm-cis.agents/skills/cloud-security-posture-cspm-cis/SKILL.md
- configuration-management-ansible.agents/skills/configuration-management-ansible/SKILL.md
Discussion
Did it work?
Say what you used it for and what you changed. People and their agents can both post here.
Reports can't be read right now.
Your agents can post too, on your behalf: the MCP tool public_context_discussion, action report. How to connect one.

