Read-only cloud discovery of the Scrivas AWS Organization (o-qfj0pvhhv7) to inform a proposal. - scripts/: boto3 org assessment, member-account assessment, fast discovery - findings/: self-contained HTML dashboards, written report, summary JSON, and the rendered Prowler benchmark report - docs/full_discovery_plan.md: phased full-discovery plan - index.html: landing page linking all reports - Pipfile/.python-version: reproducible pipenv env (Python 3.12.11) Large raw scans (OCSF JSON, CSV, compliance/) are git-ignored.
923 lines
25 KiB
JSON
923 lines
25 KiB
JSON
{
|
|
"generated": "2026-08-19T16:08:34.074423+00:00",
|
|
"caller": {
|
|
"Account": "716468089330",
|
|
"Arn": "arn:aws:iam::716468089330:user/louis"
|
|
},
|
|
"organization": {
|
|
"Id": "o-qfj0pvhhv7",
|
|
"Arn": "arn:aws:organizations::716468089330:organization/o-qfj0pvhhv7",
|
|
"FeatureSet": "ALL",
|
|
"MasterAccountArn": "arn:aws:organizations::716468089330:account/o-qfj0pvhhv7/716468089330",
|
|
"MasterAccountId": "716468089330",
|
|
"MasterAccountEmail": "ScrivasAdmin@scrivas.com",
|
|
"AvailablePolicyTypes": [
|
|
{
|
|
"Type": "SERVICE_CONTROL_POLICY",
|
|
"Status": "ENABLED"
|
|
}
|
|
]
|
|
},
|
|
"trusted_access_services": [
|
|
{
|
|
"ServicePrincipal": "cloudtrail.amazonaws.com",
|
|
"DateEnabled": "2025-10-20T14:05:58.424000-04:00"
|
|
},
|
|
{
|
|
"ServicePrincipal": "guardduty.amazonaws.com",
|
|
"DateEnabled": "2026-02-19T06:26:23.375000-05:00"
|
|
},
|
|
{
|
|
"ServicePrincipal": "inspector2.amazonaws.com",
|
|
"DateEnabled": "2026-02-19T06:26:23.873000-05:00"
|
|
},
|
|
{
|
|
"ServicePrincipal": "malware-protection.guardduty.amazonaws.com",
|
|
"DateEnabled": "2026-02-19T06:26:25.203000-05:00"
|
|
},
|
|
{
|
|
"ServicePrincipal": "notifications.amazonaws.com",
|
|
"DateEnabled": "2026-04-07T11:57:56.557000-04:00"
|
|
},
|
|
{
|
|
"ServicePrincipal": "securityhub.amazonaws.com",
|
|
"DateEnabled": "2026-02-19T06:26:23.087000-05:00"
|
|
}
|
|
],
|
|
"delegated_administrators": [],
|
|
"org_resource_policy": {
|
|
"error": "An error occurred (ResourcePolicyNotFoundException) when calling the DescribeResourcePolicy operation: No resource-based policy found."
|
|
},
|
|
"iam_role_trust_policies": [
|
|
{
|
|
"RoleName": "AmazonEKSAutoClusterRole",
|
|
"Path": "/",
|
|
"Arn": "arn:aws:iam::716468089330:role/AmazonEKSAutoClusterRole",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": [
|
|
"sts:AssumeRole",
|
|
"sts:TagSession"
|
|
],
|
|
"Principal": {
|
|
"Service": "eks.amazonaws.com"
|
|
},
|
|
"Condition": null
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "AmazonEKSAutoNodeRole",
|
|
"Path": "/",
|
|
"Arn": "arn:aws:iam::716468089330:role/AmazonEKSAutoNodeRole",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"Service": "ec2.amazonaws.com"
|
|
},
|
|
"Condition": null
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "AmazonEKSPodIdentityAmazonEBSCSIDriverRole",
|
|
"Path": "/",
|
|
"Arn": "arn:aws:iam::716468089330:role/AmazonEKSPodIdentityAmazonEBSCSIDriverRole",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": [
|
|
"sts:AssumeRole",
|
|
"sts:TagSession"
|
|
],
|
|
"Principal": {
|
|
"Service": "pods.eks.amazonaws.com"
|
|
},
|
|
"Condition": null
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "AmazonEKSPodIdentityAmazonVPCCNIRole",
|
|
"Path": "/",
|
|
"Arn": "arn:aws:iam::716468089330:role/AmazonEKSPodIdentityAmazonVPCCNIRole",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": [
|
|
"sts:AssumeRole",
|
|
"sts:TagSession"
|
|
],
|
|
"Principal": {
|
|
"Service": "pods.eks.amazonaws.com"
|
|
},
|
|
"Condition": null
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "AmazonEKS_EBS_CSI_DriverRole",
|
|
"Path": "/",
|
|
"Arn": "arn:aws:iam::716468089330:role/AmazonEKS_EBS_CSI_DriverRole",
|
|
"Kind": [
|
|
"federated"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRoleWithWebIdentity",
|
|
"Principal": {
|
|
"Federated": "arn:aws:iam::716468089330:oidc-provider/oidc.eks.us-east-2.amazonaws.com/id/8C10FE346B856864E285348C79AE4EAF"
|
|
},
|
|
"Condition": {
|
|
"StringEquals": {
|
|
"oidc.eks.us-east-2.amazonaws.com/id/8C10FE346B856864E285348C79AE4EAF:aud": "sts.amazonaws.com",
|
|
"oidc.eks.us-east-2.amazonaws.com/id/8C10FE346B856864E285348C79AE4EAF:sub": "system:serviceaccount:kube-system:ebs-csi-controller-sa"
|
|
}
|
|
}
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "applications-eks-node-group-20251007184911320300000008",
|
|
"Path": "/",
|
|
"Arn": "arn:aws:iam::716468089330:role/applications-eks-node-group-20251007184911320300000008",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"Service": "ec2.amazonaws.com"
|
|
},
|
|
"Condition": null
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "AWSServiceRoleForAccessAnalyzer",
|
|
"Path": "/aws-service-role/access-analyzer.amazonaws.com/",
|
|
"Arn": "arn:aws:iam::716468089330:role/aws-service-role/access-analyzer.amazonaws.com/AWSServiceRoleForAccessAnalyzer",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"Service": "access-analyzer.amazonaws.com"
|
|
},
|
|
"Condition": null
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "AWSServiceRoleForAmazonEKS",
|
|
"Path": "/aws-service-role/eks.amazonaws.com/",
|
|
"Arn": "arn:aws:iam::716468089330:role/aws-service-role/eks.amazonaws.com/AWSServiceRoleForAmazonEKS",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"Service": "eks.amazonaws.com"
|
|
},
|
|
"Condition": null
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "AWSServiceRoleForAmazonEKSNodegroup",
|
|
"Path": "/aws-service-role/eks-nodegroup.amazonaws.com/",
|
|
"Arn": "arn:aws:iam::716468089330:role/aws-service-role/eks-nodegroup.amazonaws.com/AWSServiceRoleForAmazonEKSNodegroup",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"Service": "eks-nodegroup.amazonaws.com"
|
|
},
|
|
"Condition": null
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "AWSServiceRoleForAmazonGuardDuty",
|
|
"Path": "/aws-service-role/guardduty.amazonaws.com/",
|
|
"Arn": "arn:aws:iam::716468089330:role/aws-service-role/guardduty.amazonaws.com/AWSServiceRoleForAmazonGuardDuty",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"Service": "guardduty.amazonaws.com"
|
|
},
|
|
"Condition": null
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "AWSServiceRoleForAmazonGuardDutyMalwareProtection",
|
|
"Path": "/aws-service-role/malware-protection.guardduty.amazonaws.com/",
|
|
"Arn": "arn:aws:iam::716468089330:role/aws-service-role/malware-protection.guardduty.amazonaws.com/AWSServiceRoleForAmazonGuardDutyMalwareProtection",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"Service": "malware-protection.guardduty.amazonaws.com"
|
|
},
|
|
"Condition": null
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "AWSServiceRoleForAmazonInspector2",
|
|
"Path": "/aws-service-role/inspector2.amazonaws.com/",
|
|
"Arn": "arn:aws:iam::716468089330:role/aws-service-role/inspector2.amazonaws.com/AWSServiceRoleForAmazonInspector2",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"Service": "inspector2.amazonaws.com"
|
|
},
|
|
"Condition": null
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "AWSServiceRoleForAmazonInspector2Agentless",
|
|
"Path": "/aws-service-role/agentless.inspector2.amazonaws.com/",
|
|
"Arn": "arn:aws:iam::716468089330:role/aws-service-role/agentless.inspector2.amazonaws.com/AWSServiceRoleForAmazonInspector2Agentless",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"Service": "agentless.inspector2.amazonaws.com"
|
|
},
|
|
"Condition": null
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "AWSServiceRoleForAmazonMacie",
|
|
"Path": "/aws-service-role/macie.amazonaws.com/",
|
|
"Arn": "arn:aws:iam::716468089330:role/aws-service-role/macie.amazonaws.com/AWSServiceRoleForAmazonMacie",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"Service": "macie.amazonaws.com"
|
|
},
|
|
"Condition": null
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "AWSServiceRoleForApplicationInsights",
|
|
"Path": "/aws-service-role/application-insights.amazonaws.com/",
|
|
"Arn": "arn:aws:iam::716468089330:role/aws-service-role/application-insights.amazonaws.com/AWSServiceRoleForApplicationInsights",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"Service": "application-insights.amazonaws.com"
|
|
},
|
|
"Condition": null
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "AWSServiceRoleForAutoScaling",
|
|
"Path": "/aws-service-role/autoscaling.amazonaws.com/",
|
|
"Arn": "arn:aws:iam::716468089330:role/aws-service-role/autoscaling.amazonaws.com/AWSServiceRoleForAutoScaling",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"Service": "autoscaling.amazonaws.com"
|
|
},
|
|
"Condition": null
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "AWSServiceRoleForAwsUserNotifications",
|
|
"Path": "/aws-service-role/notifications.amazonaws.com/",
|
|
"Arn": "arn:aws:iam::716468089330:role/aws-service-role/notifications.amazonaws.com/AWSServiceRoleForAwsUserNotifications",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"Service": "notifications.amazonaws.com"
|
|
},
|
|
"Condition": null
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "AWSServiceRoleForCloudTrail",
|
|
"Path": "/aws-service-role/cloudtrail.amazonaws.com/",
|
|
"Arn": "arn:aws:iam::716468089330:role/aws-service-role/cloudtrail.amazonaws.com/AWSServiceRoleForCloudTrail",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"Service": "cloudtrail.amazonaws.com"
|
|
},
|
|
"Condition": null
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "AWSServiceRoleForConfig",
|
|
"Path": "/aws-service-role/config.amazonaws.com/",
|
|
"Arn": "arn:aws:iam::716468089330:role/aws-service-role/config.amazonaws.com/AWSServiceRoleForConfig",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"Service": "config.amazonaws.com"
|
|
},
|
|
"Condition": null
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "AWSServiceRoleForEC2Spot",
|
|
"Path": "/aws-service-role/spot.amazonaws.com/",
|
|
"Arn": "arn:aws:iam::716468089330:role/aws-service-role/spot.amazonaws.com/AWSServiceRoleForEC2Spot",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"Service": "spot.amazonaws.com"
|
|
},
|
|
"Condition": null
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "AWSServiceRoleForElasticLoadBalancing",
|
|
"Path": "/aws-service-role/elasticloadbalancing.amazonaws.com/",
|
|
"Arn": "arn:aws:iam::716468089330:role/aws-service-role/elasticloadbalancing.amazonaws.com/AWSServiceRoleForElasticLoadBalancing",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"Service": "elasticloadbalancing.amazonaws.com"
|
|
},
|
|
"Condition": null
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "AWSServiceRoleForGlobalAccelerator",
|
|
"Path": "/aws-service-role/globalaccelerator.amazonaws.com/",
|
|
"Arn": "arn:aws:iam::716468089330:role/aws-service-role/globalaccelerator.amazonaws.com/AWSServiceRoleForGlobalAccelerator",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"Service": "globalaccelerator.amazonaws.com"
|
|
},
|
|
"Condition": null
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "AWSServiceRoleForOrganizations",
|
|
"Path": "/aws-service-role/organizations.amazonaws.com/",
|
|
"Arn": "arn:aws:iam::716468089330:role/aws-service-role/organizations.amazonaws.com/AWSServiceRoleForOrganizations",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"Service": "organizations.amazonaws.com"
|
|
},
|
|
"Condition": null
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "AWSServiceRoleForRDS",
|
|
"Path": "/aws-service-role/rds.amazonaws.com/",
|
|
"Arn": "arn:aws:iam::716468089330:role/aws-service-role/rds.amazonaws.com/AWSServiceRoleForRDS",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"Service": "rds.amazonaws.com"
|
|
},
|
|
"Condition": null
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "AWSServiceRoleForResourceExplorer",
|
|
"Path": "/aws-service-role/resource-explorer-2.amazonaws.com/",
|
|
"Arn": "arn:aws:iam::716468089330:role/aws-service-role/resource-explorer-2.amazonaws.com/AWSServiceRoleForResourceExplorer",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"Service": "resource-explorer-2.amazonaws.com"
|
|
},
|
|
"Condition": null
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "AWSServiceRoleForSecurityHub",
|
|
"Path": "/aws-service-role/securityhub.amazonaws.com/",
|
|
"Arn": "arn:aws:iam::716468089330:role/aws-service-role/securityhub.amazonaws.com/AWSServiceRoleForSecurityHub",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"Service": "securityhub.amazonaws.com"
|
|
},
|
|
"Condition": null
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "AWSServiceRoleForSecurityHubV2",
|
|
"Path": "/aws-service-role/securityhubv2.amazonaws.com/",
|
|
"Arn": "arn:aws:iam::716468089330:role/aws-service-role/securityhubv2.amazonaws.com/AWSServiceRoleForSecurityHubV2",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"Service": "securityhubv2.amazonaws.com"
|
|
},
|
|
"Condition": null
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "AWSServiceRoleForServiceQuotas",
|
|
"Path": "/aws-service-role/servicequotas.amazonaws.com/",
|
|
"Arn": "arn:aws:iam::716468089330:role/aws-service-role/servicequotas.amazonaws.com/AWSServiceRoleForServiceQuotas",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"Service": "servicequotas.amazonaws.com"
|
|
},
|
|
"Condition": null
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "AWSServiceRoleForSupport",
|
|
"Path": "/aws-service-role/support.amazonaws.com/",
|
|
"Arn": "arn:aws:iam::716468089330:role/aws-service-role/support.amazonaws.com/AWSServiceRoleForSupport",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"Service": "support.amazonaws.com"
|
|
},
|
|
"Condition": null
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "AWSServiceRoleForTrustedAdvisor",
|
|
"Path": "/aws-service-role/trustedadvisor.amazonaws.com/",
|
|
"Arn": "arn:aws:iam::716468089330:role/aws-service-role/trustedadvisor.amazonaws.com/AWSServiceRoleForTrustedAdvisor",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"Service": "trustedadvisor.amazonaws.com"
|
|
},
|
|
"Condition": null
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "AWSSystemsManagerDefaultEC2InstanceManagementRole",
|
|
"Path": "/service-role/",
|
|
"Arn": "arn:aws:iam::716468089330:role/service-role/AWSSystemsManagerDefaultEC2InstanceManagementRole",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"Service": "ssm.amazonaws.com"
|
|
},
|
|
"Condition": null
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "CloudTrailRoleForCloudWatchLogs_MainTrail",
|
|
"Path": "/service-role/",
|
|
"Arn": "arn:aws:iam::716468089330:role/service-role/CloudTrailRoleForCloudWatchLogs_MainTrail",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"Service": "cloudtrail.amazonaws.com"
|
|
},
|
|
"Condition": {
|
|
"StringEquals": {
|
|
"aws:SourceArn": "arn:aws:cloudtrail:us-east-2:716468089330:trail/us-east-2",
|
|
"aws:SourceAccount": "716468089330"
|
|
}
|
|
}
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "EC2-CloudWatchAgent-Role",
|
|
"Path": "/",
|
|
"Arn": "arn:aws:iam::716468089330:role/EC2-CloudWatchAgent-Role",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"Service": "ec2.amazonaws.com"
|
|
},
|
|
"Condition": null
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "EC2-SSM-Access",
|
|
"Path": "/",
|
|
"Arn": "arn:aws:iam::716468089330:role/EC2-SSM-Access",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"Service": "ec2.amazonaws.com"
|
|
},
|
|
"Condition": null
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "EC2SSMRole",
|
|
"Path": "/",
|
|
"Arn": "arn:aws:iam::716468089330:role/EC2SSMRole",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"Service": "ec2.amazonaws.com"
|
|
},
|
|
"Condition": null
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "FlowLogsToCloudWatch",
|
|
"Path": "/",
|
|
"Arn": "arn:aws:iam::716468089330:role/FlowLogsToCloudWatch",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"Service": "vpc-flow-logs.amazonaws.com"
|
|
},
|
|
"Condition": null
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "gpu-eks-node-group-20251007184911320100000007",
|
|
"Path": "/",
|
|
"Arn": "arn:aws:iam::716468089330:role/gpu-eks-node-group-20251007184911320100000007",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"Service": "ec2.amazonaws.com"
|
|
},
|
|
"Condition": null
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "infrastructure-eks-node-group-20251007184911319500000006",
|
|
"Path": "/",
|
|
"Arn": "arn:aws:iam::716468089330:role/infrastructure-eks-node-group-20251007184911319500000006",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"Service": "ec2.amazonaws.com"
|
|
},
|
|
"Condition": null
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "IntruderReadOnlyRole",
|
|
"Path": "/",
|
|
"Arn": "arn:aws:iam::716468089330:role/IntruderReadOnlyRole",
|
|
"Kind": [
|
|
"cross-account/aws"
|
|
],
|
|
"Vendor": "Intruder.io (external vulnerability scanning)",
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"AWS": "arn:aws:iam::123311413059:root"
|
|
},
|
|
"Condition": {
|
|
"StringEquals": {
|
|
"sts:ExternalId": "8bb7691d-579b-41ef-ae48-5cc3983bcc7f"
|
|
}
|
|
}
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "rds-monitoring-role",
|
|
"Path": "/",
|
|
"Arn": "arn:aws:iam::716468089330:role/rds-monitoring-role",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"Service": "monitoring.rds.amazonaws.com"
|
|
},
|
|
"Condition": null
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "scrivas-staging-cluster-20251007184855668200000001",
|
|
"Path": "/",
|
|
"Arn": "arn:aws:iam::716468089330:role/scrivas-staging-cluster-20251007184855668200000001",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"Service": "eks.amazonaws.com"
|
|
},
|
|
"Condition": null
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "SecureframeRole-f983f1e89008",
|
|
"Path": "/",
|
|
"Arn": "arn:aws:iam::716468089330:role/SecureframeRole-f983f1e89008",
|
|
"Kind": [
|
|
"cross-account/aws"
|
|
],
|
|
"Vendor": "Secureframe (SOC 2 / compliance automation)",
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"AWS": "arn:aws:iam::728997465891:root"
|
|
},
|
|
"Condition": {
|
|
"StringEquals": {
|
|
"sts:ExternalId": "d3f0ba8c-2023-4cf6-8846-f983f1e89008"
|
|
}
|
|
}
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "vpc-flow-logs-role",
|
|
"Path": "/",
|
|
"Arn": "arn:aws:iam::716468089330:role/vpc-flow-logs-role",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"Service": "vpc-flow-logs.amazonaws.com"
|
|
},
|
|
"Condition": null
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"RoleName": "VPCFlowLogs-Cloudwatch-1781174191538",
|
|
"Path": "/service-role/",
|
|
"Arn": "arn:aws:iam::716468089330:role/service-role/VPCFlowLogs-Cloudwatch-1781174191538",
|
|
"Kind": [
|
|
"service"
|
|
],
|
|
"Vendor": null,
|
|
"Statements": [
|
|
{
|
|
"Effect": "Allow",
|
|
"Action": "sts:AssumeRole",
|
|
"Principal": {
|
|
"Service": "vpc-flow-logs.amazonaws.com"
|
|
},
|
|
"Condition": {
|
|
"StringEquals": {
|
|
"aws:SourceAccount": "716468089330"
|
|
},
|
|
"ArnLike": {
|
|
"aws:SourceArn": "arn:aws:ec2:us-east-2:716468089330:vpc-flow-log/*"
|
|
}
|
|
}
|
|
}
|
|
]
|
|
}
|
|
]
|
|
} |