Skip to content
This repository has been archived by the owner on Dec 6, 2024. It is now read-only.

Commit

Permalink
Revert "[feat] Use S3VPCE to prevent S3 access outside of VPC" (#1187)
Browse files Browse the repository at this point in the history
  • Loading branch information
aws-tyler authored Apr 28, 2023
1 parent c75600c commit 9e5c6d8
Show file tree
Hide file tree
Showing 4 changed files with 0 additions and 38 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -1227,10 +1227,3 @@ Outputs:
Description: Route53 hosted zone
Condition: isAppStreamAndCustomDomain
Value: !Ref Route53HostedZone

S3VPCE:
Description: S3 interface endpoint
Condition: isAppStream
Value: !Ref S3Endpoint
Export:
Name: !Join [ '', [ Ref: Namespace, '-S3VPCE' ] ]
Original file line number Diff line number Diff line change
Expand Up @@ -79,18 +79,6 @@ Resources:
Action:
- 'sts:AssumeRole'
Resource: 'arn:aws:iam::*:role/swb-*'
- Effect: Deny
Action: '*'
Resource: '*'
Condition:
StringNotEquals:
aws:Ec2InstanceSourceVPC: "${aws:SourceVpc}"
aws:ec2InstanceSourcePrivateIPv4: "${aws:VpcSourceIp}"
BoolIfExists:
aws:ViaAWSService: "false"
'Null':
aws:ec2InstanceSourceVPC: "false"

IAMRole:
Type: 'AWS::IAM::Role'
Properties:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -101,17 +101,6 @@ Resources:
Action:
- 'sts:AssumeRole'
Resource: 'arn:aws:iam::*:role/swb-*'
- Effect: Deny
Action: '*'
Resource: '*'
Condition:
StringNotEquals:
aws:Ec2InstanceSourceVPC: "${aws:SourceVpc}"
aws:ec2InstanceSourcePrivateIPv4: "${aws:VpcSourceIp}"
BoolIfExists:
aws:ViaAWSService: "false"
'Null':
aws:ec2InstanceSourceVPC: "false"
IAMRole:
Type: 'AWS::IAM::Role'
Properties:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -122,14 +122,6 @@ Resources:
- sagemaker:DescribeNotebookInstance
- sagemaker:StopNotebookInstance
Resource: '*'
- Effect: Deny
Action: 's3:*'
Resource: '*'
Condition:
StringNotEquals:
aws:SourceVpce:
Fn::ImportValue: !Sub '${SolutionNamespace}-S3VPCE'


IAMRoleSageMakerURL:
Type: 'AWS::IAM::Role'
Expand Down

0 comments on commit 9e5c6d8

Please sign in to comment.