# Cloud GUI editing access, template v2. # # OPTIONAL. Creates a second IAM role, used only when someone on your team takes # an action in Cloud GUI: downloading, uploading or deleting a file, running a # function, starting, stopping or rebooting a server, or clearing a website's # cache. Viewing keeps using the read-only role, which this doesn't change. # # - Same rules as the read-only role: no access keys, your ExternalId required, # at most an hour per session, and every session names the Cloud GUI user who # took the action, so each change shows up in CloudTrail under that person. # - BucketPrefix and FunctionPrefix limit it to names that start with them. # Left empty, it covers every bucket and every function in this account. # - OnlyTaggedServers 'true' limits servers to those tagged cloudgui:editable=true. # 'false' covers every server in this account. It can't create, resize or # terminate servers, or change a CloudFront distribution's settings. # - To turn editing off, delete this stack. Viewing keeps working. # # Plain-English version: https://cloudgui.com/security#editing AWSTemplateFormatVersion: '2010-09-09' Description: >- Cloud GUI editing access (v2). An optional role that lets Cloud GUI download, upload and delete S3 files, run Lambda functions, start, stop and reboot EC2 servers, and clear CloudFront caches when a user asks. Delete this stack to turn editing off. Parameters: ConnectionId: Type: String Description: Identifies this connection in Cloud GUI. Filled in for you. AllowedPattern: '[0-9a-f]{8}' ExternalId: Type: String Description: Cloud GUI must present this value to use the role. Filled in for you. AllowedPattern: '[0-9a-f]{32}' BucketPrefix: Type: String Default: '' Description: Only buckets whose names start with this. Leave empty for every bucket. AllowedPattern: '[a-z0-9.-]{0,63}' FunctionPrefix: Type: String Default: '' Description: Only functions whose names start with this. Leave empty for every function. AllowedPattern: '[A-Za-z0-9_-]{0,64}' OnlyTaggedServers: Type: String Default: 'false' AllowedValues: ['true', 'false'] Description: "'true' = only servers tagged cloudgui:editable with the value true can be started, stopped or rebooted. 'false' = every server." Conditions: ServersNeedTag: !Equals [!Ref OnlyTaggedServers, 'true'] Resources: EditorRole: Type: AWS::IAM::Role Properties: RoleName: !Sub 'cloudgui-editor-${ConnectionId}' Description: Editing access for Cloud GUI (cloudgui.com). Delete the CloudFormation stack to turn editing off. MaxSessionDuration: 3600 AssumeRolePolicyDocument: Version: '2012-10-17' Statement: # Cloud GUI may use this role only with your ExternalId, and only when the # session names the Cloud GUI user it's for (so CloudTrail always can). - Sid: CloudGUIWithExternalId Effect: Allow Principal: AWS: 'arn:aws:iam::487275459989:root' Action: sts:AssumeRole Condition: StringEquals: sts:ExternalId: !Ref ExternalId 'Null': sts:SourceIdentity: 'false' # Lets that session carry the user's email as its source identity. On its # own it grants nothing: it only applies within an AssumeRole allowed above. - Sid: NameTheUser Effect: Allow Principal: AWS: 'arn:aws:iam::487275459989:root' Action: sts:SetSourceIdentity Policies: - PolicyName: cloudgui-editor PolicyDocument: Version: '2012-10-17' Statement: # Download files - Sid: DownloadFiles Effect: Allow Action: - s3:GetObject Resource: !Sub 'arn:aws:s3:::${BucketPrefix}*/*' # Upload files - Sid: UploadFiles Effect: Allow Action: - s3:PutObject Resource: !Sub 'arn:aws:s3:::${BucketPrefix}*/*' # Delete files - Sid: DeleteFiles Effect: Allow Action: - s3:DeleteObject Resource: !Sub 'arn:aws:s3:::${BucketPrefix}*/*' # Run functions - Sid: RunFunctions Effect: Allow Action: - lambda:InvokeFunction Resource: !Sub 'arn:aws:lambda:*:${AWS::AccountId}:function:${FunctionPrefix}*' # Start, stop and reboot servers - Sid: StartStopServers Effect: Allow Action: - ec2:StartInstances - ec2:StopInstances - ec2:RebootInstances Resource: !Sub 'arn:aws:ec2:*:${AWS::AccountId}:instance/*' Condition: !If - ServersNeedTag - StringEquals: 'aws:ResourceTag/cloudgui:editable': 'true' - !Ref AWS::NoValue # Clear a website's cache - Sid: ClearWebsiteCaches Effect: Allow Action: - cloudfront:CreateInvalidation - cloudfront:GetInvalidation Resource: !Sub 'arn:aws:cloudfront::${AWS::AccountId}:distribution/*' Tags: - Key: cloudgui:connection Value: !Ref ConnectionId - Key: cloudgui:template-version Value: '2' Outputs: RoleArn: Description: The role Cloud GUI uses for actions. Cloud GUI finds it on its own; nothing to copy. Value: !GetAtt EditorRole.Arn