iam-floyd
iam-floyd copied to clipboard
Check type of all generated condition operators
Many should be of type number, ARN or Date instead of string.
For example s3:object-lock-remaining-retention-days should most probably be numeric instead of string
Logic has been implemented and a first condition ec2:SnapshotTime has been fixed (and tested).
Not sure if you're aware of https://github.com/Netflix-Skunkworks/policyuniverse, but there's a data.json file containing interesting information. No involvement with the project! Just wanted to share.