Skip to content

Allow STS #50

@gricey432

Description

@gricey432

It looks to me like sts:* should be fine in the InnovationSandboxAwsNukeSupportedServicesScp but would be interested to know if it's purposefully omitted due to some concern.

Use case is a developer is trying to sandbox a solution which involves a role making an assumerole call to another role. This is being blocked by the SCP.

I've added sts:* to our copy of the SCP and that has resolved the issue but would love to understand if there's a risk to that or if it's something that could be contributed back to this repo.

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Projects

Status

No status

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions