
Curated catalog of AWS resource types that can be publicly exposed, with CLI commands for creating and auditing public access configurations across services.
The goal of this repo is to maintain a list of all AWS resources that can be publicly exposed, and eventually, those that can be shared with untrusted accounts (that section is still in development and not included here yet).
The following concepts are applied in this list:
I would like this repo to eventually contain the following:
Actions:
Allows invoking the function
Actions:
Actions:
Actions:
Actions:
TODO: Need to confirm this can actually be shared with other accounts. Some of the doc wording leads me to think this might only be shareable to principals within an account.
Actions:
Actions:
S3 buckets can be public via policies and ACL. S3 objects can be public via ACL. ACLs can be set at bucket or object creation.
Actions:
Actions:
Actions:
Actions:
Actions:
Only allows sending data into an account
Actions:
Actions:
Actions:
Actions:
Actions:
Actions:
Actions:
Actions:
Actions:
Actions:
Actions:
Actions:
There are associated resource policies (see here) that may make this something that should be in multiple categories?
Actions:
Actions:
Actions:
Actions:
Actions:
Actions:
Actions:
Actions:
Actions:
Actions:
Actions:
Actions:
Actions: