-
Notifications
You must be signed in to change notification settings - Fork 10
/
Copy pathdelete-resources.sh
executable file
·46 lines (31 loc) · 1.35 KB
/
delete-resources.sh
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
#!/usr/bin/env bash
# Deletes all AWS IAM resources required for Duckbill Group remote access.
set -euo pipefail
user_arn=$(aws sts get-caller-identity --output text --query 'Arn' | tr -d '\r')
account_number=$(aws sts get-caller-identity --output text --query 'Account' | tr -d '\r')
echo "Logged into AWS as ${user_arn}"
echo "Deleting Duckbill Group role and policies..."
aws iam detach-role-policy \
--role-name DuckbillGroupRole \
--policy-arn arn:aws:iam::aws:policy/job-function/ViewOnlyAccess
aws iam detach-role-policy \
--role-name DuckbillGroupRole \
--policy-arn "arn:aws:iam::${account_number}:policy/DuckbillGroupBilling"
aws iam detach-role-policy \
--role-name DuckbillGroupRole \
--policy-arn "arn:aws:iam::${account_number}:policy/DuckbillGroupResourceDiscovery"
aws iam delete-policy \
--policy-arn "arn:aws:iam::${account_number}:policy/DuckbillGroupBilling"
aws iam delete-policy \
--policy-arn "arn:aws:iam::${account_number}:policy/DuckbillGroupResourceDiscovery"
aws iam delete-role \
--role-name DuckbillGroupRole
echo "Deleting Skyway role and policies..."
aws iam detach-role-policy \
--role-name SkywayRole \
--policy-arn "arn:aws:iam::${account_number}:policy/SkywayAccess"
aws iam delete-policy \
--policy-arn "arn:aws:iam::${account_number}:policy/SkywayAccess"
aws iam delete-role \
--role-name SkywayRole
echo "Done!"