diff --git a/docs/example-iam-policy.json b/docs/example-iam-policy.json index 0ab5790470..6c12061455 100644 --- a/docs/example-iam-policy.json +++ b/docs/example-iam-policy.json @@ -24,8 +24,8 @@ "ec2:CreateTags" ], "Resource": [ - "arn:aws:ec2:*:*:volume/*", - "arn:aws:ec2:*:*:snapshot/*" + "arn:*:ec2:*:*:volume/*", + "arn:*:ec2:*:*:snapshot/*" ] }, { @@ -34,8 +34,8 @@ "ec2:DeleteTags" ], "Resource": [ - "arn:aws:ec2:*:*:volume/*", - "arn:aws:ec2:*:*:snapshot/*" + "arn:*:ec2:*:*:volume/*", + "arn:*:ec2:*:*:snapshot/*" ] }, { @@ -43,7 +43,7 @@ "Action": [ "ec2:CreateVolume" ], - "Resource": "arn:aws:ec2:*:*:volume/*", + "Resource": "arn:*:ec2:*:*:volume/*", "Condition": { "StringLike": { "aws:RequestTag/ebs.csi.aws.com/cluster": "true" @@ -55,7 +55,7 @@ "Action": [ "ec2:CreateVolume" ], - "Resource": "arn:aws:ec2:*:*:volume/*", + "Resource": "arn:*:ec2:*:*:volume/*", "Condition": { "StringLike": { "aws:RequestTag/CSIVolumeName": "*" @@ -67,7 +67,7 @@ "Action": [ "ec2:CreateVolume" ], - "Resource": "arn:aws:ec2:*:*:snapshot/*" + "Resource": "arn:*:ec2:*:*:snapshot/*" }, { "Effect": "Allow", diff --git a/hack/e2e/kops/patch-cluster.yaml b/hack/e2e/kops/patch-cluster.yaml index e3c0db2153..291cbaab92 100644 --- a/hack/e2e/kops/patch-cluster.yaml +++ b/hack/e2e/kops/patch-cluster.yaml @@ -47,8 +47,8 @@ spec: "ec2:CreateTags" ], "Resource": [ - "arn:aws:ec2:*:*:volume/*", - "arn:aws:ec2:*:*:snapshot/*" + "arn:*:ec2:*:*:volume/*", + "arn:*:ec2:*:*:snapshot/*" ] }, { @@ -57,8 +57,8 @@ spec: "ec2:DeleteTags" ], "Resource": [ - "arn:aws:ec2:*:*:volume/*", - "arn:aws:ec2:*:*:snapshot/*" + "arn:*:ec2:*:*:volume/*", + "arn:*:ec2:*:*:snapshot/*" ] }, { @@ -66,7 +66,7 @@ spec: "Action": [ "ec2:CreateVolume" ], - "Resource": "arn:aws:ec2:*:*:volume/*", + "Resource": "arn:*:ec2:*:*:volume/*", "Condition": { "StringLike": { "aws:RequestTag/ebs.csi.aws.com/cluster": "true" @@ -78,7 +78,7 @@ spec: "Action": [ "ec2:CreateVolume" ], - "Resource": "arn:aws:ec2:*:*:volume/*", + "Resource": "arn:*:ec2:*:*:volume/*", "Condition": { "StringLike": { "aws:RequestTag/CSIVolumeName": "*" @@ -90,7 +90,7 @@ spec: "Action": [ "ec2:CreateVolume" ], - "Resource": "arn:aws:ec2:*:*:snapshot/*" + "Resource": "arn:*:ec2:*:*:snapshot/*" }, { "Effect": "Allow",