AWS AmazonCloudWatch: Use ArnLike instead of StringLike in Firehose destination policies
Summary
Updates two IAM policy examples (destination policy and role trust/output policy) so the aws:SourceArn condition uses ArnLike instead of StringLike.
Security assessment
Both the destination access policy and the role policy for the Kinesis Firehose cross-account delivery example now evaluate aws:SourceArn with ArnLike, which enforces ARN-structured matching and avoids the overly permissive string matching that StringLike permits on the account/resource portions. This tightens the documented cross-account authorization boundary; no CVE or advisory is referenced.
Evidence
+ "ArnLike": {
Diff
diff --git a/AmazonCloudWatch/latest/logs/CreateFirehoseStreamDestination-Account.md b/AmazonCloudWatch/latest/logs/CreateFirehoseStreamDestination-Account.md index 325be7d83..b581987d6 100644 --- a//AmazonCloudWatch/latest/logs/CreateFirehoseStreamDestination-Account.md +++ b//AmazonCloudWatch/latest/logs/CreateFirehoseStreamDestination-Account.md @@ -88 +88 @@ This policy includes a `aws:SourceArn` global condition context key that specifi - "StringLike": { + "ArnLike": { @@ -121 +121 @@ The following is a sample output. Take note of the returned `Role.Arn` value, be - "StringLike": { + "ArnLike": {