AWS documentdb: Fix IAM action names in DocumentDB VPC endpoint policy example
Summary
Corrects the example VPC endpoint policy to use rds: action prefixes instead of docdb:, adds the missing "Version": "2012-10-17" statement element, and rewords headings/text about the Amazon DocumentDB API endpoint policy.
Security assessment
The diff corrects the IAM action identifiers in a VPC endpoint policy example (docdb: -> rds:) and adds the required Version element, so readers copy a valid, enforceable policy. This is documentation of access-control configuration rather than a fix for a specific vulnerability.
Evidence
+ "rds:CreateDBInstance",
Diff
diff --git a/documentdb/latest/devguide/docdb-private-link.md b/documentdb/latest/devguide/docdb-private-link.md index abddb9a40..56f92f762 100644 --- a//documentdb/latest/devguide/docdb-private-link.md +++ b//documentdb/latest/devguide/docdb-private-link.md @@ -7 +7 @@ -Considerations for VPC endpointsRegion availabilityCreating an interface VPC endpoint for Amazon DocumentDB APICreating a VPC endpoint policy for Amazon DocumentDB API +Considerations for VPC endpointsRegion availabilityCreating an interface VPC endpoint for Amazon DocumentDB APICreating a VPC endpoint policy for the Amazon DocumentDB API @@ -31 +31 @@ For more information about VPC endpoints, see [Access an AWS service using an in - * Creating a VPC endpoint policy for Amazon DocumentDB API + * Creating a VPC endpoint policy for the Amazon DocumentDB API @@ -111 +111 @@ For more information, see [Access an AWS service using an interface VPC endpoint -## Creating a VPC endpoint policy for Amazon DocumentDB API +## Creating a VPC endpoint policy for the Amazon DocumentDB API @@ -128 +128 @@ For more information, see [Control access to VPC endpoints using endpoint polici -The following is an example of an endpoint policy for Amazon DocumentDB API. When attached to an endpoint, this policy grants access to the listed Amazon DocumentDB API actions for all principals on all resources. +The following is an example of an endpoint policy for the Amazon DocumentDB API. When attached to an endpoint, this policy grants access to the listed Amazon DocumentDB API actions for all principals on all resources. @@ -131,0 +132 @@ The following is an example of an endpoint policy for Amazon DocumentDB API. Whe + "Version": "2012-10-17", @@ -137,3 +138,3 @@ The following is an example of an endpoint policy for Amazon DocumentDB API. Whe - "docdb:CreateDBInstance", - "docdb:ModifyDBInstance", - "docdb:CreateDBSnapshot" + "rds:CreateDBInstance", + "rds:ModifyDBInstance", + "rds:CreateDBSnapshot" @@ -148 +149 @@ The following is an example of an endpoint policy for Amazon DocumentDB API. Whe -The following VPC endpoint policy denies AWS account 123456789012 all access to resources using the endpoint. The policy allows all actions from other accounts. +The following VPC endpoint policy denies AWS account 123456789012 all access to resources using the endpoint. The policy allows all actions from other AWS accounts. @@ -151,0 +153 @@ The following VPC endpoint policy denies AWS account 123456789012 all access to + "Version": "2012-10-17",