Notifies slack when an IAM policy is created, changed or assigned to a role
Notifies slack when an IAM policy is created, changed or assigned to a role
Notifies a slack channel when an AWS IAM policy is manipulated
Before installing anything to AWS, you will need to configure a "bot" in Slack to handle the posts for you. To do this:
The stack asks for the function zip file location in S3, the slack API Key and the slack channel to post notifications to. Once the stack is created, a cloudwatch event is created to subscribe the lambda function to several IAM events around policy manipulation.
Using some optional environment variables defined on the Lambda function, you can also exclude certain Slack notifications for specific policy manipultation events. Set the following variables on the function to 0
if you wish to exclude these events from notifying Slack: