Создана политика IAM, которая должна ограничивать пользователя до сих пор, чтобы разрешить создание экземпляра ec2, когда значение тегов не встречается
{"Version": "2012-10-17", "Statement": [{"Sid":" AllowToDescribeAll "," Effect ":" Allow "," Action ": [" ec2: Describe * "]," Resource ":" "}, {" Sid ":" AllowRunInstances "," Effect ": «Разрешить», «Действие»: «ec2: RunInstances», «Resource»: [«arn: aws: ec2: :: image / », «arn: aws: ec2: :: снимок / "," arn: aws: ec2: : : подсеть /"," arn: aws: ec2: : : сетевой интерфейс / "," arn: aws: ec2: : : группа безопасности /"," arn: aws: ec2: : : пара ключей / "]}, {" Sid ":" AllowRunInstancesWithRestrictions "," Effect ":" Allow "," Action ": [" ec2: CreateVolume "," ec2: RunInstances "]," Resource ": [" arn: aws: ec2: : : том /"," arn: aws: ec2: : : instance / "]," Condition ": {" StringEquals ": {"aws: RequestTag / shutdown ":" true "," aws: RequestTag / terminate ":" true "}," ForAllValues: StringEquals ": {"aws: TagKeys": ["shutdown", "terminate"]}}}, {"Sid": "AllowCreateTagsOnlyLaunching", "Effect": "Allow", "Action": ["ec2: CreateTags"], "Resource": [" arn: aws: ec2: : : том /"," arn: aws: ec2: : : instance / * "]," Condition ":{"StringEquals": {"ec2: CreateAction": "RunInstances"}}}]}