
amazon web services - Writing an OPA Policy that enforces tagging, but only for AWS resources that allow tagging - Stack Overflo


In the project I'm working on, we're getting OPA failures because our policy checks for tags on resources, but some resources do not allow tags, such as SNS. Is it possible to write a policy that can check whether or not a resource allows tagging, and if it does, ensure that it has tags? Or is the only way to do this a manually maintained whitelist of resources to exclude from the tagging enforcement policy?




  1. 暂无评论