Create limit policy

Create policy to limit resource usage by Region

  1. After successfully creating the user. In the left menu, click Policies.

CostGovernance

  1. On the Policies page.
    • Click Create Policy.

CostGovernance

  1. On the Create policy page.
    • Click the JSON tab.

CostGovernance

  1. Copy and Paste the policy content below.
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": [
                "ec2:*",
                "rds:*",
                "s3:*"
            ],
            "Resource": "*",
    "Condition": {"StringEquals": {"aws:RequestedRegion": "ap-southeast-1"}}
        }
    ]
}

CostGovernance

You can change the Region information in the above policy to match the Region where you want to grant permissions for EC2, RDS, and S3 services.

  1. Click Next.

CostGovernance

  1. On the Review policy page.
    • Set Name as RegionRestrict.
    • Set Description as EC2, RDS, S3 access in a single Region only.
    • Click Create policy.

CostGovernance

  1. Ensure the RegionRestrict policy is created successfully.

CostGovernance

In the next step, we will attach the policy to the CostTest group and then test the effectiveness of this policy.