AWSConfigRemediation-DropInvalidHeadersForALB
Description
The AWSConfigRemediation-DropInvalidHeadersForALB
runbook enables
the application load balancer you specify to remove HTTP headers with invalid
headers.
Document type
Automation
Owner
Amazon
Platforms
Linux, macOS, Windows
Parameters
-
AutomationAssumeRole
Type: String
Description: (Required) The Amazon Resource Name (ARN) of the AWS Identity and Access Management (IAM) role that allows Systems Manager Automation to perform the actions on your behalf.
-
LoadBalancerArn
Type: String
Description: (Required) The Amazon Resource Name (ARN) of the load balancer that you want to drop invalid headers.
Required IAM permissions
The AutomationAssumeRole
parameter requires the following actions to
use the runbook successfully.
-
ssm:StartAutomationExecution
-
ssm:GetAutomationExecution
-
elasticloadbalancing:DescribeLoadBalancerAttributes
-
elasticloadbalancing:ModifyLoadBalancerAttributes
Document Steps
-
aws:executeAwsApi
- Enables the drop invalid headers setting for the load balancer you specify in theLoadBalancerArn
parameter. -
aws:executeScript
- Verifies the drop invalid headers setting has been enabled on the load balancer you specify in theLoadBalancerArn
parameter.