Skip to content

Commit 0fda371

Browse files
committed
[ELI-702] - adding permissions
1 parent d55e992 commit 0fda371

2 files changed

Lines changed: 10 additions & 1 deletion

File tree

infrastructure/stacks/iams-developer-roles/github_actions_policies.tf

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -726,7 +726,9 @@ resource "aws_iam_policy" "code_signing_management" {
726726
"lambda:DeleteCodeSigningConfig",
727727
"lambda:GetCodeSigningConfig",
728728
"lambda:ListCodeSigningConfigs",
729-
"lambda:GetFunctionCodeSigningConfig"
729+
"lambda:GetFunctionCodeSigningConfig",
730+
"lambda:ListTags",
731+
"lambda:DeleteFunctionCodeSigningConfig"
730732
],
731733
Resource = "*"
732734
},

infrastructure/stacks/iams-developer-roles/iams_permissions_boundary.tf

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -89,6 +89,9 @@ data "aws_iam_policy_document" "permissions_boundary" {
8989
# Kinesis Stream - audit log streaming
9090
"kinesis:*",
9191

92+
# CodeSigning
93+
"signer:*",
94+
9295
# IAM - specific role and policy management
9396
"iam:GetRole*",
9497
"iam:GetPolicy*",
@@ -156,6 +159,10 @@ data "aws_iam_policy_document" "permissions_boundary" {
156159
"lambda:DeleteProvisionedConcurrencyConfig",
157160
"lambda:ListProvisionedConcurrencyConfigs",
158161
"lambda:PutFunctionConcurrency",
162+
"lambda:GetCodeSigningConfig",
163+
"lambda:DeleteFunctionCodeSigningConfig",
164+
"lambda:PutFunctionCodeSigningConfig",
165+
"lambda:DeleteCodeSigningConfig",
159166

160167
# CloudWatch Logs - log management
161168
"logs:*",

0 commit comments

Comments
 (0)