Skip to content

Commit 17fcad9

Browse files
committed
[ELI-731] adding region to arn
1 parent beebdaf commit 17fcad9

1 file changed

Lines changed: 3 additions & 3 deletions

File tree

infrastructure/stacks/iams-developer-roles/github_actions_policies.tf

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -181,7 +181,7 @@ resource "aws_iam_policy" "dynamodb_management" {
181181
"dynamodb:UpdateTable",
182182
],
183183
Resource = [
184-
"arn:aws:dynamodb:*:${data.aws_caller_identity.current.account_id}:table/*eligibility-signposting-api-${var.environment}-eligibility_datastore"
184+
"arn:aws:dynamodb:${var.default_aws_region}:${data.aws_caller_identity.current.account_id}:table/*eligibility-signposting-api-${var.environment}-eligibility_datastore"
185185
]
186186
},
187187

@@ -218,7 +218,7 @@ resource "aws_iam_policy" "dynamodb_management" {
218218
"dynamodb:Query"
219219
],
220220
Resource = [
221-
"arn:aws:dynamodb:*:${data.aws_caller_identity.current.account_id}:table/*eligibility-signposting-api-${var.environment}-eligibility_datastore"
221+
"arn:aws:dynamodb:${var.default_aws_region}:${data.aws_caller_identity.current.account_id}:table/*eligibility-signposting-api-${var.environment}-eligibility_datastore"
222222
]
223223
}
224224
] : []
@@ -843,7 +843,7 @@ data "aws_iam_policy_document" "regression_test_permissions" {
843843
"dynamodb:ListTagsOfResource"
844844
]
845845
resources = [
846-
"arn:aws:dynamodb:*:${data.aws_caller_identity.current.account_id}:table/*eligibility-signposting-api-${var.environment}-eligibility_datastore"
846+
"arn:aws:dynamodb:${var.default_aws_region}:${data.aws_caller_identity.current.account_id}:table/*eligibility-signposting-api-${var.environment}-eligibility_datastore"
847847
]
848848
}
849849

0 commit comments

Comments
 (0)