Skip to content

Commit 1e00ee3

Browse files
committed
[ELI-731] addressing comments
1 parent a7754e7 commit 1e00ee3

1 file changed

Lines changed: 11 additions & 3 deletions

File tree

infrastructure/stacks/iams-developer-roles/github_actions_policies.tf

Lines changed: 11 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -815,7 +815,7 @@ data "aws_iam_policy_document" "regression_test_permissions" {
815815
"s3:GetObjectTagging",
816816
"s3:PutObjectTagging",
817817
"s3:GetObjectVersion"
818-
],
818+
]
819819
resources = [
820820
"arn:aws:s3:::*eligibility-signposting-api-${var.environment}-eli-rules",
821821
"arn:aws:s3:::*eligibility-signposting-api-${var.environment}-eli-rules/*",
@@ -835,9 +835,7 @@ data "aws_iam_policy_document" "regression_test_permissions" {
835835
"dynamodb:UpdateItem",
836836
"dynamodb:DeleteItem",
837837
"dynamodb:DescribeTable",
838-
"dynamodb:ListTables",
839838
"dynamodb:DeleteTable",
840-
"dynamodb:CreateTable",
841839
"dynamodb:TagResource",
842840
"dynamodb:UntagResource",
843841
"dynamodb:ListTagsOfResource"
@@ -847,6 +845,16 @@ data "aws_iam_policy_document" "regression_test_permissions" {
847845
]
848846
}
849847

848+
statement {
849+
sid = "DynamoGlobal"
850+
effect = "Allow"
851+
actions = [
852+
"dynamodb:ListTables",
853+
"dynamodb:CreateTable"
854+
]
855+
resources = ["*"]
856+
}
857+
850858
statement {
851859
sid = "SecretsManagerAccess"
852860
effect = "Allow"

0 commit comments

Comments
 (0)