Skip to content

Commit 358dc0c

Browse files
committed
[ELI-702] - adding permissions
1 parent 0fda371 commit 358dc0c

2 files changed

Lines changed: 3 additions & 1 deletion

File tree

infrastructure/stacks/iams-developer-roles/github_actions_policies.tf

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -728,7 +728,8 @@ resource "aws_iam_policy" "code_signing_management" {
728728
"lambda:ListCodeSigningConfigs",
729729
"lambda:GetFunctionCodeSigningConfig",
730730
"lambda:ListTags",
731-
"lambda:DeleteFunctionCodeSigningConfig"
731+
"lambda:DeleteFunctionCodeSigningConfig",
732+
"lambda:PutFunctionCodeSigningConfig"
732733
],
733734
Resource = "*"
734735
},

infrastructure/stacks/iams-developer-roles/iams_permissions_boundary.tf

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -163,6 +163,7 @@ data "aws_iam_policy_document" "permissions_boundary" {
163163
"lambda:DeleteFunctionCodeSigningConfig",
164164
"lambda:PutFunctionCodeSigningConfig",
165165
"lambda:DeleteCodeSigningConfig",
166+
"lambda:CreateCodeSigningConfig",
166167

167168
# CloudWatch Logs - log management
168169
"logs:*",

0 commit comments

Comments
 (0)