Skip to content

Commit 508a7bc

Browse files
committed
[ELI] addressing comments
1 parent 93780f6 commit 508a7bc

1 file changed

Lines changed: 2 additions & 0 deletions

File tree

infrastructure/stacks/iams-developer-roles/github_actions_iam_bootstrap_policies.tf

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -88,6 +88,7 @@ data "aws_iam_policy_document" "iam_bootstrap_iam_management" {
8888
"iam:DetachRolePolicy",
8989
"iam:PutRolePolicy",
9090
"iam:DeleteRolePolicy",
91+
"iam:UpdateAssumeRolePolicy",
9192
"iam:PutRolePermissionsBoundary",
9293
"iam:DeleteRolePermissionsBoundary",
9394
]
@@ -101,6 +102,7 @@ data "aws_iam_policy_document" "iam_bootstrap_iam_management" {
101102
sid = "DenyBootstrapBoundaryModification"
102103
effect = "Deny"
103104
actions = [
105+
"iam:CreatePolicyVersion",
104106
"iam:DeletePolicy",
105107
"iam:DeletePolicyVersion",
106108
"iam:SetDefaultPolicyVersion",

0 commit comments

Comments
 (0)