File tree Expand file tree Collapse file tree
infrastructure/stacks/iams-developer-roles Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -843,7 +843,7 @@ data "aws_iam_policy_document" "regression_test_permissions" {
843843 " dynamodb:ListTagsOfResource"
844844 ]
845845 resources = [
846- " arn:aws:dynamodb:${ var . default_aws_region } :${ data . aws_caller_identity . current . account_id } :table/my-table "
846+ " arn:aws:dynamodb:* :${ data . aws_caller_identity . current . account_id } :table/*eligibility-signposting-api- ${ var . environment } -eligibility_datastore "
847847 ]
848848 }
849849
@@ -899,7 +899,10 @@ data "aws_iam_policy_document" "regression_test_permissions" {
899899 " ssm:GetParametersByPath"
900900 ]
901901 resources = [
902- " arn:aws:ssm:${ var . default_aws_region } :${ data . aws_caller_identity . current . account_id } :parameter/my-app/*"
902+ " arn:aws:ssm:${ var . default_aws_region } :${ data . aws_caller_identity . current . account_id } :parameter/${ var . environment } /*" ,
903+ " arn:aws:ssm:${ var . default_aws_region } :${ data . aws_caller_identity . current . account_id } :parameter/splunk/*" ,
904+ " arn:aws:ssm:${ var . default_aws_region } :${ data . aws_caller_identity . current . account_id } :parameter/ptl/*" ,
905+ " arn:aws:ssm:${ var . default_aws_region } :${ data . aws_caller_identity . current . account_id } :parameter/prod/*"
903906 ]
904907 }
905908}
@@ -1028,7 +1031,7 @@ resource "aws_iam_role_policy_attachment" "regression_test_permissions" {
10281031 policy_arn = aws_iam_policy. regression_test_permissions . arn
10291032}
10301033
1031- resource "aws_iam_role_policy_attachment" "security_management " {
1034+ resource "aws_iam_role_policy_attachment" "regression_security_management " {
10321035 role = aws_iam_role. regression_test_role . name
10331036 policy_arn = aws_iam_policy. security_management . arn
10341037}
You can’t perform that action at this time.
0 commit comments