Skip to content

Commit 8afd37c

Browse files
committed
[ELI-731] addressing commments
1 parent 7f4609e commit 8afd37c

1 file changed

Lines changed: 6 additions & 3 deletions

File tree

infrastructure/stacks/iams-developer-roles/github_actions_policies.tf

Lines changed: 6 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -843,7 +843,7 @@ data "aws_iam_policy_document" "regression_test_permissions" {
843843
"dynamodb:ListTagsOfResource"
844844
]
845845
resources = [
846-
"arn:aws:dynamodb:${var.default_aws_region}:${data.aws_caller_identity.current.account_id}:table/my-table"
846+
"arn:aws:dynamodb:*:${data.aws_caller_identity.current.account_id}:table/*eligibility-signposting-api-${var.environment}-eligibility_datastore"
847847
]
848848
}
849849

@@ -899,7 +899,10 @@ data "aws_iam_policy_document" "regression_test_permissions" {
899899
"ssm:GetParametersByPath"
900900
]
901901
resources = [
902-
"arn:aws:ssm:${var.default_aws_region}:${data.aws_caller_identity.current.account_id}:parameter/my-app/*"
902+
"arn:aws:ssm:${var.default_aws_region}:${data.aws_caller_identity.current.account_id}:parameter/${var.environment}/*",
903+
"arn:aws:ssm:${var.default_aws_region}:${data.aws_caller_identity.current.account_id}:parameter/splunk/*",
904+
"arn:aws:ssm:${var.default_aws_region}:${data.aws_caller_identity.current.account_id}:parameter/ptl/*",
905+
"arn:aws:ssm:${var.default_aws_region}:${data.aws_caller_identity.current.account_id}:parameter/prod/*"
903906
]
904907
}
905908
}
@@ -1028,7 +1031,7 @@ resource "aws_iam_role_policy_attachment" "regression_test_permissions" {
10281031
policy_arn = aws_iam_policy.regression_test_permissions.arn
10291032
}
10301033

1031-
resource "aws_iam_role_policy_attachment" "security_management" {
1034+
resource "aws_iam_role_policy_attachment" "regression_security_management" {
10321035
role = aws_iam_role.regression_test_role.name
10331036
policy_arn = aws_iam_policy.security_management.arn
10341037
}

0 commit comments

Comments
 (0)