Skip to content

Commit 90b3906

Browse files
authored
Added missing permissions (#570)
1 parent e22eee0 commit 90b3906

2 files changed

Lines changed: 4 additions & 0 deletions

File tree

infrastructure/stacks/iams-developer-roles/github_actions_policies.tf

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -400,6 +400,7 @@ resource "aws_iam_policy" "api_infrastructure" {
400400
"ssm:ListTagsForResource",
401401
"ssm:PutParameter",
402402
"ssm:AddTagsToResource",
403+
"ssm:DeleteParameter",
403404

404405
# acm
405406
"acm:ListTagsForCertificate",
@@ -457,6 +458,8 @@ resource "aws_iam_policy" "api_infrastructure" {
457458
"arn:aws:logs:${var.default_aws_region}:${data.aws_caller_identity.current.account_id}:log-group:NHSDAudit_trail_log_group*",
458459
"arn:aws:ssm:${var.default_aws_region}:${data.aws_caller_identity.current.account_id}:parameter/${var.environment}/*",
459460
"arn:aws:ssm:${var.default_aws_region}:${data.aws_caller_identity.current.account_id}:parameter/splunk/*",
461+
"arn:aws:ssm:${var.default_aws_region}:${data.aws_caller_identity.current.account_id}:parameter/ptl/*",
462+
"arn:aws:ssm:${var.default_aws_region}:${data.aws_caller_identity.current.account_id}:parameter/prod/*",
460463
"arn:aws:acm:${var.default_aws_region}:${data.aws_caller_identity.current.account_id}:certificate/*",
461464
"arn:aws:events:${var.default_aws_region}:${data.aws_caller_identity.current.account_id}:rule/cloudwatch-alarm-state-change-to-splunk*",
462465
"arn:aws:wafv2:${var.default_aws_region}:${data.aws_caller_identity.current.account_id}:regional/webacl/*",

infrastructure/stacks/iams-developer-roles/iams_permissions_boundary.tf

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -193,6 +193,7 @@ data "aws_iam_policy_document" "permissions_boundary" {
193193
"ssm:ListTagsForResource",
194194
"ssm:PutParameter",
195195
"ssm:AddTagsToResource",
196+
"ssm:DeleteParameter",
196197

197198
# WAFv2 - web application firewall management
198199
"wafv2:CreateWebACL",

0 commit comments

Comments
 (0)