File tree Expand file tree Collapse file tree
infrastructure/stacks/iams-developer-roles Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -400,6 +400,7 @@ resource "aws_iam_policy" "api_infrastructure" {
400400 " ssm:ListTagsForResource" ,
401401 " ssm:PutParameter" ,
402402 " ssm:AddTagsToResource" ,
403+ " ssm:DeleteParameter" ,
403404
404405 # acm
405406 " acm:ListTagsForCertificate" ,
@@ -457,6 +458,8 @@ resource "aws_iam_policy" "api_infrastructure" {
457458 " arn:aws:logs:${ var . default_aws_region } :${ data . aws_caller_identity . current . account_id } :log-group:NHSDAudit_trail_log_group*" ,
458459 " arn:aws:ssm:${ var . default_aws_region } :${ data . aws_caller_identity . current . account_id } :parameter/${ var . environment } /*" ,
459460 " arn:aws:ssm:${ var . default_aws_region } :${ data . aws_caller_identity . current . account_id } :parameter/splunk/*" ,
461+ " arn:aws:ssm:${ var . default_aws_region } :${ data . aws_caller_identity . current . account_id } :parameter/ptl/*" ,
462+ " arn:aws:ssm:${ var . default_aws_region } :${ data . aws_caller_identity . current . account_id } :parameter/prod/*" ,
460463 " arn:aws:acm:${ var . default_aws_region } :${ data . aws_caller_identity . current . account_id } :certificate/*" ,
461464 " arn:aws:events:${ var . default_aws_region } :${ data . aws_caller_identity . current . account_id } :rule/cloudwatch-alarm-state-change-to-splunk*" ,
462465 " arn:aws:wafv2:${ var . default_aws_region } :${ data . aws_caller_identity . current . account_id } :regional/webacl/*" ,
Original file line number Diff line number Diff line change @@ -193,6 +193,7 @@ data "aws_iam_policy_document" "permissions_boundary" {
193193 " ssm:ListTagsForResource" ,
194194 " ssm:PutParameter" ,
195195 " ssm:AddTagsToResource" ,
196+ " ssm:DeleteParameter" ,
196197
197198 # WAFv2 - web application firewall management
198199 " wafv2:CreateWebACL" ,
You can’t perform that action at this time.
0 commit comments