Skip to content

Commit 9b6b182

Browse files
checkov fixes
1 parent 5f57107 commit 9b6b182

1 file changed

Lines changed: 9 additions & 3 deletions

File tree

infrastructure/stacks/iams-developer-roles/github_actions_policies.tf

Lines changed: 9 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -447,11 +447,17 @@ resource "aws_iam_policy" "firehose_readonly" {
447447
Statement = [
448448
{
449449
Effect = "Allow",
450-
Action = [
450+
actions = [
451+
"firehose:CreateDeliveryStream",
452+
"firehose:DeleteDeliveryStream",
451453
"firehose:DescribeDeliveryStream",
454+
"firehose:UpdateDestination",
455+
"firehose:PutRecord",
456+
"firehose:PutRecordBatch",
457+
"firehose:TagDeliveryStream",
452458
"firehose:ListTagsForDeliveryStream",
453-
"firehose:TagDeliveryStream"
454-
],
459+
"firehose:UntagDeliveryStream"
460+
]
455461
Resource = "arn:aws:firehose:${var.default_aws_region}:${data.aws_caller_identity.current.account_id}:deliverystream/eligibility-signposting-api*"
456462
}
457463
]

0 commit comments

Comments
 (0)