Skip to content

Commit b6492a1

Browse files
authored
Merge branch 'main' into chore/eja-cross-repo-triggering-of-my-vaccines-test-data-action
2 parents 38e76be + 252331a commit b6492a1

2 files changed

Lines changed: 6 additions & 1 deletion

File tree

infrastructure/stacks/api-layer/iam_policies.tf

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -190,7 +190,8 @@ data "aws_iam_policy_document" "audit_s3_bucket_policy" {
190190
}
191191

192192
# Attach s3 read policy to Lambda role
193-
resource "aws_iam_role_policy" "lambda_s3_rules_read_policy" {
193+
resource "aws_iam_role_policy" "lambda_s3_read_policy" {
194+
# for rules bucket
194195
name = "S3ReadAccess"
195196
role = aws_iam_role.eligibility_lambda_role.id
196197
policy = data.aws_iam_policy_document.s3_rules_bucket_policy.json

infrastructure/stacks/iams-developer-roles/github_actions_policies.tf

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -209,12 +209,16 @@ resource "aws_iam_policy" "s3_management" {
209209
Resource = [
210210
"arn:aws:s3:::*eligibility-signposting-api-${var.environment}-eli-rules",
211211
"arn:aws:s3:::*eligibility-signposting-api-${var.environment}-eli-rules/*",
212+
"arn:aws:s3:::*eligibility-signposting-api-${var.environment}-eli-consumer-map",
213+
"arn:aws:s3:::*eligibility-signposting-api-${var.environment}-eli-consumer-map/*",
212214
"arn:aws:s3:::*eligibility-signposting-api-${var.environment}-eli-audit",
213215
"arn:aws:s3:::*eligibility-signposting-api-${var.environment}-eli-audit/*",
214216
"arn:aws:s3:::*eligibility-signposting-api-${var.environment}-eli-rules-access-logs",
215217
"arn:aws:s3:::*eligibility-signposting-api-${var.environment}-eli-rules-access-logs/*",
216218
"arn:aws:s3:::*eligibility-signposting-api-${var.environment}-eli-audit-access-logs",
217219
"arn:aws:s3:::*eligibility-signposting-api-${var.environment}-eli-audit-access-logs/*",
220+
"arn:aws:s3:::*eligibility-signposting-api-${var.environment}-eli-consumer-map-access-logs",
221+
"arn:aws:s3:::*eligibility-signposting-api-${var.environment}-eli-consumer-map-access-logs/*",
218222
"arn:aws:s3:::*eligibility-signposting-api-${var.environment}-truststore",
219223
"arn:aws:s3:::*eligibility-signposting-api-${var.environment}-truststore/*",
220224
"arn:aws:s3:::*eligibility-signposting-api-${var.environment}-truststore-access-logs",

0 commit comments

Comments
 (0)