File tree Expand file tree Collapse file tree
infrastructure/stacks/iams-developer-roles Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -852,11 +852,9 @@ data "aws_iam_policy_document" "regression_test_permissions" {
852852 effect = " Allow"
853853 actions = [
854854 " secretsmanager:GetSecretValue" ,
855- " secretsmanager:PutSecretValue" ,
856- " secretsmanager:DescribeSecret" ,
857- " secretsmanager:UpdateSecretVersionStage"
855+ " secretsmanager:DescribeSecret"
858856 ]
859- resources = [" *" ]
857+ resources = [" arn:aws:secretsmanager: ${ var . default_aws_region } : ${ data . aws_caller_identity . current . account_id } :secret:eligibility-signposting-api- *" ]
860858 }
861859
862860 statement {
@@ -900,10 +898,7 @@ data "aws_iam_policy_document" "regression_test_permissions" {
900898 " ssm:GetParametersByPath"
901899 ]
902900 resources = [
903- " arn:aws:ssm:${ var . default_aws_region } :${ data . aws_caller_identity . current . account_id } :parameter/${ var . environment } /*" ,
904- " arn:aws:ssm:${ var . default_aws_region } :${ data . aws_caller_identity . current . account_id } :parameter/splunk/*" ,
905- " arn:aws:ssm:${ var . default_aws_region } :${ data . aws_caller_identity . current . account_id } :parameter/ptl/*" ,
906- " arn:aws:ssm:${ var . default_aws_region } :${ data . aws_caller_identity . current . account_id } :parameter/prod/*"
901+ " arn:aws:ssm:${ var . default_aws_region } :${ data . aws_caller_identity . current . account_id } :parameter/${ var . environment } /*"
907902 ]
908903 }
909904}
You can’t perform that action at this time.
0 commit comments