Skip to content

Commit d20d6ad

Browse files
committed
[ELI-731] addressing comments
1 parent b2a9a45 commit d20d6ad

1 file changed

Lines changed: 3 additions & 8 deletions

File tree

infrastructure/stacks/iams-developer-roles/github_actions_policies.tf

Lines changed: 3 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -852,11 +852,9 @@ data "aws_iam_policy_document" "regression_test_permissions" {
852852
effect = "Allow"
853853
actions = [
854854
"secretsmanager:GetSecretValue",
855-
"secretsmanager:PutSecretValue",
856-
"secretsmanager:DescribeSecret",
857-
"secretsmanager:UpdateSecretVersionStage"
855+
"secretsmanager:DescribeSecret"
858856
]
859-
resources = ["*"]
857+
resources = ["arn:aws:secretsmanager:${var.default_aws_region}:${data.aws_caller_identity.current.account_id}:secret:eligibility-signposting-api-*"]
860858
}
861859

862860
statement {
@@ -900,10 +898,7 @@ data "aws_iam_policy_document" "regression_test_permissions" {
900898
"ssm:GetParametersByPath"
901899
]
902900
resources = [
903-
"arn:aws:ssm:${var.default_aws_region}:${data.aws_caller_identity.current.account_id}:parameter/${var.environment}/*",
904-
"arn:aws:ssm:${var.default_aws_region}:${data.aws_caller_identity.current.account_id}:parameter/splunk/*",
905-
"arn:aws:ssm:${var.default_aws_region}:${data.aws_caller_identity.current.account_id}:parameter/ptl/*",
906-
"arn:aws:ssm:${var.default_aws_region}:${data.aws_caller_identity.current.account_id}:parameter/prod/*"
901+
"arn:aws:ssm:${var.default_aws_region}:${data.aws_caller_identity.current.account_id}:parameter/${var.environment}/*"
907902
]
908903
}
909904
}

0 commit comments

Comments
 (0)