Skip to content

Commit d78e8e8

Browse files
authored
Merge pull request #635 from NHSDigital/fix/perms-boundry-issues
[ELI-702] adding required boundry widening
2 parents 05e69da + b25f662 commit d78e8e8

1 file changed

Lines changed: 7 additions & 0 deletions

File tree

infrastructure/stacks/iams-developer-roles/iams_permissions_boundary.tf

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -91,6 +91,8 @@ data "aws_iam_policy_document" "permissions_boundary" {
9191

9292
# Kinesis Stream - audit log streaming
9393
"kinesis:*",
94+
# signing - code signing for Lambda functions
95+
"signer:*",
9496

9597
# IAM - specific role and policy management
9698
"iam:GetRole*",
@@ -159,6 +161,11 @@ data "aws_iam_policy_document" "permissions_boundary" {
159161
"lambda:DeleteProvisionedConcurrencyConfig",
160162
"lambda:ListProvisionedConcurrencyConfigs",
161163
"lambda:PutFunctionConcurrency",
164+
"lambda:GetCodeSigningConfig",
165+
"lambda:DeleteFunctionCodeSigningConfig",
166+
"lambda:PutFunctionCodeSigningConfig",
167+
"lambda:DeleteCodeSigningConfig",
168+
"lambda:CreateCodeSigningConfig",
162169

163170
# CloudWatch Logs - log management
164171
"logs:*",

0 commit comments

Comments
 (0)