Skip to content

Commit ea1f4c9

Browse files
committed
eli-279 moving more api gateway permissions to * resource
1 parent df7430e commit ea1f4c9

1 file changed

Lines changed: 5 additions & 2 deletions

File tree

infrastructure/stacks/iams-developer-roles/github_actions_policies.tf

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -182,10 +182,15 @@ resource "aws_iam_policy" "api_infrastructure" {
182182
Effect = "Allow",
183183
Action = [
184184
"logs:Describe*",
185+
"logs:PutLogEvents",
186+
"logs:CreateLogGroup",
187+
"logs:CreateLogStream",
185188
"ssm:DescribeParameters",
186189
"ec2:Describe*",
187190
"ec2:DescribeVpcs",
188191
"acm:ListCertificates",
192+
"acm:DescribeCertificate",
193+
"acm:GetCertificate",
189194
"apigateway:*",
190195
"iam:PassRole",
191196
],
@@ -231,8 +236,6 @@ resource "aws_iam_policy" "api_infrastructure" {
231236
"ssm:AddTagsToResource",
232237

233238
# acm
234-
"acm:DescribeCertificate",
235-
"acm:GetCertificate",
236239
"acm:ListTagsForCertificate",
237240
"acm:RequestCertificate",
238241
"acm:AddTagsToCertificate",

0 commit comments

Comments
 (0)