Skip to content

Commit f2d9abf

Browse files
committed
replaced explicit cloudtrail action list to reduce policy size
1 parent 78a6e02 commit f2d9abf

1 file changed

Lines changed: 1 addition & 14 deletions

File tree

infrastructure/stacks/iams-developer-roles/iams_permissions_boundary.tf

Lines changed: 1 addition & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -29,20 +29,7 @@ data "aws_iam_policy_document" "permissions_boundary" {
2929
"cloudwatch:GetMetricWidgetImage",
3030

3131
# CloudTrail - trail management
32-
"cloudtrail:AddTags",
33-
"cloudtrail:CreateTrail",
34-
"cloudtrail:DeleteTrail",
35-
"cloudtrail:DescribeTrails",
36-
"cloudtrail:GetEventSelectors",
37-
"cloudtrail:GetTrail",
38-
"cloudtrail:GetTrailStatus",
39-
"cloudtrail:ListTags",
40-
"cloudtrail:ListTrails",
41-
"cloudtrail:PutEventSelectors",
42-
"cloudtrail:RemoveTags",
43-
"cloudtrail:StartLogging",
44-
"cloudtrail:StopLogging",
45-
"cloudtrail:UpdateTrail",
32+
"cloudtrail:*",
4633

4734
# DynamoDB - table management
4835
"dynamodb:Describe*",

0 commit comments

Comments
 (0)