mirror of
https://github.com/Sea-Haven-Industries/afi-backup-monitor.git
synced 2026-10-07 11:39:02 +00:00
fix(iam): replace deprecated managed_policy_arns (PLAT-146)
Keep exclusive attachment control so the apply role stays empty and the plan role keeps ViewOnlyAccess.
This commit is contained in:
parent
7fbff09f66
commit
d2b7857e3a
1 changed files with 33 additions and 2 deletions
|
|
@ -37,6 +37,21 @@ import {
|
|||
id = "hcptf-afi-backup-monitor-plan:afi-backup-monitor-plan-refresh"
|
||||
}
|
||||
|
||||
import {
|
||||
to = aws_iam_role_policy_attachments_exclusive.hcptf_apply
|
||||
id = "hcptf-afi-backup-monitor"
|
||||
}
|
||||
|
||||
import {
|
||||
to = aws_iam_role_policy_attachment.hcptf_plan_viewonly
|
||||
id = "hcptf-afi-backup-monitor-plan/arn:aws:iam::aws:policy/job-function/ViewOnlyAccess"
|
||||
}
|
||||
|
||||
import {
|
||||
to = aws_iam_role_policy_attachments_exclusive.hcptf_plan
|
||||
id = "hcptf-afi-backup-monitor-plan"
|
||||
}
|
||||
|
||||
data "aws_iam_policy_document" "hcptf_apply_trust" {
|
||||
statement {
|
||||
sid = "HcpApply"
|
||||
|
|
@ -358,7 +373,6 @@ resource "aws_iam_role" "hcptf_apply" {
|
|||
name = "hcptf-afi-backup-monitor"
|
||||
assume_role_policy = data.aws_iam_policy_document.hcptf_apply_trust.json
|
||||
max_session_duration = 3600
|
||||
managed_policy_arns = []
|
||||
|
||||
tags = {
|
||||
Project = "afi-backup-monitor"
|
||||
|
|
@ -367,11 +381,16 @@ resource "aws_iam_role" "hcptf_apply" {
|
|||
}
|
||||
}
|
||||
|
||||
# Empty exclusive set keeps seahaven-hcptf-iam-management detached.
|
||||
resource "aws_iam_role_policy_attachments_exclusive" "hcptf_apply" {
|
||||
role_name = aws_iam_role.hcptf_apply.name
|
||||
policy_arns = []
|
||||
}
|
||||
|
||||
resource "aws_iam_role" "hcptf_plan" {
|
||||
name = "hcptf-afi-backup-monitor-plan"
|
||||
assume_role_policy = data.aws_iam_policy_document.hcptf_plan_trust.json
|
||||
max_session_duration = 3600
|
||||
managed_policy_arns = ["arn:aws:iam::aws:policy/job-function/ViewOnlyAccess"]
|
||||
|
||||
tags = {
|
||||
Project = "afi-backup-monitor"
|
||||
|
|
@ -380,6 +399,18 @@ resource "aws_iam_role" "hcptf_plan" {
|
|||
}
|
||||
}
|
||||
|
||||
resource "aws_iam_role_policy_attachment" "hcptf_plan_viewonly" {
|
||||
role = aws_iam_role.hcptf_plan.name
|
||||
policy_arn = "arn:aws:iam::aws:policy/job-function/ViewOnlyAccess"
|
||||
}
|
||||
|
||||
resource "aws_iam_role_policy_attachments_exclusive" "hcptf_plan" {
|
||||
role_name = aws_iam_role.hcptf_plan.name
|
||||
policy_arns = [
|
||||
aws_iam_role_policy_attachment.hcptf_plan_viewonly.policy_arn,
|
||||
]
|
||||
}
|
||||
|
||||
resource "aws_iam_role_policy" "hcptf_scoped_iam" {
|
||||
name = "scoped-iam-management"
|
||||
role = aws_iam_role.hcptf_apply.id
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue