fix(terraform): let the plan role read backup object metadata

HeadObject on the Lambda zip is s3:GetObject. The plan role only had the bucket ARNs.
This commit is contained in:
Adam Moussa 2026-09-29 19:25:14 -04:00
parent d511861296
commit 566a669c7b
No known key found for this signature in database

View file

@ -605,13 +605,17 @@ data "aws_iam_policy_document" "hcptf_plan_refresh" {
"s3:GetBucketWebsite",
"s3:GetEncryptionConfiguration",
"s3:GetLifecycleConfiguration",
"s3:GetObject",
"s3:GetReplicationConfiguration",
"s3:ListBucket",
]
resources = [
"arn:aws:s3:::${local.backup_bucket_name}",
"arn:aws:s3:::${local.backup_bucket_name}/*",
"arn:aws:s3:::${local.replica_bucket_name}",
"arn:aws:s3:::${local.replica_bucket_name}/*",
"arn:aws:s3:::${local.artifacts_bucket_name}",
"arn:aws:s3:::${local.artifacts_bucket_name}/*",
]
}