mirror of
https://github.com/Sea-Haven-Industries/forgejo.git
synced 2026-09-30 17:53:10 +00:00
fix(terraform): let the plan role read backup object metadata
HeadObject on the Lambda zip is s3:GetObject. The plan role only had the bucket ARNs.
This commit is contained in:
parent
d511861296
commit
566a669c7b
1 changed files with 4 additions and 0 deletions
|
|
@ -605,13 +605,17 @@ data "aws_iam_policy_document" "hcptf_plan_refresh" {
|
|||
"s3:GetBucketWebsite",
|
||||
"s3:GetEncryptionConfiguration",
|
||||
"s3:GetLifecycleConfiguration",
|
||||
"s3:GetObject",
|
||||
"s3:GetReplicationConfiguration",
|
||||
"s3:ListBucket",
|
||||
]
|
||||
resources = [
|
||||
"arn:aws:s3:::${local.backup_bucket_name}",
|
||||
"arn:aws:s3:::${local.backup_bucket_name}/*",
|
||||
"arn:aws:s3:::${local.replica_bucket_name}",
|
||||
"arn:aws:s3:::${local.replica_bucket_name}/*",
|
||||
"arn:aws:s3:::${local.artifacts_bucket_name}",
|
||||
"arn:aws:s3:::${local.artifacts_bucket_name}/*",
|
||||
]
|
||||
}
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue