From 566a669c7b07e883e0ed3bf990b42e522ab1ec52 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Tue, 29 Sep 2026 19:25:14 -0400 Subject: [PATCH] fix(terraform): let the plan role read backup object metadata HeadObject on the Lambda zip is s3:GetObject. The plan role only had the bucket ARNs. --- terraform/hcp_iam.tf | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/terraform/hcp_iam.tf b/terraform/hcp_iam.tf index ceb87b6..f2e8ee5 100644 --- a/terraform/hcp_iam.tf +++ b/terraform/hcp_iam.tf @@ -605,13 +605,17 @@ data "aws_iam_policy_document" "hcptf_plan_refresh" { "s3:GetBucketWebsite", "s3:GetEncryptionConfiguration", "s3:GetLifecycleConfiguration", + "s3:GetObject", "s3:GetReplicationConfiguration", "s3:ListBucket", ] resources = [ "arn:aws:s3:::${local.backup_bucket_name}", + "arn:aws:s3:::${local.backup_bucket_name}/*", "arn:aws:s3:::${local.replica_bucket_name}", + "arn:aws:s3:::${local.replica_bucket_name}/*", "arn:aws:s3:::${local.artifacts_bucket_name}", + "arn:aws:s3:::${local.artifacts_bucket_name}/*", ] }