mirror of
https://github.com/Sea-Haven-Industries/forgejo.git
synced 2026-09-30 06:33:11 +00:00
fix(terraform): allow HCP refresh of the log group and parameter
The scoped apply role can create those resources, but CloudWatch and SSM list them on a wildcard ARN. DescribeLogGroups and DescribeParameters need that resource.
This commit is contained in:
parent
e4982b87ad
commit
8360cfb1db
1 changed files with 31 additions and 1 deletions
|
|
@ -437,6 +437,7 @@ data "aws_iam_policy_document" "hcptf_apply_services" {
|
||||||
}
|
}
|
||||||
|
|
||||||
# CreateLogGroup is not reliable on the log-group ARN before the group exists.
|
# CreateLogGroup is not reliable on the log-group ARN before the group exists.
|
||||||
|
# DescribeLogGroups is a list API. Its resource is log-group::log-stream:, not the group ARN.
|
||||||
statement {
|
statement {
|
||||||
sid = "CreateVerificationLogGroup"
|
sid = "CreateVerificationLogGroup"
|
||||||
effect = "Allow"
|
effect = "Allow"
|
||||||
|
|
@ -444,6 +445,13 @@ data "aws_iam_policy_document" "hcptf_apply_services" {
|
||||||
resources = ["*"]
|
resources = ["*"]
|
||||||
}
|
}
|
||||||
|
|
||||||
|
statement {
|
||||||
|
sid = "DescribeVerificationLogGroups"
|
||||||
|
effect = "Allow"
|
||||||
|
actions = ["logs:DescribeLogGroups"]
|
||||||
|
resources = ["*"]
|
||||||
|
}
|
||||||
|
|
||||||
statement {
|
statement {
|
||||||
sid = "VerificationLogs"
|
sid = "VerificationLogs"
|
||||||
effect = "Allow"
|
effect = "Allow"
|
||||||
|
|
@ -501,6 +509,14 @@ data "aws_iam_policy_document" "hcptf_apply_services" {
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# DescribeParameters does not accept a parameter ARN. The provider calls it on *.
|
||||||
|
statement {
|
||||||
|
sid = "DescribeBackupParameters"
|
||||||
|
effect = "Allow"
|
||||||
|
actions = ["ssm:DescribeParameters"]
|
||||||
|
resources = ["*"]
|
||||||
|
}
|
||||||
|
|
||||||
statement {
|
statement {
|
||||||
sid = "AlertTopicRead"
|
sid = "AlertTopicRead"
|
||||||
effect = "Allow"
|
effect = "Allow"
|
||||||
|
|
@ -687,7 +703,6 @@ data "aws_iam_policy_document" "hcptf_plan_refresh" {
|
||||||
sid = "RefreshLogs"
|
sid = "RefreshLogs"
|
||||||
effect = "Allow"
|
effect = "Allow"
|
||||||
actions = [
|
actions = [
|
||||||
"logs:DescribeLogGroups",
|
|
||||||
"logs:ListTagsForResource",
|
"logs:ListTagsForResource",
|
||||||
]
|
]
|
||||||
resources = [
|
resources = [
|
||||||
|
|
@ -696,6 +711,14 @@ data "aws_iam_policy_document" "hcptf_plan_refresh" {
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# DescribeLogGroups is a list API. Its resource is log-group::log-stream:, not the group ARN.
|
||||||
|
statement {
|
||||||
|
sid = "DescribeVerificationLogGroups"
|
||||||
|
effect = "Allow"
|
||||||
|
actions = ["logs:DescribeLogGroups"]
|
||||||
|
resources = ["*"]
|
||||||
|
}
|
||||||
|
|
||||||
statement {
|
statement {
|
||||||
sid = "RefreshAlarms"
|
sid = "RefreshAlarms"
|
||||||
effect = "Allow"
|
effect = "Allow"
|
||||||
|
|
@ -718,6 +741,13 @@ data "aws_iam_policy_document" "hcptf_plan_refresh" {
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|
||||||
|
statement {
|
||||||
|
sid = "DescribeBackupParameters"
|
||||||
|
effect = "Allow"
|
||||||
|
actions = ["ssm:DescribeParameters"]
|
||||||
|
resources = ["*"]
|
||||||
|
}
|
||||||
|
|
||||||
statement {
|
statement {
|
||||||
sid = "RefreshSnapshots"
|
sid = "RefreshSnapshots"
|
||||||
effect = "Allow"
|
effect = "Allow"
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue