fix(terraform): allow HCP refresh of the log group and parameter

The scoped apply role can create those resources, but CloudWatch and SSM list them on a wildcard ARN. DescribeLogGroups and DescribeParameters need that resource.
This commit is contained in:
Adam Moussa 2026-09-29 19:10:08 -04:00
parent e4982b87ad
commit 8360cfb1db
No known key found for this signature in database

View file

@ -437,6 +437,7 @@ data "aws_iam_policy_document" "hcptf_apply_services" {
} }
# CreateLogGroup is not reliable on the log-group ARN before the group exists. # CreateLogGroup is not reliable on the log-group ARN before the group exists.
# DescribeLogGroups is a list API. Its resource is log-group::log-stream:, not the group ARN.
statement { statement {
sid = "CreateVerificationLogGroup" sid = "CreateVerificationLogGroup"
effect = "Allow" effect = "Allow"
@ -444,6 +445,13 @@ data "aws_iam_policy_document" "hcptf_apply_services" {
resources = ["*"] resources = ["*"]
} }
statement {
sid = "DescribeVerificationLogGroups"
effect = "Allow"
actions = ["logs:DescribeLogGroups"]
resources = ["*"]
}
statement { statement {
sid = "VerificationLogs" sid = "VerificationLogs"
effect = "Allow" effect = "Allow"
@ -501,6 +509,14 @@ data "aws_iam_policy_document" "hcptf_apply_services" {
] ]
} }
# DescribeParameters does not accept a parameter ARN. The provider calls it on *.
statement {
sid = "DescribeBackupParameters"
effect = "Allow"
actions = ["ssm:DescribeParameters"]
resources = ["*"]
}
statement { statement {
sid = "AlertTopicRead" sid = "AlertTopicRead"
effect = "Allow" effect = "Allow"
@ -687,7 +703,6 @@ data "aws_iam_policy_document" "hcptf_plan_refresh" {
sid = "RefreshLogs" sid = "RefreshLogs"
effect = "Allow" effect = "Allow"
actions = [ actions = [
"logs:DescribeLogGroups",
"logs:ListTagsForResource", "logs:ListTagsForResource",
] ]
resources = [ resources = [
@ -696,6 +711,14 @@ data "aws_iam_policy_document" "hcptf_plan_refresh" {
] ]
} }
# DescribeLogGroups is a list API. Its resource is log-group::log-stream:, not the group ARN.
statement {
sid = "DescribeVerificationLogGroups"
effect = "Allow"
actions = ["logs:DescribeLogGroups"]
resources = ["*"]
}
statement { statement {
sid = "RefreshAlarms" sid = "RefreshAlarms"
effect = "Allow" effect = "Allow"
@ -718,6 +741,13 @@ data "aws_iam_policy_document" "hcptf_plan_refresh" {
] ]
} }
statement {
sid = "DescribeBackupParameters"
effect = "Allow"
actions = ["ssm:DescribeParameters"]
resources = ["*"]
}
statement { statement {
sid = "RefreshSnapshots" sid = "RefreshSnapshots"
effect = "Allow" effect = "Allow"