fix(terraform): let the plan role read object tags and retention

The S3 provider refreshes tagging, ACL, attributes, and Object Lock on the Lambda zip.
This commit is contained in:
Adam Moussa 2026-09-29 19:28:05 -04:00
parent 566a669c7b
commit 8eb19b4e55
No known key found for this signature in database

View file

@ -606,6 +606,11 @@ data "aws_iam_policy_document" "hcptf_plan_refresh" {
"s3:GetEncryptionConfiguration",
"s3:GetLifecycleConfiguration",
"s3:GetObject",
"s3:GetObjectAcl",
"s3:GetObjectAttributes",
"s3:GetObjectLegalHold",
"s3:GetObjectRetention",
"s3:GetObjectTagging",
"s3:GetReplicationConfiguration",
"s3:ListBucket",
]