From 8eb19b4e551c537c5907d6efe1da6dfd43164024 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Tue, 29 Sep 2026 19:28:05 -0400 Subject: [PATCH] fix(terraform): let the plan role read object tags and retention The S3 provider refreshes tagging, ACL, attributes, and Object Lock on the Lambda zip. --- terraform/hcp_iam.tf | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/terraform/hcp_iam.tf b/terraform/hcp_iam.tf index f2e8ee5..409d437 100644 --- a/terraform/hcp_iam.tf +++ b/terraform/hcp_iam.tf @@ -606,6 +606,11 @@ data "aws_iam_policy_document" "hcptf_plan_refresh" { "s3:GetEncryptionConfiguration", "s3:GetLifecycleConfiguration", "s3:GetObject", + "s3:GetObjectAcl", + "s3:GetObjectAttributes", + "s3:GetObjectLegalHold", + "s3:GetObjectRetention", + "s3:GetObjectTagging", "s3:GetReplicationConfiguration", "s3:ListBucket", ]