diff --git a/terraform/hcp_iam.tf b/terraform/hcp_iam.tf index 96ffb17..fb35358 100644 --- a/terraform/hcp_iam.tf +++ b/terraform/hcp_iam.tf @@ -462,48 +462,6 @@ resource "aws_iam_role_policy" "hcptf_apply_services" { Effect = "Allow" Sid = "SchedulerAccount" }, - { - Action = [ - "ec2:AssociateRouteTable", - "ec2:AttachInternetGateway", - "ec2:AuthorizeSecurityGroupEgress", - "ec2:AuthorizeSecurityGroupIngress", - "ec2:CreateInternetGateway", - "ec2:CreateRoute", - "ec2:CreateRouteTable", - "ec2:CreateSecurityGroup", - "ec2:CreateSubnet", - "ec2:CreateTags", - "ec2:CreateVpc", - "ec2:DeleteInternetGateway", - "ec2:DeleteRoute", - "ec2:DeleteRouteTable", - "ec2:DeleteSecurityGroup", - "ec2:DeleteSubnet", - "ec2:DeleteTags", - "ec2:DeleteVpc", - "ec2:DescribeAccountAttributes", - "ec2:DescribeAvailabilityZones", - "ec2:DescribeInternetGateways", - "ec2:DescribeNetworkInterfaces", - "ec2:DescribeRouteTables", - "ec2:DescribeSecurityGroupRules", - "ec2:DescribeSecurityGroups", - "ec2:DescribeSubnets", - "ec2:DescribeTags", - "ec2:DescribeVpcAttribute", - "ec2:DescribeVpcs", - "ec2:DetachInternetGateway", - "ec2:DisassociateRouteTable", - "ec2:ModifySubnetAttribute", - "ec2:ModifyVpcAttribute", - "ec2:RevokeSecurityGroupEgress", - "ec2:RevokeSecurityGroupIngress", - ] - Resource = "*" - Effect = "Allow" - Sid = "Ec2VpcManagement" - }, { Action = [ "events:*", @@ -754,6 +712,58 @@ resource "aws_iam_role_policy" "hcptf_apply_services" { }) } +resource "aws_iam_role_policy" "hcptf_apply_ec2" { + name = "meal-order-manager-ec2" + role = aws_iam_role.hcptf_apply.id + policy = jsonencode({ + Version = "2012-10-17" + Statement = [ + { + Action = [ + "ec2:AssociateRouteTable", + "ec2:AttachInternetGateway", + "ec2:AuthorizeSecurityGroupEgress", + "ec2:AuthorizeSecurityGroupIngress", + "ec2:CreateInternetGateway", + "ec2:CreateRoute", + "ec2:CreateRouteTable", + "ec2:CreateSecurityGroup", + "ec2:CreateSubnet", + "ec2:CreateTags", + "ec2:CreateVpc", + "ec2:DeleteInternetGateway", + "ec2:DeleteRoute", + "ec2:DeleteRouteTable", + "ec2:DeleteSecurityGroup", + "ec2:DeleteSubnet", + "ec2:DeleteTags", + "ec2:DeleteVpc", + "ec2:DescribeAccountAttributes", + "ec2:DescribeAvailabilityZones", + "ec2:DescribeInternetGateways", + "ec2:DescribeNetworkInterfaces", + "ec2:DescribeRouteTables", + "ec2:DescribeSecurityGroupRules", + "ec2:DescribeSecurityGroups", + "ec2:DescribeSubnets", + "ec2:DescribeTags", + "ec2:DescribeVpcAttribute", + "ec2:DescribeVpcs", + "ec2:DetachInternetGateway", + "ec2:DisassociateRouteTable", + "ec2:ModifySubnetAttribute", + "ec2:ModifyVpcAttribute", + "ec2:RevokeSecurityGroupEgress", + "ec2:RevokeSecurityGroupIngress", + ] + Resource = "*" + Effect = "Allow" + Sid = "Ec2VpcManagement" + }, + ] + }) +} + resource "aws_iam_role_policy" "hcptf_plan_refresh" { name = "meal-order-manager-plan-refresh" role = aws_iam_role.hcptf_plan.id diff --git a/terraform/vpc.tf b/terraform/vpc.tf index 1a8e625..d1961c5 100644 --- a/terraform/vpc.tf +++ b/terraform/vpc.tf @@ -12,7 +12,10 @@ resource "aws_vpc" "this" { } # First apply updates the live hcptf apply role before CreateVpc. - depends_on = [aws_iam_role_policy.hcptf_apply_services] + depends_on = [ + aws_iam_role_policy.hcptf_apply_services, + aws_iam_role_policy.hcptf_apply_ec2, + ] } resource "aws_internet_gateway" "this" {