fix(iam): split EC2 grants so the hcptf apply policy fits (#200)

This commit is contained in:
Adam Moussa 2026-09-21 19:48:09 +00:00 • committed by GitHub
parent f48a82c476
commit 424b1ce1ac
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 56 additions and 43 deletions

View file

@ -462,48 +462,6 @@ resource "aws_iam_role_policy" "hcptf_apply_services" {
Effect = "Allow"
Sid = "SchedulerAccount"
},
{
Action = [
"ec2:AssociateRouteTable",
"ec2:AttachInternetGateway",
"ec2:AuthorizeSecurityGroupEgress",
"ec2:AuthorizeSecurityGroupIngress",
"ec2:CreateInternetGateway",
"ec2:CreateRoute",
"ec2:CreateRouteTable",
"ec2:CreateSecurityGroup",
"ec2:CreateSubnet",
"ec2:CreateTags",
"ec2:CreateVpc",
"ec2:DeleteInternetGateway",
"ec2:DeleteRoute",
"ec2:DeleteRouteTable",
"ec2:DeleteSecurityGroup",
"ec2:DeleteSubnet",
"ec2:DeleteTags",
"ec2:DeleteVpc",
"ec2:DescribeAccountAttributes",
"ec2:DescribeAvailabilityZones",
"ec2:DescribeInternetGateways",
"ec2:DescribeNetworkInterfaces",
"ec2:DescribeRouteTables",
"ec2:DescribeSecurityGroupRules",
"ec2:DescribeSecurityGroups",
"ec2:DescribeSubnets",
"ec2:DescribeTags",
"ec2:DescribeVpcAttribute",
"ec2:DescribeVpcs",
"ec2:DetachInternetGateway",
"ec2:DisassociateRouteTable",
"ec2:ModifySubnetAttribute",
"ec2:ModifyVpcAttribute",
"ec2:RevokeSecurityGroupEgress",
"ec2:RevokeSecurityGroupIngress",
]
Resource = "*"
Effect = "Allow"
Sid = "Ec2VpcManagement"
},
{
Action = [
"events:*",
@ -754,6 +712,58 @@ resource "aws_iam_role_policy" "hcptf_apply_services" {
})
}
resource "aws_iam_role_policy" "hcptf_apply_ec2" {
name = "meal-order-manager-ec2"
role = aws_iam_role.hcptf_apply.id
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"ec2:AssociateRouteTable",
"ec2:AttachInternetGateway",
"ec2:AuthorizeSecurityGroupEgress",
"ec2:AuthorizeSecurityGroupIngress",
"ec2:CreateInternetGateway",
"ec2:CreateRoute",
"ec2:CreateRouteTable",
"ec2:CreateSecurityGroup",
"ec2:CreateSubnet",
"ec2:CreateTags",
"ec2:CreateVpc",
"ec2:DeleteInternetGateway",
"ec2:DeleteRoute",
"ec2:DeleteRouteTable",
"ec2:DeleteSecurityGroup",
"ec2:DeleteSubnet",
"ec2:DeleteTags",
"ec2:DeleteVpc",
"ec2:DescribeAccountAttributes",
"ec2:DescribeAvailabilityZones",
"ec2:DescribeInternetGateways",
"ec2:DescribeNetworkInterfaces",
"ec2:DescribeRouteTables",
"ec2:DescribeSecurityGroupRules",
"ec2:DescribeSecurityGroups",
"ec2:DescribeSubnets",
"ec2:DescribeTags",
"ec2:DescribeVpcAttribute",
"ec2:DescribeVpcs",
"ec2:DetachInternetGateway",
"ec2:DisassociateRouteTable",
"ec2:ModifySubnetAttribute",
"ec2:ModifyVpcAttribute",
"ec2:RevokeSecurityGroupEgress",
"ec2:RevokeSecurityGroupIngress",
]
Resource = "*"
Effect = "Allow"
Sid = "Ec2VpcManagement"
},
]
})
}
resource "aws_iam_role_policy" "hcptf_plan_refresh" {
name = "meal-order-manager-plan-refresh"
role = aws_iam_role.hcptf_plan.id

View file

@ -12,7 +12,10 @@ resource "aws_vpc" "this" {
}
# First apply updates the live hcptf apply role before CreateVpc.
depends_on = [aws_iam_role_policy.hcptf_apply_services]
depends_on = [
aws_iam_role_policy.hcptf_apply_services,
aws_iam_role_policy.hcptf_apply_ec2,
]
}
resource "aws_internet_gateway" "this" {