mirror of
https://github.com/Sea-Haven-Industries/meal-order-manager.git
synced 2026-10-01 14:03:11 +00:00
fix(iam): move hcptf apply grants off the 10KB inline quota
This commit is contained in:
parent
424b1ce1ac
commit
cf9867adf7
2 changed files with 41 additions and 33 deletions
|
|
@ -24,11 +24,6 @@ import {
|
|||
id = "hcptf-meal-order-manager-plan"
|
||||
}
|
||||
|
||||
import {
|
||||
to = aws_iam_role_policy.hcptf_apply_services
|
||||
id = "hcptf-meal-order-manager:meal-order-manager-services"
|
||||
}
|
||||
|
||||
import {
|
||||
to = aws_iam_role_policy.hcptf_plan_refresh
|
||||
id = "hcptf-meal-order-manager-plan:meal-order-manager-plan-refresh"
|
||||
|
|
@ -319,33 +314,12 @@ data "aws_iam_policy_document" "hcptf_scoped_iam" {
|
|||
}
|
||||
}
|
||||
|
||||
resource "aws_iam_role_policy" "hcptf_apply_services" {
|
||||
name = "meal-order-manager-services"
|
||||
role = aws_iam_role.hcptf_apply.id
|
||||
resource "aws_iam_policy" "hcptf_apply_compute" {
|
||||
name = "meal-order-manager-apply-compute"
|
||||
path = "/tf-managed/"
|
||||
policy = jsonencode({
|
||||
Version = "2012-10-17"
|
||||
Statement = [
|
||||
{
|
||||
Action = [
|
||||
"lambda:*",
|
||||
]
|
||||
Resource = [
|
||||
"arn:aws:lambda:us-east-1:${local.account_id}:function:meal-order-manager-*",
|
||||
"arn:aws:lambda:us-east-1:${local.account_id}:layer:meal-order-manager-*",
|
||||
]
|
||||
Effect = "Allow"
|
||||
Sid = "LambdaAll"
|
||||
},
|
||||
{
|
||||
Action = [
|
||||
"lambda:ListFunctions",
|
||||
"lambda:ListLayers",
|
||||
"lambda:GetAccountSettings",
|
||||
]
|
||||
Resource = "*"
|
||||
Effect = "Allow"
|
||||
Sid = "LambdaList"
|
||||
},
|
||||
{
|
||||
Action = [
|
||||
"ecs:*",
|
||||
|
|
@ -462,6 +436,37 @@ resource "aws_iam_role_policy" "hcptf_apply_services" {
|
|||
Effect = "Allow"
|
||||
Sid = "SchedulerAccount"
|
||||
},
|
||||
]
|
||||
})
|
||||
}
|
||||
|
||||
resource "aws_iam_policy" "hcptf_apply_services" {
|
||||
name = "meal-order-manager-apply-services"
|
||||
path = "/tf-managed/"
|
||||
policy = jsonencode({
|
||||
Version = "2012-10-17"
|
||||
Statement = [
|
||||
{
|
||||
Action = [
|
||||
"lambda:*",
|
||||
]
|
||||
Resource = [
|
||||
"arn:aws:lambda:us-east-1:${local.account_id}:function:meal-order-manager-*",
|
||||
"arn:aws:lambda:us-east-1:${local.account_id}:layer:meal-order-manager-*",
|
||||
]
|
||||
Effect = "Allow"
|
||||
Sid = "LambdaAll"
|
||||
},
|
||||
{
|
||||
Action = [
|
||||
"lambda:ListFunctions",
|
||||
"lambda:ListLayers",
|
||||
"lambda:GetAccountSettings",
|
||||
]
|
||||
Resource = "*"
|
||||
Effect = "Allow"
|
||||
Sid = "LambdaList"
|
||||
},
|
||||
{
|
||||
Action = [
|
||||
"events:*",
|
||||
|
|
@ -1037,10 +1042,13 @@ resource "aws_iam_role" "hcptf_apply" {
|
|||
}
|
||||
}
|
||||
|
||||
# Empty exclusive set keeps seahaven-hcptf-iam-management detached.
|
||||
# Exclusive set keeps seahaven-hcptf-iam-management detached.
|
||||
resource "aws_iam_role_policy_attachments_exclusive" "hcptf_apply" {
|
||||
role_name = aws_iam_role.hcptf_apply.name
|
||||
policy_arns = []
|
||||
role_name = aws_iam_role.hcptf_apply.name
|
||||
policy_arns = [
|
||||
aws_iam_policy.hcptf_apply_services.arn,
|
||||
aws_iam_policy.hcptf_apply_compute.arn,
|
||||
]
|
||||
}
|
||||
|
||||
resource "aws_iam_role" "hcptf_plan" {
|
||||
|
|
|
|||
|
|
@ -13,7 +13,7 @@ resource "aws_vpc" "this" {
|
|||
|
||||
# First apply updates the live hcptf apply role before CreateVpc.
|
||||
depends_on = [
|
||||
aws_iam_role_policy.hcptf_apply_services,
|
||||
aws_iam_role_policy_attachments_exclusive.hcptf_apply,
|
||||
aws_iam_role_policy.hcptf_apply_ec2,
|
||||
]
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue