mirror of
https://github.com/Sea-Haven-Industries/meal-order-manager.git
synced 2026-10-06 22:51:57 +00:00
fix(iam): move hcptf apply grants off the 10KB inline quota
This commit is contained in:
parent
424b1ce1ac
commit
cf9867adf7
2 changed files with 41 additions and 33 deletions
|
|
@ -24,11 +24,6 @@ import {
|
||||||
id = "hcptf-meal-order-manager-plan"
|
id = "hcptf-meal-order-manager-plan"
|
||||||
}
|
}
|
||||||
|
|
||||||
import {
|
|
||||||
to = aws_iam_role_policy.hcptf_apply_services
|
|
||||||
id = "hcptf-meal-order-manager:meal-order-manager-services"
|
|
||||||
}
|
|
||||||
|
|
||||||
import {
|
import {
|
||||||
to = aws_iam_role_policy.hcptf_plan_refresh
|
to = aws_iam_role_policy.hcptf_plan_refresh
|
||||||
id = "hcptf-meal-order-manager-plan:meal-order-manager-plan-refresh"
|
id = "hcptf-meal-order-manager-plan:meal-order-manager-plan-refresh"
|
||||||
|
|
@ -319,33 +314,12 @@ data "aws_iam_policy_document" "hcptf_scoped_iam" {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
resource "aws_iam_role_policy" "hcptf_apply_services" {
|
resource "aws_iam_policy" "hcptf_apply_compute" {
|
||||||
name = "meal-order-manager-services"
|
name = "meal-order-manager-apply-compute"
|
||||||
role = aws_iam_role.hcptf_apply.id
|
path = "/tf-managed/"
|
||||||
policy = jsonencode({
|
policy = jsonencode({
|
||||||
Version = "2012-10-17"
|
Version = "2012-10-17"
|
||||||
Statement = [
|
Statement = [
|
||||||
{
|
|
||||||
Action = [
|
|
||||||
"lambda:*",
|
|
||||||
]
|
|
||||||
Resource = [
|
|
||||||
"arn:aws:lambda:us-east-1:${local.account_id}:function:meal-order-manager-*",
|
|
||||||
"arn:aws:lambda:us-east-1:${local.account_id}:layer:meal-order-manager-*",
|
|
||||||
]
|
|
||||||
Effect = "Allow"
|
|
||||||
Sid = "LambdaAll"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
Action = [
|
|
||||||
"lambda:ListFunctions",
|
|
||||||
"lambda:ListLayers",
|
|
||||||
"lambda:GetAccountSettings",
|
|
||||||
]
|
|
||||||
Resource = "*"
|
|
||||||
Effect = "Allow"
|
|
||||||
Sid = "LambdaList"
|
|
||||||
},
|
|
||||||
{
|
{
|
||||||
Action = [
|
Action = [
|
||||||
"ecs:*",
|
"ecs:*",
|
||||||
|
|
@ -462,6 +436,37 @@ resource "aws_iam_role_policy" "hcptf_apply_services" {
|
||||||
Effect = "Allow"
|
Effect = "Allow"
|
||||||
Sid = "SchedulerAccount"
|
Sid = "SchedulerAccount"
|
||||||
},
|
},
|
||||||
|
]
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
resource "aws_iam_policy" "hcptf_apply_services" {
|
||||||
|
name = "meal-order-manager-apply-services"
|
||||||
|
path = "/tf-managed/"
|
||||||
|
policy = jsonencode({
|
||||||
|
Version = "2012-10-17"
|
||||||
|
Statement = [
|
||||||
|
{
|
||||||
|
Action = [
|
||||||
|
"lambda:*",
|
||||||
|
]
|
||||||
|
Resource = [
|
||||||
|
"arn:aws:lambda:us-east-1:${local.account_id}:function:meal-order-manager-*",
|
||||||
|
"arn:aws:lambda:us-east-1:${local.account_id}:layer:meal-order-manager-*",
|
||||||
|
]
|
||||||
|
Effect = "Allow"
|
||||||
|
Sid = "LambdaAll"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
Action = [
|
||||||
|
"lambda:ListFunctions",
|
||||||
|
"lambda:ListLayers",
|
||||||
|
"lambda:GetAccountSettings",
|
||||||
|
]
|
||||||
|
Resource = "*"
|
||||||
|
Effect = "Allow"
|
||||||
|
Sid = "LambdaList"
|
||||||
|
},
|
||||||
{
|
{
|
||||||
Action = [
|
Action = [
|
||||||
"events:*",
|
"events:*",
|
||||||
|
|
@ -1037,10 +1042,13 @@ resource "aws_iam_role" "hcptf_apply" {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
# Empty exclusive set keeps seahaven-hcptf-iam-management detached.
|
# Exclusive set keeps seahaven-hcptf-iam-management detached.
|
||||||
resource "aws_iam_role_policy_attachments_exclusive" "hcptf_apply" {
|
resource "aws_iam_role_policy_attachments_exclusive" "hcptf_apply" {
|
||||||
role_name = aws_iam_role.hcptf_apply.name
|
role_name = aws_iam_role.hcptf_apply.name
|
||||||
policy_arns = []
|
policy_arns = [
|
||||||
|
aws_iam_policy.hcptf_apply_services.arn,
|
||||||
|
aws_iam_policy.hcptf_apply_compute.arn,
|
||||||
|
]
|
||||||
}
|
}
|
||||||
|
|
||||||
resource "aws_iam_role" "hcptf_plan" {
|
resource "aws_iam_role" "hcptf_plan" {
|
||||||
|
|
|
||||||
|
|
@ -13,7 +13,7 @@ resource "aws_vpc" "this" {
|
||||||
|
|
||||||
# First apply updates the live hcptf apply role before CreateVpc.
|
# First apply updates the live hcptf apply role before CreateVpc.
|
||||||
depends_on = [
|
depends_on = [
|
||||||
aws_iam_role_policy.hcptf_apply_services,
|
aws_iam_role_policy_attachments_exclusive.hcptf_apply,
|
||||||
aws_iam_role_policy.hcptf_apply_ec2,
|
aws_iam_role_policy.hcptf_apply_ec2,
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue