mirror of
https://github.com/Sea-Haven-Industries/procurement-ingest.git
synced 2026-09-30 08:23:14 +00:00
fix(iam): attach scoped IAM as a managed policy (PLAT-146)
The apply role's services inline already uses 6894 of 10240 bytes, so a second inline policy cannot hold scoped IAM.
This commit is contained in:
parent
e72873409e
commit
fa6bcc90cc
1 changed files with 22 additions and 7 deletions
|
|
@ -8,7 +8,7 @@
|
|||
# 2. Point this workspace's TFC_AWS_* at hcptf-bootstrap /
|
||||
# hcptf-bootstrap-plan (workspace vars, never a project set).
|
||||
# 3. One Manual apply (import + detach seahaven-hcptf-iam-management +
|
||||
# put scoped inline).
|
||||
# put scoped IAM as a customer-managed policy).
|
||||
# 4. Point TFC_AWS_* back at hcptf-procurement-ingest / hcptf-procurement-ingest-plan.
|
||||
# 5. Re-run the script without --allow-workspace to pin trust back to
|
||||
# iam-bootstrap-prod only.
|
||||
|
|
@ -821,10 +821,14 @@ resource "aws_iam_role" "hcptf_apply" {
|
|||
}
|
||||
}
|
||||
|
||||
# Empty exclusive set keeps seahaven-hcptf-iam-management detached.
|
||||
# Services inline is 6894 bytes; a second inline for scoped IAM exceeds the
|
||||
# 10240 role quota. Attach scoped IAM as a customer-managed policy instead.
|
||||
# Exclusive set keeps seahaven-hcptf-iam-management detached.
|
||||
resource "aws_iam_role_policy_attachments_exclusive" "hcptf_apply" {
|
||||
role_name = aws_iam_role.hcptf_apply.name
|
||||
policy_arns = []
|
||||
role_name = aws_iam_role.hcptf_apply.name
|
||||
policy_arns = [
|
||||
aws_iam_policy.hcptf_scoped_iam.arn,
|
||||
]
|
||||
}
|
||||
|
||||
resource "aws_iam_role" "hcptf_plan" {
|
||||
|
|
@ -851,8 +855,19 @@ resource "aws_iam_role_policy_attachments_exclusive" "hcptf_plan" {
|
|||
]
|
||||
}
|
||||
|
||||
resource "aws_iam_role_policy" "hcptf_scoped_iam" {
|
||||
name = "scoped-iam-management"
|
||||
role = aws_iam_role.hcptf_apply.id
|
||||
resource "aws_iam_policy" "hcptf_scoped_iam" {
|
||||
name = "hcptf-procurement-ingest-scoped-iam"
|
||||
path = "/tf-managed/"
|
||||
policy = data.aws_iam_policy_document.hcptf_scoped_iam.json
|
||||
|
||||
tags = {
|
||||
Project = "procurement-ingest"
|
||||
Owner = "adam@seahavenind.com"
|
||||
ManagedBy = "terraform"
|
||||
}
|
||||
}
|
||||
|
||||
resource "aws_iam_role_policy_attachment" "hcptf_scoped_iam" {
|
||||
role = aws_iam_role.hcptf_apply.name
|
||||
policy_arn = aws_iam_policy.hcptf_scoped_iam.arn
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue