mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-10-01 20:13:20 +00:00
fix(iam): grant frontend HCP plan named SSM describe and tag reads (PLAT-212)
This commit is contained in:
parent
707d795b47
commit
0857174b6d
2 changed files with 20 additions and 11 deletions
|
|
@ -476,7 +476,8 @@ policies. Live apply roles may `UpdateAssumeRolePolicy` only on the matching
|
|||
`githubdeploy-shoc-frontend-new-<env>` role. `DenySecretAccess` still denies
|
||||
Secrets Manager and KMS decrypt; SSM GetParameter/GetParameters/GetParametersByPath
|
||||
are denied except `/shoc-frontend-new/<env>/deploy/*`, which plan and apply
|
||||
may read by named GetParameter/GetParameters/DescribeParameters. `UpdateDistribution` is allowed on the exact pinned distribution ARN.
|
||||
may read by named GetParameter/GetParameters/ListTagsForResource. DescribeParameters
|
||||
is a collection API, so it is named on `*` (not `ssm:Get*`). `UpdateDistribution` is allowed on the exact pinned distribution ARN.
|
||||
`CreateInvalidation` and `GetInvalidation` are allowed on that same ARN so the
|
||||
Terraform invalidation action can run. `GetObject`/`GetObjectTagging`/`PutObject`/`PutObjectTagging` on
|
||||
`.release/current` lets Terraform own the release pointer, including the
|
||||
|
|
|
|||
|
|
@ -236,16 +236,24 @@ const frontendReadPolicy = (
|
|||
},
|
||||
];
|
||||
if (isLiveFrontendEnvironment(environment)) {
|
||||
statements.push({
|
||||
Sid: `Read${environmentSid(environment)}DeploySsm`,
|
||||
Effect: "Allow",
|
||||
Action: [
|
||||
"ssm:GetParameter",
|
||||
"ssm:GetParameters",
|
||||
"ssm:DescribeParameters",
|
||||
],
|
||||
Resource: deployParameterArn(environment),
|
||||
});
|
||||
statements.push(
|
||||
{
|
||||
Sid: `Read${environmentSid(environment)}DeploySsm`,
|
||||
Effect: "Allow",
|
||||
Action: [
|
||||
"ssm:GetParameter",
|
||||
"ssm:GetParameters",
|
||||
"ssm:ListTagsForResource",
|
||||
],
|
||||
Resource: deployParameterArn(environment),
|
||||
},
|
||||
{
|
||||
Sid: `Describe${environmentSid(environment)}DeploySsm`,
|
||||
Effect: "Allow",
|
||||
Action: "ssm:DescribeParameters",
|
||||
Resource: "*",
|
||||
},
|
||||
);
|
||||
}
|
||||
return {
|
||||
Version: "2012-10-17",
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue