diff --git a/README.md b/README.md index 17ba359..7fe0ccd 100644 --- a/README.md +++ b/README.md @@ -476,7 +476,8 @@ policies. Live apply roles may `UpdateAssumeRolePolicy` only on the matching `githubdeploy-shoc-frontend-new-` role. `DenySecretAccess` still denies Secrets Manager and KMS decrypt; SSM GetParameter/GetParameters/GetParametersByPath are denied except `/shoc-frontend-new//deploy/*`, which plan and apply -may read by named GetParameter/GetParameters/DescribeParameters. `UpdateDistribution` is allowed on the exact pinned distribution ARN. +may read by named GetParameter/GetParameters/ListTagsForResource. DescribeParameters +is a collection API, so it is named on `*` (not `ssm:Get*`). `UpdateDistribution` is allowed on the exact pinned distribution ARN. `CreateInvalidation` and `GetInvalidation` are allowed on that same ARN so the Terraform invalidation action can run. `GetObject`/`GetObjectTagging`/`PutObject`/`PutObjectTagging` on `.release/current` lets Terraform own the release pointer, including the diff --git a/lib/terraform-substrate/shoc-frontend-resources.ts b/lib/terraform-substrate/shoc-frontend-resources.ts index 6b826d8..8fca5ac 100644 --- a/lib/terraform-substrate/shoc-frontend-resources.ts +++ b/lib/terraform-substrate/shoc-frontend-resources.ts @@ -236,16 +236,24 @@ const frontendReadPolicy = ( }, ]; if (isLiveFrontendEnvironment(environment)) { - statements.push({ - Sid: `Read${environmentSid(environment)}DeploySsm`, - Effect: "Allow", - Action: [ - "ssm:GetParameter", - "ssm:GetParameters", - "ssm:DescribeParameters", - ], - Resource: deployParameterArn(environment), - }); + statements.push( + { + Sid: `Read${environmentSid(environment)}DeploySsm`, + Effect: "Allow", + Action: [ + "ssm:GetParameter", + "ssm:GetParameters", + "ssm:ListTagsForResource", + ], + Resource: deployParameterArn(environment), + }, + { + Sid: `Describe${environmentSid(environment)}DeploySsm`, + Effect: "Allow", + Action: "ssm:DescribeParameters", + Resource: "*", + }, + ); } return { Version: "2012-10-17",