mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-10-06 22:41:58 +00:00
fix(iam): grant frontend HCP plan named SSM describe and tag reads (PLAT-212)
This commit is contained in:
parent
707d795b47
commit
0857174b6d
2 changed files with 20 additions and 11 deletions
|
|
@ -476,7 +476,8 @@ policies. Live apply roles may `UpdateAssumeRolePolicy` only on the matching
|
||||||
`githubdeploy-shoc-frontend-new-<env>` role. `DenySecretAccess` still denies
|
`githubdeploy-shoc-frontend-new-<env>` role. `DenySecretAccess` still denies
|
||||||
Secrets Manager and KMS decrypt; SSM GetParameter/GetParameters/GetParametersByPath
|
Secrets Manager and KMS decrypt; SSM GetParameter/GetParameters/GetParametersByPath
|
||||||
are denied except `/shoc-frontend-new/<env>/deploy/*`, which plan and apply
|
are denied except `/shoc-frontend-new/<env>/deploy/*`, which plan and apply
|
||||||
may read by named GetParameter/GetParameters/DescribeParameters. `UpdateDistribution` is allowed on the exact pinned distribution ARN.
|
may read by named GetParameter/GetParameters/ListTagsForResource. DescribeParameters
|
||||||
|
is a collection API, so it is named on `*` (not `ssm:Get*`). `UpdateDistribution` is allowed on the exact pinned distribution ARN.
|
||||||
`CreateInvalidation` and `GetInvalidation` are allowed on that same ARN so the
|
`CreateInvalidation` and `GetInvalidation` are allowed on that same ARN so the
|
||||||
Terraform invalidation action can run. `GetObject`/`GetObjectTagging`/`PutObject`/`PutObjectTagging` on
|
Terraform invalidation action can run. `GetObject`/`GetObjectTagging`/`PutObject`/`PutObjectTagging` on
|
||||||
`.release/current` lets Terraform own the release pointer, including the
|
`.release/current` lets Terraform own the release pointer, including the
|
||||||
|
|
|
||||||
|
|
@ -236,16 +236,24 @@ const frontendReadPolicy = (
|
||||||
},
|
},
|
||||||
];
|
];
|
||||||
if (isLiveFrontendEnvironment(environment)) {
|
if (isLiveFrontendEnvironment(environment)) {
|
||||||
statements.push({
|
statements.push(
|
||||||
Sid: `Read${environmentSid(environment)}DeploySsm`,
|
{
|
||||||
Effect: "Allow",
|
Sid: `Read${environmentSid(environment)}DeploySsm`,
|
||||||
Action: [
|
Effect: "Allow",
|
||||||
"ssm:GetParameter",
|
Action: [
|
||||||
"ssm:GetParameters",
|
"ssm:GetParameter",
|
||||||
"ssm:DescribeParameters",
|
"ssm:GetParameters",
|
||||||
],
|
"ssm:ListTagsForResource",
|
||||||
Resource: deployParameterArn(environment),
|
],
|
||||||
});
|
Resource: deployParameterArn(environment),
|
||||||
|
},
|
||||||
|
{
|
||||||
|
Sid: `Describe${environmentSid(environment)}DeploySsm`,
|
||||||
|
Effect: "Allow",
|
||||||
|
Action: "ssm:DescribeParameters",
|
||||||
|
Resource: "*",
|
||||||
|
},
|
||||||
|
);
|
||||||
}
|
}
|
||||||
return {
|
return {
|
||||||
Version: "2012-10-17",
|
Version: "2012-10-17",
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue