mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 06:53:17 +00:00
fix(iam): allow API GW and ESM tagging for procurement-ingest
Provider default_tags need apigateway /tags/* and unconditioned ESM TagResource after import-in-place.
This commit is contained in:
parent
33a1ab9ba6
commit
202103041c
1 changed files with 6 additions and 2 deletions
|
|
@ -1180,6 +1180,10 @@ Resources:
|
|||
Action:
|
||||
- lambda:GetEventSourceMapping
|
||||
- lambda:ListTags
|
||||
# Tag/Untag on ESM UUID ARNs do not carry FunctionArn in the
|
||||
# request context (provider default_tags on import).
|
||||
- lambda:TagResource
|
||||
- lambda:UntagResource
|
||||
Resource: "*"
|
||||
- Sid: LambdaEventSourceMappings
|
||||
Effect: Allow
|
||||
|
|
@ -1187,8 +1191,6 @@ Resources:
|
|||
- lambda:CreateEventSourceMapping
|
||||
- lambda:DeleteEventSourceMapping
|
||||
- lambda:UpdateEventSourceMapping
|
||||
- lambda:TagResource
|
||||
- lambda:UntagResource
|
||||
Resource: "*"
|
||||
Condition:
|
||||
"ForAnyValue:StringLike":
|
||||
|
|
@ -1308,6 +1310,8 @@ Resources:
|
|||
- !Sub "arn:aws:apigateway:us-east-1::/restapis/mvul1efda2/*"
|
||||
- arn:aws:apigateway:us-east-1::/domainnames/procurement-api.seahaven.com
|
||||
- arn:aws:apigateway:us-east-1::/domainnames/procurement-api.seahaven.com/*
|
||||
# TagResource/UntagResource authorize against /tags/<arn>.
|
||||
- arn:aws:apigateway:us-east-1::/tags/*
|
||||
- Sid: SesReceiptRules
|
||||
Effect: Allow
|
||||
Action:
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue