Merge pull request #78 from Sea-Haven-Industries/fix/hcptf-afi-provider-read-actions
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run

fix(iam): use lambda:* and events:* on afi hcptf apply scope (PLAT-56)
This commit is contained in:
Adam Moussa 2026-08-05 12:59:34 -04:00 • committed by GitHub
commit 2c5c644a5e
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -433,12 +433,7 @@ Resources:
- Sid: RefreshLambda
Effect: Allow
Action:
- lambda:GetFunction
- lambda:GetFunctionConfiguration
- lambda:GetPolicy
- lambda:GetLayerVersion
- lambda:ListVersionsByFunction
- lambda:ListTags
- lambda:*
Resource:
- !Sub "arn:aws:lambda:us-east-1:${AWS::AccountId}:function:afi-*"
- !Sub "arn:aws:lambda:us-east-1:${AWS::AccountId}:layer:afi-shared*"
@ -480,34 +475,15 @@ Resources:
PolicyDocument:
Version: "2012-10-17"
Statement:
- Sid: LambdaFunctions
# lambda:*/events:* on stack prefixes — AWS provider reads many
# Get* attributes (e.g. GetFunctionCodeSigningConfig) that lag any
# enumerated allow-list (PLAT-56 first-apply misses).
- Sid: LambdaAll
Effect: Allow
Action:
- lambda:CreateFunction
- lambda:DeleteFunction
- lambda:GetFunction
- lambda:GetFunctionConfiguration
- lambda:UpdateFunctionCode
- lambda:UpdateFunctionConfiguration
- lambda:ListVersionsByFunction
- lambda:PublishVersion
- lambda:TagResource
- lambda:UntagResource
- lambda:ListTags
- lambda:AddPermission
- lambda:RemovePermission
- lambda:GetPolicy
- lambda:InvokeFunction
- lambda:*
Resource:
- !Sub "arn:aws:lambda:us-east-1:${AWS::AccountId}:function:afi-*"
- Sid: LambdaLayers
Effect: Allow
Action:
- lambda:PublishLayerVersion
- lambda:DeleteLayerVersion
- lambda:GetLayerVersion
- lambda:ListLayerVersions
Resource:
- !Sub "arn:aws:lambda:us-east-1:${AWS::AccountId}:layer:afi-shared*"
- Sid: LambdaList
Effect: Allow
@ -519,17 +495,7 @@ Resources:
- Sid: EventBridgeRules
Effect: Allow
Action:
- events:PutRule
- events:DeleteRule
- events:DescribeRule
- events:EnableRule
- events:DisableRule
- events:PutTargets
- events:RemoveTargets
- events:ListTargetsByRule
- events:TagResource
- events:UntagResource
- events:ListTagsForResource
- events:*
Resource:
- !Sub "arn:aws:events:us-east-1:${AWS::AccountId}:rule/afi-*"
- Sid: CloudWatchLogs