mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 08:03:19 +00:00
fix(iam): allow s3:* on afi artifact bucket for provider reads
First HCP apply failed on s3:GetBucketAcl after CreateBucket; scope remains the single artifact bucket ARN.
This commit is contained in:
parent
4e1cf4c0bd
commit
3512214d14
1 changed files with 5 additions and 17 deletions
|
|
@ -498,26 +498,14 @@ Resources:
|
|||
Resource: "*"
|
||||
# Artifact bucket for HCP plan/apply split: zip bytes travel in the
|
||||
# plan via aws_s3_object content_base64 (local archive_file paths
|
||||
# from the plan worker are not on the apply worker).
|
||||
# from the plan worker are not on the apply worker). Action set is
|
||||
# s3:* on this bucket only — the AWS provider reads many GetBucket*
|
||||
# attributes (e.g. GetBucketAcl) after CreateBucket; enumerating
|
||||
# them lags provider upgrades (PLAT-56 first-apply miss).
|
||||
- Sid: LambdaArtifactsBucket
|
||||
Effect: Allow
|
||||
Action:
|
||||
- s3:CreateBucket
|
||||
- s3:DeleteBucket
|
||||
- s3:GetBucketLocation
|
||||
- s3:GetBucketPolicy
|
||||
- s3:PutBucketPolicy
|
||||
- s3:DeleteBucketPolicy
|
||||
- s3:GetBucketVersioning
|
||||
- s3:PutBucketVersioning
|
||||
- s3:GetBucketPublicAccessBlock
|
||||
- s3:PutBucketPublicAccessBlock
|
||||
- s3:GetBucketTagging
|
||||
- s3:PutBucketTagging
|
||||
- s3:ListBucket
|
||||
- s3:GetObject
|
||||
- s3:PutObject
|
||||
- s3:DeleteObject
|
||||
- s3:*
|
||||
Resource:
|
||||
- !Sub "arn:aws:s3:::afi-backup-monitor-artifacts-${AWS::AccountId}"
|
||||
- !Sub "arn:aws:s3:::afi-backup-monitor-artifacts-${AWS::AccountId}/*"
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue