mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-09-30 05:43:17 +00:00
feat(iam): allow tf-poc HCP apply destroy (#136)
This commit is contained in:
parent
6d5811f08e
commit
35dc61b806
1 changed files with 33 additions and 0 deletions
|
|
@ -3157,6 +3157,39 @@ Resources:
|
||||||
StringEquals:
|
StringEquals:
|
||||||
"aws:ResourceTag/project": shoc
|
"aws:ResourceTag/project": shoc
|
||||||
"aws:ResourceTag/env": tf-poc
|
"aws:ResourceTag/env": tf-poc
|
||||||
|
- Sid: TerminatePocEnvironment
|
||||||
|
Effect: Allow
|
||||||
|
Action: elasticbeanstalk:TerminateEnvironment
|
||||||
|
Resource: arn:aws:elasticbeanstalk:us-east-1:396287094661:environment/shoc-backend/shoc-backend-tf-poc
|
||||||
|
- Sid: DeletePocRuntimeIam
|
||||||
|
Effect: Allow
|
||||||
|
Action:
|
||||||
|
- iam:DeleteRole
|
||||||
|
- iam:DeleteRolePolicy
|
||||||
|
- iam:DetachRolePolicy
|
||||||
|
Resource: arn:aws:iam::396287094661:role/shoc-backend-tf-poc
|
||||||
|
- Sid: DeletePocInstanceProfile
|
||||||
|
Effect: Allow
|
||||||
|
Action:
|
||||||
|
- iam:DeleteInstanceProfile
|
||||||
|
- iam:RemoveRoleFromInstanceProfile
|
||||||
|
Resource: arn:aws:iam::396287094661:instance-profile/shoc-backend-tf-poc
|
||||||
|
- Sid: DeletePocAppConfig
|
||||||
|
Effect: Allow
|
||||||
|
Action: secretsmanager:DeleteSecret
|
||||||
|
Resource: arn:aws:secretsmanager:us-east-1:396287094661:secret:shoc/tf-poc/app-config-*
|
||||||
|
- Sid: DeletePocHostedZone
|
||||||
|
Effect: Allow
|
||||||
|
Action: route53:DeleteHostedZone
|
||||||
|
Resource: arn:aws:route53:::hostedzone/Z02451891BSZD93CMMGDU
|
||||||
|
- Sid: DeletePocCertificate
|
||||||
|
Effect: Allow
|
||||||
|
Action: acm:DeleteCertificate
|
||||||
|
Resource: arn:aws:acm:us-east-1:396287094661:certificate/*
|
||||||
|
Condition:
|
||||||
|
StringEquals:
|
||||||
|
"aws:ResourceTag/project": shoc
|
||||||
|
"aws:ResourceTag/env": tf-poc
|
||||||
|
|
||||||
HcptfShocBackendDevPlanRole:
|
HcptfShocBackendDevPlanRole:
|
||||||
Type: AWS::IAM::Role
|
Type: AWS::IAM::Role
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue