fix(iam): allow backend Terraform refresh (PLAT-141) (#134)
Some checks are pending
Deploy / deploy-management (push) Waiting to run
Deploy / deploy-external-dev (push) Waiting to run
Deploy / deploy-security (push) Waiting to run
Deploy / deploy-dev (push) Waiting to run
Deploy / deploy-prod (push) Waiting to run

* fix(iam): allow backend import plan reads

* fix(iam): authorize backend EB refresh

* fix(iam): authorize backend EB ownership check
This commit is contained in:
Adam Moussa 2026-08-31 17:04:00 +00:00 • committed by GitHub
parent 6a0713f49d
commit 559eed1e98
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -3217,6 +3217,7 @@ Resources:
Effect: Allow
Action:
- acm:ListCertificates
- autoscaling:DescribeAutoScalingGroups
- ec2:DescribeSecurityGroups
- ec2:DescribeSubnets
- ec2:DescribeVpcs
@ -3227,12 +3228,26 @@ Resources:
- elasticbeanstalk:DescribeEnvironments
- elasticbeanstalk:ListTagsForResource
- rds:DescribeDBInstances
- route53:ListHostedZones
- route53:ListHostedZonesByName
Resource: "*"
# Elastic Beanstalk DescribeConfigurationSettings calls
# CreateBucket against its existing regional service bucket
# during both plan and apply refresh.
- Sid: AuthorizeExistingEbBucketDiscovery
Effect: Allow
Action:
- s3:CreateBucket
- s3:PutBucketOwnershipControls
Resource: arn:aws:s3:::elasticbeanstalk-us-east-1-396287094661
Condition:
StringEquals:
s3:x-amz-object-ownership: ObjectWriter
- Sid: ReadSharedCertificate
Effect: Allow
Action:
- acm:DescribeCertificate
- acm:GetCertificate
- acm:ListTagsForCertificate
Resource: arn:aws:acm:us-east-1:396287094661:certificate/2b78e74f-7b65-4b82-a413-7a498b102f00
- Sid: ReadSharedRdsTags