mirror of
https://github.com/Sea-Haven-Industries/seahaven-org-baseline.git
synced 2026-10-04 04:13:12 +00:00
fix(iam): let the site plan role describe SSM parameters
This commit is contained in:
parent
38ed1bfe00
commit
ce6b59b552
2 changed files with 10 additions and 4 deletions
6
.github/workflows/deploy.yaml
vendored
6
.github/workflows/deploy.yaml
vendored
|
|
@ -56,10 +56,8 @@ jobs:
|
|||
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@e5691d8a7f96ac4d5a841a82975ff0a4354d53ac # v1.0.7
|
||||
with:
|
||||
node-version: "24"
|
||||
# seahaven-site-hcptf stays off this list until `cdk import` adopts the
|
||||
# live roles. A create fails, and a failed create blocks the import.
|
||||
# Add the id here in the change that follows a successful import.
|
||||
stacks: "prod-baseline dynamodb-cmk-prod alarm-topic-prod deploy-substrate-prod terraform-substrate-prod app-web-acl-prod"
|
||||
# seahaven-site-hcptf was imported after the roles left terraform-substrate.
|
||||
stacks: "prod-baseline dynamodb-cmk-prod alarm-topic-prod deploy-substrate-prod terraform-substrate-prod app-web-acl-prod seahaven-site-hcptf"
|
||||
stack-name: "seahaven-prod-baseline"
|
||||
secrets:
|
||||
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN_PROD }}
|
||||
|
|
|
|||
|
|
@ -459,6 +459,14 @@ function planPolicy(
|
|||
Action: ["ssm:GetParameter", "ssm:GetParameters", "ssm:ListTagsForResource"],
|
||||
Resource: [wafParam, deployParams],
|
||||
},
|
||||
{
|
||||
// DescribeParameters accepts only Resource "*". The AWS provider
|
||||
// calls it while refreshing aws_ssm_parameter.
|
||||
Sid: "DescribeParameters",
|
||||
Effect: "Allow",
|
||||
Action: "ssm:DescribeParameters",
|
||||
Resource: "*",
|
||||
},
|
||||
{
|
||||
Sid: "RefreshWafWebAcl",
|
||||
Effect: "Allow",
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue