mirror of
https://github.com/Sea-Haven-Industries/sh-openswe-traces.git
synced 2026-09-30 06:53:16 +00:00
fix(ci): grant exec role cloudformation:CreateChangeSet on the SAM transform (#2)
Some checks failed
Deploy / deploy (push) Has been cancelled
Some checks failed
Deploy / deploy (push) Has been cancelled
The dedicated CFN exec role hit AccessDenied on CreateChangeSet against arn:...:aws:transform/Serverless-2016-10-31 during the first CI deploy (template uses Transform: AWS::Serverless-2016-10-31). Scoped grant on that transform ARN only. Cross-review: APPROVE (non-escalating).
This commit is contained in:
parent
1ec33d2937
commit
6e9749fe07
1 changed files with 7 additions and 0 deletions
|
|
@ -121,6 +121,13 @@ Resources:
|
||||||
- "iam:ListAttachedUserPolicies"
|
- "iam:ListAttachedUserPolicies"
|
||||||
- "iam:ListGroupsForUser"
|
- "iam:ListGroupsForUser"
|
||||||
Resource: !Sub "arn:aws:iam::${AWS::AccountId}:user/sh-openswe-traces-*"
|
Resource: !Sub "arn:aws:iam::${AWS::AccountId}:user/sh-openswe-traces-*"
|
||||||
|
# Required because template.yaml uses Transform: AWS::Serverless-2016-10-31.
|
||||||
|
# CloudFormation (as this exec role) must CreateChangeSet on the AWS-managed
|
||||||
|
# SAM transform macro. Scoped to only that transform ARN.
|
||||||
|
- Sid: SamTransform
|
||||||
|
Effect: Allow
|
||||||
|
Action: "cloudformation:CreateChangeSet"
|
||||||
|
Resource: !Sub "arn:aws:cloudformation:${AWS::Region}:aws:transform/Serverless-2016-10-31"
|
||||||
|
|
||||||
DeployRole:
|
DeployRole:
|
||||||
Type: AWS::IAM::Role
|
Type: AWS::IAM::Role
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue