mirror of
https://github.com/Sea-Haven-Industries/sh-openswe-traces.git
synced 2026-09-30 06:53:16 +00:00
fix(ci): grant exec role cloudformation:CreateChangeSet on the SAM transform
The dedicated CFN exec role hit AccessDenied on CreateChangeSet against arn:...:aws:transform/Serverless-2016-10-31 during the first CI deploy (template uses Transform: AWS::Serverless-2016-10-31). Scoped grant on that transform ARN only. Cross-review: APPROVE (non-escalating).
This commit is contained in:
parent
1ec33d2937
commit
e9678a0105
1 changed files with 7 additions and 0 deletions
|
|
@ -121,6 +121,13 @@ Resources:
|
|||
- "iam:ListAttachedUserPolicies"
|
||||
- "iam:ListGroupsForUser"
|
||||
Resource: !Sub "arn:aws:iam::${AWS::AccountId}:user/sh-openswe-traces-*"
|
||||
# Required because template.yaml uses Transform: AWS::Serverless-2016-10-31.
|
||||
# CloudFormation (as this exec role) must CreateChangeSet on the AWS-managed
|
||||
# SAM transform macro. Scoped to only that transform ARN.
|
||||
- Sid: SamTransform
|
||||
Effect: Allow
|
||||
Action: "cloudformation:CreateChangeSet"
|
||||
Resource: !Sub "arn:aws:cloudformation:${AWS::Region}:aws:transform/Serverless-2016-10-31"
|
||||
|
||||
DeployRole:
|
||||
Type: AWS::IAM::Role
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue