From 213c40d321916f30c88e344e4e50d2e144ca01c5 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Thu, 17 Sep 2026 19:22:30 +0000 Subject: [PATCH] fix(infra): keep instance boundary description to avoid IAM replace (PLAT-206) (#44) Changing aws_iam_policy.description forces replacement. The live policy is attached, so keep the original description and version the document in place. --- terraform/iam.tf | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/terraform/iam.tf b/terraform/iam.tf index 31fda65..855d4b7 100644 --- a/terraform/iam.tf +++ b/terraform/iam.tf @@ -134,7 +134,7 @@ resource "aws_iam_policy" "instance_boundary" { # checkov:skip=CKV_AWS_111: SSM managed policy requires Resource=* for ssmmessages and describe APIs. Firehose and S3 writes are ARN-prefixed. name = local.boundary_name path = "/tf-managed/" - description = "Per-workload permissions boundary for syslog-server EC2 and Firehose (PLAT-206)." + description = "Per-workload EC2 permissions boundary for syslog-server (PLAT-78)." policy = data.aws_iam_policy_document.instance_boundary.json }