mirror of
https://github.com/Sea-Haven-Industries/syslog-server.git
synced 2026-09-30 07:43:15 +00:00
fix(infra): keep instance boundary description to avoid IAM replace (PLAT-206)
Changing aws_iam_policy.description forces replacement. The live policy is attached, so keep the original description and version the document in place.
This commit is contained in:
parent
58f69b1af1
commit
24f5962630
1 changed files with 1 additions and 1 deletions
|
|
@ -134,7 +134,7 @@ resource "aws_iam_policy" "instance_boundary" {
|
||||||
# checkov:skip=CKV_AWS_111: SSM managed policy requires Resource=* for ssmmessages and describe APIs. Firehose and S3 writes are ARN-prefixed.
|
# checkov:skip=CKV_AWS_111: SSM managed policy requires Resource=* for ssmmessages and describe APIs. Firehose and S3 writes are ARN-prefixed.
|
||||||
name = local.boundary_name
|
name = local.boundary_name
|
||||||
path = "/tf-managed/"
|
path = "/tf-managed/"
|
||||||
description = "Per-workload permissions boundary for syslog-server EC2 and Firehose (PLAT-206)."
|
description = "Per-workload EC2 permissions boundary for syslog-server (PLAT-78)."
|
||||||
policy = data.aws_iam_policy_document.instance_boundary.json
|
policy = data.aws_iam_policy_document.instance_boundary.json
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue