mirror of
https://github.com/Sea-Haven-Industries/syslog-server.git
synced 2026-09-30 05:23:16 +00:00
fix(infra): split hcptf apply inline policy under 10KB (PLAT-206)
The combined syslog-server-services document exceeded IAM's 10240-byte inline policy limit and blocked the bootstrap apply.
This commit is contained in:
parent
2b12aba50e
commit
3553ce5dfc
1 changed files with 13 additions and 3 deletions
|
|
@ -260,8 +260,8 @@ data "aws_iam_policy_document" "hcptf_scoped_iam" {
|
|||
}
|
||||
}
|
||||
|
||||
data "aws_iam_policy_document" "hcptf_apply_services" {
|
||||
# checkov:skip=CKV_AWS_111: EC2 describe APIs and Glue catalog ARNs require Resource=*. S3, Firehose, Athena, and SNS writes are ARN-prefixed.
|
||||
data "aws_iam_policy_document" "hcptf_apply_archive" {
|
||||
# checkov:skip=CKV_AWS_111: Glue catalog ARNs require Resource=*. S3, Firehose, Athena, and SNS writes are ARN-prefixed.
|
||||
statement {
|
||||
sid = "DescribeLogGroups"
|
||||
effect = "Allow"
|
||||
|
|
@ -456,7 +456,10 @@ data "aws_iam_policy_document" "hcptf_apply_services" {
|
|||
"arn:aws:iam::${local.account_id}:policy/tf-managed/${local.stack_prefix}*",
|
||||
]
|
||||
}
|
||||
}
|
||||
|
||||
data "aws_iam_policy_document" "hcptf_apply_services" {
|
||||
# checkov:skip=CKV_AWS_111: EC2 describe APIs require Resource=*.
|
||||
statement {
|
||||
sid = "Ec2VpcManagement"
|
||||
effect = "Allow"
|
||||
|
|
@ -774,8 +777,15 @@ resource "aws_iam_role_policy" "hcptf_scoped_iam" {
|
|||
policy = data.aws_iam_policy_document.hcptf_scoped_iam.json
|
||||
}
|
||||
|
||||
resource "aws_iam_role_policy" "hcptf_apply_archive" {
|
||||
# checkov:skip=CKV_AWS_111: Glue catalog ARNs require Resource=*. S3, Firehose, Athena, and SNS writes are ARN-prefixed.
|
||||
name = "syslog-server-archive"
|
||||
role = aws_iam_role.hcptf_apply.id
|
||||
policy = data.aws_iam_policy_document.hcptf_apply_archive.json
|
||||
}
|
||||
|
||||
resource "aws_iam_role_policy" "hcptf_apply_services" {
|
||||
# checkov:skip=CKV_AWS_111: EC2 VPC/instance lifecycle and describe APIs require Resource=*. Log group, alarm, and SNS writes are ARN-prefixed.
|
||||
# checkov:skip=CKV_AWS_111: EC2 VPC/instance lifecycle and describe APIs require Resource=*.
|
||||
name = "syslog-server-services"
|
||||
role = aws_iam_role.hcptf_apply.id
|
||||
policy = data.aws_iam_policy_document.hcptf_apply_services.json
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue