From 3553ce5dfcf1d49a37c012d9b8b1cebe0648576a Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Thu, 17 Sep 2026 14:57:42 -0400 Subject: [PATCH] fix(infra): split hcptf apply inline policy under 10KB (PLAT-206) The combined syslog-server-services document exceeded IAM's 10240-byte inline policy limit and blocked the bootstrap apply. --- terraform/hcp_iam.tf | 16 +++++++++++++--- 1 file changed, 13 insertions(+), 3 deletions(-) diff --git a/terraform/hcp_iam.tf b/terraform/hcp_iam.tf index 57ebdc7..23dc706 100644 --- a/terraform/hcp_iam.tf +++ b/terraform/hcp_iam.tf @@ -260,8 +260,8 @@ data "aws_iam_policy_document" "hcptf_scoped_iam" { } } -data "aws_iam_policy_document" "hcptf_apply_services" { - # checkov:skip=CKV_AWS_111: EC2 describe APIs and Glue catalog ARNs require Resource=*. S3, Firehose, Athena, and SNS writes are ARN-prefixed. +data "aws_iam_policy_document" "hcptf_apply_archive" { + # checkov:skip=CKV_AWS_111: Glue catalog ARNs require Resource=*. S3, Firehose, Athena, and SNS writes are ARN-prefixed. statement { sid = "DescribeLogGroups" effect = "Allow" @@ -456,7 +456,10 @@ data "aws_iam_policy_document" "hcptf_apply_services" { "arn:aws:iam::${local.account_id}:policy/tf-managed/${local.stack_prefix}*", ] } +} +data "aws_iam_policy_document" "hcptf_apply_services" { + # checkov:skip=CKV_AWS_111: EC2 describe APIs require Resource=*. statement { sid = "Ec2VpcManagement" effect = "Allow" @@ -774,8 +777,15 @@ resource "aws_iam_role_policy" "hcptf_scoped_iam" { policy = data.aws_iam_policy_document.hcptf_scoped_iam.json } +resource "aws_iam_role_policy" "hcptf_apply_archive" { + # checkov:skip=CKV_AWS_111: Glue catalog ARNs require Resource=*. S3, Firehose, Athena, and SNS writes are ARN-prefixed. + name = "syslog-server-archive" + role = aws_iam_role.hcptf_apply.id + policy = data.aws_iam_policy_document.hcptf_apply_archive.json +} + resource "aws_iam_role_policy" "hcptf_apply_services" { - # checkov:skip=CKV_AWS_111: EC2 VPC/instance lifecycle and describe APIs require Resource=*. Log group, alarm, and SNS writes are ARN-prefixed. + # checkov:skip=CKV_AWS_111: EC2 VPC/instance lifecycle and describe APIs require Resource=*. name = "syslog-server-services" role = aws_iam_role.hcptf_apply.id policy = data.aws_iam_policy_document.hcptf_apply_services.json