mirror of
https://github.com/Sea-Haven-Industries/syslog-server.git
synced 2026-09-30 03:03:14 +00:00
fix(infra): shrink apply archive policy to fit the 10KB role quota (PLAT-206) (#43)
IAM sums all inline policies on hcptf-syslog-server. Compact S3/Firehose/Glue/Athena actions so the archive sidecar fits beside scoped-iam-management.
This commit is contained in:
parent
ed90bc5238
commit
58f69b1af1
1 changed files with 8 additions and 77 deletions
|
|
@ -284,51 +284,15 @@ data "aws_iam_policy_document" "hcptf_apply_archive" {
|
|||
}
|
||||
|
||||
statement {
|
||||
sid = "S3ArchiveBucket"
|
||||
sid = "S3Archive"
|
||||
effect = "Allow"
|
||||
actions = [
|
||||
"s3:CreateBucket",
|
||||
"s3:DeleteBucket",
|
||||
"s3:DeleteBucketPolicy",
|
||||
"s3:GetAccelerateConfiguration",
|
||||
"s3:GetBucketAcl",
|
||||
"s3:GetBucketCORS",
|
||||
"s3:GetBucketLocation",
|
||||
"s3:GetBucketLogging",
|
||||
"s3:GetBucketNotification",
|
||||
"s3:GetBucketObjectLockConfiguration",
|
||||
"s3:GetBucketOwnershipControls",
|
||||
"s3:GetBucketPolicy",
|
||||
"s3:GetBucketPolicyStatus",
|
||||
"s3:GetBucketPublicAccessBlock",
|
||||
"s3:GetBucketRequestPayment",
|
||||
"s3:GetBucketTagging",
|
||||
"s3:GetBucketVersioning",
|
||||
"s3:GetBucketWebsite",
|
||||
"s3:GetEncryptionConfiguration",
|
||||
"s3:GetLifecycleConfiguration",
|
||||
"s3:GetReplicationConfiguration",
|
||||
"s3:ListBucket",
|
||||
"s3:PutBucketOwnershipControls",
|
||||
"s3:PutBucketPolicy",
|
||||
"s3:PutBucketPublicAccessBlock",
|
||||
"s3:PutBucketTagging",
|
||||
"s3:PutEncryptionConfiguration",
|
||||
"s3:PutLifecycleConfiguration",
|
||||
"s3:*",
|
||||
]
|
||||
resources = ["arn:aws:s3:::${local.bucket_name}"]
|
||||
}
|
||||
|
||||
statement {
|
||||
sid = "S3ArchiveObjects"
|
||||
effect = "Allow"
|
||||
actions = [
|
||||
"s3:AbortMultipartUpload",
|
||||
"s3:DeleteObject",
|
||||
"s3:GetObject",
|
||||
"s3:PutObject",
|
||||
resources = [
|
||||
"arn:aws:s3:::${local.bucket_name}",
|
||||
"arn:aws:s3:::${local.bucket_name}/*",
|
||||
]
|
||||
resources = ["arn:aws:s3:::${local.bucket_name}/*"]
|
||||
}
|
||||
|
||||
statement {
|
||||
|
|
@ -342,15 +306,7 @@ data "aws_iam_policy_document" "hcptf_apply_archive" {
|
|||
sid = "FirehoseStream"
|
||||
effect = "Allow"
|
||||
actions = [
|
||||
"firehose:CreateDeliveryStream",
|
||||
"firehose:DeleteDeliveryStream",
|
||||
"firehose:DescribeDeliveryStream",
|
||||
"firehose:ListTagsForDeliveryStream",
|
||||
"firehose:StartDeliveryStreamEncryption",
|
||||
"firehose:StopDeliveryStreamEncryption",
|
||||
"firehose:TagDeliveryStream",
|
||||
"firehose:UntagDeliveryStream",
|
||||
"firehose:UpdateDestination",
|
||||
"firehose:*",
|
||||
]
|
||||
resources = [
|
||||
"arn:aws:firehose:${var.aws_region}:${local.account_id}:deliverystream/${local.firehose_name}",
|
||||
|
|
@ -361,22 +317,7 @@ data "aws_iam_policy_document" "hcptf_apply_archive" {
|
|||
sid = "GlueCatalog"
|
||||
effect = "Allow"
|
||||
actions = [
|
||||
"glue:CreateDatabase",
|
||||
"glue:DeleteDatabase",
|
||||
"glue:GetDatabase",
|
||||
"glue:GetDatabases",
|
||||
"glue:UpdateDatabase",
|
||||
"glue:CreateTable",
|
||||
"glue:DeleteTable",
|
||||
"glue:GetTable",
|
||||
"glue:GetTables",
|
||||
"glue:UpdateTable",
|
||||
"glue:GetPartition",
|
||||
"glue:GetPartitions",
|
||||
"glue:BatchCreatePartition",
|
||||
"glue:TagResource",
|
||||
"glue:UntagResource",
|
||||
"glue:GetTags",
|
||||
"glue:*",
|
||||
]
|
||||
resources = [
|
||||
"arn:aws:glue:${var.aws_region}:${local.account_id}:catalog",
|
||||
|
|
@ -389,17 +330,7 @@ data "aws_iam_policy_document" "hcptf_apply_archive" {
|
|||
sid = "AthenaWorkgroup"
|
||||
effect = "Allow"
|
||||
actions = [
|
||||
"athena:CreateWorkGroup",
|
||||
"athena:DeleteWorkGroup",
|
||||
"athena:GetWorkGroup",
|
||||
"athena:UpdateWorkGroup",
|
||||
"athena:CreateNamedQuery",
|
||||
"athena:DeleteNamedQuery",
|
||||
"athena:GetNamedQuery",
|
||||
"athena:ListNamedQueries",
|
||||
"athena:ListTagsForResource",
|
||||
"athena:TagResource",
|
||||
"athena:UntagResource",
|
||||
"athena:*",
|
||||
]
|
||||
resources = [
|
||||
"arn:aws:athena:${var.aws_region}:${local.account_id}:workgroup/${local.athena_workgroup}",
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue