From 58f69b1af1e68a951a5b5829901b4b7105630003 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Thu, 17 Sep 2026 19:15:05 +0000 Subject: [PATCH] fix(infra): shrink apply archive policy to fit the 10KB role quota (PLAT-206) (#43) IAM sums all inline policies on hcptf-syslog-server. Compact S3/Firehose/Glue/Athena actions so the archive sidecar fits beside scoped-iam-management. --- terraform/hcp_iam.tf | 85 +++++--------------------------------------- 1 file changed, 8 insertions(+), 77 deletions(-) diff --git a/terraform/hcp_iam.tf b/terraform/hcp_iam.tf index 23dc706..54153d8 100644 --- a/terraform/hcp_iam.tf +++ b/terraform/hcp_iam.tf @@ -284,51 +284,15 @@ data "aws_iam_policy_document" "hcptf_apply_archive" { } statement { - sid = "S3ArchiveBucket" + sid = "S3Archive" effect = "Allow" actions = [ - "s3:CreateBucket", - "s3:DeleteBucket", - "s3:DeleteBucketPolicy", - "s3:GetAccelerateConfiguration", - "s3:GetBucketAcl", - "s3:GetBucketCORS", - "s3:GetBucketLocation", - "s3:GetBucketLogging", - "s3:GetBucketNotification", - "s3:GetBucketObjectLockConfiguration", - "s3:GetBucketOwnershipControls", - "s3:GetBucketPolicy", - "s3:GetBucketPolicyStatus", - "s3:GetBucketPublicAccessBlock", - "s3:GetBucketRequestPayment", - "s3:GetBucketTagging", - "s3:GetBucketVersioning", - "s3:GetBucketWebsite", - "s3:GetEncryptionConfiguration", - "s3:GetLifecycleConfiguration", - "s3:GetReplicationConfiguration", - "s3:ListBucket", - "s3:PutBucketOwnershipControls", - "s3:PutBucketPolicy", - "s3:PutBucketPublicAccessBlock", - "s3:PutBucketTagging", - "s3:PutEncryptionConfiguration", - "s3:PutLifecycleConfiguration", + "s3:*", ] - resources = ["arn:aws:s3:::${local.bucket_name}"] - } - - statement { - sid = "S3ArchiveObjects" - effect = "Allow" - actions = [ - "s3:AbortMultipartUpload", - "s3:DeleteObject", - "s3:GetObject", - "s3:PutObject", + resources = [ + "arn:aws:s3:::${local.bucket_name}", + "arn:aws:s3:::${local.bucket_name}/*", ] - resources = ["arn:aws:s3:::${local.bucket_name}/*"] } statement { @@ -342,15 +306,7 @@ data "aws_iam_policy_document" "hcptf_apply_archive" { sid = "FirehoseStream" effect = "Allow" actions = [ - "firehose:CreateDeliveryStream", - "firehose:DeleteDeliveryStream", - "firehose:DescribeDeliveryStream", - "firehose:ListTagsForDeliveryStream", - "firehose:StartDeliveryStreamEncryption", - "firehose:StopDeliveryStreamEncryption", - "firehose:TagDeliveryStream", - "firehose:UntagDeliveryStream", - "firehose:UpdateDestination", + "firehose:*", ] resources = [ "arn:aws:firehose:${var.aws_region}:${local.account_id}:deliverystream/${local.firehose_name}", @@ -361,22 +317,7 @@ data "aws_iam_policy_document" "hcptf_apply_archive" { sid = "GlueCatalog" effect = "Allow" actions = [ - "glue:CreateDatabase", - "glue:DeleteDatabase", - "glue:GetDatabase", - "glue:GetDatabases", - "glue:UpdateDatabase", - "glue:CreateTable", - "glue:DeleteTable", - "glue:GetTable", - "glue:GetTables", - "glue:UpdateTable", - "glue:GetPartition", - "glue:GetPartitions", - "glue:BatchCreatePartition", - "glue:TagResource", - "glue:UntagResource", - "glue:GetTags", + "glue:*", ] resources = [ "arn:aws:glue:${var.aws_region}:${local.account_id}:catalog", @@ -389,17 +330,7 @@ data "aws_iam_policy_document" "hcptf_apply_archive" { sid = "AthenaWorkgroup" effect = "Allow" actions = [ - "athena:CreateWorkGroup", - "athena:DeleteWorkGroup", - "athena:GetWorkGroup", - "athena:UpdateWorkGroup", - "athena:CreateNamedQuery", - "athena:DeleteNamedQuery", - "athena:GetNamedQuery", - "athena:ListNamedQueries", - "athena:ListTagsForResource", - "athena:TagResource", - "athena:UntagResource", + "athena:*", ] resources = [ "arn:aws:athena:${var.aws_region}:${local.account_id}:workgroup/${local.athena_workgroup}",