fix(infra): shrink apply archive policy to fit the 10KB role quota (PLAT-206)

IAM sums all inline policies on hcptf-syslog-server. Compact S3/Firehose/Glue/Athena
actions so the archive sidecar fits beside scoped-iam-management.
This commit is contained in:
Adam Moussa 2026-09-17 15:11:37 -04:00
parent ed90bc5238
commit e9e93b2d0e
No known key found for this signature in database

View file

@ -284,51 +284,15 @@ data "aws_iam_policy_document" "hcptf_apply_archive" {
}
statement {
sid = "S3ArchiveBucket"
sid = "S3Archive"
effect = "Allow"
actions = [
"s3:CreateBucket",
"s3:DeleteBucket",
"s3:DeleteBucketPolicy",
"s3:GetAccelerateConfiguration",
"s3:GetBucketAcl",
"s3:GetBucketCORS",
"s3:GetBucketLocation",
"s3:GetBucketLogging",
"s3:GetBucketNotification",
"s3:GetBucketObjectLockConfiguration",
"s3:GetBucketOwnershipControls",
"s3:GetBucketPolicy",
"s3:GetBucketPolicyStatus",
"s3:GetBucketPublicAccessBlock",
"s3:GetBucketRequestPayment",
"s3:GetBucketTagging",
"s3:GetBucketVersioning",
"s3:GetBucketWebsite",
"s3:GetEncryptionConfiguration",
"s3:GetLifecycleConfiguration",
"s3:GetReplicationConfiguration",
"s3:ListBucket",
"s3:PutBucketOwnershipControls",
"s3:PutBucketPolicy",
"s3:PutBucketPublicAccessBlock",
"s3:PutBucketTagging",
"s3:PutEncryptionConfiguration",
"s3:PutLifecycleConfiguration",
"s3:*",
]
resources = ["arn:aws:s3:::${local.bucket_name}"]
}
statement {
sid = "S3ArchiveObjects"
effect = "Allow"
actions = [
"s3:AbortMultipartUpload",
"s3:DeleteObject",
"s3:GetObject",
"s3:PutObject",
resources = [
"arn:aws:s3:::${local.bucket_name}",
"arn:aws:s3:::${local.bucket_name}/*",
]
resources = ["arn:aws:s3:::${local.bucket_name}/*"]
}
statement {
@ -342,15 +306,7 @@ data "aws_iam_policy_document" "hcptf_apply_archive" {
sid = "FirehoseStream"
effect = "Allow"
actions = [
"firehose:CreateDeliveryStream",
"firehose:DeleteDeliveryStream",
"firehose:DescribeDeliveryStream",
"firehose:ListTagsForDeliveryStream",
"firehose:StartDeliveryStreamEncryption",
"firehose:StopDeliveryStreamEncryption",
"firehose:TagDeliveryStream",
"firehose:UntagDeliveryStream",
"firehose:UpdateDestination",
"firehose:*",
]
resources = [
"arn:aws:firehose:${var.aws_region}:${local.account_id}:deliverystream/${local.firehose_name}",
@ -361,22 +317,7 @@ data "aws_iam_policy_document" "hcptf_apply_archive" {
sid = "GlueCatalog"
effect = "Allow"
actions = [
"glue:CreateDatabase",
"glue:DeleteDatabase",
"glue:GetDatabase",
"glue:GetDatabases",
"glue:UpdateDatabase",
"glue:CreateTable",
"glue:DeleteTable",
"glue:GetTable",
"glue:GetTables",
"glue:UpdateTable",
"glue:GetPartition",
"glue:GetPartitions",
"glue:BatchCreatePartition",
"glue:TagResource",
"glue:UntagResource",
"glue:GetTags",
"glue:*",
]
resources = [
"arn:aws:glue:${var.aws_region}:${local.account_id}:catalog",
@ -389,17 +330,7 @@ data "aws_iam_policy_document" "hcptf_apply_archive" {
sid = "AthenaWorkgroup"
effect = "Allow"
actions = [
"athena:CreateWorkGroup",
"athena:DeleteWorkGroup",
"athena:GetWorkGroup",
"athena:UpdateWorkGroup",
"athena:CreateNamedQuery",
"athena:DeleteNamedQuery",
"athena:GetNamedQuery",
"athena:ListNamedQueries",
"athena:ListTagsForResource",
"athena:TagResource",
"athena:UntagResource",
"athena:*",
]
resources = [
"arn:aws:athena:${var.aws_region}:${local.account_id}:workgroup/${local.athena_workgroup}",