mirror of
https://github.com/Sea-Haven-Industries/syslog-server.git
synced 2026-09-30 07:43:15 +00:00
fix(infra): split hcptf apply inline policy under 10KB (PLAT-206) (#42)
The combined syslog-server-services document exceeded IAM's 10240-byte inline policy limit and blocked the bootstrap apply.
This commit is contained in:
parent
2b12aba50e
commit
ed90bc5238
1 changed files with 13 additions and 3 deletions
|
|
@ -260,8 +260,8 @@ data "aws_iam_policy_document" "hcptf_scoped_iam" {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
data "aws_iam_policy_document" "hcptf_apply_services" {
|
data "aws_iam_policy_document" "hcptf_apply_archive" {
|
||||||
# checkov:skip=CKV_AWS_111: EC2 describe APIs and Glue catalog ARNs require Resource=*. S3, Firehose, Athena, and SNS writes are ARN-prefixed.
|
# checkov:skip=CKV_AWS_111: Glue catalog ARNs require Resource=*. S3, Firehose, Athena, and SNS writes are ARN-prefixed.
|
||||||
statement {
|
statement {
|
||||||
sid = "DescribeLogGroups"
|
sid = "DescribeLogGroups"
|
||||||
effect = "Allow"
|
effect = "Allow"
|
||||||
|
|
@ -456,7 +456,10 @@ data "aws_iam_policy_document" "hcptf_apply_services" {
|
||||||
"arn:aws:iam::${local.account_id}:policy/tf-managed/${local.stack_prefix}*",
|
"arn:aws:iam::${local.account_id}:policy/tf-managed/${local.stack_prefix}*",
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
data "aws_iam_policy_document" "hcptf_apply_services" {
|
||||||
|
# checkov:skip=CKV_AWS_111: EC2 describe APIs require Resource=*.
|
||||||
statement {
|
statement {
|
||||||
sid = "Ec2VpcManagement"
|
sid = "Ec2VpcManagement"
|
||||||
effect = "Allow"
|
effect = "Allow"
|
||||||
|
|
@ -774,8 +777,15 @@ resource "aws_iam_role_policy" "hcptf_scoped_iam" {
|
||||||
policy = data.aws_iam_policy_document.hcptf_scoped_iam.json
|
policy = data.aws_iam_policy_document.hcptf_scoped_iam.json
|
||||||
}
|
}
|
||||||
|
|
||||||
|
resource "aws_iam_role_policy" "hcptf_apply_archive" {
|
||||||
|
# checkov:skip=CKV_AWS_111: Glue catalog ARNs require Resource=*. S3, Firehose, Athena, and SNS writes are ARN-prefixed.
|
||||||
|
name = "syslog-server-archive"
|
||||||
|
role = aws_iam_role.hcptf_apply.id
|
||||||
|
policy = data.aws_iam_policy_document.hcptf_apply_archive.json
|
||||||
|
}
|
||||||
|
|
||||||
resource "aws_iam_role_policy" "hcptf_apply_services" {
|
resource "aws_iam_role_policy" "hcptf_apply_services" {
|
||||||
# checkov:skip=CKV_AWS_111: EC2 VPC/instance lifecycle and describe APIs require Resource=*. Log group, alarm, and SNS writes are ARN-prefixed.
|
# checkov:skip=CKV_AWS_111: EC2 VPC/instance lifecycle and describe APIs require Resource=*.
|
||||||
name = "syslog-server-services"
|
name = "syslog-server-services"
|
||||||
role = aws_iam_role.hcptf_apply.id
|
role = aws_iam_role.hcptf_apply.id
|
||||||
policy = data.aws_iam_policy_document.hcptf_apply_services.json
|
policy = data.aws_iam_policy_document.hcptf_apply_services.json
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue