Skip to content

Commit 579918a

Browse files
authored
allow access to airflow env stg or prod in all containers (#1997)
* allow access to airflow env stg or prod in all containers * add the arn in prod
1 parent 3faba2f commit 579918a

File tree

1 file changed

+3
-1
lines changed

1 file changed

+3
-1
lines changed

terraform/modules/department/50-aws-iam-policies.tf

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -433,7 +433,9 @@ data "aws_iam_policy_document" "secrets_manager_read_only" {
433433
aws_secretsmanager_secret.redshift_cluster_credentials.arn,
434434
module.google_service_account.credentials_secret.arn,
435435
"arn:aws:secretsmanager:eu-west-2:${data.aws_caller_identity.current.account_id}:secret:${var.identifier_prefix}/${local.department_identifier}/*",
436-
"arn:aws:secretsmanager:eu-west-2:${data.aws_caller_identity.current.account_id}:secret:${var.short_identifier_prefix}/${local.department_identifier}*"
436+
"arn:aws:secretsmanager:eu-west-2:${data.aws_caller_identity.current.account_id}:secret:${var.short_identifier_prefix}/${local.department_identifier}*",
437+
"arn:aws:secretsmanager:eu-west-2:${data.aws_caller_identity.current.account_id}:secret:airflow/variables/env-fxe5CD",
438+
"arn:aws:secretsmanager:eu-west-2:${data.aws_caller_identity.current.account_id}:secret:airflow/variables/env-jeCYYl",
437439
]
438440
}
439441

0 commit comments

Comments
 (0)