Skip to content

Commit fc059e6

Browse files
Revert "NRL-1793 align tf for developer role with current in aws"
This reverts commit 0266dda. This change was useful to avoid releasing unreleased changes to the test environments, but it is no longer needed as those will be released shortly on the release cut.
1 parent 3f0e0cb commit fc059e6

File tree

1 file changed

+13
-3
lines changed

1 file changed

+13
-3
lines changed

terraform/account-wide-infrastructure/mgmt/iam__developer-role.tf

Lines changed: 13 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -46,9 +46,6 @@ module "developer_policy" {
4646
Resource = [
4747
"${data.aws_s3_bucket.terraform_state.arn}/${local.project}/prod/*",
4848
"${data.aws_s3_bucket.terraform_state.arn}/${local.project}/mgmt/*",
49-
"${data.aws_s3_bucket.truststore.arn}/ca/prod.*",
50-
"${data.aws_s3_bucket.truststore.arn}/client/prod.*",
51-
"${data.aws_s3_bucket.truststore.arn}/server/prod.*"
5249
]
5350
},
5451
{
@@ -103,6 +100,19 @@ module "developer_policy" {
103100
"${data.aws_s3_bucket.ci_logging.arn}/*"
104101
]
105102
},
103+
{
104+
Action = [
105+
"s3:PutObject",
106+
"s3:GetObject",
107+
"s3:DeleteObject"
108+
]
109+
Effect = "Deny"
110+
Resource = [
111+
"${data.aws_s3_bucket.truststore.arn}/ca/prod*",
112+
"${data.aws_s3_bucket.truststore.arn}/client/prod*",
113+
"${data.aws_s3_bucket.truststore.arn}/server/prod*"
114+
]
115+
},
106116
{
107117
Action = [
108118
"s3:GetObject"

0 commit comments

Comments
 (0)