Skip to content

Commit 1a94ebc

Browse files
github roles
1 parent 80db7a2 commit 1a94ebc

File tree

2 files changed

+7
-2
lines changed

2 files changed

+7
-2
lines changed

infrastructure/stacks/iams-developer-roles/github_actions_policies.tf

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -65,11 +65,14 @@ resource "aws_iam_policy" "lambda_management" {
6565
"lambda:GetPolicy",
6666
"lambda:GetAlias",
6767
"lambda:GetFunction",
68-
"lambda:GetProvisionedConcurrencyConfig"
68+
"lambda:GetProvisionedConcurrencyConfig",
69+
"lambda:GetLayerVersion",
70+
"lambda:PutProvisionedConcurrencyConfig"
6971
],
7072
Resource = [
7173
"arn:aws:lambda:*:${data.aws_caller_identity.current.account_id}:function:eligibility_signposting_api",
72-
"arn:aws:lambda:*:${data.aws_caller_identity.current.account_id}:function:eligibility_signposting_api:*"
74+
"arn:aws:lambda:*:${data.aws_caller_identity.current.account_id}:function:eligibility_signposting_api:*",
75+
"arn:aws:lambda:*:580247275435:layer:LambdaInsightsExtension:*"
7376
]
7477
}
7578
]

infrastructure/stacks/iams-developer-roles/iams_permissions_boundary.tf

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -152,6 +152,8 @@ data "aws_iam_policy_document" "permissions_boundary" {
152152
"lambda:GetPolicy",
153153
"lambda:GetAlias",
154154
"lambda:GetProvisionedConcurrencyConfig",
155+
"lambda:GetLayerVersion",
156+
"lambda:PutProvisionedConcurrencyConfig",
155157

156158
# CloudWatch Logs - log management
157159
"logs:CreateLogGroup",

0 commit comments

Comments
 (0)