Skip to content

Commit 3faf948

Browse files
committed
Merge remote-tracking branch 'origin/main' into feature/eja-eli-238-address-checkov-flagged-issues
2 parents b8d30c5 + af21a9b commit 3faf948

File tree

1 file changed

+7
-0
lines changed

1 file changed

+7
-0
lines changed

infrastructure/stacks/iams-developer-roles/github_actions_policies.tf

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -68,6 +68,11 @@ resource "aws_iam_policy" "api_infrastructure" {
6868
"kms:GetKeyPolicy*",
6969
"kms:GetKeyRotationStatus",
7070
"kms:Decrypt*",
71+
"kms:DeleteAlias",
72+
"kms:UpdateKeyDescription",
73+
"kms:CreateGrant",
74+
"kms:CreateAlias",
75+
7176

7277
# Cloudwatch permissions
7378
"logs:Describe*",
@@ -85,6 +90,8 @@ resource "aws_iam_policy" "api_infrastructure" {
8590
"iam:Create*",
8691
"iam:Update*",
8792
"iam:Delete*",
93+
"iam:PutRolePermissionsBoundary",
94+
"iam:PutRolePolicy",
8895

8996
# ssm
9097
"ssm:GetParameter",

0 commit comments

Comments
 (0)