Skip to content

Commit 52d14b5

Browse files
authored
Rgjb te eli 422 add kms permissions to external role (#397)
* Added new kms policy for external write role * Moved ref checkout to the top of deploy job * Remove repeated code * Appended firehouse kms permissions to external write role
1 parent 6a6e055 commit 52d14b5

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

infrastructure/stacks/api-layer/iam_policies.tf

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -515,7 +515,8 @@ data "aws_iam_policy_document" "external_role_s3_audit_kms_access_policy" {
515515
"kms:DescribeKey"
516516
]
517517
resources = [
518-
module.s3_audit_bucket.storage_bucket_kms_key_arn
518+
module.s3_audit_bucket.storage_bucket_kms_key_arn,
519+
module.eligibility_audit_firehose_delivery_stream.kinesis_firehose_cmk_arn
519520
]
520521
}
521522
}

0 commit comments

Comments
 (0)