Skip to content

Commit 6fbb112

Browse files
eli-417 permission for preprod db seeding (#322)
1 parent eb10cb2 commit 6fbb112

File tree

2 files changed

+4
-2
lines changed

2 files changed

+4
-2
lines changed

infrastructure/stacks/iams-developer-roles/github_actions_policies.tf

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -117,7 +117,8 @@ resource "aws_iam_policy" "dynamodb_management" {
117117
"dynamodb:PutItem",
118118
"dynamodb:DeleteItem",
119119
"dynamodb:Scan",
120-
"dynamodb:BatchWriteItem"
120+
"dynamodb:BatchWriteItem",
121+
"dynamodb:Query"
121122
],
122123
Resource = [
123124
"arn:aws:dynamodb:*:${data.aws_caller_identity.current.account_id}:table/*eligibility-signposting-api-${var.environment}-eligibility_datastore"

infrastructure/stacks/iams-developer-roles/iams_permissions_boundary.tf

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -244,7 +244,8 @@ data "aws_iam_policy_document" "permissions_boundary" {
244244
"dynamodb:PutItem",
245245
"dynamodb:DeleteItem",
246246
"dynamodb:Scan",
247-
"dynamodb:BatchWriteItem"
247+
"dynamodb:BatchWriteItem",
248+
"dynamodb:Query"
248249
]
249250
resources = ["*"]
250251
}

0 commit comments

Comments
 (0)