Skip to content

Commit af21a9b

Browse files
authored
Merge pull request #123 from NHSDigital/bugfix/eja-eli-131-adding-additional-permissions-for-deployment-role
eli-131 adding additional permissions for github role
2 parents 1a62f0b + d1886f3 commit af21a9b

File tree

1 file changed

+7
-0
lines changed

1 file changed

+7
-0
lines changed

infrastructure/stacks/iams-developer-roles/github_actions_policies.tf

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -61,6 +61,11 @@ resource "aws_iam_policy" "api_infrastructure" {
6161
"kms:GetKeyPolicy*",
6262
"kms:GetKeyRotationStatus",
6363
"kms:Decrypt*",
64+
"kms:DeleteAlias",
65+
"kms:UpdateKeyDescription",
66+
"kms:CreateGrant",
67+
"kms:CreateAlias",
68+
6469

6570
# Cloudwatch permissions
6671
"logs:Describe*",
@@ -78,6 +83,8 @@ resource "aws_iam_policy" "api_infrastructure" {
7883
"iam:Create*",
7984
"iam:Update*",
8085
"iam:Delete*",
86+
"iam:PutRolePermissionsBoundary",
87+
"iam:PutRolePolicy",
8188

8289
# ssm
8390
"ssm:GetParameter",

0 commit comments

Comments
 (0)