Skip to content

Commit b2913f3

Browse files
committed
eli-382 more permissions
1 parent dc1430f commit b2913f3

File tree

2 files changed

+7
-1
lines changed

2 files changed

+7
-1
lines changed

infrastructure/stacks/iams-developer-roles/github_actions_policies.tf

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -244,7 +244,12 @@ resource "aws_iam_policy" "api_infrastructure" {
244244
# CloudWatch Logs resource policies (require wildcard)
245245
"logs:PutResourcePolicy",
246246
"logs:DeleteResourcePolicy",
247-
"logs:DescribeResourcePolicies"
247+
"logs:DescribeResourcePolicies",
248+
# CloudWatch Logs delivery for WAF
249+
"logs:CreateLogDelivery",
250+
"logs:DeleteLogDelivery",
251+
# IAM service-linked role for WAF logging
252+
"iam:CreateServiceLinkedRole"
248253

249254
],
250255
Resource = "*"

infrastructure/stacks/iams-developer-roles/iams_permissions_boundary.tf

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -116,6 +116,7 @@ data "aws_iam_policy_document" "permissions_boundary" {
116116
"iam:UntagPolicy",
117117
"iam:PassRole",
118118
"iam:TagPolicy",
119+
"iam:CreateServiceLinkedRole",
119120

120121
# KMS - encryption key management
121122
"kms:CreateKey",

0 commit comments

Comments
 (0)