Skip to content

Commit c7aa3a6

Browse files
authored
[ELI-422] Added S3 tagging operations to permissions boundary (#382)
* Added s3 tagging operations to permissions boundary * Added s3 bucket and obj version operations to permissions boundary
1 parent a9a057f commit c7aa3a6

File tree

1 file changed

+5
-1
lines changed

1 file changed

+5
-1
lines changed

infrastructure/stacks/api-layer/assumed_role_permissions_boundary.tf

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,14 +15,18 @@ data "aws_iam_policy_document" "assumed_role_permissions_boundary" {
1515
"dynamodb:DeleteItem",
1616
"dynamodb:BatchWriteItem",
1717

18-
# S3 - bucket and object operations for Lambda and Firehose
18+
# S3 - bucket and object operations for Lambda, Firehose and External Role
1919
"s3:GetObject",
2020
"s3:ListBucket",
2121
"s3:PutObject",
2222
"s3:PutObjectAcl",
2323
"s3:AbortMultipartUpload",
2424
"s3:GetBucketLocation",
2525
"s3:ListBucketMultipartUploads",
26+
"s3:GetObjectTagging",
27+
"s3:PutObjectTagging",
28+
"s3:ListBucketVersions",
29+
"s3:GetObjectVersion",
2630

2731
# KMS - encryption/decryption for DynamoDB and S3
2832
"kms:Encrypt",

0 commit comments

Comments
 (0)