Skip to content

Commit 1bd0b77

Browse files
[PRMT-862] updated policies to allow to shut down transfer family
1 parent be91ac2 commit 1bd0b77

File tree

1 file changed

+6
-1
lines changed

1 file changed

+6
-1
lines changed

infrastructure/policies.tf

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -67,6 +67,11 @@ resource "aws_iam_policy" "administrator_permission_restrictions" {
6767
Workspace = "core"
6868
}
6969
}
70+
data "aws_ssm_parameter" "transfer_server_id" {
71+
name = "/prs/${var.environment}/transfer-server-id"
72+
with_decryption = true
73+
}
74+
7075
resource "aws_iam_policy" "transfer_kill_switch_policy" {
7176
name = "${terraform.workspace}_transfer_kill_switch_policy"
7277

@@ -80,7 +85,7 @@ resource "aws_iam_policy" "transfer_kill_switch_policy" {
8085
"transfer:DescribeServer"
8186
],
8287
Resource = [
83-
"arn:aws:transfer:${var.region}:${data.aws_caller_identity.current.account_id}:server/${var.transfer_server_id}"
88+
"arn:aws:transfer:${var.region}:${data.aws_caller_identity.current.account_id}:server/${data.aws_ssm_parameter.transfer_server_id.value}"
8489
]
8590
}
8691
]

0 commit comments

Comments
 (0)