@@ -20,7 +20,7 @@ module "login_redirect_lambda" {
2020 name = " LoginRedirectHandler"
2121 handler = " handlers.login_redirect_handler.lambda_handler"
2222 iam_role_policy_documents = [
23- aws_iam_policy . ssm_policy_oidc . policy ,
23+ aws_iam_policy . ssm_access_policy . policy ,
2424 module . auth_state_dynamodb_table . dynamodb_read_policy_document ,
2525 module . auth_state_dynamodb_table . dynamodb_write_policy_document ,
2626 module . ndr-app-config . app_config_policy
@@ -40,7 +40,7 @@ module "login_redirect_lambda" {
4040 depends_on = [
4141 aws_api_gateway_rest_api . ndr_doc_store_api ,
4242 aws_api_gateway_resource . login_resource ,
43- aws_iam_policy . ssm_policy_oidc ,
43+ aws_iam_policy . ssm_access_policy ,
4444 module . auth_state_dynamodb_table ,
4545 module . ndr-app-config
4646 ]
@@ -89,22 +89,3 @@ module "login_redirect-alarm_topic" {
8989 depends_on = [module . login_redirect_lambda , module . sns_encryption_key ]
9090}
9191
92- resource "aws_iam_policy" "ssm_policy_oidc" {
93- name = " ${ terraform . workspace } _ssm_oidc_policy"
94- policy = jsonencode ({
95- Version = " 2012-10-17" ,
96- Statement = [
97- {
98- Effect = " Allow" ,
99- Action = [
100- " ssm:GetParameters" ,
101- " ssm:GetParameter" ,
102- " ssm:GetParametersByPath"
103- ],
104- Resource = [
105- " arn:aws:ssm:*:*:parameter/*" ,
106- ]
107- }
108- ]
109- })
110- }
0 commit comments