Skip to content

Commit b79cd80

Browse files
[PRMP-1587] - Remove DeleteItem and BatchWriteItem from iam policy
1 parent 1d3fcc9 commit b79cd80

File tree

1 file changed

+2
-4
lines changed
  • infrastructure/modules/dynamo_db

1 file changed

+2
-4
lines changed

infrastructure/modules/dynamo_db/main.tf

Lines changed: 2 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -122,13 +122,11 @@ data "aws_iam_policy_document" "dynamodb_write_policy" {
122122
}
123123
}
124124

125-
data "aws_iam_policy_document" "dynamodb_write_without_update_policy" {
125+
data "aws_iam_policy_document" "dynamodb_put_item_policy" {
126126
statement {
127127
effect = "Allow"
128128
actions = [
129-
"dynamodb:PutItem",
130-
"dynamodb:DeleteItem",
131-
"dynamodb:BatchWriteItem"
129+
"dynamodb:PutItem"
132130
]
133131
resources = [
134132
aws_dynamodb_table.ndr_dynamodb_table.arn,

0 commit comments

Comments
 (0)