Skip to content

Commit ca2a3cd

Browse files
committed
[PRMP-1318] replace aws_iam_policy references with local variables for SSM access policies
Signed-off-by: NogaNHS <127490765+NogaNHS@users.noreply.github.com>
1 parent fae4e6d commit ca2a3cd

32 files changed

+69
-35
lines changed

infrastructure/lambda-back-channel-logout.tf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ module "back_channel_logout_lambda" {
1414
name = "BackChannelLogoutHandler"
1515
handler = "handlers.back_channel_logout_handler.lambda_handler"
1616
iam_role_policy_documents = [
17-
aws_iam_policy.ssm_access_policy.policy,
17+
local.ssm_access_policy_policy,
1818
module.auth_session_dynamodb_table.dynamodb_read_policy_document,
1919
module.auth_session_dynamodb_table.dynamodb_write_policy_document,
2020
module.ndr-app-config.app_config_policy

infrastructure/lambda-bulk-upload-metadata-processor.tf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ module "bulk-upload-metadata-processor-lambda" {
1515
module.lg-bulk-upload-expedite-metadata-queue.sqs_read_policy_document,
1616
module.lg-bulk-upload-expedite-metadata-queue.sqs_write_policy_document,
1717
module.ndr-app-config.app_config_policy,
18-
aws_iam_policy.ssm_access_policy.policy,
18+
local.ssm_access_policy_policy,
1919
data.aws_iam_policy.aws_lambda_vpc_access_execution_role.policy,
2020
]
2121

infrastructure/lambda-bulk-upload.tf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ module "bulk-upload-lambda" {
1919
module.sqs-lg-bulk-upload-invalid-queue.sqs_write_policy_document,
2020
module.lg-bulk-upload-expedite-metadata-queue.sqs_write_policy_document,
2121
module.lg-bulk-upload-expedite-metadata-queue.sqs_read_policy_document,
22-
aws_iam_policy.ssm_access_policy.policy,
22+
local.ssm_access_policy_policy,
2323
module.ndr-app-config.app_config_policy
2424
]
2525
kms_deletion_window = var.kms_deletion_window

infrastructure/lambda-create-doc-ref.tf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -56,7 +56,7 @@ module "create-doc-ref-lambda" {
5656
module.stitch_metadata_reference_dynamodb_table.dynamodb_write_policy_document,
5757
module.lloyd_george_reference_dynamodb_table.dynamodb_write_policy_document,
5858
module.lloyd_george_reference_dynamodb_table.dynamodb_read_policy_document,
59-
aws_iam_policy.ssm_access_policy.policy,
59+
local.ssm_access_policy_policy,
6060
module.ndr-app-config.app_config_policy,
6161
]
6262
kms_deletion_window = var.kms_deletion_window

infrastructure/lambda-document-status-check-result.tf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -57,7 +57,7 @@ module "document-status-check-lambda" {
5757
handler = "handlers.document_status_check_handler.lambda_handler"
5858
iam_role_policy_documents = [
5959
module.ndr-app-config.app_config_policy,
60-
aws_iam_policy.ssm_access_policy.policy,
60+
local.ssm_access_policy_policy,
6161
module.document_reference_dynamodb_table.dynamodb_read_policy_document,
6262
module.document_reference_dynamodb_table.dynamodb_write_policy_document,
6363
module.lloyd_george_reference_dynamodb_table.dynamodb_read_policy_document,

infrastructure/lambda-document-upload-check.tf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ module "document_upload_check_lambda" {
77
module.ndr-bulk-staging-store.s3_write_policy_document,
88
module.ndr-lloyd-george-store.s3_write_policy_document,
99
module.pdm-document-store.s3_write_policy_document,
10-
aws_iam_policy.ssm_access_policy.policy,
10+
local.ssm_access_policy_policy,
1111
module.lloyd_george_reference_dynamodb_table.dynamodb_read_policy_document,
1212
module.lloyd_george_reference_dynamodb_table.dynamodb_write_policy_document,
1313
data.aws_iam_policy.aws_lambda_vpc_access_execution_role.policy,

infrastructure/lambda-dynamodb-migration.tf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ module "migration-dynamodb-lambda" {
99
module.bulk_upload_report_dynamodb_table.dynamodb_read_policy_document,
1010
module.ndr-bulk-staging-store.s3_read_policy_document,
1111
module.ndr-lloyd-george-store.s3_read_policy_document,
12-
aws_iam_policy.ssm_access_policy.policy,
12+
local.ssm_access_policy_policy,
1313
module.ndr-app-config.app_config_policy,
1414
module.migration-failed-items-store.s3_write_policy_document
1515
]

infrastructure/lambda-feature-flags.tf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -57,7 +57,7 @@ module "feature-flags-lambda" {
5757
handler = "handlers.feature_flags_handler.lambda_handler"
5858
iam_role_policy_documents = [
5959
module.ndr-app-config.app_config_policy,
60-
aws_iam_policy.ssm_access_policy.policy,
60+
local.ssm_access_policy_policy,
6161
]
6262
kms_deletion_window = var.kms_deletion_window
6363
rest_api_id = aws_api_gateway_rest_api.ndr_doc_store_api.id

infrastructure/lambda-get-doc-ref.tf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -45,7 +45,7 @@ module "get-doc-ref-lambda" {
4545
iam_role_policy_documents = [
4646
module.ndr-lloyd-george-store.s3_read_policy_document,
4747
module.lloyd_george_reference_dynamodb_table.dynamodb_read_policy_document,
48-
aws_iam_policy.ssm_access_policy.policy,
48+
local.ssm_access_policy_policy,
4949
module.ndr-app-config.app_config_policy,
5050
module.cloudfront_edge_dynamodb_table.dynamodb_write_policy_document
5151
]

infrastructure/lambda-get-document-fhir.tf

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -40,8 +40,8 @@ module "get-doc-fhir-lambda" {
4040
module.ndr-app-config.app_config_policy,
4141
module.lloyd_george_reference_dynamodb_table.dynamodb_read_policy_document,
4242
module.core_dynamodb_table.dynamodb_read_policy_document,
43-
aws_iam_policy.ssm_access_policy.policy,
44-
aws_iam_policy.mtls_access_ssm_policy.policy,
43+
local.ssm_access_policy_policy,
44+
local.mtls_access_ssm_policy_policy,
4545
module.ndr-lloyd-george-store.s3_read_policy_document,
4646
module.pdm-document-store.s3_read_policy_document,
4747
]

0 commit comments

Comments
 (0)