Skip to content

Commit ddac921

Browse files
TASK AS/AJ Update github iam role policy permissions
- Remove r53 permissions in test env policy - Add firehose permissions in test env policy
1 parent 422d695 commit ddac921

File tree

2 files changed

+10
-10
lines changed

2 files changed

+10
-10
lines changed

infrastructure/environments/test/test-github-iam-role-policy.json

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -125,6 +125,12 @@
125125
"events:PutTargets",
126126
"events:RemoveTargets",
127127
"events:TagResource",
128+
"firehose:CreateDeliveryStream",
129+
"firehose:DescribeDeliveryStream",
130+
"firehose:ListTagsForDeliveryStream",
131+
"firehose:StartDeliveryStreamEncryption",
132+
"firehose:TagDeliveryStream",
133+
"firehose:UpdateDestination",
128134
"iam:AttachRolePolicy",
129135
"iam:CreatePolicy",
130136
"iam:CreatePolicyVersion",
@@ -189,15 +195,6 @@
189195
"logs:PutMetricFilter",
190196
"logs:PutRetentionPolicy",
191197
"logs:PutSubscriptionFilter",
192-
"route53:AssociateVPCWithHostedZone",
193-
"route53:ChangeResourceRecordSets",
194-
"route53:ChangeTagsForResource",
195-
"route53:CreateHostedZone",
196-
"route53:DeleteHostedZone",
197-
"route53:GetChange",
198-
"route53:GetHostedZone",
199-
"route53:ListResourceRecordSets",
200-
"route53:ListTagsForResource",
201198
"s3:CreateBucket",
202199
"s3:DeleteBucket",
203200
"s3:DeleteBucketPolicy",
@@ -225,6 +222,9 @@
225222
"s3:PutBucketTagging",
226223
"s3:PutBucketVersioning",
227224
"s3:PutObject",
225+
"secretsmanager:DescribeSecret",
226+
"secretsmanager:GetResourcePolicy",
227+
"secretsmanager:GetSecretValue",
228228
"SNS:CreateTopic",
229229
"SNS:DeleteTopic",
230230
"SNS:GetTopicAttributes",

infrastructure/github-iam-role-policy.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -99,8 +99,8 @@
9999
"lambda:ListTags",
100100
"lambda:ListVersionsByFunction",
101101
"lambda:PublishVersion",
102-
"lambda:PutFunctionEventInvokeConfig",
103102
"lambda:PutFunctionConcurrency",
103+
"lambda:PutFunctionEventInvokeConfig",
104104
"lambda:RemovePermission",
105105
"lambda:TagResource",
106106
"lambda:UpdateAlias",

0 commit comments

Comments
 (0)