Skip to content

Commit 5664e54

Browse files
brent-anyscalehongchaodeng
authored andcommitted
fix: IAM - Remove constraint on SetRulePriorities for ELBs (#74)
The SetRulePriorities action is required for the Anyscale control plane to modify the priority of rules in the Anyscale ALB. This removes the tagging constraint for the `elasticloadbalancing:SetRulePriorities` action as tag constraints for this action are not supported by AWS. On branch brent/fix-service-iam-policy Changes to be committed: modified: modules/aws-anyscale-iam/anyscale-control_plane-services-v2.tmpl
1 parent faa92be commit 5664e54

File tree

1 file changed

+3
-5
lines changed

1 file changed

+3
-5
lines changed

modules/aws-anyscale-iam/anyscale-control_plane-services-v2.tmpl

Lines changed: 3 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -200,13 +200,14 @@
200200
]
201201
},
202202
{
203-
"Sid": "ELBDirectCreate",
203+
"Sid": "ELBDirectCreateUpdate",
204204
"Effect": "Allow",
205205
"Action": [
206206
"elasticloadbalancing:CreateRule",
207207
"elasticloadbalancing:CreateListener",
208208
"elasticloadbalancing:CreateLoadBalancer",
209-
"elasticloadbalancing:CreateTargetGroup"
209+
"elasticloadbalancing:CreateTargetGroup",
210+
"elasticloadbalancing:SetRulePriorities"
210211
],
211212
"Resource": [
212213
"arn:aws:elasticloadbalancing:*:${account_id}:loadbalancer/app/anyscale*",
@@ -224,7 +225,6 @@
224225
"elasticloadbalancing:RemoveTags",
225226
"elasticloadbalancing:ModifyRule",
226227
"elasticloadbalancing:DeleteRule",
227-
"elasticloadbalancing:SetRulePriorities",
228228
"elasticloadbalancing:ModifyListener",
229229
"elasticloadbalancing:DeleteListener",
230230
"elasticloadbalancing:DeleteLoadBalancer",
@@ -247,7 +247,6 @@
247247
}
248248
%{ endif ~}
249249
%{ if cloud_id_provided == true ~}
250-
251250
{
252251
"Sid": "ELBDirectModifyDelete",
253252
"Effect": "Allow",
@@ -256,7 +255,6 @@
256255
"elasticloadbalancing:RemoveTags",
257256
"elasticloadbalancing:ModifyRule",
258257
"elasticloadbalancing:DeleteRule",
259-
"elasticloadbalancing:SetRulePriorities",
260258
"elasticloadbalancing:ModifyListener",
261259
"elasticloadbalancing:DeleteListener",
262260
"elasticloadbalancing:DeleteLoadBalancer",

0 commit comments

Comments
 (0)