Skip to content

Commit 7e141c7

Browse files
gmarcianihanwen-pcluste
authored andcommitted
[Isolated Regions] [Policies] Omit AWSXRayDaemonWriteAccess policy of ParallelClusterLambdaRole in US isolated regions as the policy is not supported in these regions.
Signed-off-by: Giacomo Marciani <[email protected]>
1 parent 0527b89 commit 7e141c7

File tree

1 file changed

+7
-1
lines changed

1 file changed

+7
-1
lines changed

cloudformation/policies/parallelcluster-policies.yaml

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -100,6 +100,9 @@ Conditions:
100100
EnableIamPolicy: !Or
101101
- !Equals [!Ref EnableIamAdminAccess, true]
102102
- !Condition EnablePermissionsBoundary
103+
InIsolatedRegion: !Or
104+
- !Equals [!Ref AWS::Partition, 'aws-iso']
105+
- !Equals [!Ref AWS::Partition, 'aws-iso-b']
103106

104107
Resources:
105108
### IAM POLICIES
@@ -184,7 +187,10 @@ Resources:
184187
Service: lambda.amazonaws.com
185188
ManagedPolicyArns:
186189
# Required for Lambda logging and XRay
187-
- !Sub arn:${AWS::Partition}:iam::aws:policy/AWSXRayDaemonWriteAccess
190+
- !If
191+
- InIsolatedRegion
192+
- !Ref AWS::NoValue
193+
- !Sub arn:${AWS::Partition}:iam::aws:policy/AWSXRayDaemonWriteAccess
188194
- !Sub arn:${AWS::Partition}:iam::aws:policy/service-role/AWSLambdaBasicExecutionRole
189195
# Required to run ParallelCluster functionalities
190196
- !Ref ParallelClusterClusterPolicy

0 commit comments

Comments
 (0)