Skip to content

Commit 5a84f58

Browse files
authored
add ssm get params permission to service role (#19)
1 parent 6acd27b commit 5a84f58

File tree

1 file changed

+4
-3
lines changed

1 file changed

+4
-3
lines changed

main.tf

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -106,15 +106,16 @@ data "aws_iam_policy_document" "permissions" {
106106
sid = ""
107107

108108
actions = [
109-
"logs:CreateLogGroup",
110-
"logs:CreateLogStream",
111-
"logs:PutLogEvents",
112109
"ecr:BatchCheckLayerAvailability",
113110
"ecr:CompleteLayerUpload",
114111
"ecr:GetAuthorizationToken",
115112
"ecr:InitiateLayerUpload",
116113
"ecr:PutImage",
117114
"ecr:UploadLayerPart",
115+
"logs:CreateLogGroup",
116+
"logs:CreateLogStream",
117+
"logs:PutLogEvents",
118+
"ssm:GetParameters",
118119
]
119120

120121
effect = "Allow"

0 commit comments

Comments
 (0)