Skip to content

Commit e4810ed

Browse files
Add GitHub Actions role to KMS key policy principals
1 parent 6d8b558 commit e4810ed

File tree

2 files changed

+2
-2
lines changed

2 files changed

+2
-2
lines changed

examples/simple/main.tf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -29,7 +29,7 @@ locals {
2929
]
3030
resources = ["arn:aws:kms:*:${data.aws_caller_identity.current.account_id}:key/*"]
3131
principals = {
32-
"AWS" = tolist(data.aws_iam_roles.administrator_access.arns)
32+
"AWS" = concat(tolist(data.aws_iam_roles.administrator_access.arns), ["arn:aws:iam::020127659860:role/github-actions-deploy-role-terraform"])
3333
}
3434
}
3535
}

examples/with_condition/main.tf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -36,7 +36,7 @@ locals {
3636
]
3737
resources = ["arn:aws:kms:*:${data.aws_caller_identity.current.account_id}:key/*"]
3838
principals = {
39-
"AWS" = tolist(data.aws_iam_roles.administrator_access.arns)
39+
"AWS" = concat(tolist(data.aws_iam_roles.administrator_access.arns), ["arn:aws:iam::020127659860:role/github-actions-deploy-role-terraform"])
4040
}
4141
condition = [
4242
{

0 commit comments

Comments
 (0)