Skip to content

Commit b0b65c6

Browse files
authored
bug: allow external secrets to get secrets from AWS Secrets Manager (#241)
1 parent 44835b9 commit b0b65c6

File tree

1 file changed

+7
-1
lines changed

1 file changed

+7
-1
lines changed

terraform/layer2-k8s/eks-external-secrets.tf

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -90,7 +90,13 @@ module "aws_iam_external_secrets" {
9090
"Statement" : [
9191
{
9292
"Effect" : "Allow",
93-
"Action" : "ssm:GetParameter",
93+
"Action" : [
94+
"ssm:GetParameter",
95+
"secretsmanager:GetResourcePolicy",
96+
"secretsmanager:GetSecretValue",
97+
"secretsmanager:DescribeSecret",
98+
"secretsmanager:ListSecretVersionIds"
99+
],
94100
"Resource" : "*"
95101
}
96102
]

0 commit comments

Comments
 (0)