Skip to content

Commit 27e8689

Browse files
authored
fix: Fixes resource permissions for resource-policy (#1185)
1 parent bc65709 commit 27e8689

File tree

2 files changed

+14
-6
lines changed

2 files changed

+14
-6
lines changed

cfn-resources/resource-policy/mongodb-atlas-resourcepolicy.json

Lines changed: 12 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -110,16 +110,24 @@
110110
"sourceUrl": "https://github.com/mongodb/mongodbatlas-cloudformation-resources/tree/master/cfn-resources/resource-policy",
111111
"handlers": {
112112
"create": {
113-
"permissions": []
113+
"permissions": [
114+
"secretsmanager:GetSecretValue"
115+
]
114116
},
115117
"read": {
116-
"permissions": []
118+
"permissions": [
119+
"secretsmanager:GetSecretValue"
120+
]
117121
},
118122
"update": {
119-
"permissions": []
123+
"permissions": [
124+
"secretsmanager:GetSecretValue"
125+
]
120126
},
121127
"delete": {
122-
"permissions": []
128+
"permissions": [
129+
"secretsmanager:GetSecretValue"
130+
]
123131
}
124132
},
125133
"primaryIdentifier": [

cfn-resources/resource-policy/resource-role.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -28,9 +28,9 @@ Resources:
2828
PolicyDocument:
2929
Version: '2012-10-17'
3030
Statement:
31-
- Effect: Deny
31+
- Effect: Allow
3232
Action:
33-
- "*"
33+
- "secretsmanager:GetSecretValue"
3434
Resource: "*"
3535
Outputs:
3636
ExecutionRoleArn:

0 commit comments

Comments
 (0)