Skip to content

Commit 3b34a3d

Browse files
committed
updated permissions
1 parent 60342c0 commit 3b34a3d

File tree

1 file changed

+2
-1
lines changed
  • cloud-foundation/modules/cloud-foundation-library/identity/module

1 file changed

+2
-1
lines changed

cloud-foundation/modules/cloud-foundation-library/identity/module/security.tf

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -90,7 +90,8 @@ resource "oci_identity_policy" "security" {
9090
]),
9191
# security users in security compartment
9292
formatlist("allow group ${oci_identity_group.security_service[0].name} to %s in compartment ${oci_identity_compartment.security[0].name}", [
93-
"read vss-family", "use bastion", "manage bastion-session", "read vaults", "inspect keys", "manage instance-images",
93+
"read vss-family", "use bastion", "manage bastion-session", "use vaults", "inspect keys",
94+
"manage secrets", "manage secret-versions", "manage instance-images",
9495
]),
9596
)
9697
}

0 commit comments

Comments
 (0)