@@ -33,27 +33,6 @@ resource "aws_iam_role_policy" "github_runner_execution_role_policy" {
3333 aws_cloudwatch_log_group.github_runner.arn,
3434 " ${ aws_cloudwatch_log_group . github_runner . arn } *"
3535 ]
36- },
37- {
38- Effect = " Allow"
39- Action = [
40- " ecr:GetAuthorizationToken" ,
41- " ecr:BatchCheckLayerAvailability" ,
42- " ecr:GetDownloadUrlForLayer" ,
43- " ecr:BatchGetImage" ,
44- " ecr:GetDownloadUrlForLayer" ,
45- " ecr:BatchGetImage" ,
46- " ecr:BatchCheckLayerAvailability" ,
47- " ecr:PutImage" ,
48- " ecr:InitiateLayerUpload" ,
49- " ecr:UploadLayerPart" ,
50- " ecr:CompleteLayerUpload" ,
51- " ecr:DescribeRepositories" ,
52- " ecr:GetRepositoryPolicy" ,
53- " ecr:ListImages" ,
54- " ecr:BatchDeleteImage" ,
55- ]
56- Resource = " *"
5736 }
5837 ]
5938 })
@@ -92,6 +71,27 @@ resource "aws_iam_role_policy" "github_runner_task_role_policy" {
9271 " ssmmessages:*"
9372 ]
9473 Resource = " *"
74+ },
75+ {
76+ Effect = " Allow"
77+ Action = [
78+ " ecr:GetAuthorizationToken" ,
79+ " ecr:BatchCheckLayerAvailability" ,
80+ " ecr:GetDownloadUrlForLayer" ,
81+ " ecr:BatchGetImage" ,
82+ " ecr:GetDownloadUrlForLayer" ,
83+ " ecr:BatchGetImage" ,
84+ " ecr:BatchCheckLayerAvailability" ,
85+ " ecr:PutImage" ,
86+ " ecr:InitiateLayerUpload" ,
87+ " ecr:UploadLayerPart" ,
88+ " ecr:CompleteLayerUpload" ,
89+ " ecr:DescribeRepositories" ,
90+ " ecr:GetRepositoryPolicy" ,
91+ " ecr:ListImages" ,
92+ " ecr:BatchDeleteImage" ,
93+ ]
94+ Resource = " *"
9595 }
9696 ]
9797 })
0 commit comments