@@ -210,45 +210,45 @@ Resources:
210210 Condition:
211211 StringEquals:
212212 sts:ExternalId: !Ref ExternalID
213- ECRPolicy:
214- Type: AWS::IAM::Policy
215- Properties:
216- PolicyName: !Sub sysdig-vm-workload-scanning-${NameSuffix}-ecr
217- Roles:
218- - !Ref ScanningRole
219- PolicyDocument:
220- Version: '2012-10-17'
221- Statement:
222- - Effect: Allow
223- Action:
224- - ecr:GetDownloadUrlForLayer
225- - ecr:BatchGetImage
226- - ecr:BatchCheckLayerAvailability
227- - ecr:ListImages
228- - ecr:GetAuthorizationToken
229- Resource: '*'
230- LambdaPolicy:
231- Type: AWS::IAM::Policy
232- Condition: LambdaScanningEnabled
233- Properties:
234- PolicyName: !Sub sysdig-vm-workload-scanning-${NameSuffix}-lambda
235- Roles:
236- - !Ref ScanningRole
237- PolicyDocument:
238- Version: '2012-10-17'
239- Statement:
240- - Effect: Allow
241- Action:
242- - lambda:GetFunction
243- - lambda:GetFunctionConfiguration
244- - lambda:GetRuntimeManagementConfig
245- - lambda:ListFunctions
246- - lambda:ListTagsForResource
247- - lambda:GetLayerVersionByArn
248- - lambda:GetLayerVersion
249- - lambda:ListLayers
250- - lambda:ListLayerVersions
251- Resource: '*'
213+ ECRPolicy:
214+ Type: AWS::IAM::Policy
215+ Properties:
216+ PolicyName: !Sub sysdig-vm-workload-scanning-${NameSuffix}-ecr
217+ Roles:
218+ - !Ref ScanningRole
219+ PolicyDocument:
220+ Version: '2012-10-17'
221+ Statement:
222+ - Effect: Allow
223+ Action:
224+ - ecr:GetDownloadUrlForLayer
225+ - ecr:BatchGetImage
226+ - ecr:BatchCheckLayerAvailability
227+ - ecr:ListImages
228+ - ecr:GetAuthorizationToken
229+ Resource: '*'
230+ LambdaPolicy:
231+ Type: AWS::IAM::Policy
232+ Condition: LambdaScanningEnabled
233+ Properties:
234+ PolicyName: !Sub sysdig-vm-workload-scanning-${NameSuffix}-lambda
235+ Roles:
236+ - !Ref ScanningRole
237+ PolicyDocument:
238+ Version: '2012-10-17'
239+ Statement:
240+ - Effect: Allow
241+ Action:
242+ - lambda:GetFunction
243+ - lambda:GetFunctionConfiguration
244+ - lambda:GetRuntimeManagementConfig
245+ - lambda:ListFunctions
246+ - lambda:ListTagsForResource
247+ - lambda:GetLayerVersionByArn
248+ - lambda:GetLayerVersion
249+ - lambda:ListLayers
250+ - lambda:ListLayerVersions
251+ Resource: '*'
252252
253253
254254
0 commit comments