Skip to content

Commit fb9acaa

Browse files
SSPROD-62451 - add cspm permissions (#160)
1 parent bd044c3 commit fb9acaa

File tree

1 file changed

+21
-0
lines changed

1 file changed

+21
-0
lines changed

modules/foundational.cft.yaml

Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -194,6 +194,27 @@ Resources:
194194
- Effect: "Allow"
195195
Action: "bedrock:GetGuardrail"
196196
Resource: "*"
197+
- Effect: Allow
198+
Action: ce:GetAnomalyMonitors
199+
Resource: '*'
200+
- Effect: Allow
201+
Action: macie2:GetClassificationExportConfiguration
202+
Resource: '*'
203+
- Effect: Allow
204+
Action: compute-optimizer:GetRecommendationSummaries
205+
Resource: '*'
206+
- Effect: Allow
207+
Action: ce:GetReservationCoverage
208+
Resource: '*'
209+
- Effect: Allow
210+
Action: dlm:GetLifecyclePolicies
211+
Resource: '*'
212+
- Effect: Allow
213+
Action: eks:ListAddons
214+
Resource: '*'
215+
- Effect: Allow
216+
Action: wellarchitected:ListWorkloads
217+
Resource: '*'
197218
OnboardingRole:
198219
Type: AWS::IAM::Role
199220
Properties:

0 commit comments

Comments
 (0)