Skip to content

Commit 3c3cf71

Browse files
SSPROD-60803 - Add iam:ListAccountAliases permission for account alias retrieval
1 parent 5fb4c54 commit 3c3cf71

File tree

2 files changed

+2
-0
lines changed

2 files changed

+2
-0
lines changed

modules/onboarding/main.tf

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -65,6 +65,7 @@ resource "aws_iam_role_policy" "onboarding_role_policy" {
6565
Action = [
6666
"account:Get*",
6767
"account:List*",
68+
"iam:ListAccountAliases",
6869
]
6970
Effect = "Allow"
7071
Resource = "*"

modules/onboarding/organizational.tf

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -47,6 +47,7 @@ Resources:
4747
Action:
4848
- "account:Get*"
4949
- "account:List*"
50+
- "iam:ListAccountAliases"
5051
Resource: "*"
5152
ManagedPolicyArns:
5253
- "${local.arn_prefix}:iam::aws:policy/AWSOrganizationsReadOnlyAccess"

0 commit comments

Comments
 (0)