Skip to content

Commit 9bc8032

Browse files
authored
fix: Fix IAM policy for External Secrets (#28)
Signed-off-by: Carlos Lopez <[email protected]>
1 parent a8b1ec6 commit 9bc8032

File tree

1 file changed

+2
-3
lines changed

1 file changed

+2
-3
lines changed

external_secrets.tf

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -36,7 +36,7 @@ data "aws_iam_policy_document" "external_secrets" {
3636
for_each = length(var.external_secrets_secrets_manager_arns) > 0 ? [1] : []
3737

3838
content {
39-
actions = ["secretsmanager:ListSecrets"]
39+
actions = ["secretsmanager:ListSecrets", "secretsmanager:BatchGetSecretValue"]
4040
resources = ["*"]
4141
}
4242
}
@@ -49,8 +49,7 @@ data "aws_iam_policy_document" "external_secrets" {
4949
"secretsmanager:GetResourcePolicy",
5050
"secretsmanager:GetSecretValue",
5151
"secretsmanager:DescribeSecret",
52-
"secretsmanager:ListSecretVersionIds",
53-
"secretsmanager:BatchGetSecretValue",
52+
"secretsmanager:ListSecretVersionIds"
5453
]
5554

5655
resources = var.external_secrets_secrets_manager_arns

0 commit comments

Comments
 (0)