Skip to content

Commit 47cb7a2

Browse files
authored
feat: Update efs_csi policy to support resource tagging (#352)
1 parent 51eb17c commit 47cb7a2

File tree

1 file changed

+11
-0
lines changed

1 file changed

+11
-0
lines changed

modules/iam-role-for-service-accounts-eks/policies.tf

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -341,6 +341,17 @@ data "aws_iam_policy_document" "efs_csi" {
341341
}
342342
}
343343

344+
statement {
345+
actions = ["elasticfilesystem:TagResource"]
346+
resources = ["*"]
347+
348+
condition {
349+
test = "StringLike"
350+
variable = "aws:RequestTag/efs.csi.aws.com/cluster"
351+
values = ["true"]
352+
}
353+
}
354+
344355
statement {
345356
actions = ["elasticfilesystem:DeleteAccessPoint"]
346357
resources = ["*"]

0 commit comments

Comments
 (0)