We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 201688d commit a49f767Copy full SHA for a49f767
modules/iam-role-for-service-accounts-eks/policies.tf
@@ -431,11 +431,15 @@ resource "aws_iam_role_policy_attachment" "external_dns" {
431
data "aws_iam_policy_document" "external_secrets" {
432
count = var.create_role && var.attach_external_secrets_policy ? 1 : 0
433
434
+ statement {
435
+ actions = ["ssm:DescribeParameters"]
436
+ resources = ["*"]
437
+ }
438
+
439
statement {
440
actions = [
441
"ssm:GetParameter",
442
"ssm:GetParameters",
- "ssm:DescribeParameters",
443
]
444
resources = var.external_secrets_ssm_parameter_arns
445
}
0 commit comments