File tree Expand file tree Collapse file tree 1 file changed +9
-1
lines changed Expand file tree Collapse file tree 1 file changed +9
-1
lines changed Original file line number Diff line number Diff line change @@ -26,14 +26,22 @@ locals {
26
26
resources = [var.kms_key_arn]
27
27
}
28
28
29
+ lambda_policy_document_securityhub = {
30
+ sid = " AllowSecurityHub"
31
+ effect = " Allow"
32
+ actions = [" securityhub:BatchImportFindings" ]
33
+ resources = [" *" ]
34
+ }
35
+
29
36
lambda_handler = try (split (" ." , basename (var. lambda_source_path ))[0 ], " notify_slack" )
30
37
}
31
38
32
39
data "aws_iam_policy_document" "lambda" {
33
40
count = var. create ? 1 : 0
34
41
35
42
dynamic "statement" {
36
- for_each = concat ([local . lambda_policy_document ], var. kms_key_arn != " " ? [local . lambda_policy_document_kms ] : [])
43
+ for_each = concat ([local . lambda_policy_document ,
44
+ local . lambda_policy_document_securityhub ], var. kms_key_arn != " " ? [local . lambda_policy_document_kms ] : [])
37
45
content {
38
46
sid = statement. value . sid
39
47
effect = statement. value . effect
You can’t perform that action at this time.
0 commit comments