Skip to content

Commit 61343d7

Browse files
committedAug 26, 2024··
chore(CI): provide more required perms to GHA
1 parent 51e4dff commit 61343d7

File tree

1 file changed

+20
-0
lines changed

1 file changed

+20
-0
lines changed
 

‎infra/aws-github-oidc/main.tf

+20
Original file line numberDiff line numberDiff line change
@@ -31,10 +31,30 @@ data "aws_iam_policy_document" "assume_role" {
3131
data "aws_iam_policy_document" "iam_policy" {
3232
statement {
3333
actions = [
34+
"apigateway:DELETE",
35+
"apigateway:GET",
36+
"apigateway:POST",
37+
"apigateway:PUT",
38+
"iam:AttachRolePolicy",
39+
"iam:CreateRole",
40+
"iam:DeleteRolePolicy",
41+
"iam:DetachRolePolicy",
42+
"iam:GetRole",
43+
"iam:PassRole",
44+
"iam:PutRolePolicy",
45+
"lambda:AddPermission",
46+
"lambda:CreateFunction",
47+
"lambda:DeleteFunction",
48+
"lambda:GetFunction",
3449
"lambda:PublishLayerVersion",
50+
"lambda:RemovePermission",
3551
"lambda:UpdateFunctionCode",
3652
"lambda:UpdateFunctionConfiguration",
3753
"logs:CreateLogGroup",
54+
"logs:DeleteLogGroup",
55+
"logs:DeleteRetentionPolicy",
56+
"logs:DescribeLogGroups",
57+
"logs:ListTagsForResource",
3858
"logs:PutRetentionPolicy",
3959
]
4060
effect = "Allow"

0 commit comments

Comments
 (0)
Please sign in to comment.