Skip to content

Commit 6a80452

Browse files
committed
fix(CI): grant GHA access to create loggroup
1 parent 4fc7048 commit 6a80452

File tree

1 file changed

+4
-3
lines changed

1 file changed

+4
-3
lines changed

infra/aws-github-oidc/main.tf

+4-3
Original file line numberDiff line numberDiff line change
@@ -28,12 +28,13 @@ data "aws_iam_policy_document" "assume_role" {
2828
}
2929
}
3030

31-
data "aws_iam_policy_document" "lambda_policy" {
31+
data "aws_iam_policy_document" "iam_policy" {
3232
statement {
3333
actions = [
3434
"lambda:PublishLayerVersion",
3535
"lambda:UpdateFunctionCode",
3636
"lambda:UpdateFunctionConfiguration",
37+
"logs:CreateLogGroup",
3738
]
3839
effect = "Allow"
3940
resources = ["*"]
@@ -53,7 +54,7 @@ resource "aws_iam_role" "this" {
5354
assume_role_policy = data.aws_iam_policy_document.assume_role.json
5455

5556
inline_policy {
56-
name = "lambda_policy"
57-
policy = data.aws_iam_policy_document.lambda_policy.json
57+
name = "iam-policy"
58+
policy = data.aws_iam_policy_document.iam_policy.json
5859
}
5960
}

0 commit comments

Comments
 (0)