Skip to content

Commit

Permalink
Add sqs and secrets manager to boundary policy
Browse files Browse the repository at this point in the history
  • Loading branch information
prabhukiran9999 committed Oct 18, 2024
1 parent 8803230 commit d87d42d
Showing 1 changed file with 28 additions and 9 deletions.
37 changes: 28 additions & 9 deletions modules/iam-users/main.tf
Original file line number Diff line number Diff line change
Expand Up @@ -209,18 +209,37 @@ resource "aws_iam_policy" "s3_full_access_boundary" {
Resource = "*"
},
{
Sid = "SSMandKMSAccess",
Effect = "Allow",
Action = [
"Sid" : "SQSFullAccess",
"Effect" : "Allow",
"Action" : "sqs:*",
"Resource" : "*"
},
{
"Sid" : "AllowSecretsManagerFullAccessToExternalSecrets",
"Effect" : "Allow",
"Action" : [
"secretsmanager:*"
],
"Resource" : "arn:aws:secretsmanager:*:*:secret:external/*"
},
{
"Sid" : "SSMAccess",
"Effect" : "Allow",
"Action" : [
"ssm:GetParameter",
"ssm:GetParameters",
"ssm:GetParametersByPath",
"kms:Decrypt"
"ssm:GetParametersByPath"
],
"Resource" : "arn:aws:ssm:*:*:parameter/iam_users/*"
},
{
"Sid" : "KMSAccess",
"Effect" : "Allow",
"Action" : [
"kms:Decrypt",
"kms:Encrypt"
],
Resource = [
"arn:aws:ssm:*:*:parameter/iam_users/*",
"arn:aws:kms:*:*:key/*"
]
"Resource" : "arn:aws:kms:*:*:key/*"
}
]
})
Expand Down

0 comments on commit d87d42d

Please sign in to comment.