Skip to content

Commit

Permalink
chore: aws-ecs: updated permissions
Browse files Browse the repository at this point in the history
  • Loading branch information
fidiego committed Dec 9, 2024
1 parent 73a9b67 commit 5f2cae4
Showing 1 changed file with 18 additions and 0 deletions.
18 changes: 18 additions & 0 deletions pkg/sandboxes/aws-ecs/iam.go
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,10 @@ import perms "github.com/nuonco/sandboxes/pkg/sandboxes/permissions"
// provision role permissions specific to this sandbox
var ProvisionPermissions = append([]string{
"application-autoscaling:*",
"acm:DescribeCertificate",
"acm:RequestCertificate",
"acm:ListTagsForCertificate",
"acm:AddTagsToCertificate",
"ec2:DescribeAddressesAttribute",
"ec2:CreateNetworkAclEntry",
"ec2:DeleteNetworkAclEntry",
Expand All @@ -24,12 +28,26 @@ var ProvisionPermissions = append([]string{
"ecs:DescribeTaskDefinition",
"ecs:RegisterTaskDefinition",
"ecs:ListTaskDefinitions",
"elasticloadbalancing:CreateLoadBalancer",
"elasticloadbalancing:DeleteLoadBalancer",
"elasticloadbalancing:DescribeLoadBalancerAttributes",
"elasticloadbalancing:ModifyLoadBalancerAttributes",
"elasticloadbalancing:DescribeLoadBalancers",
"elasticloadbalancing:AddTags",
"elasticloadbalancing:DescribeTags",
"elasticloadbalancing:CreateTargetGroup",
"elasticloadbalancing:DescribeTargetGroupAttributes",
"elasticloadbalancing:ModifyTargetGroupAttributes",
"elasticloadbalancing:DescribeTargetGroups",
"kms:CreateGrant",
"logs:ListTagsForResource",
"rds:CreateDBSubnetGroup",
"rds:DeleteDBSubnetGroup",
"rds:DescribeDBSubnetGroups",
"rds:ListTagsForResource",
"rds:AddTagsToResource",
"servicediscovery:CreateHttpNamespace",
"servicediscovery:GetOperation",
}, perms.BaseProvisionPermissions...)

// Full provision rol policy for this sandbox
Expand Down

0 comments on commit 5f2cae4

Please sign in to comment.