Skip to content

Commit 222bfba

Browse files
authored
It 3860: Make execution role name unique (#1262)
IT-3860: Make role name unique
1 parent 2536fb7 commit 222bfba

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

org-formation/090-systems-manager/Scheduled-Script-Automation.yaml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -137,7 +137,7 @@ Resources:
137137
- Fn::Sub: arn:${AWS::Partition}:ssm:${AWS::Region}:${AWS::AccountId}:parameter*
138138
- Action: iam:PassRole
139139
Resource:
140-
- Fn::Sub: arn:${AWS::Partition}:iam::${AWS::AccountId}:role/AWS-SystemsManager-AutomationAdministrationRole
140+
- Fn::Sub: arn:${AWS::Partition}:iam::${AWS::AccountId}:role/AWS-SystemsManager-ScriptExecution-Automation-Role
141141
Effect: Allow
142142
- Action: logs:CreateLogGroup
143143
Resource:
@@ -204,7 +204,7 @@ Resources:
204204
DocumentName=f'{AutomationDocumentScriptExecution}',
205205
206206
Parameters={
207-
'AutomationAssumeRole':[f'arn:aws:iam::{MasterAccountID}:role/AWS-SystemsManager-AutomationAdministrationRole'],
207+
'AutomationAssumeRole':[f'arn:aws:iam::{MasterAccountID}:role/AWS-SystemsManager-ScriptExecution-Automation-Role'],
208208
'TargetTagName' : [TargetTagName],
209209
'TargetTagValue' : [TargetTagValue],
210210
'ScriptUrl' : [ScriptUrl],
@@ -248,7 +248,7 @@ Resources:
248248
Type: AWS::IAM::Role
249249
Condition: CreateAutomationAdministrationRoleCondition
250250
Properties:
251-
RoleName: AWS-SystemsManager-AutomationAdministrationRole
251+
RoleName: AWS-SystemsManager-ScriptExecution-Automation-Role
252252
AssumeRolePolicyDocument:
253253
Version: '2012-10-17'
254254
Statement:

0 commit comments

Comments
 (0)