Skip to content

Commit 261f670

Browse files
authored
IT-4497: try using Sub with literal role arn (#1440)
IT-4497: try using Sub with literal role arn
1 parent 1288584 commit 261f670

File tree

1 file changed

+12
-9
lines changed

1 file changed

+12
-9
lines changed

org-formation/700-aws-sso/_tasks.yaml

Lines changed: 12 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -435,17 +435,20 @@ SsoDeveloper:
435435
- 'arn:aws:iam::aws:policy/AWSBillingReadOnlyAccess'
436436
- 'arn:aws:iam::aws:policy/AmazonBedrockFullAccess'
437437
sessionDuration: 'PT12H'
438-
inlinePolicy: >-
439-
{
440-
"Version": "2012-10-17",
441-
"Statement": [
442-
{
438+
inlinePolicy:
439+
Fn::Sub:
440+
- >-
441+
{
442+
"Version": "2012-10-17",
443+
"Statement": [
444+
{
443445
"Effect": "Allow",
444446
"Action": "sts:AssumeRole",
445-
"Resource": "arn:aws:iam::050451359079:role/synapsellmprod-bedrock-full-access-ServiceRole-WpQ20TgVRPeR"
446-
}
447-
]
448-
}
447+
"Resource": "${AllowedRole}"
448+
}
449+
]
450+
}
451+
- AllowedRole: 'arn:aws:iam::050451359079:role/synapsellmprod-bedrock-full-access-ServiceRole-WpQ20TgVRPeR'
449452

450453
SsoFinanceAuditor:
451454
Type: update-stacks

0 commit comments

Comments
 (0)