Skip to content

Commit 6fb5259

Browse files
committed
chore(lza-sample-config): enhance SCP statements for invocation of Lambda functions
1 parent 5dd49da commit 6fb5259

File tree

7 files changed

+10
-0
lines changed

7 files changed

+10
-0
lines changed

CHANGELOG.md

+4
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,10 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
1111

1212
- chore: upgrade github action to node20
1313

14+
### Configuration Changes
15+
16+
- chore(lza-sample-config): enhance SCP statements for invocation of Lambda functions
17+
1418
## [1.9.0] - 07-25-2024
1519

1620
### Added

reference/sample-configurations/lza-sample-config-govcloud-us/govcloud-us-config/service-control-policies/guardrails-1.json

+1
Original file line numberDiff line numberDiff line change
@@ -32,6 +32,7 @@
3232
"lambda:DeleteEventSourceMapping",
3333
"lambda:DeleteFunction",
3434
"lambda:DeleteFunctionConcurrency",
35+
"lambda:Invoke*",
3536
"lambda:PutFunctionConcurrency",
3637
"lambda:RemovePermission",
3738
"lambda:UpdateEventSourceMapping",

reference/sample-configurations/lza-sample-config/service-control-policies/guardrails-1.json

+1
Original file line numberDiff line numberDiff line change
@@ -32,6 +32,7 @@
3232
"lambda:DeleteEventSourceMapping",
3333
"lambda:DeleteFunction",
3434
"lambda:DeleteFunctionConcurrency",
35+
"lambda:Invoke*",
3536
"lambda:PutFunctionConcurrency",
3637
"lambda:RemovePermission",
3738
"lambda:UpdateEventSourceMapping",

source/packages/@aws-accelerator/accelerator/test/configs/all-enabled-delegated-admin/service-control-policies/guardrails-1.json

+1
Original file line numberDiff line numberDiff line change
@@ -32,6 +32,7 @@
3232
"lambda:DeleteEventSourceMapping",
3333
"lambda:DeleteFunction",
3434
"lambda:DeleteFunctionConcurrency",
35+
"lambda:Invoke*",
3536
"lambda:PutFunctionConcurrency",
3637
"lambda:RemovePermission",
3738
"lambda:UpdateEventSourceMapping",

source/packages/@aws-accelerator/accelerator/test/configs/all-enabled-ou-targets/service-control-policies/guardrails-1.json

+1
Original file line numberDiff line numberDiff line change
@@ -32,6 +32,7 @@
3232
"lambda:DeleteEventSourceMapping",
3333
"lambda:DeleteFunction",
3434
"lambda:DeleteFunctionConcurrency",
35+
"lambda:Invoke*",
3536
"lambda:PutFunctionConcurrency",
3637
"lambda:RemovePermission",
3738
"lambda:UpdateEventSourceMapping",

source/packages/@aws-accelerator/accelerator/test/configs/all-enabled/service-control-policies/guardrails-1.json

+1
Original file line numberDiff line numberDiff line change
@@ -32,6 +32,7 @@
3232
"lambda:DeleteEventSourceMapping",
3333
"lambda:DeleteFunction",
3434
"lambda:DeleteFunctionConcurrency",
35+
"lambda:Invoke*",
3536
"lambda:PutFunctionConcurrency",
3637
"lambda:RemovePermission",
3738
"lambda:UpdateEventSourceMapping",

source/packages/@aws-accelerator/accelerator/test/configs/snapshot-only/service-control-policies/guardrails-1.json

+1
Original file line numberDiff line numberDiff line change
@@ -32,6 +32,7 @@
3232
"lambda:DeleteEventSourceMapping",
3333
"lambda:DeleteFunction",
3434
"lambda:DeleteFunctionConcurrency",
35+
"lambda:Invoke*",
3536
"lambda:PutFunctionConcurrency",
3637
"lambda:RemovePermission",
3738
"lambda:UpdateEventSourceMapping",

0 commit comments

Comments
 (0)