Skip to content

Commit 9de55fe

Browse files
committed
Cleanup permissions
1 parent 074e6cd commit 9de55fe

File tree

1 file changed

+1
-14
lines changed
  • operations/deployment/terraform/modules/aws/ecs

1 file changed

+1
-14
lines changed

operations/deployment/terraform/modules/aws/ecs/aws_ecs.tf

Lines changed: 1 addition & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -232,25 +232,12 @@ resource "aws_iam_policy" "ecs_firelens_policy" {
232232
policy = jsonencode({
233233
Version = "2012-10-17"
234234
Statement = [
235-
{
236-
Effect = "Allow"
237-
Action = [
238-
"ec2:CreateNetworkInterface",
239-
"ec2:DescribeNetworkInterfaces",
240-
"ec2:DeleteNetworkInterface",
241-
"ec2:AttachNetworkInterface",
242-
"ec2:DetachNetworkInterface"
243-
]
244-
Resource = "*"
245-
},
246235
{
247236
Effect = "Allow"
248237
Action = [
249238
"logs:CreateLogGroup",
250239
"logs:CreateLogStream",
251-
"logs:PutLogEvents",
252-
"logs:DescribeLogStreams",
253-
"logs:DescribeLogGroups"
240+
"logs:PutLogEvents"
254241
]
255242
Resource = [
256243
"arn:aws:logs:${var.aws_region_current_name}:*:log-group:/ecs/firelens*",

0 commit comments

Comments
 (0)