Skip to content

Commit 133cb5c

Browse files
authored
[bugfix] fix permissions on aws-ecs-service secrets (#143)
1 parent 10727b6 commit 133cb5c

File tree

2 files changed

+0
-30
lines changed

2 files changed

+0
-30
lines changed

aws-ecs-service-fargate/iam.tf

-15
Original file line numberDiff line numberDiff line change
@@ -26,26 +26,11 @@ resource "aws_iam_role_policy_attachment" "task_execution_role" {
2626
data "aws_iam_policy_document" "registry_secretsmanager" {
2727
count = var.registry_secretsmanager_arn != null ? 1 : 0
2828

29-
statement {
30-
actions = [
31-
"kms:Decrypt",
32-
]
33-
34-
resources = [var.registry_secretsmanager_arn]
35-
}
36-
3729
statement {
3830
actions = [
3931
"secretsmanager:GetSecretValue",
4032
]
4133

42-
# Limit to only current version of the secret
43-
condition {
44-
test = "ForAnyValue:StringEquals"
45-
variable = "secretsmanager:VersionStage"
46-
values = ["AWSCURRENT"]
47-
}
48-
4934
resources = [var.registry_secretsmanager_arn]
5035
}
5136
}

aws-ecs-service/iam.tf

-15
Original file line numberDiff line numberDiff line change
@@ -27,26 +27,11 @@ resource "aws_iam_role_policy_attachment" "task_execution_role" {
2727
data "aws_iam_policy_document" "registry_secretsmanager" {
2828
count = var.registry_secretsmanager_arn != null ? 1 : 0
2929

30-
statement {
31-
actions = [
32-
"kms:Decrypt",
33-
]
34-
35-
resources = [var.registry_secretsmanager_arn]
36-
}
37-
3830
statement {
3931
actions = [
4032
"secretsmanager:GetSecretValue",
4133
]
4234

43-
# Limit to only current version of the secret
44-
condition {
45-
test = "ForAnyValue:StringEquals"
46-
variable = "secretsmanager:VersionStage"
47-
values = ["AWSCURRENT"]
48-
}
49-
5035
resources = [var.registry_secretsmanager_arn]
5136
}
5237
}

0 commit comments

Comments
 (0)