File tree 2 files changed +0
-30
lines changed
2 files changed +0
-30
lines changed Original file line number Diff line number Diff line change @@ -26,26 +26,11 @@ resource "aws_iam_role_policy_attachment" "task_execution_role" {
26
26
data "aws_iam_policy_document" "registry_secretsmanager" {
27
27
count = var. registry_secretsmanager_arn != null ? 1 : 0
28
28
29
- statement {
30
- actions = [
31
- " kms:Decrypt" ,
32
- ]
33
-
34
- resources = [var . registry_secretsmanager_arn ]
35
- }
36
-
37
29
statement {
38
30
actions = [
39
31
" secretsmanager:GetSecretValue" ,
40
32
]
41
33
42
- # Limit to only current version of the secret
43
- condition {
44
- test = " ForAnyValue:StringEquals"
45
- variable = " secretsmanager:VersionStage"
46
- values = [" AWSCURRENT" ]
47
- }
48
-
49
34
resources = [var . registry_secretsmanager_arn ]
50
35
}
51
36
}
Original file line number Diff line number Diff line change @@ -27,26 +27,11 @@ resource "aws_iam_role_policy_attachment" "task_execution_role" {
27
27
data "aws_iam_policy_document" "registry_secretsmanager" {
28
28
count = var. registry_secretsmanager_arn != null ? 1 : 0
29
29
30
- statement {
31
- actions = [
32
- " kms:Decrypt" ,
33
- ]
34
-
35
- resources = [var . registry_secretsmanager_arn ]
36
- }
37
-
38
30
statement {
39
31
actions = [
40
32
" secretsmanager:GetSecretValue" ,
41
33
]
42
34
43
- # Limit to only current version of the secret
44
- condition {
45
- test = " ForAnyValue:StringEquals"
46
- variable = " secretsmanager:VersionStage"
47
- values = [" AWSCURRENT" ]
48
- }
49
-
50
35
resources = [var . registry_secretsmanager_arn ]
51
36
}
52
37
}
You can’t perform that action at this time.
0 commit comments