File tree 2 files changed +0
-30
lines changed
2 files changed +0
-30
lines changed Original file line number Diff line number Diff line change @@ -27,26 +27,11 @@ resource "aws_iam_role_policy_attachment" "task_execution_role" {
27
27
data "aws_iam_policy_document" "registry_secretsmanager" {
28
28
count = var. registry_secretsmanager_arn != null ? 1 : 0
29
29
30
- statement {
31
- actions = [
32
- " kms:Decrypt" ,
33
- ]
34
-
35
- resources = [var . registry_secretsmanager_arn ]
36
- }
37
-
38
30
statement {
39
31
actions = [
40
32
" secretsmanager:GetSecretValue" ,
41
33
]
42
34
43
- # Limit to only current version of the secret
44
- condition {
45
- test = " ForAnyValue:StringEquals"
46
- variable = " secretsmanager:VersionStage"
47
- values = [" AWSCURRENT" ]
48
- }
49
-
50
35
resources = [var . registry_secretsmanager_arn ]
51
36
}
52
37
}
Original file line number Diff line number Diff line change @@ -28,26 +28,11 @@ resource "aws_iam_role_policy_attachment" "task_execution_role" {
28
28
data "aws_iam_policy_document" "registry_secretsmanager" {
29
29
count = var. registry_secretsmanager_arn != null ? 1 : 0
30
30
31
- statement {
32
- actions = [
33
- " kms:Decrypt" ,
34
- ]
35
-
36
- resources = [var . registry_secretsmanager_arn ]
37
- }
38
-
39
31
statement {
40
32
actions = [
41
33
" secretsmanager:GetSecretValue" ,
42
34
]
43
35
44
- # Limit to only current version of the secret
45
- condition {
46
- test = " ForAnyValue:StringEquals"
47
- variable = " secretsmanager:VersionStage"
48
- values = [" AWSCURRENT" ]
49
- }
50
-
51
36
resources = [var . registry_secretsmanager_arn ]
52
37
}
53
38
}
You can’t perform that action at this time.
0 commit comments