terraform-aws-lambda icon indicating copy to clipboard operation
terraform-aws-lambda copied to clipboard

allow ssm:GetParameter with ssm config

Open moritzzimmer opened this issue 5 years ago • 1 comments

Currently this module configures the following policy for ssm_parameter_names:

data "aws_iam_policy_document" "ssm_policy_document" {
  count = length(var.ssm_parameter_names)

  statement {
    actions = [
      "ssm:GetParameters",
      "ssm:GetParametersByPath",
    ]

    resources = [
      "arn:aws:ssm:${data.aws_region.current.name}:${data.aws_caller_identity.current.account_id}:parameter/${element(var.ssm_parameter_names, count.index)}",
    ]
  }
}

This datasource should also permit ssm:GetParameter.

moritzzimmer avatar Jul 01 '20 13:07 moritzzimmer

this is fixed with https://github.com/moritzzimmer/terraform-aws-lambda/releases/tag/v5.4.0

moritzzimmer avatar Aug 31 '20 06:08 moritzzimmer