sst.dev icon indicating copy to clipboard operation
sst.dev copied to clipboard

customize-the-serverless-iam-policy.md - suggestions

Open Lior-G opened this issue 5 years ago • 4 comments

under "An advanced IAM Policy template", recommending the following updates

  • update (twice)

Why: PATCH is needed for any deployment after the first one

"apigateway:GET",
"apigateway:POST",
"apigateway:PUT",
"apigateway:DELETE"

to

"apigateway:GET",
"apigateway:PATCH",
"apigateway:POST",
"apigateway:PUT",
"apigateway:DELETE"
  • update

WHY: ensure code only has access to S3 permissions within project; create, update, delete, list

"arn:aws:s3:::*"

to

"arn:aws:s3:::<service_name>*"
  • update

WHY: ensure code only has access to S3 permissions within project; upload

"arn:aws:s3:::*/*"

to

"arn:aws:s3:::<service_name>*/*"

Lior-G avatar Feb 01 '20 17:02 Lior-G

Yeah these make sense. Do you mind editing the chapter and submitting a PR?

jayair avatar Feb 08 '20 18:02 jayair

Yeah these make sense. Do you mind editing the chapter and submitting a PR?

Jay: sure, no problem. Looking at your CONTRIBUTING.md, don't see if there is a branching naming convention, or steps to properly submit a PR. Is there any? if so, can you please point me to it?

Lior-G avatar Feb 10 '20 15:02 Lior-G

For this case you can simply edit this chapter through the GitHub web interface and submit a PR. Does that make sense?

jayair avatar Mar 08 '20 21:03 jayair

already done, and PR has already been merged

cheers

Lior

On Sun, Mar 8, 2020 at 5:53 PM Jay V [email protected] wrote:

For this case you can simply edit this chapter through the GitHub web interface and submit a PR. Does that make sense?

— You are receiving this because you authored the thread. Reply to this email directly, view it on GitHub https://github.com/AnomalyInnovations/serverless-stack-com/issues/439?email_source=notifications&email_token=AGJLHEGRLCWCKZI2RCEHDKDRGQOXLA5CNFSM4KOUKAR2YY3PNVWWK3TUL52HS4DFVREXG43VMVBW63LNMVXHJKTDN5WW2ZLOORPWSZGOEOFCT5Y#issuecomment-596257271, or unsubscribe https://github.com/notifications/unsubscribe-auth/AGJLHEC54PHEN42LRCLYBBDRGQOXLANCNFSM4KOUKARQ .

Lior-G avatar Mar 09 '20 12:03 Lior-G