alexcasalboni / alexcasalboni/aws-lambda-power-tuning

Policy AWSLambdaExecute removed from existing roles when using terraform

Đang mở
#259 1 bình luận 0 reaction 0 người được giao Xem trên GitHub
Ngôn ngữ chính
JavaScript
Star
6.1k
Fork
415
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Mô tả

AWS provider resource `aws_iam_policy_attachment` creates an exclusive relationship between the policy and roles defined. As this is almost never what you want, it is suggested to use `aws_iam_role_policy_attachment` to create an attachment between one policy and one role.

In context here, the policy `AWSLambdaExecute` policy is being attached to a set of roles created in the terraform module
```
resource "aws_iam_policy_attachment" "execute-attach" {
name = "execute-attachment"
roles = [aws_iam_role.analyzer_role.name, aws_iam_role.optimizer_role.name, aws_iam_role.executor_role.name, aws_iam_role.cleaner_role.name, aws_iam_role.initializer_role.name]
policy_arn = data.aws_iam_policy.analyzer_policy.arn
}
```
Upon creating this resource, all roles that currently have policy `AWSLambdaExecute` attached will have that policy detached, resulting in resources that previously had permission to execute lambda functions no longer having that permission.

See https://registry.terraform.io/providers/hashicorp/aws/2.70.1/docs/resources/iam_policy_attachment

Hướng dẫn đóng góp

Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.