We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent acba5e7 commit 9e319e3Copy full SHA for 9e319e3
main.tf
@@ -254,11 +254,16 @@ data "aws_iam_policy_document" "default" {
254
sid = "AllowS3OperationsOnElasticBeanstalkBuckets"
255
256
actions = [
257
- "s3:*"
+ "s3:PutObject",
258
+ "s3:ListBucketVersions",
259
+ "s3:ListBucket",
260
+ "s3:GetObjectVersion",
261
+ "s3:GetObject"
262
]
263
264
resources = [
- "arn:aws:s3:::*"
265
+ "arn:aws:s3:::${var.namespace}-${var.stage}-bucket/*",
266
+ "arn:aws:s3:::${var.namespace}-${var.stage}-bucket",
267
268
269
effect = "Allow"
0 commit comments