Skip to content

Commit b158b46

Browse files
authored
Added iam:getRole perms to CF1 remediation (#140)
* Added iam:getRole perms to CF1 remediation * tightened up perms * Trying to use the orchestrator role instead * Reverting back to wildcard after failures narrowing it down
1 parent 9fdbe85 commit b158b46

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

source/lib/remediation_runbook-stack.ts

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1358,7 +1358,7 @@ export class RemediationRunbookStack extends cdk.Stack {
13581358
inlinePolicy.addStatements(snsPerms);
13591359

13601360
const remediationPolicy = new PolicyStatement();
1361-
remediationPolicy.addActions('servicecatalog:GetApplication');
1361+
remediationPolicy.addActions('servicecatalog:GetApplication', 'iam:GetRole');
13621362
remediationPolicy.effect = Effect.ALLOW;
13631363
remediationPolicy.addResources('*');
13641364
inlinePolicy.addStatements(remediationPolicy);

0 commit comments

Comments
 (0)