Skip to content

Commit 63150d0

Browse files
committed
DOPS-101 Add dynamodb permissions to jenkins role
1 parent e6ab269 commit 63150d0

File tree

2 files changed

+200
-20
lines changed

2 files changed

+200
-20
lines changed

terraform/bootstrap/jenkins.tf

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -31,6 +31,13 @@ data "aws_iam_policy_document" "terraform_backend_role_policy_document" {
3131
actions = ["s3:*"]
3232
resources = ["arn:aws:s3:::${module.bootstrap.state_bucket}/*"]
3333
}
34+
35+
statement {
36+
effect = "Allow"
37+
38+
actions = ["dynamodb:*"]
39+
resources = ["arn:aws:dynamodb:${var.aws_region}:${data.aws_caller_identity.current.account_id}:table/${module.bootstrap.dynamodb_table}"]
40+
}
3441
}
3542

3643
resource "aws_iam_policy" "terraform_backend_role_policy" {

0 commit comments

Comments
 (0)