Skip to content

Commit 17e5351

Browse files
authored
[Permissions] Fix permissions to read/delete logs from SSM. (#409)
1 parent bc28c07 commit 17e5351

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

infrastructure/parallelcluster-ui.yaml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1074,14 +1074,14 @@ Resources:
10741074
- Action:
10751075
- logs:GetLogEvents
10761076
Resource:
1077-
- !Sub "arn:${AWS::Partition}:logs:${AWS::Region}:${AWS::AccountId}:log-group:${SsmLogGroup}:*"
1078-
- !Sub "arn:${AWS::Partition}:logs:${AWS::Region}:${AWS::AccountId}:log-group:${SsmLogGroup}:log-stream:*"
1077+
- !Sub "arn:${AWS::Partition}:logs:*:${AWS::AccountId}:log-group:${SsmLogGroup}:*"
1078+
- !Sub "arn:${AWS::Partition}:logs:*:${AWS::AccountId}:log-group:${SsmLogGroup}:log-stream:*"
10791079
Effect: Allow
10801080
Sid: CloudWatchLogsRead
10811081
- Action:
10821082
- logs:DeleteLogStream
10831083
Resource:
1084-
- !Sub "arn:${AWS::Partition}:logs:${AWS::Region}:${AWS::AccountId}:log-group:${SsmLogGroup}:log-stream:*/*/aws-runShellScript/stdout"
1084+
- !Sub "arn:${AWS::Partition}:logs:*:${AWS::AccountId}:log-group:${SsmLogGroup}:log-stream:*/*/aws-runShellScript/stdout"
10851085
Effect: Allow
10861086
Sid: CloudWatchLogsDelete
10871087

0 commit comments

Comments
 (0)