Skip to content

Commit 0e77849

Browse files
fix: Add ssm:GetParameters permission to external-secrets policy (#316)
Co-authored-by: Bryant Biggs <[email protected]>
1 parent 8349479 commit 0e77849

File tree

2 files changed

+6
-3
lines changed

2 files changed

+6
-3
lines changed

.pre-commit-config.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
repos:
22
- repo: https://github.com/antonbabenko/pre-commit-terraform
3-
rev: v1.76.0
3+
rev: v1.77.0
44
hooks:
55
- id: terraform_fmt
66
- id: terraform_validate
@@ -23,7 +23,7 @@ repos:
2323
- '--args=--only=terraform_standard_module_structure'
2424
- '--args=--only=terraform_workspace_remote'
2525
- repo: https://github.com/pre-commit/pre-commit-hooks
26-
rev: v4.3.0
26+
rev: v4.4.0
2727
hooks:
2828
- id: check-merge-conflict
2929
- id: end-of-file-fixer

modules/iam-role-for-service-accounts-eks/policies.tf

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -410,7 +410,10 @@ data "aws_iam_policy_document" "external_secrets" {
410410
count = var.create_role && var.attach_external_secrets_policy ? 1 : 0
411411

412412
statement {
413-
actions = ["ssm:GetParameter"]
413+
actions = [
414+
"ssm:GetParameter",
415+
"ssm:GetParameters",
416+
]
414417
resources = var.external_secrets_ssm_parameter_arns
415418
}
416419

0 commit comments

Comments
 (0)