-
Notifications
You must be signed in to change notification settings - Fork 4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
aws-ecs: downscope permissions required by instance draining hook #1204
Comments
Reference to source where downscoping should happen: |
@rix0rrr For the autoscaling permissions in particular, the required resource for CompleteLifecycleAction (according in the IAM docs ) is an autoscaling group, and if I'm understanding it, the policy won't work if the resource is not compatible with the required ones. All this to say, I think that the way the policy is defined in the Lambda should be fine, but feel free to clarify if I'm missing something. |
Probably: asg:CompleteLifeCycleAction will need ASG ARN? And the ecs calls need the ClusterArn? Describe calls can stay at resource-* for all I care. |
This can be resolved. |
No description provided.
The text was updated successfully, but these errors were encountered: