Skip to content

Commit

Permalink
Merge pull request #8547 from ministryofjustice/update/github-oidc-sp…
Browse files Browse the repository at this point in the history
…rinkler

Update sprinkler GitHub OIDC Role
  • Loading branch information
sukeshreddyg authored Nov 20, 2024
2 parents d22adba + 8949144 commit f245cf6
Showing 1 changed file with 14 additions and 0 deletions.
14 changes: 14 additions & 0 deletions terraform/environments/sprinkler/iam.tf
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,20 @@ module "github-oidc" {
}

data "aws_iam_policy_document" "oidc_deny_specific_actions" {
statement {
sid = "AllowOIDCToAssumeRoles"
effect = "Allow"
resources = [
format("arn:aws:iam::%s:role/modernisation-account-limited-read-member-access", local.environment_management.modernisation_platform_account_id),
format("arn:aws:iam::%s:role/modernisation-account-terraform-state-member-access", local.environment_management.modernisation_platform_account_id)
]
condition {
test = "StringEquals"
variable = "aws:PrincipalAccount"
values = [local.environment_management.account_ids[terraform.workspace]]
}
actions = ["sts:AssumeRole"]
}
statement {
effect = "Deny"
actions = [
Expand Down

0 comments on commit f245cf6

Please sign in to comment.