Skip to content

Commit 16d03f3

Browse files
committed
CCM-9378: Allowing sqs service to sendmessage to dlq
1 parent f2cfe79 commit 16d03f3

1 file changed

Lines changed: 20 additions & 0 deletions

File tree

infrastructure/modules/sqs/data_iam_policy_document_deadletter_queue.tf

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -21,4 +21,24 @@ data "aws_iam_policy_document" "deadletter_queue" {
2121
identifiers = [var.aws_account_id]
2222
}
2323
}
24+
25+
statement {
26+
sid = "AllowSendMessage"
27+
effect = "Allow"
28+
29+
actions = [
30+
"sqs:SendMessage",
31+
]
32+
33+
resources = [
34+
aws_sqs_queue.dlq.arn,
35+
]
36+
37+
principals {
38+
type = "Service"
39+
identifiers = [
40+
"sqs.amazonaws.com"
41+
]
42+
}
43+
}
2444
}

0 commit comments

Comments
 (0)