Skip to content

Commit 22d5057

Browse files
CCM-10039 addingBackupTagResourcePerm
1 parent 2eee676 commit 22d5057

1 file changed

Lines changed: 27 additions & 0 deletions

File tree

infrastructure/modules/aws-backup-source/iam_role_backup.tf

Lines changed: 27 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -35,3 +35,30 @@ resource "aws_iam_role_policy_attachment" "s3_backup" {
3535
policy_arn = "arn:aws:iam::aws:policy/AWSBackupServiceRolePolicyForS3Backup"
3636
role = aws_iam_role.backup.name
3737
}
38+
39+
40+
resource "aws_iam_role_policy_attachment" "backup_additional" {
41+
role = aws_iam_role.backup.name
42+
policy_arn = aws_iam_policy.backup_additional.arn
43+
}
44+
45+
resource "aws_iam_policy" "backup_additional" {
46+
name = "${local.csi}-backup_additional"
47+
description = "Amplify "
48+
policy = data.aws_iam_policy_document.backup_additional.json
49+
}
50+
51+
data "aws_iam_policy_document" "backup_additional" {
52+
statement {
53+
effect = "Allow"
54+
55+
actions = [
56+
"backup:TagResource",
57+
]
58+
59+
#trivy:ignore:aws-iam-no-policy-wildcards
60+
resources = [
61+
"*",
62+
]
63+
}
64+
}

0 commit comments

Comments
 (0)