Explorar el Código

Allows moose-hf to access cloudwatch logs

to be tagged v3.4.11
Brad Poulton hace 3 años
padre
commit
14228d284b
Se han modificado 1 ficheros con 3 adiciones y 0 borrados
  1. 3 0
      base/account_standards_c2/iam.moose-hf.tf

+ 3 - 0
base/account_standards_c2/iam.moose-hf.tf

@@ -54,6 +54,9 @@ resource "aws_iam_policy" "moose-hf" {
     {
       "Effect": "Allow",
       "Action": "sts:AssumeRole",
+                "logs:DescribeLogGroups",
+                "logs:DescribeLogStreams",
+                "logs:GetLogEvents",
       "Resource": "*"
     }
   ]