浏览代码

Removes invalid principal from kms policy for github EFS

To be tagged v1.20.11
Fred Damstra 4 年之前
父节点
当前提交
a027d2c60a
共有 1 个文件被更改,包括 4 次插入2 次删除
  1. 4 2
      base/github/kms.tf

+ 4 - 2
base/github/kms.tf

@@ -67,7 +67,8 @@ data "aws_iam_policy_document" "ghe_backup_data_policy" {
       identifiers = [
         "arn:${var.aws_partition}:iam::${var.aws_account_id}:role/user/mdr_terraformer",
         "arn:${var.aws_partition}:iam::${var.aws_account_id}:role/msoc-default-instance-role",
-        "arn:${var.aws_partition}:iam::${var.aws_account_id}:role/portal-instance-role",
+        # Portal was in legacy, but doesn't make sense. Removing, but leaving commented for now in case we need to re-add it.
+        # "arn:${var.aws_partition}:iam::${var.aws_account_id}:role/portal-instance-role",
         "arn:${var.aws_partition}:iam::${var.aws_account_id}:role/aws-service-role/autoscaling.amazonaws.com/AWSServiceRoleForAutoScaling",
       ]
     }
@@ -93,7 +94,8 @@ data "aws_iam_policy_document" "ghe_backup_data_policy" {
       identifiers = [
         "arn:${var.aws_partition}:iam::${var.aws_account_id}:role/user/mdr_terraformer",
         "arn:${var.aws_partition}:iam::${var.aws_account_id}:role/msoc-default-instance-role",
-        "arn:${var.aws_partition}:iam::${var.aws_account_id}:role/portal-instance-role",
+        # Portal was in legacy, but doesn't make sense. Removing, but leaving commented for now in case we need to re-add it.
+        #"arn:${var.aws_partition}:iam::${var.aws_account_id}:role/portal-instance-role",
         "arn:${var.aws_partition}:iam::${var.aws_account_id}:role/aws-service-role/autoscaling.amazonaws.com/AWSServiceRoleForAutoScaling",
       ]
     }