Переглянути джерело

Removes invalid principal from kms policy for github EFS

To be tagged v1.20.11
Fred Damstra 4 роки тому
батько
коміт
a027d2c60a
1 змінених файлів з 4 додано та 2 видалено
  1. 4 2
      base/github/kms.tf

+ 4 - 2
base/github/kms.tf

@@ -67,7 +67,8 @@ data "aws_iam_policy_document" "ghe_backup_data_policy" {
       identifiers = [
         "arn:${var.aws_partition}:iam::${var.aws_account_id}:role/user/mdr_terraformer",
         "arn:${var.aws_partition}:iam::${var.aws_account_id}:role/msoc-default-instance-role",
-        "arn:${var.aws_partition}:iam::${var.aws_account_id}:role/portal-instance-role",
+        # Portal was in legacy, but doesn't make sense. Removing, but leaving commented for now in case we need to re-add it.
+        # "arn:${var.aws_partition}:iam::${var.aws_account_id}:role/portal-instance-role",
         "arn:${var.aws_partition}:iam::${var.aws_account_id}:role/aws-service-role/autoscaling.amazonaws.com/AWSServiceRoleForAutoScaling",
       ]
     }
@@ -93,7 +94,8 @@ data "aws_iam_policy_document" "ghe_backup_data_policy" {
       identifiers = [
         "arn:${var.aws_partition}:iam::${var.aws_account_id}:role/user/mdr_terraformer",
         "arn:${var.aws_partition}:iam::${var.aws_account_id}:role/msoc-default-instance-role",
-        "arn:${var.aws_partition}:iam::${var.aws_account_id}:role/portal-instance-role",
+        # Portal was in legacy, but doesn't make sense. Removing, but leaving commented for now in case we need to re-add it.
+        #"arn:${var.aws_partition}:iam::${var.aws_account_id}:role/portal-instance-role",
         "arn:${var.aws_partition}:iam::${var.aws_account_id}:role/aws-service-role/autoscaling.amazonaws.com/AWSServiceRoleForAutoScaling",
       ]
     }