Skip to content

Commit

Permalink
Merge pull request #29222 from ministryofjustice/fix-audit-dev-permis…
Browse files Browse the repository at this point in the history
…sions

Fix Athena permission for audit in dev
  • Loading branch information
ma226860 authored Jan 30, 2025
2 parents cb1756a + 664afc5 commit 6561c3c
Show file tree
Hide file tree
Showing 2 changed files with 6 additions and 16 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -37,20 +37,15 @@ data "aws_iam_policy_document" "athena" {
]

resources = [
aws_athena_workgroup.queries.arn,
"${aws_athena_workgroup.queries.arn}/*",
"arn:aws:athena:eu-west-2:*:workgroup/${aws_athena_workgroup.queries.name}",
"arn:aws:athena:eu-west-2:*:workgroup/${aws_athena_workgroup.queries.name}/*",
"arn:aws:athena:eu-west-2:*:query/*",
"arn:aws:glue:eu-west-2:*:catalog",
"arn:aws:glue:eu-west-2:*:database/${aws_athena_database.audit_database.id}",
"arn:aws:glue:eu-west-2:*:database/${aws_athena_database.audit_database.id}/*",
"arn:aws:glue:eu-west-2:*:table/${aws_athena_database.audit_database.id}",
"arn:aws:glue:eu-west-2:*:table/${aws_athena_database.audit_database.id}/*",
module.s3.bucket_arn,
"${module.s3.bucket_arn}/*",

"arn:aws:athena:*:*:workgroup/hmpps_audit_${var.environment-name}",
"arn:aws:glue:eu-west-2:*:database/audit_${var.environment-name}",
"arn:aws:s3:::${module.s3.bucket_name}",
"arn:aws:s3:::${module.s3.bucket_name}/*"
]
}
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -80,21 +80,16 @@ data "aws_iam_policy_document" "document" {
"glue:DeleteTable",
]
resources = [
aws_athena_workgroup.queries.arn,
"${aws_athena_workgroup.queries.arn}/*",
"arn:aws:athena:eu-west-2:*:workgroup/${aws_athena_workgroup.queries.name}",
"arn:aws:athena:eu-west-2:*:workgroup/${aws_athena_workgroup.queries.name}/*",
"arn:aws:athena:eu-west-2:*:query/*",
"arn:aws:glue:eu-west-2:*:catalog",
"arn:aws:glue:eu-west-2:*:database/${aws_athena_database.audit_database.id}",
"arn:aws:glue:eu-west-2:*:database/${aws_athena_database.audit_database.id}/*",
"arn:aws:glue:eu-west-2:*:table/${aws_athena_database.audit_database.id}",
"arn:aws:glue:eu-west-2:*:table/${aws_athena_database.audit_database.id}/*",
module.s3.bucket_arn,
"${module.s3.bucket_arn}/*",

"arn:aws:athena:*:*:workgroup/hmpps_audit_${var.environment-name}",
"arn:aws:glue:eu-west-2:*:database/audit_${var.environment-name}",
"arn:aws:s3:::${module.s3.bucket_name}",
"arn:aws:s3:::${module.s3.bucket_name}/*"

]
}
}
Expand Down

0 comments on commit 6561c3c

Please sign in to comment.