Skip to content

Conversation

@StewartW
Copy link
Contributor

Issue #, if available: #474

Description of changes:
Broken down in the gist here

Separates out the policies for cloudformation-role in the target accounts and codepipeline role in the deployment account.
Now have policies for S3, KMS and a base policy that catches everything else.

Updated the shared IAM library to take in a list of policies to update now, also accepts single string and will treat it accordingly.
Existing update policy code also provides backward compatibility because it checks if the statement with the SID exists in the policy and if it can't find it - it does nothing.

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

Copy link
Collaborator

@sbkok sbkok left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Only a few trailing space issues to be fixed. Except those it looks good, thanks!

@StewartW StewartW requested review from javydekoning and sbkok August 11, 2022 13:49
Copy link
Collaborator

@sbkok sbkok left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks!

@sbkok sbkok merged commit 88d7aec into awslabs:master Aug 12, 2022
@sbkok sbkok added this to the v3.2.0 milestone Jan 24, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants