Skip to content
This repository has been archived by the owner on Dec 6, 2024. It is now read-only.

Commit

Permalink
Patch release 2 1 2 (#419)
Browse files Browse the repository at this point in the history
* fix: adding log stream resource

* chore: update changelog doc

* fix: doc typo

* fix: adding line in Changelog for CW arn fix
  • Loading branch information
SanketD92 authored Apr 1, 2021
1 parent a8c1aae commit ceb76ba
Show file tree
Hide file tree
Showing 2 changed files with 21 additions and 4 deletions.
11 changes: 11 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,17 @@

All notable changes to this project will be documented in this file.

## [2.1.2] - 2021-04-01

### Added
- fix: managing AppDeployer role permission boundary
- fix: CW log resources corrected in backend CFN template
- refactor: restrict ApiHandler role permissions
- refactor: restrict WorkflowLoopRunner role permissions
- refactor: restrict CrossAcctExec role permissions
- chore: team email removed from feedback section in readme
- chore: updates to npm dependencies

## [2.1.1] - 2021-03-19

### Added
Expand Down
14 changes: 10 additions & 4 deletions main/solution/backend/config/infra/cloudformation.yml
Original file line number Diff line number Diff line change
Expand Up @@ -429,9 +429,12 @@ Resources:
- !Sub 'arn:aws:iam::${AWS::AccountId}:role/*-xacc-env-mgmt'
- Effect: Allow
Action:
- logs:CreateLog*
- logs:CreateLogGroup
- logs:CreateLogStream
- logs:PutLogEvents
Resource: !Sub 'arn:aws:logs:${AWS::Region}:${AWS::AccountId}:log-group:aws/lambda/${self:custom.settings.awsRegionShortName}-${self:custom.settings.solutionName}-backend-${self:custom.settings.envName}*'
Resource:
- !Sub 'arn:aws:logs:${AWS::Region}:${AWS::AccountId}:log-group:/aws/lambda/${self:custom.settings.awsRegionShortName}-${self:custom.settings.solutionName}-backend-${self:custom.settings.envName}-*:*'
- !Sub 'arn:aws:logs:${AWS::Region}:${AWS::AccountId}:log-group:/aws/lambda/${self:custom.settings.awsRegionShortName}-${self:custom.settings.solutionName}-backend-${self:custom.settings.envName}-*:log-stream:*'

# IAM Role for the apiHandler Function
RoleApiHandler:
Expand Down Expand Up @@ -577,9 +580,12 @@ Resources:
- !Sub 'arn:aws:iam::${AWS::AccountId}:role/*-xacc-env-mgmt'
- Effect: Allow
Action:
- logs:CreateLog*
- logs:CreateLogGroup
- logs:CreateLogStream
- logs:PutLogEvents
Resource: !Sub 'arn:aws:logs:${AWS::Region}:${AWS::AccountId}:log-group:aws/lambda/${self:custom.settings.awsRegionShortName}-${self:custom.settings.solutionName}-backend-${self:custom.settings.envName}*'
Resource:
- !Sub 'arn:aws:logs:${AWS::Region}:${AWS::AccountId}:log-group:/aws/lambda/${self:custom.settings.awsRegionShortName}-${self:custom.settings.solutionName}-backend-${self:custom.settings.envName}-workflowLoopRunner:*'
- !Sub 'arn:aws:logs:${AWS::Region}:${AWS::AccountId}:log-group:/aws/lambda/${self:custom.settings.awsRegionShortName}-${self:custom.settings.solutionName}-backend-${self:custom.settings.envName}-workflowLoopRunner:log-stream:*'

# IAM Role for the workflowLoopRunner Function
RoleWorkflowLoopRunner:
Expand Down

0 comments on commit ceb76ba

Please sign in to comment.