@@ -81,13 +81,7 @@ resource "aws_ssoadmin_permission_set" "read_only_access" {
81
81
82
82
resource "aws_ssoadmin_managed_policy_attachment" "read_only_access" {
83
83
instance_arn = local. instance_arn
84
- managed_policy_arn = " arn:aws:iam::aws:policy/job-function/ViewOnlyAccess"
85
- permission_set_arn = aws_ssoadmin_permission_set. read_only_access . arn
86
- }
87
-
88
- resource "aws_ssoadmin_managed_policy_attachment" "cloudwatch_readonly" {
89
- instance_arn = local. instance_arn
90
- managed_policy_arn = " arn:aws:iam::aws:policy/CloudWatchLogsReadOnlyAccess"
84
+ managed_policy_arn = " arn:aws:iam::aws:policy/ReadOnlyAccess"
91
85
permission_set_arn = aws_ssoadmin_permission_set. read_only_access . arn
92
86
}
93
87
@@ -124,23 +118,31 @@ locals {
124
118
account : aws_organizations_account.crates_io_staging,
125
119
groups : [
126
120
{ group : aws_identitystore_group.infra- admins,
127
- permissions : [aws_ssoadmin_permission_set.view_only_access, aws_ssoadmin_permission_set.administrator_access] },
121
+ permissions : [
122
+ aws_ssoadmin_permission_set.view_only_access,
123
+ aws_ssoadmin_permission_set.read_only_access,
124
+ aws_ssoadmin_permission_set.administrator_access
125
+ ] },
128
126
{ group : aws_identitystore_group.infra,
129
- permissions : [aws_ssoadmin_permission_set.view_only_access , aws_ssoadmin_permission_set.administrator_access] },
127
+ permissions : [aws_ssoadmin_permission_set.read_only_access , aws_ssoadmin_permission_set.administrator_access] },
130
128
{ group : aws_identitystore_group.crates_io,
131
- permissions : [aws_ssoadmin_permission_set.view_only_access ] },
129
+ permissions : [aws_ssoadmin_permission_set.read_only_access ] },
132
130
]
133
131
},
134
132
# crates-io Production
135
133
{
136
134
account : aws_organizations_account.crates_io_prod,
137
135
groups : [
138
136
{ group : aws_identitystore_group.infra- admins,
139
- permissions : [aws_ssoadmin_permission_set.view_only_access, aws_ssoadmin_permission_set.administrator_access] },
137
+ permissions : [
138
+ aws_ssoadmin_permission_set.view_only_access,
139
+ aws_ssoadmin_permission_set.read_only_access,
140
+ aws_ssoadmin_permission_set.administrator_access
141
+ ] },
140
142
{ group : aws_identitystore_group.infra,
141
- permissions : [aws_ssoadmin_permission_set.view_only_access ] },
143
+ permissions : [aws_ssoadmin_permission_set.read_only_access, aws_ssoadmin_permission_set.administrator_access ] },
142
144
{ group : aws_identitystore_group.crates_io,
143
- permissions : [aws_ssoadmin_permission_set.view_only_access ] },
145
+ permissions : [aws_ssoadmin_permission_set.read_only_access ] },
144
146
]
145
147
},
146
148
# docs-rs Staging
0 commit comments