Skip to content

Commit

Permalink
Browse files Browse the repository at this point in the history
  • Loading branch information
panther-bot authored Dec 17, 2024
1 parent 337429f commit f3d010c
Showing 1 changed file with 3 additions and 1 deletion.
4 changes: 3 additions & 1 deletion cloudformation/panther-deployment-role.yml
Original file line number Diff line number Diff line change
Expand Up @@ -112,6 +112,7 @@ Resources:
- cloudformation:UpdateStack
Resource:
- !Sub arn:${AWS::Partition}:cloudformation:${AWS::Region}:${AWS::AccountId}:stack/panther*
- !Sub arn:${AWS::Partition}:cloudformation:${AWS::Region}:${AWS::AccountId}:stack/onboard-*
- !Sub arn:${AWS::Partition}:cloudformation:${AWS::Region}:aws:transform/Serverless*
# The following permissions are needed when self-onboarding is enabled.
- !Sub arn:${AWS::Partition}:cloudformation:${AWS::Region}:${AWS::AccountId}:stack/onboard-log-processing-role-*
Expand Down Expand Up @@ -237,6 +238,7 @@ Resources:
- !Sub arn:${AWS::Partition}:events:${AWS::Region}:${AWS::AccountId}:rule/system-status-publish-sources-last-received-event-cron
- !Sub arn:${AWS::Partition}:events:${AWS::Region}:${AWS::AccountId}:rule/system-status-publish-sources-permission-status-cron
- !Sub arn:${AWS::Partition}:events:${AWS::Region}:${AWS::AccountId}:rule/system-status-refresh-log-type-metrics-cron
- !Sub arn:${AWS::Partition}:events:${AWS::Region}:${AWS::AccountId}:rule/onboard-real-time-events*
- !Sub arn:${AWS::Partition}:events:${AWS::Region}:${AWS::AccountId}:rule/users-api-deactivate-support-users-cron
# This is required when self-onboarding is enabled.
- !Sub arn:${AWS::Partition}:events:${AWS::Region}:${AWS::AccountId}:rule/onboard-real-time-events-*
Expand All @@ -253,7 +255,7 @@ Resources:
- !Sub arn:${AWS::Partition}:apigateway:${AWS::Region}::/apis*
- !Sub arn:${AWS::Partition}:apigateway:${AWS::Region}::/restapis*
- !Sub arn:${AWS::Partition}:apigateway:${AWS::Region}::/tags/*
- !Sub arn:${AWS::Partition}:apigateway:${AWS::Region}::/usageplans/*
- !Sub arn:${AWS::Partition}:apigateway:${AWS::Region}::/usageplans*
Condition:
StringLikeIfExists:
apigateway:Request/apiName: panther*
Expand Down

0 comments on commit f3d010c

Please sign in to comment.