@@ -43,6 +43,8 @@ data "aws_iam_policy_document" "lb_controller" {
43
43
" ec2:GetCoipPoolUsage" ,
44
44
" ec2:DescribeCoipPools" ,
45
45
" ec2:GetSecurityGroupsForVpc" ,
46
+ " ec2:DescribeIpamPools" ,
47
+ " ec2:DescribeRouteTables" ,
46
48
" elasticloadbalancing:DescribeLoadBalancers" ,
47
49
" elasticloadbalancing:DescribeLoadBalancerAttributes" ,
48
50
" elasticloadbalancing:DescribeListeners" ,
@@ -54,7 +56,8 @@ data "aws_iam_policy_document" "lb_controller" {
54
56
" elasticloadbalancing:DescribeTargetHealth" ,
55
57
" elasticloadbalancing:DescribeTags" ,
56
58
" elasticloadbalancing:DescribeTrustStores" ,
57
- " elasticloadbalancing:DescribeListenerAttributes"
59
+ " elasticloadbalancing:DescribeListenerAttributes" ,
60
+ " elasticloadbalancing:DescribeCapacityReservation"
58
61
]
59
62
resources = [
60
63
" *" ,
@@ -285,7 +288,9 @@ data "aws_iam_policy_document" "lb_controller" {
285
288
" elasticloadbalancing:ModifyTargetGroup" ,
286
289
" elasticloadbalancing:ModifyTargetGroupAttributes" ,
287
290
" elasticloadbalancing:DeleteTargetGroup" ,
288
- " elasticloadbalancing:ModifyListenerAttributes"
291
+ " elasticloadbalancing:ModifyListenerAttributes" ,
292
+ " elasticloadbalancing:ModifyCapacityReservation" ,
293
+ " elasticloadbalancing:ModifyIpPools"
289
294
]
290
295
resources = [" *" ]
291
296
condition {
@@ -348,7 +353,8 @@ data "aws_iam_policy_document" "lb_controller" {
348
353
" elasticloadbalancing:ModifyListener" ,
349
354
" elasticloadbalancing:AddListenerCertificates" ,
350
355
" elasticloadbalancing:RemoveListenerCertificates" ,
351
- " elasticloadbalancing:ModifyRule"
356
+ " elasticloadbalancing:ModifyRule" ,
357
+ " elasticloadbalancing:SetRulePriorities"
352
358
]
353
359
resources = [
354
360
" *"
0 commit comments