Skip to content

Commit c363601

Browse files
authored
Merge pull request #40 from qasado/feature/iam-policy-update
Updated iam policy to reflect the required permissions by aws load balancer controller
2 parents 60c350a + 5eb1826 commit c363601

File tree

1 file changed

+9
-3
lines changed

1 file changed

+9
-3
lines changed

iam.tf

Lines changed: 9 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -43,6 +43,8 @@ data "aws_iam_policy_document" "lb_controller" {
4343
"ec2:GetCoipPoolUsage",
4444
"ec2:DescribeCoipPools",
4545
"ec2:GetSecurityGroupsForVpc",
46+
"ec2:DescribeIpamPools",
47+
"ec2:DescribeRouteTables",
4648
"elasticloadbalancing:DescribeLoadBalancers",
4749
"elasticloadbalancing:DescribeLoadBalancerAttributes",
4850
"elasticloadbalancing:DescribeListeners",
@@ -54,7 +56,8 @@ data "aws_iam_policy_document" "lb_controller" {
5456
"elasticloadbalancing:DescribeTargetHealth",
5557
"elasticloadbalancing:DescribeTags",
5658
"elasticloadbalancing:DescribeTrustStores",
57-
"elasticloadbalancing:DescribeListenerAttributes"
59+
"elasticloadbalancing:DescribeListenerAttributes",
60+
"elasticloadbalancing:DescribeCapacityReservation"
5861
]
5962
resources = [
6063
"*",
@@ -285,7 +288,9 @@ data "aws_iam_policy_document" "lb_controller" {
285288
"elasticloadbalancing:ModifyTargetGroup",
286289
"elasticloadbalancing:ModifyTargetGroupAttributes",
287290
"elasticloadbalancing:DeleteTargetGroup",
288-
"elasticloadbalancing:ModifyListenerAttributes"
291+
"elasticloadbalancing:ModifyListenerAttributes",
292+
"elasticloadbalancing:ModifyCapacityReservation",
293+
"elasticloadbalancing:ModifyIpPools"
289294
]
290295
resources = ["*"]
291296
condition {
@@ -348,7 +353,8 @@ data "aws_iam_policy_document" "lb_controller" {
348353
"elasticloadbalancing:ModifyListener",
349354
"elasticloadbalancing:AddListenerCertificates",
350355
"elasticloadbalancing:RemoveListenerCertificates",
351-
"elasticloadbalancing:ModifyRule"
356+
"elasticloadbalancing:ModifyRule",
357+
"elasticloadbalancing:SetRulePriorities"
352358
]
353359
resources = [
354360
"*"

0 commit comments

Comments
 (0)