Skip to content

Commit

Permalink
Add Cognito permissions for AWS LBC.
Browse files Browse the repository at this point in the history
  • Loading branch information
danports committed Sep 15, 2023
1 parent f012cad commit 292cf3f
Show file tree
Hide file tree
Showing 9 changed files with 10 additions and 0 deletions.
2 changes: 2 additions & 0 deletions pkg/model/iam/iam_builder.go
Original file line number Diff line number Diff line change
Expand Up @@ -921,6 +921,8 @@ func AddCCMPermissions(p *Policy, cloudRoutes bool) {
// AddAWSLoadbalancerControllerPermissions adds the permissions needed for the AWS Load Balancer Controller to the givnen policy
func AddAWSLoadbalancerControllerPermissions(p *Policy, enableWAF, enableWAFv2, enableShield bool) {
p.unconditionalAction.Insert(
"cognito-idp:DescribeUserPoolClient",

"acm:DescribeCertificate",
"acm:ListCertificates",

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -37,6 +37,7 @@
"Action": [
"acm:DescribeCertificate",
"acm:ListCertificates",
"cognito-idp:DescribeUserPoolClient",
"ec2:DescribeAccountAttributes",
"ec2:DescribeAvailabilityZones",
"ec2:DescribeInstances",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -37,6 +37,7 @@
"Action": [
"acm:DescribeCertificate",
"acm:ListCertificates",
"cognito-idp:DescribeUserPoolClient",
"ec2:DescribeAccountAttributes",
"ec2:DescribeAvailabilityZones",
"ec2:DescribeInstances",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -37,6 +37,7 @@
"Action": [
"acm:DescribeCertificate",
"acm:ListCertificates",
"cognito-idp:DescribeUserPoolClient",
"ec2:DescribeAccountAttributes",
"ec2:DescribeAvailabilityZones",
"ec2:DescribeInstances",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -37,6 +37,7 @@
"Action": [
"acm:DescribeCertificate",
"acm:ListCertificates",
"cognito-idp:DescribeUserPoolClient",
"ec2:DescribeAccountAttributes",
"ec2:DescribeAvailabilityZones",
"ec2:DescribeInstances",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -37,6 +37,7 @@
"Action": [
"acm:DescribeCertificate",
"acm:ListCertificates",
"cognito-idp:DescribeUserPoolClient",
"ec2:DescribeAccountAttributes",
"ec2:DescribeAvailabilityZones",
"ec2:DescribeInstances",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -37,6 +37,7 @@
"Action": [
"acm:DescribeCertificate",
"acm:ListCertificates",
"cognito-idp:DescribeUserPoolClient",
"ec2:DescribeAccountAttributes",
"ec2:DescribeAvailabilityZones",
"ec2:DescribeInstances",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -214,6 +214,7 @@
"autoscaling:DescribeLaunchConfigurations",
"autoscaling:DescribeScalingActivities",
"autoscaling:DescribeTags",
"cognito-idp:DescribeUserPoolClient",
"ec2:AssignPrivateIpAddresses",
"ec2:AttachNetworkInterface",
"ec2:CreateNetworkInterface",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -214,6 +214,7 @@
"autoscaling:DescribeLaunchConfigurations",
"autoscaling:DescribeScalingActivities",
"autoscaling:DescribeTags",
"cognito-idp:DescribeUserPoolClient",
"ec2:AssignPrivateIpAddresses",
"ec2:AttachNetworkInterface",
"ec2:CreateNetworkInterface",
Expand Down

0 comments on commit 292cf3f

Please sign in to comment.