Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remove CreateLogGroup permission from service role #8

Merged
merged 2 commits into from
Apr 5, 2021

Commits on Jan 6, 2021

  1. Remove CreateLogGroup permission from service role

    This permission is not needed because we create the log group with Terraform so the VPC Flow Logs service doesn’t need to do it. On the other hand having this permission causes a bug where, on `terraform destroy` the log group will be destroyed, but then if there is still a few messages in a VPC Flow Logs queue the managed service will see that the log group does not exist and create it again using.
    
    You’ll then have the log group lingering after the tf destroy, which can cause trouble if you try to `terraform apply` again with the same name: the log group will be already existing and your apply will fail. Not having the permission prevents that as the managed service will not be able to recreate the log group after the tf destroy.
    navaati committed Jan 6, 2021
    Configuration menu
    Copy the full SHA
    85e3a6f View commit details
    Browse the repository at this point in the history

Commits on Apr 5, 2021

  1. Configuration menu
    Copy the full SHA
    e1aa41d View commit details
    Browse the repository at this point in the history