Skip to content

Commit 1731752

Browse files
committed
Template Fixes
1 parent c74c4be commit 1731752

File tree

1 file changed

+5
-43
lines changed

1 file changed

+5
-43
lines changed

aws_sra_examples/solutions/patch_mgmt/patch_mgmt_org/templates/sra-patch_mgmt-configuration-role.yaml

Lines changed: 5 additions & 43 deletions
Original file line numberDiff line numberDiff line change
@@ -70,8 +70,8 @@ Parameters:
7070
Description: Default Host Config IAM Role Name
7171
Type: String
7272
pSRASolutionName:
73-
AllowedValues: [sra-patch-mgmt]
74-
Default: sra-patch-mgmt
73+
AllowedValues: [sra-patch-mgmt-org]
74+
Default: sra-patch-mgmt-org
7575
Description: The SRA solution name. The default value is the folder name of the solution
7676
Type: String
7777

@@ -255,47 +255,9 @@ Resources:
255255
Principal:
256256
Service:
257257
- ssm.amazonaws.com
258-
Path: "/"
259-
Policies:
260-
- PolicyName: sra-amazon-ssm-managed-ec2-instance-default-policy-passrole
261-
PolicyDocument:
262-
Version: 2012-10-17
263-
Statement:
264-
- Sid: AllowPassRoleSimple
265-
Effect: Allow
266-
Action: iam:PassRole
267-
Resource:
268-
- !Sub arn:${AWS::Partition}:iam::${AWS::AccountId}:role/AWSSystemsManagerDefaultEC2InstanceManagementRole
269-
- PolicyName: sra-amazon-ssm-managed-ec2-instance-default-policy
270-
PolicyDocument:
271-
Version: 2012-10-17
272-
Statement:
273-
Effect: Allow
274-
Action:
275-
- ssm:DescribeAssociation
276-
- ssm:GetDeployablePatchSnapshotForInstance
277-
- ssm:GetDocument
278-
- ssm:DescribeDocument
279-
- ssm:GetManifest
280-
- ssm:ListAssociations
281-
- ssm:ListInstanceAssociations
282-
- ssm:PutInventory
283-
- ssm:PutComplianceItems
284-
- ssm:PutConfigurePackageResult
285-
- ssm:UpdateAssociationStatus
286-
- ssm:UpdateInstanceAssociationStatus
287-
- ssm:UpdateInstanceInformation
288-
- ssmmessages:CreateControlChannel
289-
- ssmmessages:CreateDataChannel
290-
- ssmmessages:OpenControlChannel
291-
- ssmmessages:OpenDataChannel
292-
- ec2messages:AcknowledgeMessage
293-
- ec2messages:DeleteMessage
294-
- ec2messages:FailMessage
295-
- ec2messages:GetEndpoint
296-
- ec2messages:GetMessages
297-
- ec2messages:SendReply
298-
Resource: "*"
258+
Path: "/service-role/"
259+
ManagedPolicyArns:
260+
- !Sub arn:${AWS::Partition}:iam::${AWS::Partition}:policy/AmazonSSMManagedEC2InstanceDefaultPolicy
299261
Tags:
300262
- Key: sra-solution
301263
Value: !Ref pSRASolutionName

0 commit comments

Comments
 (0)