File tree Expand file tree Collapse file tree 2 files changed +28
-1
lines changed Expand file tree Collapse file tree 2 files changed +28
-1
lines changed Original file line number Diff line number Diff line change @@ -139,4 +139,14 @@ The audit policy is comprised of the following permissions:
139
139
| | ses: GetImportJob | |
140
140
| | ses: ListRecommendations | |
141
141
| | ses: ListSuppressedDestinations | |
142
- | | ses: GetSuppressedDestination | |
142
+ | | ses: GetSuppressedDestination | |
143
+ | COMPUTE-OPTIMIZER | compute-optimizer: DescribeRecommendationExportJobs | * |
144
+ | | compute-optimizer: GetAutoScalingGroupRecommendations | |
145
+ | | compute-optimizer: GetEffectiveRecommendationPreferences | |
146
+ | | compute-optimizer: GetEBSVolumeRecommendations | |
147
+ | | compute-optimizer: GetEC2InstanceRecommendations | |
148
+ | | compute-optimizer: GetEnrollmentStatus | |
149
+ | | compute-optimizer: GetEnrollmentStatusesForOrganization | |
150
+ | | compute-optimizer: GetLambdaFunctionRecommendations | |
151
+ | | compute-optimizer: GetRecommendationPreferences | |
152
+ | | compute-optimizer: GetRecommendationSummaries | |
Original file line number Diff line number Diff line change @@ -180,6 +180,23 @@ data "aws_iam_policy_document" "lacework_audit_policy" {
180
180
]
181
181
resources = [" *" ]
182
182
}
183
+
184
+ statement {
185
+ sid = " COMPUTE-OPTIMIZER"
186
+ actions = [
187
+ " compute-optimizer:DescribeRecommendationExportJobs" ,
188
+ " compute-optimizer:GetAutoScalingGroupRecommendations" ,
189
+ " compute-optimizer:GetEffectiveRecommendationPreferences" ,
190
+ " compute-optimizer:GetEBSVolumeRecommendations" ,
191
+ " compute-optimizer:GetEC2InstanceRecommendations" ,
192
+ " compute-optimizer:GetEnrollmentStatus" ,
193
+ " compute-optimizer:GetEnrollmentStatusesForOrganization" ,
194
+ " compute-optimizer:GetLambdaFunctionRecommendations" ,
195
+ " compute-optimizer:GetRecommendationPreferences" ,
196
+ " compute-optimizer:GetRecommendationSummaries"
197
+ ]
198
+ resources = [" *" ]
199
+ }
183
200
}
184
201
185
202
resource "aws_iam_policy" "lacework_audit_policy" {
You can’t perform that action at this time.
0 commit comments