Skip to content

Commit 2edc387

Browse files
committed
add terraform permissions for aws service compute-optimizer
1 parent 4b4d052 commit 2edc387

File tree

2 files changed

+28
-1
lines changed

2 files changed

+28
-1
lines changed

README.md

Lines changed: 11 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -139,4 +139,14 @@ The audit policy is comprised of the following permissions:
139139
| | ses:GetImportJob | |
140140
| | ses:ListRecommendations | |
141141
| | ses:ListSuppressedDestinations | |
142-
| | ses:GetSuppressedDestination | |
142+
| | ses:GetSuppressedDestination | |
143+
| COMPUTE-OPTIMIZER | compute-optimizer:DescribeRecommendationExportJobs | * |
144+
| | compute-optimizer:GetAutoScalingGroupRecommendations | |
145+
| | compute-optimizer:GetEffectiveRecommendationPreferences | |
146+
| | compute-optimizer:GetEBSVolumeRecommendations | |
147+
| | compute-optimizer:GetEC2InstanceRecommendations | |
148+
| | compute-optimizer:GetEnrollmentStatus | |
149+
| | compute-optimizer:GetEnrollmentStatusesForOrganization | |
150+
| | compute-optimizer:GetLambdaFunctionRecommendations | |
151+
| | compute-optimizer:GetRecommendationPreferences | |
152+
| | compute-optimizer:GetRecommendationSummaries | |

main.tf

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -180,6 +180,23 @@ data "aws_iam_policy_document" "lacework_audit_policy" {
180180
]
181181
resources = ["*"]
182182
}
183+
184+
statement {
185+
sid = "COMPUTE-OPTIMIZER"
186+
actions = [
187+
"compute-optimizer:DescribeRecommendationExportJobs",
188+
"compute-optimizer:GetAutoScalingGroupRecommendations",
189+
"compute-optimizer:GetEffectiveRecommendationPreferences",
190+
"compute-optimizer:GetEBSVolumeRecommendations",
191+
"compute-optimizer:GetEC2InstanceRecommendations",
192+
"compute-optimizer:GetEnrollmentStatus",
193+
"compute-optimizer:GetEnrollmentStatusesForOrganization",
194+
"compute-optimizer:GetLambdaFunctionRecommendations",
195+
"compute-optimizer:GetRecommendationPreferences",
196+
"compute-optimizer:GetRecommendationSummaries"
197+
]
198+
resources = ["*"]
199+
}
183200
}
184201

185202
resource "aws_iam_policy" "lacework_audit_policy" {

0 commit comments

Comments
 (0)