File tree Expand file tree Collapse file tree 2 files changed +27
-0
lines changed Expand file tree Collapse file tree 2 files changed +27
-0
lines changed Original file line number Diff line number Diff line change @@ -168,3 +168,13 @@ The audit policy is comprised of the following permissions:
168
168
| | cognito-idp: GetCSVHeader | |
169
169
| | cognito-idp: GetUserPoolMfaConfig | |
170
170
| | cognito-idp: GetUICustomization | |
171
+ | COMPUTEOPTIMIZER | compute-optimizer: DescribeRecommendationExportJobs | * |
172
+ | | compute-optimizer: GetAutoScalingGroupRecommendations | |
173
+ | | compute-optimizer: GetEffectiveRecommendationPreferences | |
174
+ | | compute-optimizer: GetEBSVolumeRecommendations | |
175
+ | | compute-optimizer: GetEC2InstanceRecommendations | |
176
+ | | compute-optimizer: GetEnrollmentStatus | |
177
+ | | compute-optimizer: GetEnrollmentStatusesForOrganization | |
178
+ | | compute-optimizer: GetLambdaFunctionRecommendations | |
179
+ | | compute-optimizer: GetRecommendationPreferences | |
180
+ | | compute-optimizer: GetRecommendationSummaries | |
Original file line number Diff line number Diff line change @@ -221,6 +221,23 @@ data "aws_iam_policy_document" "lacework_audit_policy" {
221
221
]
222
222
resources = [" *" ]
223
223
}
224
+
225
+ statement {
226
+ sid = " COMPUTEOPTIMIZER"
227
+ actions = [
228
+ " compute-optimizer:DescribeRecommendationExportJobs" ,
229
+ " compute-optimizer:GetAutoScalingGroupRecommendations" ,
230
+ " compute-optimizer:GetEffectiveRecommendationPreferences" ,
231
+ " compute-optimizer:GetEBSVolumeRecommendations" ,
232
+ " compute-optimizer:GetEC2InstanceRecommendations" ,
233
+ " compute-optimizer:GetEnrollmentStatus" ,
234
+ " compute-optimizer:GetEnrollmentStatusesForOrganization" ,
235
+ " compute-optimizer:GetLambdaFunctionRecommendations" ,
236
+ " compute-optimizer:GetRecommendationPreferences" ,
237
+ " compute-optimizer:GetRecommendationSummaries"
238
+ ]
239
+ resources = [" *" ]
240
+ }
224
241
}
225
242
226
243
resource "aws_iam_policy" "lacework_audit_policy" {
You can’t perform that action at this time.
0 commit comments