Skip to content

Commit 6e56d20

Browse files
committed
add permission for compute-optimizer
Signed-off-by: Yingxin Li <yingxin.li@lacework.net>
1 parent fb67991 commit 6e56d20

File tree

2 files changed

+27
-0
lines changed

2 files changed

+27
-0
lines changed

README.md

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -168,3 +168,13 @@ The audit policy is comprised of the following permissions:
168168
| | cognito-idp:GetCSVHeader | |
169169
| | cognito-idp:GetUserPoolMfaConfig | |
170170
| | cognito-idp:GetUICustomization | |
171+
| COMPUTEOPTIMIZER | compute-optimizer:DescribeRecommendationExportJobs | * |
172+
| | compute-optimizer:GetAutoScalingGroupRecommendations | |
173+
| | compute-optimizer:GetEffectiveRecommendationPreferences | |
174+
| | compute-optimizer:GetEBSVolumeRecommendations | |
175+
| | compute-optimizer:GetEC2InstanceRecommendations | |
176+
| | compute-optimizer:GetEnrollmentStatus | |
177+
| | compute-optimizer:GetEnrollmentStatusesForOrganization | |
178+
| | compute-optimizer:GetLambdaFunctionRecommendations | |
179+
| | compute-optimizer:GetRecommendationPreferences | |
180+
| | compute-optimizer:GetRecommendationSummaries | |

main.tf

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -221,6 +221,23 @@ data "aws_iam_policy_document" "lacework_audit_policy" {
221221
]
222222
resources = ["*"]
223223
}
224+
225+
statement {
226+
sid = "COMPUTEOPTIMIZER"
227+
actions = [
228+
"compute-optimizer:DescribeRecommendationExportJobs",
229+
"compute-optimizer:GetAutoScalingGroupRecommendations",
230+
"compute-optimizer:GetEffectiveRecommendationPreferences",
231+
"compute-optimizer:GetEBSVolumeRecommendations",
232+
"compute-optimizer:GetEC2InstanceRecommendations",
233+
"compute-optimizer:GetEnrollmentStatus",
234+
"compute-optimizer:GetEnrollmentStatusesForOrganization",
235+
"compute-optimizer:GetLambdaFunctionRecommendations",
236+
"compute-optimizer:GetRecommendationPreferences",
237+
"compute-optimizer:GetRecommendationSummaries"
238+
]
239+
resources = ["*"]
240+
}
224241
}
225242

226243
resource "aws_iam_policy" "lacework_audit_policy" {

0 commit comments

Comments
 (0)