Skip to content

Commit

Permalink
Remove developer role as not used on intg
Browse files Browse the repository at this point in the history
  • Loading branch information
TomJKing committed Oct 12, 2023
1 parent a87fb08 commit b22aaa2
Show file tree
Hide file tree
Showing 3 changed files with 3 additions and 9 deletions.
2 changes: 1 addition & 1 deletion da-terraform-modules
8 changes: 1 addition & 7 deletions root_export_bucket_access.tf
Original file line number Diff line number Diff line change
@@ -1,9 +1,7 @@
# AWS SSO groups that require access to encrypted s3 export buckets need updating with relevant decrypt permissions for KMS s3 Key

locals {
aws_sso_export_bucket_access_roles = local.environment == "intg" ? [
data.aws_ssm_parameter.aws_sso_admin_role.value, data.aws_ssm_parameter.aws_sso_developer_role.value, data.aws_ssm_parameter.aws_sso_export_role.value] : [
data.aws_ssm_parameter.aws_sso_admin_role.value, data.aws_ssm_parameter.aws_sso_export_role.value]
aws_sso_export_bucket_access_roles = [data.aws_ssm_parameter.aws_sso_admin_role.value, data.aws_ssm_parameter.aws_sso_export_role.value]
}

data "aws_ssm_parameter" "aws_sso_admin_role" {
Expand All @@ -14,10 +12,6 @@ data "aws_ssm_parameter" "aws_sso_export_role" {
name = "/${local.environment}/export_role"
}

data "aws_ssm_parameter" "aws_sso_developer_role" {
name = "/${local.environment}/developer_role"
}

module "aws_sso_export_roles_ssm_parameters" {
source = "./da-terraform-modules/ssm_parameter"
parameters = [
Expand Down
2 changes: 1 addition & 1 deletion tdr-configurations

0 comments on commit b22aaa2

Please sign in to comment.