Skip to content

Commit c19fb57

Browse files
CCM-18334: Firehose Delivery Stream Permissions Update
1 parent acb3fff commit c19fb57

1 file changed

Lines changed: 14 additions & 0 deletions

File tree

infrastructure/terraform/modules/eventpub/iam_role_sns.tf

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -49,4 +49,18 @@ data "aws_iam_policy_document" "firehose_delivery" {
4949
"${aws_kinesis_firehose_delivery_stream.main[0].arn}",
5050
]
5151
}
52+
53+
statement {
54+
sid = "AllowKmsAccessForFirehoseDelivery"
55+
effect = "Allow"
56+
57+
actions = [
58+
"kms:GenerateDataKey",
59+
"kms:Decrypt",
60+
]
61+
62+
resources = [
63+
var.kms_key_arn,
64+
]
65+
}
5266
}

0 commit comments

Comments
 (0)