@@ -137,10 +137,9 @@ Resources:
137
137
ManagedPolicyArns :
138
138
- !Ref CryptoToolsKMS
139
139
- !Ref CodeBuildBatchPolicy
140
- - !Ref CodeBuildBasePolicy
140
+ - !Ref CodeBuildBasePolicyCI
141
141
- !Ref SecretsManagerPolicyCI
142
142
- !Ref ParameterStorePolicy
143
- - !Ref CodeBuildBasePolicyCI
144
143
- !Ref CodeBuildCISTSAllow
145
144
- " arn:aws:iam::aws:policy/AWSCodeArtifactReadOnlyAccess"
146
145
- " arn:aws:iam::aws:policy/AWSCodeArtifactAdminAccess"
@@ -194,9 +193,7 @@ Resources:
194
193
{
195
194
"Effect": "Allow",
196
195
"Resource": [
197
- "arn:aws:codebuild:${AWS::Region}:${AWS::AccountId}:project/${ProjectName}-Release",
198
- "arn:aws:codebuild:${AWS::Region}:${AWS::AccountId}:project/${ProjectName}-CI",
199
- "arn:aws:codebuild:${AWS::Region}:${AWS::AccountId}:project/${ProjectName}"
196
+ "arn:aws:codebuild:${AWS::Region}:${AWS::AccountId}:project/${ProjectName}-CI"
200
197
],
201
198
"Action": [
202
199
"codebuild:StartBuild",
@@ -221,7 +218,7 @@ Resources:
221
218
{
222
219
"Effect": "Allow",
223
220
"Resource": [
224
- "arn:aws:codebuild:us-west-2: ${AWS::AccountId}:project/AWS-ESDK-Java -Release"
221
+ "arn:aws:codebuild:${AWS::Region}: ${AWS::AccountId}:project/${ProjectName} -Release"
225
222
],
226
223
"Action": [
227
224
"codebuild:StartBuild",
@@ -244,8 +241,6 @@ Resources:
244
241
{
245
242
"Effect": "Allow",
246
243
"Resource": [
247
- "arn:aws:logs:${AWS::Region}:${AWS::AccountId}:log-group:/aws/codebuild/${ProjectName}",
248
- "arn:aws:logs:${AWS::Region}:${AWS::AccountId}:log-group:/aws/codebuild/${ProjectName}:*",
249
244
"arn:aws:logs:${AWS::Region}:${AWS::AccountId}:log-group:/aws/codebuild/${ProjectName}-CI",
250
245
"arn:aws:logs:${AWS::Region}:${AWS::AccountId}:log-group:/aws/codebuild/${ProjectName}-CI:*",
251
246
"arn:aws:logs:${AWS::Region}:${AWS::AccountId}:log-group:/aws/codebuild/${ProjectName}-Release",
@@ -305,7 +300,8 @@ Resources:
305
300
"Action": [
306
301
"logs:CreateLogGroup",
307
302
"logs:CreateLogStream",
308
- "logs:PutLogEvents"
303
+ "logs:PutLogEvents",
304
+ "logs:GetLogEvents"
309
305
]
310
306
},
311
307
{
@@ -331,7 +327,7 @@ Resources:
331
327
"codebuild:BatchPutCodeCoverages"
332
328
],
333
329
"Resource": [
334
- "arn:aws:codebuild:us-west-2:${AWS::AccountId}:report-group/AWS-ESDK-Java -CI-*"
330
+ "arn:aws:codebuild:us-west-2:${AWS::AccountId}:report-group/${ProjectName} -CI-*"
335
331
]
336
332
}
337
333
]
0 commit comments