Skip to content

Conversation

wideawakening
Copy link
Contributor

@wideawakening wideawakening commented Feb 7, 2022

as they're not required

  • kms:Decrypt is only required in cloudtrail module, not cloud-connector, as its encryption is done in transport, not persitence
  • secretsmanager:GetSecretValue is not used. we got it confused with what we're currently using: ssm:GetParameters over a "SecureString" type of parameter

@wideawakening wideawakening linked an issue Feb 7, 2022 that may be closed by this pull request
@wideawakening wideawakening marked this pull request as ready for review February 10, 2022 18:05
@wideawakening wideawakening merged commit 7a18058 into master Feb 10, 2022
@wideawakening wideawakening deleted the chore/refine-permissions branch February 10, 2022 18:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Dangerous/broad policy attached to ECS tasks

1 participant