Skip to content

Commit 1eeed4e

Browse files
give dynamoDB delete:itme permissions to idempotency
1 parent e53e6c7 commit 1eeed4e

1 file changed

Lines changed: 16 additions & 1 deletion

File tree

infrastructure/terraform/components/api/module_lambda_upsert_letter.tf

Lines changed: 16 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -67,11 +67,26 @@ data "aws_iam_policy_document" "upsert_letter_lambda" {
6767

6868
resources = [
6969
aws_dynamodb_table.letters.arn,
70-
aws_dynamodb_table.idempotency.arn,
7170
"${aws_dynamodb_table.letters.arn}/index/supplierStatus-index"
7271
]
7372
}
7473

74+
statement {
75+
sid = "AllowIdempotencyTableWrite"
76+
effect = "Allow"
77+
78+
actions = [
79+
"dynamodb:PutItem",
80+
"dynamodb:GetItem",
81+
"dynamodb:UpdateItem",
82+
"dynamodb:DeleteItem"
83+
]
84+
85+
resources = [
86+
aws_dynamodb_table.idempotency.arn,
87+
]
88+
}
89+
7590
statement {
7691
sid = "AllowSQSRead"
7792
effect = "Allow"

0 commit comments

Comments
 (0)