Skip to content

Commit f423ad4

Browse files
authored
Fix duplicate prefix for s3 buckets (#25)
This resolved to `arn:aws:s3:::arn:aws:s3:::btsbx-lambda-responses-20250218214129013900000001` which incorrectly duplicates the prefix (`arn:aws:s3:::`) and caused the lambda to not have permissions to write to the buckets.
2 parents 8708c59 + 8958927 commit f423ad4

File tree

1 file changed

+4
-4
lines changed

1 file changed

+4
-4
lines changed

modules/services/iam.tf

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -184,10 +184,10 @@ resource "aws_iam_policy" "api_handler_policy" {
184184
Action = "s3:*"
185185
Effect = "Allow"
186186
Resource = concat([
187-
"arn:aws:s3:::${aws_s3_bucket.lambda_responses_bucket.arn}",
188-
"arn:aws:s3:::${aws_s3_bucket.lambda_responses_bucket.arn}/*",
189-
"arn:aws:s3:::${aws_s3_bucket.code_bundle_bucket.arn}",
190-
"arn:aws:s3:::${aws_s3_bucket.code_bundle_bucket.arn}/*",
187+
aws_s3_bucket.lambda_responses_bucket.arn,
188+
"${aws_s3_bucket.lambda_responses_bucket.arn}/*",
189+
aws_s3_bucket.code_bundle_bucket.arn,
190+
"${aws_s3_bucket.code_bundle_bucket.arn}/*",
191191
],
192192
var.brainstore_s3_bucket_name != null && var.brainstore_s3_bucket_name != "" ? [
193193
"arn:aws:s3:::${var.brainstore_s3_bucket_name}",

0 commit comments

Comments
 (0)