Skip to content

Commit

Permalink
Identation fix
Browse files Browse the repository at this point in the history
  • Loading branch information
miguelpais committed Dec 11, 2024
1 parent 34abf9d commit 062c41b
Showing 1 changed file with 39 additions and 39 deletions.
78 changes: 39 additions & 39 deletions modules/vm_workload_scanning.cft.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -210,45 +210,45 @@ Resources:
Condition:
StringEquals:
sts:ExternalId: !Ref ExternalID
ECRPolicy:
Type: AWS::IAM::Policy
Properties:
PolicyName: !Sub sysdig-vm-workload-scanning-${NameSuffix}-ecr
Roles:
- !Ref ScanningRole
PolicyDocument:
Version: '2012-10-17'
Statement:
- Effect: Allow
Action:
- ecr:GetDownloadUrlForLayer
- ecr:BatchGetImage
- ecr:BatchCheckLayerAvailability
- ecr:ListImages
- ecr:GetAuthorizationToken
Resource: '*'
LambdaPolicy:
Type: AWS::IAM::Policy
Condition: LambdaScanningEnabled
Properties:
PolicyName: !Sub sysdig-vm-workload-scanning-${NameSuffix}-lambda
Roles:
- !Ref ScanningRole
PolicyDocument:
Version: '2012-10-17'
Statement:
- Effect: Allow
Action:
- lambda:GetFunction
- lambda:GetFunctionConfiguration
- lambda:GetRuntimeManagementConfig
- lambda:ListFunctions
- lambda:ListTagsForResource
- lambda:GetLayerVersionByArn
- lambda:GetLayerVersion
- lambda:ListLayers
- lambda:ListLayerVersions
Resource: '*'
ECRPolicy:
Type: AWS::IAM::Policy
Properties:
PolicyName: !Sub sysdig-vm-workload-scanning-${NameSuffix}-ecr
Roles:
- !Ref ScanningRole
PolicyDocument:
Version: '2012-10-17'
Statement:
- Effect: Allow
Action:
- ecr:GetDownloadUrlForLayer
- ecr:BatchGetImage
- ecr:BatchCheckLayerAvailability
- ecr:ListImages
- ecr:GetAuthorizationToken
Resource: '*'
LambdaPolicy:
Type: AWS::IAM::Policy
Condition: LambdaScanningEnabled
Properties:
PolicyName: !Sub sysdig-vm-workload-scanning-${NameSuffix}-lambda
Roles:
- !Ref ScanningRole
PolicyDocument:
Version: '2012-10-17'
Statement:
- Effect: Allow
Action:
- lambda:GetFunction
- lambda:GetFunctionConfiguration
- lambda:GetRuntimeManagementConfig
- lambda:ListFunctions
- lambda:ListTagsForResource
- lambda:GetLayerVersionByArn
- lambda:GetLayerVersion
- lambda:ListLayers
- lambda:ListLayerVersions
Resource: '*'
Expand Down

0 comments on commit 062c41b

Please sign in to comment.