We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 524554e commit 645b7dfCopy full SHA for 645b7df
mwaa-iam.tf
@@ -162,6 +162,23 @@ data "aws_iam_policy_document" "mwaa_policy" {
162
}
163
164
165
+ statement {
166
+ effect = "Allow"
167
+ actions = [
168
+ "dynamodb:Describe*",
169
+ "dynamodb:PartiQLSelect",
170
+ "dynamodb:Get*",
171
+ "dynamodb:Scan",
172
+ "dynamodb:Query",
173
+ "dynamodb:BatchGetItem",
174
+ "dynamodb:ConditionCheckItem",
175
+ "dynamodb:List*",
176
+ ]
177
+ resources = [
178
+ "arn:aws:dynamodb:*:${data.aws_caller_identity.current.account_id}:*"
179
180
+ }
181
+
182
# Policy to grant acces to SSM
183
statement {
184
effect = "Allow"
0 commit comments