diff --git a/CHANGELOG.md b/CHANGELOG.md index ad23d73eb..8735b27da 100755 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,3 +1,6 @@ +## v0.33.9 +- Allow account reset codebuild access to custom nuke config bucket + ## v0.33.8 - Upgrade the Swagger UI dependency to remove a very dangerous vulnerability (upgrade Swagger UI to v3.51.2). diff --git a/modules/reset_codebuild.tf b/modules/reset_codebuild.tf index ced0653ea..7ad78a7df 100755 --- a/modules/reset_codebuild.tf +++ b/modules/reset_codebuild.tf @@ -151,51 +151,60 @@ EOF tags = var.global_tags } -# Configure IAM Policy for CodeBuild +# Configure IAM Role for CodeBuild resource "aws_iam_role_policy" "codebuild_reset" { - role = aws_iam_role.codebuild_reset.name - name = "account-reset-codebuild-${var.namespace}" + role = aws_iam_role.codebuild_reset.name + name = "account-reset-codebuild-${var.namespace}" + policy = data.aws_iam_policy_document.codebuild_reset_policy_document.json +} - policy = <