Skip to content

Commit 44204d9

Browse files
authored
fix: update policies (#511)
1 parent c707658 commit 44204d9

File tree

2 files changed

+5
-6
lines changed

2 files changed

+5
-6
lines changed

main.tf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -994,7 +994,7 @@ module "devsecops_cc_toolchain" {
994994
# Random string for webhook token
995995
resource "random_string" "webhook_secret" {
996996
count = (var.autostart) ? 1 : 0
997-
depends_on = [module.devsecops_ci_toolchain[0].ci_pipeline_id, module.devsecops_ci_toolchain[0].app_repo_url]
997+
depends_on = [module.devsecops_ci_toolchain[0].ci_pipeline_id, module.devsecops_ci_toolchain[0].app_repo_url, module.prereqs]
998998
length = 48
999999
special = false
10001000
upper = false

prereqs/main.tf

Lines changed: 4 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -106,19 +106,18 @@ resource "ibm_iam_service_policy" "cd_policy" {
106106
resource "ibm_iam_service_policy" "kube_policy" {
107107
count = ((var.create_kubernetes_access_policy == true) && (local.create_pipeline_api_key == true)) ? 1 : 0
108108
iam_service_id = ibm_iam_service_id.pipeline_service_id[0].id
109-
roles = ["Editor"]
109+
roles = ["Manager", "Editor"]
110110
resources {
111-
service = "kubernetes"
112-
resource_group_id = data.ibm_resource_group.resource_group.id
111+
service = "containers-kubernetes"
113112
}
114113
}
115114

116115
resource "ibm_iam_service_policy" "ce_policy" {
117116
count = ((var.create_code_engine_access_policy) && (local.create_pipeline_api_key == true)) ? 1 : 0
118117
iam_service_id = ibm_iam_service_id.pipeline_service_id[0].id
119-
roles = ["Editor"]
118+
roles = ["Manager", "Editor"]
120119
resources {
121-
service = "code-engine"
120+
service = "codeengine"
122121
resource_group_id = data.ibm_resource_group.resource_group.id
123122
}
124123
}

0 commit comments

Comments
 (0)