Skip to content

Commit d185f24

Browse files
committed
Adding policy to allow execute-command
1 parent bfc1166 commit d185f24

File tree

1 file changed

+12
-0
lines changed

1 file changed

+12
-0
lines changed

iam-ecs-task.tf

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -39,6 +39,18 @@ resource "aws_iam_role_policy" "ssm_policy" {
3939
"Resource": [
4040
"arn:aws:ssm:*:*:parameter/*"
4141
]
42+
},
43+
{
44+
"Effect": "Allow",
45+
"Action": [
46+
"ssmmessages:CreateControlChannel",
47+
"ssmmessages:CreateDataChannel",
48+
"ssmmessages:OpenControlChannel",
49+
"ssmmessages:OpenDataChannel"
50+
],
51+
"Resource": [
52+
"*"
53+
]
4254
}
4355
]
4456
}

0 commit comments

Comments
 (0)