Skip to content

Commit 50cb3c7

Browse files
committed
updated permissions to SQS queues and S3 Objects
1 parent ce42c86 commit 50cb3c7

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

templates/deepwatch-logging-resource-configuration.yaml

+2
Original file line numberDiff line numberDiff line change
@@ -650,6 +650,7 @@ Resources:
650650
- 'sqs:GetQueueUrl'
651651
- 'sqs:SendMessage'
652652
- 'sqs:DeleteMessage'
653+
- 'sqs:changemessagevisibility'
653654
Resource:
654655
- !GetAtt [rCloudTrailQueue, Arn]
655656
- !GetAtt [rGuardDutyQueue, Arn]
@@ -664,6 +665,7 @@ Resources:
664665
- 's3:GetBucketLogging'
665666
- 's3:GetLifecycleConfiguration'
666667
- 's3:GetBucketCORS'
668+
- 's3:GetObjectVersion'
667669
Resource:
668670
- !Sub 'arn:${AWS::Partition}:s3:::${pGuardDutyBucketName}'
669671
- !Sub 'arn:${AWS::Partition}:s3:::${pCloudTrailBucketName}'

0 commit comments

Comments
 (0)