@@ -214,33 +214,33 @@ resource "aws_iam_policy" "shared_iam_policy" {
214214 ],
215215 Effect = " Allow" ,
216216 Resource = [
217- " arn:aws:dynamodb:${ data . aws_region . current . region } :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-events" ,
218- " arn:aws:dynamodb:${ data . aws_region . current . region } :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-events/index/*" ,
219- " arn:aws:dynamodb:${ data . aws_region . current . region } :${ data . aws_caller_identity . current . account_id } :table/infra-merchstore-purchase-history" ,
220- " arn:aws:dynamodb:${ data . aws_region . current . region } :${ data . aws_caller_identity . current . account_id } :table/infra-merchstore-purchase-history/index/*" ,
221- " arn:aws:dynamodb:${ data . aws_region . current . region } :${ data . aws_caller_identity . current . account_id } :table/infra-events-tickets" ,
222- " arn:aws:dynamodb:${ data . aws_region . current . region } :${ data . aws_caller_identity . current . account_id } :table/infra-events-ticketing-metadata" ,
223- " arn:aws:dynamodb:${ data . aws_region . current . region } :${ data . aws_caller_identity . current . account_id } :table/infra-merchstore-metadata" ,
224- " arn:aws:dynamodb:${ data . aws_region . current . region } :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-iam-assignments" ,
225- " arn:aws:dynamodb:${ data . aws_region . current . region } :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-stripe-links" ,
226- " arn:aws:dynamodb:${ data . aws_region . current . region } :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-stripe-links/index/*" ,
227- " arn:aws:dynamodb:${ data . aws_region . current . region } :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-membership-external-v3" ,
228- " arn:aws:dynamodb:${ data . aws_region . current . region } :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-membership-external-v3/index/*" ,
229- " arn:aws:dynamodb:${ data . aws_region . current . region } :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-room-requests" ,
230- " arn:aws:dynamodb:${ data . aws_region . current . region } :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-room-requests/index/*" ,
231- " arn:aws:dynamodb:${ data . aws_region . current . region } :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-room-requests-status" ,
232- " arn:aws:dynamodb:${ data . aws_region . current . region } :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-room-requests-status/index/*" ,
233- " arn:aws:dynamodb:${ data . aws_region . current . region } :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-linkry" ,
234- " arn:aws:dynamodb:${ data . aws_region . current . region } :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-linkry/index/*" ,
235- " arn:aws:dynamodb:${ data . aws_region . current . region } :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-keys" ,
236- " arn:aws:dynamodb:${ data . aws_region . current . region } :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-sigs" ,
237- " arn:aws:dynamodb:${ data . aws_region . current . region } :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-sigs/index/*" ,
217+ " arn:aws:dynamodb:us-east-2 :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-events" ,
218+ " arn:aws:dynamodb:us-east-2 :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-events/index/*" ,
219+ " arn:aws:dynamodb:us-east-2 :${ data . aws_caller_identity . current . account_id } :table/infra-merchstore-purchase-history" ,
220+ " arn:aws:dynamodb:us-east-2 :${ data . aws_caller_identity . current . account_id } :table/infra-merchstore-purchase-history/index/*" ,
221+ " arn:aws:dynamodb:us-east-2 :${ data . aws_caller_identity . current . account_id } :table/infra-events-tickets" ,
222+ " arn:aws:dynamodb:us-east-2 :${ data . aws_caller_identity . current . account_id } :table/infra-events-ticketing-metadata" ,
223+ " arn:aws:dynamodb:us-east-2 :${ data . aws_caller_identity . current . account_id } :table/infra-merchstore-metadata" ,
224+ " arn:aws:dynamodb:us-east-2 :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-iam-assignments" ,
225+ " arn:aws:dynamodb:us-east-2 :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-stripe-links" ,
226+ " arn:aws:dynamodb:us-east-2 :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-stripe-links/index/*" ,
227+ " arn:aws:dynamodb:us-east-2 :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-membership-external-v3" ,
228+ " arn:aws:dynamodb:us-east-2 :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-membership-external-v3/index/*" ,
229+ " arn:aws:dynamodb:us-east-2 :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-room-requests" ,
230+ " arn:aws:dynamodb:us-east-2 :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-room-requests/index/*" ,
231+ " arn:aws:dynamodb:us-east-2 :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-room-requests-status" ,
232+ " arn:aws:dynamodb:us-east-2 :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-room-requests-status/index/*" ,
233+ " arn:aws:dynamodb:us-east-2 :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-linkry" ,
234+ " arn:aws:dynamodb:us-east-2 :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-linkry/index/*" ,
235+ " arn:aws:dynamodb:us-east-2 :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-keys" ,
236+ " arn:aws:dynamodb:us-east-2 :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-sigs" ,
237+ " arn:aws:dynamodb:us-east-2 :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-sigs/index/*" ,
238238
239239 // added permissions for 3 new tables
240- " arn:aws:dynamodb:${ data . aws_region . current . region } :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-store-inventory" ,
241- " arn:aws:dynamodb:${ data . aws_region . current . region } :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-store-carts-orders" ,
242- " arn:aws:dynamodb:${ data . aws_region . current . region } :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-store-carts-orders/index/*" ,
243- " arn:aws:dynamodb:${ data . aws_region . current . region } :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-store-limits"
240+ " arn:aws:dynamodb:us-east-2 :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-store-inventory" ,
241+ " arn:aws:dynamodb:us-east-2 :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-store-carts-orders" ,
242+ " arn:aws:dynamodb:us-east-2 :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-store-carts-orders/index/*" ,
243+ " arn:aws:dynamodb:us-east-2 :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-store-limits"
244244 ]
245245 },
246246 {
@@ -256,7 +256,7 @@ resource "aws_iam_policy" "shared_iam_policy" {
256256 " dynamodb:UpdateItem"
257257 ],
258258 Resource = [
259- " arn:aws:dynamodb:${ data . aws_region . current . region } :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-cache" ,
259+ " arn:aws:dynamodb:us-east-2 :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-cache" ,
260260 ]
261261 },
262262 {
@@ -268,8 +268,8 @@ resource "aws_iam_policy" "shared_iam_policy" {
268268 " dynamodb:Query" ,
269269 ],
270270 Resource = [
271- " arn:aws:dynamodb:${ data . aws_region . current . region } :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-audit-log" ,
272- " arn:aws:dynamodb:${ data . aws_region . current . region } :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-audit-log/index/*" ,
271+ " arn:aws:dynamodb:us-east-2 :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-audit-log" ,
272+ " arn:aws:dynamodb:us-east-2 :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-audit-log/index/*" ,
273273 ]
274274 },
275275 {
@@ -283,8 +283,8 @@ resource "aws_iam_policy" "shared_iam_policy" {
283283 " dynamodb:Query" ,
284284 ],
285285 Resource = [
286- " arn:aws:dynamodb:${ data . aws_region . current . region } :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-user-info" ,
287- " arn:aws:dynamodb:${ data . aws_region . current . region } :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-user-info/index/*" ,
286+ " arn:aws:dynamodb:us-east-2 :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-user-info" ,
287+ " arn:aws:dynamodb:us-east-2 :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-user-info/index/*" ,
288288 ]
289289 },
290290 {
@@ -297,8 +297,8 @@ resource "aws_iam_policy" "shared_iam_policy" {
297297 " dynamodb:ListStreams"
298298 ],
299299 Resource = [
300- " arn:aws:dynamodb:${ data . aws_region . current . region } :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-stripe-links/stream/*" ,
301- " arn:aws:dynamodb:${ data . aws_region . current . region } :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-events/stream/*" ,
300+ " arn:aws:dynamodb:us-east-2 :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-stripe-links/stream/*" ,
301+ " arn:aws:dynamodb:us-east-2 :${ data . aws_caller_identity . current . account_id } :table/infra-core-api-events/stream/*" ,
302302 ]
303303 },
304304 {
0 commit comments