You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
"Allow group id ${local.dd_group_ocid} to read all-resources in tenancy",
191
191
"Allow group id ${local.dd_group_ocid} to use tag-namespaces in tenancy",
192
192
"Allow group id ${local.dd_group_ocid} to manage serviceconnectors in compartment id ${var.compartment_id}",
193
-
"Allow group id ${local.dd_group_ocid} to manage functions-family in compartment id ${var.compartment_id} where ANY {request.permission = 'FN_FUNCTION_UPDATE', request.permission = 'FN_FUNCTION_LIST', request.permission = 'FN_APP_LIST'}",
193
+
"Allow group id ${local.dd_group_ocid} to manage functions-family in compartment id ${var.compartment_id}",
194
+
"Allow group id ${local.dd_group_ocid} to manage buckets in compartment id ${var.compartment_id} where target.bucket.name=/dd-*/",
195
+
"Allow group id ${local.dd_group_ocid} to manage object-family in compartment id ${var.compartment_id} where target.bucket.name=/dd-*/",
196
+
"Allow group id ${local.dd_group_ocid} to use fn-invocation in compartment id ${var.compartment_id}",
194
197
"Endorse group id ${local.dd_group_ocid} to read objects in tenancy usage-report"
description="[DO NOT REMOVE] Policy to have any connector hub read from eligible sources and write to a target function"
224
+
description="[DO NOT REMOVE] Policy for connector hubs and forwarding functions"
222
225
name=var.dg_policy_name
223
226
statements=[
224
227
"Allow dynamic-group id ${oci_identity_domains_dynamic_resource_group.service_connector.ocid} to read log-content in tenancy",
225
228
"Allow dynamic-group id ${oci_identity_domains_dynamic_resource_group.service_connector.ocid} to read metrics in tenancy",
226
229
"Allow dynamic-group id ${oci_identity_domains_dynamic_resource_group.service_connector.ocid} to use fn-function in compartment id ${var.compartment_id}",
227
230
"Allow dynamic-group id ${oci_identity_domains_dynamic_resource_group.service_connector.ocid} to use fn-invocation in compartment id ${var.compartment_id}",
228
-
"Allow dynamic-group id ${oci_identity_domains_dynamic_resource_group.forwarding_function.ocid} to read secret-bundles in compartment id ${var.compartment_id}"
231
+
"Allow dynamic-group id ${oci_identity_domains_dynamic_resource_group.forwarding_function.ocid} to read secret-bundles in compartment id ${var.compartment_id}",
232
+
"Allow dynamic-group id ${oci_identity_domains_dynamic_resource_group.forwarding_function.ocid} to manage object-family in compartment id ${var.compartment_id} where target.bucket.name=/dd-*/"
"Allow group id ${var.existing_group_id!=null&&var.existing_group_id!=""?var.existing_group_id:oci_identity_domains_group.dd_auth[0].ocid} to read all-resources in tenancy",
195
195
"Allow group id ${var.existing_group_id!=null&&var.existing_group_id!=""?var.existing_group_id:oci_identity_domains_group.dd_auth[0].ocid} to use tag-namespaces in tenancy",
196
196
"Allow group id ${var.existing_group_id!=null&&var.existing_group_id!=""?var.existing_group_id:oci_identity_domains_group.dd_auth[0].ocid} to manage serviceconnectors in compartment id ${var.compartment_id}",
197
-
"Allow group id ${var.existing_group_id!=null&&var.existing_group_id!=""?var.existing_group_id:oci_identity_domains_group.dd_auth[0].ocid} to manage functions-family in compartment id ${var.compartment_id} where ANY {request.permission = 'FN_FUNCTION_UPDATE', request.permission = 'FN_FUNCTION_LIST', request.permission = 'FN_APP_LIST'}",
197
+
"Allow group id ${var.existing_group_id!=null&&var.existing_group_id!=""?var.existing_group_id:oci_identity_domains_group.dd_auth[0].ocid} to manage functions-family in compartment id ${var.compartment_id}",
198
+
"Allow group id ${var.existing_group_id!=null&&var.existing_group_id!=""?var.existing_group_id:oci_identity_domains_group.dd_auth[0].ocid} to manage buckets in compartment id ${var.compartment_id} where target.bucket.name=/dd-*/",
199
+
"Allow group id ${var.existing_group_id!=null&&var.existing_group_id!=""?var.existing_group_id:oci_identity_domains_group.dd_auth[0].ocid} to manage object-family in compartment id ${var.compartment_id} where target.bucket.name=/dd-*/",
200
+
"Allow group id ${var.existing_group_id!=null&&var.existing_group_id!=""?var.existing_group_id:oci_identity_domains_group.dd_auth[0].ocid} to use fn-invocation in compartment id ${var.compartment_id}",
198
201
"Endorse group id ${var.existing_group_id!=null&&var.existing_group_id!=""?var.existing_group_id:oci_identity_domains_group.dd_auth[0].ocid} to read objects in tenancy usage-report"
description="[DO NOT REMOVE] Policy to have any connector hub read from eligible sources and write to a target function"
228
+
description="[DO NOT REMOVE] Policy for connector hubs and forwarding functions"
226
229
name=var.dg_policy_name
227
230
statements=[
228
231
"Allow dynamic-group id ${oci_identity_domains_dynamic_resource_group.service_connector.ocid} to read log-content in tenancy",
229
232
"Allow dynamic-group id ${oci_identity_domains_dynamic_resource_group.service_connector.ocid} to read metrics in tenancy",
230
233
"Allow dynamic-group id ${oci_identity_domains_dynamic_resource_group.service_connector.ocid} to use fn-function in compartment id ${var.compartment_id}",
231
234
"Allow dynamic-group id ${oci_identity_domains_dynamic_resource_group.service_connector.ocid} to use fn-invocation in compartment id ${var.compartment_id}",
232
-
"Allow dynamic-group id ${oci_identity_domains_dynamic_resource_group.forwarding_function.ocid} to read secret-bundles in compartment id ${var.compartment_id}"
235
+
"Allow dynamic-group id ${oci_identity_domains_dynamic_resource_group.forwarding_function.ocid} to read secret-bundles in compartment id ${var.compartment_id}",
236
+
"Allow dynamic-group id ${oci_identity_domains_dynamic_resource_group.forwarding_function.ocid} to manage object-family in compartment id ${var.compartment_id} where target.bucket.name=/dd-*/"
0 commit comments