Skip to content

Role/User changes in AIM should be run separately #423

@massenz

Description

@massenz

Several of the TF actions in the infrastructure/terraform/environments/shared folder make changes to the Roles and Policies in AIM, and require to essentially run the zero apply with an Admin-level user; this is probably unnecessary for most of the other deployment actions, where a much lover permission level is required.

Also, deploying resources with such a high privilege level may complicate matters when tearing them down.

It would be great if those could be separated out (zero prepare?) with a separate, admin-level user; also bearing in mind that they won't probably change much over the course of a project's life, so could easily be only run once.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions