diff --git a/terraform/environments/bootstrap/member-bootstrap/iam.tf b/terraform/environments/bootstrap/member-bootstrap/iam.tf index fd36b9853..a71584759 100644 --- a/terraform/environments/bootstrap/member-bootstrap/iam.tf +++ b/terraform/environments/bootstrap/member-bootstrap/iam.tf @@ -275,6 +275,12 @@ data "aws_iam_policy_document" "member-access" { ] resources = ["arn:aws:iam::*:user/cicd-member-user"] } + + statement { + actions = ["iam:PassRole"] + effect = "Deny" + resources = ["arn:aws:iam::*:role/MemberInfrastructureAccess"] + } } resource "aws_iam_policy" "member-access" { @@ -390,6 +396,12 @@ data "aws_iam_policy_document" "member-access-us-east" { ] resources = ["*"] } + + statement { + actions = ["iam:PassRole"] + effect = "Deny" + resources = ["arn:aws:iam::*:role/MemberInfrastructureAccessUSEast"] + } } resource "aws_iam_policy" "member-access-us-east" {