HomePhabricator
Diffusion Comm 5011835a4474

[services][terraform] Set up IAM for feature-flags service

Description

[services][terraform] Set up IAM for feature-flags service

Summary:
Sets up IAM for feature-flags service. Also this is example of how to set up IAM to give minimum required permissions to a service.

Created a role that:

  • Can be assumed by EC2 instances and ECS tasks - basically they are allowed to use it
  • Allows read operations on feature-flags DDB table

Depends on D8583

Test Plan: Tested together with next diff - they're live on AWS now.

Reviewers: tomek, michal, jon, varun

Reviewed By: jon

Subscribers: ashoat

Differential Revision: https://phab.comm.dev/D8635

Details

Provenance
bartekAuthored on Jul 26 2023, 1:49 AM
Reviewer
jon
Differential Revision
D8635: [services][terraform] Set up IAM for feature-flags service
Parents
rCOMMdeb2e9c3a1f3: [services][terraform] Set up electron-update ECS service
Branches
Unknown
Tags
Unknown