diff --git a/README.md b/README.md index 17f37ff..b8fbf0c 100644 --- a/README.md +++ b/README.md @@ -178,6 +178,8 @@ The audit policy is comprised of the following permissions: | | compute-optimizer:GetLambdaFunctionRecommendations | | | | compute-optimizer:GetRecommendationPreferences | | | | compute-optimizer:GetRecommendationSummaries | | +| | compute-optimizer:GetECSServiceRecommendations | | +| | compute-optimizer:GetLicenseRecommendations | | | KINESISANALYTICS | kinesisanalytics:ListApplicationSnapshots | | | | kinesisanalytics:ListApplicationVersions | | | | kinesisanalytics:DescribeApplicationVersion | | @@ -189,4 +191,9 @@ The audit policy is comprised of the following permissions: | | aps:DescribeLoggingConfiguration | | | | aps:DescribeWorkspace | | | | aps:ListRuleGroupsNamespaces | | -| | aps:DescribeRuleGroupsNamespace | | \ No newline at end of file +| | aps:DescribeRuleGroupsNamespace | | +| KINESISVIDEO | kinesisvideo:DescribeImageGenerationConfiguration | * | +| | kinesisvideo:GetDataEndpoint | | +| | kinesisvideo:GetSignalingChannelEndpoint | | +| | kinesisvideo:ListEdgeAgentConfigurations | | +| APPRUNNER | apprunner:ListServicesForAutoScalingConfiguration | * | \ No newline at end of file diff --git a/main.tf b/main.tf index f32f6dc..3b0be16 100644 --- a/main.tf +++ b/main.tf @@ -234,7 +234,9 @@ data "aws_iam_policy_document" "lacework_audit_policy" { "compute-optimizer:GetEnrollmentStatusesForOrganization", "compute-optimizer:GetLambdaFunctionRecommendations", "compute-optimizer:GetRecommendationPreferences", - "compute-optimizer:GetRecommendationSummaries" + "compute-optimizer:GetRecommendationSummaries", + "compute-optimizer:GetECSServiceRecommendations", + "compute-optimizer:GetLicenseRecommendations" ] resources = ["*"] } @@ -262,6 +264,25 @@ data "aws_iam_policy_document" "lacework_audit_policy" { ] resources = ["*"] } + + statement { + sid = "KINESISVIDEO" + actions = [ + "kinesisvideo:DescribeImageGenerationConfiguration", + "kinesisvideo:GetDataEndpoint", + "kinesisvideo:GetSignalingChannelEndpoint", + "kinesisvideo:ListEdgeAgentConfigurations" + ] + resources = ["*"] + } + + statement { + sid = "APPRUNNER" + actions = [ + "apprunner:ListServicesForAutoScalingConfiguration" + ] + resources = ["*"] + } } resource "aws_iam_policy" "lacework_audit_policy" {