Skip to content

Commit 21f1f93

Browse files
authored
fix(kms policy): update cfn templates with kms policy to match with CDK v2 (#397)
* fix(kms policy): update cfn templates with kms policy to match with CDK v2 * fix(kms policy): update cfn templates with kms policy to match with CDK v2
1 parent bba361e commit 21f1f93

File tree

36 files changed

+72
-829
lines changed

36 files changed

+72
-829
lines changed

.viperlightignore

+21-21
Original file line numberDiff line numberDiff line change
@@ -65,27 +65,27 @@ source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/inte
6565
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.deployFunction.expected.json:60
6666
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.deployFunction.expected.json:63
6767
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.deployFunction.expected.json:66
68-
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:609
69-
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:612
70-
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:615
71-
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:618
72-
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:621
73-
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:624
74-
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:627
75-
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:630
76-
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:633
77-
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:636
78-
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:639
79-
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:642
80-
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:645
81-
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:648
82-
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:651
83-
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:654
84-
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:657
85-
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:660
86-
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:663
87-
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:666
88-
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:669
68+
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:593
69+
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:596
70+
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:599
71+
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:602
72+
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:605
73+
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:608
74+
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:611
75+
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:614
76+
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:617
77+
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:620
78+
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:623
79+
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:626
80+
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:629
81+
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:632
82+
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:635
83+
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:638
84+
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:641
85+
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:644
86+
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:647
87+
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:650
88+
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingFunction.expected.json:653
8989
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingSageMakerEndpoint.expected.json:6
9090
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingSageMakerEndpoint.expected.json:9
9191
source/patterns/@aws-solutions-constructs/aws-lambda-sagemakerendpoint/test/integ.existingSageMakerEndpoint.expected.json:12

source/patterns/@aws-solutions-constructs/aws-eventbridge-sns/test/integ.eb-existing-bus.expected.json

+1-17
Original file line numberDiff line numberDiff line change
@@ -12,23 +12,7 @@
1212
"KeyPolicy": {
1313
"Statement": [
1414
{
15-
"Action": [
16-
"kms:Create*",
17-
"kms:Describe*",
18-
"kms:Enable*",
19-
"kms:List*",
20-
"kms:Put*",
21-
"kms:Update*",
22-
"kms:Revoke*",
23-
"kms:Disable*",
24-
"kms:Get*",
25-
"kms:Delete*",
26-
"kms:ScheduleKeyDeletion",
27-
"kms:CancelKeyDeletion",
28-
"kms:GenerateDataKey",
29-
"kms:TagResource",
30-
"kms:UntagResource"
31-
],
15+
"Action": "kms:*",
3216
"Effect": "Allow",
3317
"Principal": {
3418
"AWS": {

source/patterns/@aws-solutions-constructs/aws-eventbridge-sns/test/integ.eb-new-bus.expected.json

+1-17
Original file line numberDiff line numberDiff line change
@@ -6,23 +6,7 @@
66
"KeyPolicy": {
77
"Statement": [
88
{
9-
"Action": [
10-
"kms:Create*",
11-
"kms:Describe*",
12-
"kms:Enable*",
13-
"kms:List*",
14-
"kms:Put*",
15-
"kms:Update*",
16-
"kms:Revoke*",
17-
"kms:Disable*",
18-
"kms:Get*",
19-
"kms:Delete*",
20-
"kms:ScheduleKeyDeletion",
21-
"kms:CancelKeyDeletion",
22-
"kms:GenerateDataKey",
23-
"kms:TagResource",
24-
"kms:UntagResource"
25-
],
9+
"Action": "kms:*",
2610
"Effect": "Allow",
2711
"Principal": {
2812
"AWS": {

source/patterns/@aws-solutions-constructs/aws-eventbridge-sns/test/integ.eventbridge-no-arg.expected.json

+1-17
Original file line numberDiff line numberDiff line change
@@ -6,23 +6,7 @@
66
"KeyPolicy": {
77
"Statement": [
88
{
9-
"Action": [
10-
"kms:Create*",
11-
"kms:Describe*",
12-
"kms:Enable*",
13-
"kms:List*",
14-
"kms:Put*",
15-
"kms:Update*",
16-
"kms:Revoke*",
17-
"kms:Disable*",
18-
"kms:Get*",
19-
"kms:Delete*",
20-
"kms:ScheduleKeyDeletion",
21-
"kms:CancelKeyDeletion",
22-
"kms:GenerateDataKey",
23-
"kms:TagResource",
24-
"kms:UntagResource"
25-
],
9+
"Action": "kms:*",
2610
"Effect": "Allow",
2711
"Principal": {
2812
"AWS": {

source/patterns/@aws-solutions-constructs/aws-eventbridge-sqs/test/integ.eventbridge-existing-eventbus.expected.json

+1-17
Original file line numberDiff line numberDiff line change
@@ -6,23 +6,7 @@
66
"KeyPolicy": {
77
"Statement": [
88
{
9-
"Action": [
10-
"kms:Create*",
11-
"kms:Describe*",
12-
"kms:Enable*",
13-
"kms:List*",
14-
"kms:Put*",
15-
"kms:Update*",
16-
"kms:Revoke*",
17-
"kms:Disable*",
18-
"kms:Get*",
19-
"kms:Delete*",
20-
"kms:ScheduleKeyDeletion",
21-
"kms:CancelKeyDeletion",
22-
"kms:GenerateDataKey",
23-
"kms:TagResource",
24-
"kms:UntagResource"
25-
],
9+
"Action": "kms:*",
2610
"Effect": "Allow",
2711
"Principal": {
2812
"AWS": {

source/patterns/@aws-solutions-constructs/aws-eventbridge-sqs/test/integ.eventbridge-existing-queue.expected.json

+1-17
Original file line numberDiff line numberDiff line change
@@ -6,23 +6,7 @@
66
"KeyPolicy": {
77
"Statement": [
88
{
9-
"Action": [
10-
"kms:Create*",
11-
"kms:Describe*",
12-
"kms:Enable*",
13-
"kms:List*",
14-
"kms:Put*",
15-
"kms:Update*",
16-
"kms:Revoke*",
17-
"kms:Disable*",
18-
"kms:Get*",
19-
"kms:Delete*",
20-
"kms:ScheduleKeyDeletion",
21-
"kms:CancelKeyDeletion",
22-
"kms:GenerateDataKey",
23-
"kms:TagResource",
24-
"kms:UntagResource"
25-
],
9+
"Action": "kms:*",
2610
"Effect": "Allow",
2711
"Principal": {
2812
"AWS": {

source/patterns/@aws-solutions-constructs/aws-eventbridge-sqs/test/integ.eventbridge-new-eventbus.expected.json

+1-17
Original file line numberDiff line numberDiff line change
@@ -85,23 +85,7 @@
8585
"KeyPolicy": {
8686
"Statement": [
8787
{
88-
"Action": [
89-
"kms:Create*",
90-
"kms:Describe*",
91-
"kms:Enable*",
92-
"kms:List*",
93-
"kms:Put*",
94-
"kms:Update*",
95-
"kms:Revoke*",
96-
"kms:Disable*",
97-
"kms:Get*",
98-
"kms:Delete*",
99-
"kms:ScheduleKeyDeletion",
100-
"kms:CancelKeyDeletion",
101-
"kms:GenerateDataKey",
102-
"kms:TagResource",
103-
"kms:UntagResource"
104-
],
88+
"Action": "kms:*",
10589
"Effect": "Allow",
10690
"Principal": {
10791
"AWS": {

source/patterns/@aws-solutions-constructs/aws-eventbridge-sqs/test/integ.eventbridge-no-arguments.expected.json

+1-17
Original file line numberDiff line numberDiff line change
@@ -85,23 +85,7 @@
8585
"KeyPolicy": {
8686
"Statement": [
8787
{
88-
"Action": [
89-
"kms:Create*",
90-
"kms:Describe*",
91-
"kms:Enable*",
92-
"kms:List*",
93-
"kms:Put*",
94-
"kms:Update*",
95-
"kms:Revoke*",
96-
"kms:Disable*",
97-
"kms:Get*",
98-
"kms:Delete*",
99-
"kms:ScheduleKeyDeletion",
100-
"kms:CancelKeyDeletion",
101-
"kms:GenerateDataKey",
102-
"kms:TagResource",
103-
"kms:UntagResource"
104-
],
88+
"Action": "kms:*",
10589
"Effect": "Allow",
10690
"Principal": {
10791
"AWS": {

source/patterns/@aws-solutions-constructs/aws-events-rule-sns/test/integ.events-rule-no-arg.expected.json

+1-17
Original file line numberDiff line numberDiff line change
@@ -6,23 +6,7 @@
66
"KeyPolicy": {
77
"Statement": [
88
{
9-
"Action": [
10-
"kms:Create*",
11-
"kms:Describe*",
12-
"kms:Enable*",
13-
"kms:List*",
14-
"kms:Put*",
15-
"kms:Update*",
16-
"kms:Revoke*",
17-
"kms:Disable*",
18-
"kms:Get*",
19-
"kms:Delete*",
20-
"kms:ScheduleKeyDeletion",
21-
"kms:CancelKeyDeletion",
22-
"kms:GenerateDataKey",
23-
"kms:TagResource",
24-
"kms:UntagResource"
25-
],
9+
"Action": "kms:*",
2610
"Effect": "Allow",
2711
"Principal": {
2812
"AWS": {

source/patterns/@aws-solutions-constructs/aws-events-rule-sns/test/integ.existing-bus.expected.json

+1-17
Original file line numberDiff line numberDiff line change
@@ -12,23 +12,7 @@
1212
"KeyPolicy": {
1313
"Statement": [
1414
{
15-
"Action": [
16-
"kms:Create*",
17-
"kms:Describe*",
18-
"kms:Enable*",
19-
"kms:List*",
20-
"kms:Put*",
21-
"kms:Update*",
22-
"kms:Revoke*",
23-
"kms:Disable*",
24-
"kms:Get*",
25-
"kms:Delete*",
26-
"kms:ScheduleKeyDeletion",
27-
"kms:CancelKeyDeletion",
28-
"kms:GenerateDataKey",
29-
"kms:TagResource",
30-
"kms:UntagResource"
31-
],
15+
"Action": "kms:*",
3216
"Effect": "Allow",
3317
"Principal": {
3418
"AWS": {

source/patterns/@aws-solutions-constructs/aws-events-rule-sns/test/integ.new-bus.expected.json

+1-17
Original file line numberDiff line numberDiff line change
@@ -6,23 +6,7 @@
66
"KeyPolicy": {
77
"Statement": [
88
{
9-
"Action": [
10-
"kms:Create*",
11-
"kms:Describe*",
12-
"kms:Enable*",
13-
"kms:List*",
14-
"kms:Put*",
15-
"kms:Update*",
16-
"kms:Revoke*",
17-
"kms:Disable*",
18-
"kms:Get*",
19-
"kms:Delete*",
20-
"kms:ScheduleKeyDeletion",
21-
"kms:CancelKeyDeletion",
22-
"kms:GenerateDataKey",
23-
"kms:TagResource",
24-
"kms:UntagResource"
25-
],
9+
"Action": "kms:*",
2610
"Effect": "Allow",
2711
"Principal": {
2812
"AWS": {

source/patterns/@aws-solutions-constructs/aws-events-rule-sqs/test/integ.events-rule-existing-bus.expected.json

+1-17
Original file line numberDiff line numberDiff line change
@@ -6,23 +6,7 @@
66
"KeyPolicy": {
77
"Statement": [
88
{
9-
"Action": [
10-
"kms:Create*",
11-
"kms:Describe*",
12-
"kms:Enable*",
13-
"kms:List*",
14-
"kms:Put*",
15-
"kms:Update*",
16-
"kms:Revoke*",
17-
"kms:Disable*",
18-
"kms:Get*",
19-
"kms:Delete*",
20-
"kms:ScheduleKeyDeletion",
21-
"kms:CancelKeyDeletion",
22-
"kms:GenerateDataKey",
23-
"kms:TagResource",
24-
"kms:UntagResource"
25-
],
9+
"Action": "kms:*",
2610
"Effect": "Allow",
2711
"Principal": {
2812
"AWS": {

source/patterns/@aws-solutions-constructs/aws-events-rule-sqs/test/integ.events-rule-existing-queue.expected.json

+1-17
Original file line numberDiff line numberDiff line change
@@ -6,23 +6,7 @@
66
"KeyPolicy": {
77
"Statement": [
88
{
9-
"Action": [
10-
"kms:Create*",
11-
"kms:Describe*",
12-
"kms:Enable*",
13-
"kms:List*",
14-
"kms:Put*",
15-
"kms:Update*",
16-
"kms:Revoke*",
17-
"kms:Disable*",
18-
"kms:Get*",
19-
"kms:Delete*",
20-
"kms:ScheduleKeyDeletion",
21-
"kms:CancelKeyDeletion",
22-
"kms:GenerateDataKey",
23-
"kms:TagResource",
24-
"kms:UntagResource"
25-
],
9+
"Action": "kms:*",
2610
"Effect": "Allow",
2711
"Principal": {
2812
"AWS": {

source/patterns/@aws-solutions-constructs/aws-events-rule-sqs/test/integ.events-rule-new-bus.expected.json

+1-17
Original file line numberDiff line numberDiff line change
@@ -85,23 +85,7 @@
8585
"KeyPolicy": {
8686
"Statement": [
8787
{
88-
"Action": [
89-
"kms:Create*",
90-
"kms:Describe*",
91-
"kms:Enable*",
92-
"kms:List*",
93-
"kms:Put*",
94-
"kms:Update*",
95-
"kms:Revoke*",
96-
"kms:Disable*",
97-
"kms:Get*",
98-
"kms:Delete*",
99-
"kms:ScheduleKeyDeletion",
100-
"kms:CancelKeyDeletion",
101-
"kms:GenerateDataKey",
102-
"kms:TagResource",
103-
"kms:UntagResource"
104-
],
88+
"Action": "kms:*",
10589
"Effect": "Allow",
10690
"Principal": {
10791
"AWS": {

source/patterns/@aws-solutions-constructs/aws-events-rule-sqs/test/integ.events-rule-no-arg.expected.json

+1-17
Original file line numberDiff line numberDiff line change
@@ -85,23 +85,7 @@
8585
"KeyPolicy": {
8686
"Statement": [
8787
{
88-
"Action": [
89-
"kms:Create*",
90-
"kms:Describe*",
91-
"kms:Enable*",
92-
"kms:List*",
93-
"kms:Put*",
94-
"kms:Update*",
95-
"kms:Revoke*",
96-
"kms:Disable*",
97-
"kms:Get*",
98-
"kms:Delete*",
99-
"kms:ScheduleKeyDeletion",
100-
"kms:CancelKeyDeletion",
101-
"kms:GenerateDataKey",
102-
"kms:TagResource",
103-
"kms:UntagResource"
104-
],
88+
"Action": "kms:*",
10589
"Effect": "Allow",
10690
"Principal": {
10791
"AWS": {

0 commit comments

Comments
 (0)