diff --git a/.github/workflows/deployment.yml b/.github/workflows/deployment.yml index b928b1a..ba6b74b 100644 --- a/.github/workflows/deployment.yml +++ b/.github/workflows/deployment.yml @@ -6,7 +6,7 @@ on: - "main" push: branches: - - "montoring-impovements" + - "main" permissions: id-token: write diff --git a/modules/eks/iam.tf b/modules/eks/iam.tf index b78c05a..1ad2dd1 100644 --- a/modules/eks/iam.tf +++ b/modules/eks/iam.tf @@ -433,140 +433,140 @@ data "aws_iam_policy_document" "cloudwatch_exporter_assume_role_policy_other_aws # IAM role for Cloudwatch Exporter in development aws account -#resource "aws_iam_role" "cloudwatch_exporter_development" { -# count = terraform.workspace == "development" ? 0 : 1 -# assume_role_policy = data.aws_iam_policy_document.cloudwatch_exporter_assume_role_policy_other_aws_accounts.json -# name = "${var.prefix}-CloudwatchExporter" -# -# tags = var.tags -# -# provider = aws.development -#} - -#resource "aws_iam_policy" "cloudwatch_exporter_iam_policy_development" { -# count = terraform.workspace == "development" ? 0 : 1 -# name = "${var.prefix}-CloudwatchExporterIAMPolicy" -# path = "/" -# description = "IAM role policy for Cloudwatch Exporter in EKS Cluster for ${var.prefix}" -# -# policy = data.template_file.cloudwatch_exporter_iam_policy.rendered -# -# tags = var.tags -# -# provider = aws.development -#} - -#resource "aws_iam_role_policy_attachment" "cloudwatch_exporter_IAMPolicy_development" { -# count = terraform.workspace == "development" ? 0 : 1 -# policy_arn = aws_iam_policy.cloudwatch_exporter_iam_policy_development[0].arn -# role = aws_iam_role.cloudwatch_exporter_development[0].name -# -# provider = aws.development -#} - -#resource "aws_iam_policy" "development_cloudwatch_exporter_role_allow_assume_policy" { -# count = terraform.workspace == "development" ? 0 : 1 -# name = "development_cloudwatch_exporter_role_allow_assume_policy" -# path = "/" -# description = "Policy that allows cloudwatch exporter in EKS Cluster for ${var.prefix} to assume role in development AWS account" -# -# policy = <