awslabs / landing-zone-accelerator-on-aws

Deploy a multi-account cloud foundation to support highly-regulated workloads and complex compliance requirements.
https://aws.amazon.com/solutions/implementations/landing-zone-accelerator-on-aws/
Apache License 2.0
562 stars 448 forks source link

fix(globalConfig): provide required permissions for subscriptions #645

Open richardkeit opened 1 week ago

richardkeit commented 1 week ago

Description of changes:

When the LoggingStack:CustomUpdateSubscription custom resource runs it has insufficient permissions to complete it's function. See below graph and extract from Cloudtrail - Cheers!

Screenshot 2024-11-15 at 10 12 40 AM Screenshot 2024-11-15 at 10 11 54 AM

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.