org-formation / org-formation-reference

A reference architecture which aims to provide some best practices for any AWS Organization starting out using org-formation.
91 stars 23 forks source link

000-org-build: should OrgPipelineRole be toned down? #15

Open OlafConijn opened 3 years ago

OlafConijn commented 3 years ago

OrgPipelineRole should be able to do with less permissions.

The permissions assigned are the default permissions for a CodePipeline as created by AWS (IIRC). Could be a valid decision to leave as is so that other common pipeline stages can be added. If so: add a link to this issue as a means to document?

eduardomourar commented 3 years ago

I looked for a managed policy for this last week but no luck. I think we should simplify it