serverless-operations / serverless-step-functions

AWS Step Functions plugin for Serverless Framework ⚡️
Other
1.02k stars 204 forks source link

feat: generate iam role for dynamodb:Scan #586

Closed ebisbe closed 9 months ago

ebisbe commented 10 months ago

Fixes https://github.com/serverless-operations/serverless-step-functions/issues/584

ebisbe commented 9 months ago

@horike37 do you know who I can ping to review this? ( I'm pinging you because you merged the first closed PR from this repo )

ebisbe commented 9 months ago

Now I'm missing also those permissions:

Cannot generate IAM policy statement for Task state { Type: 'Task',
  Parameters: { 'QueueUrl.$': '$.DlQueue', MaxNumberOfMessages: 10, WaitTimeSeconds: 10 },
  Resource: 'arn:aws:states:::aws-sdk:sqs:receiveMessage',
  Next: 'Map',
  ResultPath: '$.env' }
Cannot generate IAM policy statement for Task state { Type: 'Task',
  End: true,
  Parameters: { 'QueueUrl.$': '$.env.DlQueue', 'ReceiptHandle.$': '$.ReceiptHandle' },
  Resource: 'arn:aws:states:::aws-sdk:sqs:deleteMessage' }

Is there a reason for not generating all permissions?

ebisbe commented 9 months ago

I need more permissions. Not sure what's the best approach for it?