feat(iam): allow cloudfront function updates

- grant CloudFront Function and invalidation permissions
This commit is contained in:
Daisuke Nakahara 2026-02-01 17:30:36 +09:00
parent b565fb3c4b
commit c31e4e36f7

View file

@ -63,3 +63,14 @@ Resources:
Action:
- s3:PutObject
Resource: "*"
- Effect: Allow
Action:
- cloudfront:CreateFunction
- cloudfront:UpdateFunction
- cloudfront:PublishFunction
- cloudfront:DescribeFunction
- cloudfront:GetFunction
- cloudfront:DeleteFunction
- cloudfront:ListFunctions
- cloudfront:CreateInvalidation
Resource: "*"