You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
sec(iac): secretsmanager:ListSecrets in SecretsManager block is non-functional (must use Resource="*") #1267
The SecretsManager block in terraform/environments/aws/ci-cd-permissions/policy_data.tf includes secretsmanager:ListSecrets scoped to Resource = "arn:aws:secretsmanager:*:*:secret:cudly-*":
Per the AWS Service Authorization Reference for Secrets Manager, secretsmanager:ListSecrets does NOT support resource-level permissions — it only works with Resource = "*". When granted on a specific ARN, IAM will never match the request (which is an account-level call with no resource target), so the permission is effectively a no-op.
Impact
No security regression: the permission doesn't accidentally grant anything
However, the ListSecrets entry in the SecretsManager block is dead code that misleads readers into thinking the deploy role can enumerate secrets
Resolution options
Remove secretsmanager:ListSecrets from the SecretsManager block — if Terraform deploy never actually calls ListSecrets (it uses DescribeSecret for all known-ARN lookups). This would be the cleanest outcome.
Finding
The
SecretsManagerblock interraform/environments/aws/ci-cd-permissions/policy_data.tfincludessecretsmanager:ListSecretsscoped toResource = "arn:aws:secretsmanager:*:*:secret:cudly-*":{ Sid = "SecretsManager" Effect = "Allow" Action = [ ... "secretsmanager:ListSecrets", ... ] Resource = "arn:aws:secretsmanager:*:*:secret:cudly-*" }Per the AWS Service Authorization Reference for Secrets Manager,
secretsmanager:ListSecretsdoes NOT support resource-level permissions — it only works withResource = "*". When granted on a specific ARN, IAM will never match the request (which is an account-level call with no resource target), so the permission is effectively a no-op.Impact
SecretsManagerDescribeblock: that block was already the only real grant ofListSecretsListSecretsentry in theSecretsManagerblock is dead code that misleads readers into thinking the deploy role can enumerate secretsResolution options
secretsmanager:ListSecretsfrom theSecretsManagerblock — if Terraform deploy never actually callsListSecrets(it usesDescribeSecretfor all known-ARN lookups). This would be the cleanest outcome.SecretsManagerListblock withResource = "*"— ifListSecretsis genuinely needed at deploy time (e.g. forterraform importworkflows). This would restore the functional permission that PR sec(iac): scope SecretsManagerDescribe to specific actions (closes #430) #817 removed.Discovered during adversarial review of PR #817.