Skip to content

[AWSX] feat(forwarder): allow restricting access to s3:GetObject in template#1062

Merged
RaphaelAllier merged 1 commit intomasterfrom
raphael.allier/AWSX-s3-scoped-permission
Feb 9, 2026
Merged

[AWSX] feat(forwarder): allow restricting access to s3:GetObject in template#1062
RaphaelAllier merged 1 commit intomasterfrom
raphael.allier/AWSX-s3-scoped-permission

Conversation

@RaphaelAllier
Copy link
Member

What does this PR do?

This PR introduces a change that should be backward compatible to restrict the permission s3:GetObject to something more scoped than the wildcard *.
Note that there is a risk autosubscription and other features might not work if the forwarder is denied access to the bucket it uses for tags or to any buckets that contains logs.

Motivation

Feature request / internal improvement

@RaphaelAllier RaphaelAllier requested a review from a team as a code owner February 9, 2026 09:37
@github-actions github-actions bot added the aws label Feb 9, 2026
@ge0Aja ge0Aja self-assigned this Feb 9, 2026
@RaphaelAllier RaphaelAllier merged commit a0f9539 into master Feb 9, 2026
10 checks passed
@RaphaelAllier RaphaelAllier deleted the raphael.allier/AWSX-s3-scoped-permission branch February 9, 2026 09:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants