From c19fb57747770677cf029723b3aa42acdf404200 Mon Sep 17 00:00:00 2001 From: jamesthompson26-nhs Date: Mon, 22 Jun 2026 14:55:01 +0100 Subject: [PATCH] CCM-18334: Firehose Delivery Stream Permissions Update --- .../terraform/modules/eventpub/iam_role_sns.tf | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/infrastructure/terraform/modules/eventpub/iam_role_sns.tf b/infrastructure/terraform/modules/eventpub/iam_role_sns.tf index fa48a90e..18ef8a6c 100644 --- a/infrastructure/terraform/modules/eventpub/iam_role_sns.tf +++ b/infrastructure/terraform/modules/eventpub/iam_role_sns.tf @@ -49,4 +49,18 @@ data "aws_iam_policy_document" "firehose_delivery" { "${aws_kinesis_firehose_delivery_stream.main[0].arn}", ] } + + statement { + sid = "AllowKmsAccessForFirehoseDelivery" + effect = "Allow" + + actions = [ + "kms:GenerateDataKey", + "kms:Decrypt", + ] + + resources = [ + var.kms_key_arn, + ] + } }