Skip to content

fix(iac): grant EC2 instance profile inventory reads - #111

Draft
tim-thacker-nullify wants to merge 1 commit into
mainfrom
codex/fix-ec2-instance-profile-read
Draft

tim-thacker-nullify wants to merge 1 commit into
mainfrom
codex/fix-ec2-instance-profile-read

Conversation

@tim-thacker-nullify

@tim-thacker-nullify tim-thacker-nullify commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

Codex

The connector role refused the IAM profile read required to connect EC2 instances to their actual execution roles.

  • Grant iam:ListInstanceProfiles in CloudFormation and both Terraform templates.
  • Keep existing policy restrictions and the three template action sets aligned.
  • Companion to the Nullify release remediation: deploy updated connector roles before relying on profile-to-role inventory; existing roles receive no permission change from this PR alone.

Live customer-role deployment is unverified; this PR changes templates only.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant