|
|
@ -69,14 +69,14 @@ extends_documentation_fragment:
|
|
|
|
|
|
|
|
|
|
|
|
EXAMPLES = '''
|
|
|
|
EXAMPLES = '''
|
|
|
|
- name: grant user-style access to production secrets
|
|
|
|
- name: grant user-style access to production secrets
|
|
|
|
kms:
|
|
|
|
aws_kms:
|
|
|
|
args:
|
|
|
|
args:
|
|
|
|
mode: grant
|
|
|
|
mode: grant
|
|
|
|
key_alias: "alias/my_production_secrets"
|
|
|
|
key_alias: "alias/my_production_secrets"
|
|
|
|
role_name: "prod-appServerRole-1R5AQG2BSEL6L"
|
|
|
|
role_name: "prod-appServerRole-1R5AQG2BSEL6L"
|
|
|
|
grant_types: "role,role grant"
|
|
|
|
grant_types: "role,role grant"
|
|
|
|
- name: remove access to production secrets from role
|
|
|
|
- name: remove access to production secrets from role
|
|
|
|
kms:
|
|
|
|
aws_kms:
|
|
|
|
args:
|
|
|
|
args:
|
|
|
|
mode: deny
|
|
|
|
mode: deny
|
|
|
|
key_alias: "alias/my_production_secrets"
|
|
|
|
key_alias: "alias/my_production_secrets"
|
|
|
|