Skip to content

secretsmanager grantWrite doesn't give permission to update a secret #8491

@dirknilius

Description

@dirknilius

Consider the following example:

import * as secretsmanager from '@aws-cdk/aws-secretsmanager';

const secret = new secretsmanager.Secret(this, 'Secret');
secret.grantWrite(role);

The grantWrite will give you secretsmanager:PutSecretValue permission. But it doesn't give secretsmanager:UpdateSecret permission.

Environment

  • Framework Version: 1.45.0
  • Language (Version): TypeScript 3.9.5

This is 🐛 Bug Report

Metadata

Metadata

Assignees

Labels

@aws-cdk/aws-secretsmanagerRelated to AWS Secrets ManagerbugThis issue is a bug.good first issueRelated to contributions. See CONTRIBUTING.mdin-progressThis issue is being actively worked on.p2

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions