diff --git a/action/base-setup.yml b/action/base-setup.yml index e60dfb44..42a2882f 100644 --- a/action/base-setup.yml +++ b/action/base-setup.yml @@ -231,8 +231,10 @@ Resources: Statement: - Effect: Allow Action: + # Allow the use of secret manager - 'secretsmanager:GetSecretValue' - 'kms:Decrypt' + # Allow the ECS Tasks to download images from ECR - 'ecr:GetAuthorizationToken' - 'ecr:BatchCheckLayerAvailability'