Skip to content

Commit

Permalink
Restrict sagemaker:AddTags policy to transform jobs
Browse files Browse the repository at this point in the history
  • Loading branch information
Leo Toikka committed Jun 18, 2023
1 parent 909e699 commit e27cece
Showing 1 changed file with 8 additions and 2 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -66,7 +66,7 @@ export interface SageMakerCreateTransformJobProps extends sfn.TaskStateBaseProps
readonly modelClientOptions?: ModelClientOptions;

/**
* Tags to be applied to the train job.
* Tags to be applied to the transform job.
*
* @default - No tags
*/
Expand Down Expand Up @@ -284,7 +284,13 @@ export class SageMakerCreateTransformJob extends sfn.TaskStateBase {
}),
new iam.PolicyStatement({
actions: ['sagemaker:AddTags'],
resources: ['*'],
resources: [
stack.formatArn({
service: 'sagemaker',
resource: 'transform-job',
resourceName: '*',
}),
],
}),
);
}
Expand Down

0 comments on commit e27cece

Please sign in to comment.