diff --git a/terragrunt/org_account/iam_identity_center/platform_cds_website_assignments.tf b/terragrunt/org_account/iam_identity_center/platform_cds_website_assignments.tf index d36a1876..68eac275 100644 --- a/terragrunt/org_account/iam_identity_center/platform_cds_website_assignments.tf +++ b/terragrunt/org_account/iam_identity_center/platform_cds_website_assignments.tf @@ -23,6 +23,11 @@ locals { group = aws_identitystore_group.canadian_digital_service_production_website_admin, permission_set = aws_ssoadmin_permission_set.canadian_digital_service_production_website_admin, }, + # ! Cross Account Permission Assignment - Notify Hosted Zone + { + group = aws_identitystore_group.notify_production_hosted_zone_admin, + permission_set = aws_ssoadmin_permission_set.admin_route53_notify_hosted_zone, + } ] # CdsWebsite-Production cds_website_production_permission_sets = [ diff --git a/terragrunt/org_account/iam_identity_center/platform_notify_assignments.tf b/terragrunt/org_account/iam_identity_center/platform_notify_assignments.tf index 018c9b1b..c65e9524 100644 --- a/terragrunt/org_account/iam_identity_center/platform_notify_assignments.tf +++ b/terragrunt/org_account/iam_identity_center/platform_notify_assignments.tf @@ -35,10 +35,6 @@ locals { { group = aws_identitystore_group.notify_production_read_only, permission_set = data.aws_ssoadmin_permission_set.aws_read_only_access, - }, - { - group = aws_identitystore_group.notify_production_hosted_zone_admin, - permission_set = aws_ssoadmin_permission_set.admin_route53_notify_hosted_zone, } ] # Notification-Staging