After testing the suggested policy both with the AWS policy simulator and by using it with cert-manager I have found that the ARN prefix in the resources included in the statement cause the provider to fail with an access denied error. This new policy is equivalent and valid according to the AWS policy simulator. |
||
|---|---|---|
| .. | ||
| certificates/issuer-specific-config | ||
| issuers | ||
| certificates.rst | ||
| clusterissuers.rst | ||
| index.rst | ||
| ingress-shim.rst | ||
| issuers.rst | ||