Skip to content

Commit 7deaffe

Browse files
charliejllewellynCharlie LlewellynBrian969
authored
Removed SCP removal from accounts (#711)
Co-authored-by: Charlie Llewellyn <cjl@amazon.co.uk> Co-authored-by: Brian969 <56414362+Brian969@users.noreply.github.com>
1 parent 202ba8b commit 7deaffe

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

src/core/runtime/src/add-scp-step.ts

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -84,11 +84,12 @@ export const handler = async (input: AddScpInput) => {
8484
const acceleratorOuIds = organizationalUnits.map(ou => ou.ouId);
8585
const acceleratorAccountIds = accounts.map(a => a.id);
8686
const acceleratorTargetIds = [...rootIds, ...acceleratorOuIds, ...acceleratorAccountIds];
87+
const acceleratorTargetOuIds = [...rootIds, ...acceleratorOuIds];
8788

8889
// Detach non-Accelerator policies from Accelerator accounts
8990
await scps.detachPoliciesFromTargets({
9091
policyNamesToKeep: acceleratorPolicyNames,
91-
policyTargetIdsToInclude: acceleratorTargetIds,
92+
policyTargetIdsToInclude: acceleratorTargetOuIds,
9293
});
9394

9495
await scps.attachFullAwsAccessPolicyToTargets({

0 commit comments

Comments
 (0)