diff --git a/.github/workflows/Deploy.yml b/.github/workflows/Deploy.yml index 0f1003f..4b063ec 100644 --- a/.github/workflows/Deploy.yml +++ b/.github/workflows/Deploy.yml @@ -50,7 +50,6 @@ jobs: # Fetch the secret using the secret prefix echo "::set-output name=data_bucket::${{ secrets[format('{0}_DATA_BUCKET', steps.secret_prefix.outputs.secret_prefix)] }}" echo "::set-output name=predictions_bucket::${{ secrets[format('{0}_PREDICTIONS_BUCKET', steps.secret_prefix.outputs.secret_prefix)] }}" - echo "::set-output name=model_directory_bucket::${{ secrets[format('{0}_MODEL_DIRECTORY_BUCKET', steps.secret_prefix.outputs.secret_prefix)] }}" - name: Set stack_name id: set_stack_name diff --git a/deployment/serverless.yml b/deployment/serverless.yml index 7116a42..b23158d 100644 --- a/deployment/serverless.yml +++ b/deployment/serverless.yml @@ -15,13 +15,11 @@ provider: role: name: ${env:STACK_NAME}_s3_access statements: - # Allow reading from MODEL_DIRECTORY_BUCKET and DATA_BUCKET + # Allow reading from the DATA_BUCKET - Effect: Allow Action: - s3:* Resource: - - arn:aws:s3:::${env:MODEL_DIRECTORY_BUCKET} - - arn:aws:s3:::${env:MODEL_DIRECTORY_BUCKET}/* - arn:aws:s3:::${env:DATA_BUCKET} - arn:aws:s3:::${env:DATA_BUCKET}/* # Allow reading and writing to PREDICTIONS_BUCKET