diff --git a/route53-zone-association/lambda-role/main.tf b/route53-zone-association/lambda-role/main.tf index 25de0c1..dfc7e80 100644 --- a/route53-zone-association/lambda-role/main.tf +++ b/route53-zone-association/lambda-role/main.tf @@ -48,6 +48,7 @@ data "aws_iam_policy_document" "policy" { actions = [ "iam:ListAccountAliases", "ec2:DescribeVpcs", + "ec2:DescribeAvailabilityZones", "route53:Get*", "route53:List*", "route53:TestDNSAnswer", diff --git a/route53-zone-association/terraform-role/main.tf b/route53-zone-association/terraform-role/main.tf index a72f3f9..f0f6722 100644 --- a/route53-zone-association/terraform-role/main.tf +++ b/route53-zone-association/terraform-role/main.tf @@ -48,6 +48,7 @@ data "aws_iam_policy_document" "policy" { actions = [ "iam:ListAccountAliases", "ec2:DescribeVpcs", + "ec2:DescribeAvailabilityZones", "route53:Get*", "route53:List*", "route53:AssociateVPCWithHostedZone",