data "aws_iam_policy_document" "dlm_assume" { statement { effect = "Allow" actions = ["sts:AssumeRole"] principals { type = "Service" identifiers = ["dlm.amazonaws.com"] } } } resource "aws_iam_role" "dlm" { name = "apm-wo-analysis-grafana-dlm" path = "/tf-managed/" description = "DLM snapshot role for the Grafana instance volume" assume_role_policy = data.aws_iam_policy_document.dlm_assume.json permissions_boundary = aws_iam_policy.exec_boundary.arn } data "aws_iam_policy_document" "dlm" { # checkov:skip=CKV_AWS_111: DLM CreateSnapshot/Describe* require Resource=*. Role is boundary-attached and limited to the tagged Grafana volume. statement { sid = "DlmSnapshots" effect = "Allow" actions = [ "ec2:CreateSnapshot", "ec2:CreateSnapshots", "ec2:DeleteSnapshot", "ec2:DescribeInstances", "ec2:DescribeVolumes", "ec2:DescribeSnapshots", "ec2:DescribeTags", "ec2:CreateTags", "ec2:DeleteTags", ] resources = ["*"] } statement { sid = "DlmKms" effect = "Allow" actions = [ "kms:CreateGrant", "kms:DescribeKey", "kms:GenerateDataKeyWithoutPlaintext", "kms:ReEncryptFrom", "kms:ReEncryptTo", "kms:ListGrants", ] resources = [ "arn:aws:kms:${var.aws_region}:${local.account_id}:key/*", ] } } resource "aws_iam_role_policy" "dlm" { name = "grafana-dlm-snapshots" role = aws_iam_role.dlm.id policy = data.aws_iam_policy_document.dlm.json } resource "aws_dlm_lifecycle_policy" "grafana" { description = "Daily snapshot of the apm-wo grafana volume" execution_role_arn = aws_iam_role.dlm.arn state = "ENABLED" policy_details { resource_types = ["INSTANCE"] target_tags = { (local.grafana_backup_tag) = "true" } schedule { name = "daily" create_rule { interval = 24 interval_unit = "HOURS" times = ["07:00"] } retain_rule { count = 7 } } } }