mirror of
https://github.com/Sea-Haven-Industries/apm-wo-analysis.git
synced 2026-09-30 03:03:14 +00:00
Some checks are pending
Deploy / Deploy to prod (push) Waiting to run
* feat(infra): migrate pipeline and Grafana to HCP Terraform (PLAT-75) Move apm-wo-analysis into seahaven-prod under workspace apm-wo-analysis-prod with in-repo hcptf/githubdeploy IAM, stub Lambdas, and GitHub Actions zip CD. * chore(iam): add Checkov skip comments for HCP IAM documents Pre-push HIGH findings are the DLM snapshot describe, tagged EC2 creates, exec boundary DescribeLogGroups star, and the drop-uploader user policy.
1270 lines
34 KiB
HCL
1270 lines
34 KiB
HCL
# HCP plan/apply roles for apm-wo-analysis-prod (PLAT-75).
|
|
# Copy of seahaven-org-baseline/examples/hcptf-workspace-iam/hcp_iam.tf.example
|
|
# with the apm-wo-analysis service set. Create, do not import.
|
|
#
|
|
# Live seahaven-hcptf-iam-management DenySelfMutation blocks DetachRolePolicy
|
|
# and PutRolePolicy on hcptf-* (including this role). First-apply sequence:
|
|
# 1. seahaven-org-baseline scripts/create-hcptf-bootstrap-roles.sh
|
|
# --account prod --allow-workspace apm-wo-analysis-prod
|
|
# 2. Point this workspace's TFC_AWS_* at hcptf-bootstrap /
|
|
# hcptf-bootstrap-plan (workspace vars, never a project set).
|
|
# 3. One Manual apply (create roles + scoped inline + boundary + stack).
|
|
# 4. Point TFC_AWS_* back at hcptf-apm-wo-analysis /
|
|
# hcptf-apm-wo-analysis-plan.
|
|
# 5. Re-run the script without --allow-workspace to pin trust back to
|
|
# iam-bootstrap-prod only.
|
|
# Later apply-role IAM edits use the same window. Do not add StringLike
|
|
# on bootstrap trust. CreatePolicy stays on hcptf-bootstrap only; boundary
|
|
# document changes after seal also need that window.
|
|
|
|
data "aws_iam_policy_document" "hcptf_apply_trust" {
|
|
statement {
|
|
sid = "HcpApply"
|
|
effect = "Allow"
|
|
actions = ["sts:AssumeRoleWithWebIdentity"]
|
|
|
|
principals {
|
|
type = "Federated"
|
|
identifiers = ["arn:aws:iam::${local.account_id}:oidc-provider/app.terraform.io"]
|
|
}
|
|
|
|
condition {
|
|
test = "StringEquals"
|
|
variable = "app.terraform.io:aud"
|
|
values = ["aws.workload.identity"]
|
|
}
|
|
|
|
condition {
|
|
test = "StringEquals"
|
|
variable = "app.terraform.io:sub"
|
|
values = [
|
|
"organization:seahaven:project:${local.hcp_project}:workspace:${local.hcp_workspace}:run_phase:apply",
|
|
]
|
|
}
|
|
}
|
|
}
|
|
|
|
data "aws_iam_policy_document" "hcptf_plan_trust" {
|
|
statement {
|
|
sid = "HcpPlan"
|
|
effect = "Allow"
|
|
actions = ["sts:AssumeRoleWithWebIdentity"]
|
|
|
|
principals {
|
|
type = "Federated"
|
|
identifiers = ["arn:aws:iam::${local.account_id}:oidc-provider/app.terraform.io"]
|
|
}
|
|
|
|
condition {
|
|
test = "StringEquals"
|
|
variable = "app.terraform.io:aud"
|
|
values = ["aws.workload.identity"]
|
|
}
|
|
|
|
condition {
|
|
test = "StringEquals"
|
|
variable = "app.terraform.io:sub"
|
|
values = [
|
|
"organization:seahaven:project:${local.hcp_project}:workspace:${local.hcp_workspace}:run_phase:plan",
|
|
]
|
|
}
|
|
}
|
|
}
|
|
|
|
data "aws_iam_policy_document" "hcptf_scoped_iam" {
|
|
statement {
|
|
sid = "DenyCreatePolicy"
|
|
effect = "Deny"
|
|
actions = [
|
|
"iam:CreatePolicy",
|
|
"iam:CreatePolicyVersion",
|
|
"iam:DeletePolicy",
|
|
"iam:DeletePolicyVersion",
|
|
"iam:SetDefaultPolicyVersion",
|
|
]
|
|
resources = ["*"]
|
|
}
|
|
|
|
statement {
|
|
sid = "CreateExecRoleWithBoundary"
|
|
effect = "Allow"
|
|
actions = ["iam:CreateRole"]
|
|
resources = [
|
|
"arn:aws:iam::${local.account_id}:role/tf-managed/${local.stack_prefix}*",
|
|
]
|
|
|
|
condition {
|
|
test = "StringLike"
|
|
variable = "iam:PermissionsBoundary"
|
|
values = [
|
|
"arn:aws:iam::${local.account_id}:policy/tf-managed/${local.stack_prefix}*",
|
|
"arn:aws:iam::${local.account_id}:policy/seahaven-lambda-execution-boundary",
|
|
"arn:aws:iam::${local.account_id}:policy/seahaven-lambda-execution-boundary-${local.stack_name}",
|
|
]
|
|
}
|
|
}
|
|
|
|
statement {
|
|
sid = "MutateExecRoleWithBoundary"
|
|
effect = "Allow"
|
|
actions = [
|
|
"iam:AttachRolePolicy",
|
|
"iam:PutRolePolicy",
|
|
"iam:PutRolePermissionsBoundary",
|
|
]
|
|
resources = [
|
|
"arn:aws:iam::${local.account_id}:role/tf-managed/${local.stack_prefix}*",
|
|
]
|
|
|
|
condition {
|
|
test = "StringLike"
|
|
variable = "iam:PermissionsBoundary"
|
|
values = [
|
|
"arn:aws:iam::${local.account_id}:policy/tf-managed/${local.stack_prefix}*",
|
|
"arn:aws:iam::${local.account_id}:policy/seahaven-lambda-execution-boundary",
|
|
"arn:aws:iam::${local.account_id}:policy/seahaven-lambda-execution-boundary-${local.stack_name}",
|
|
]
|
|
}
|
|
}
|
|
|
|
statement {
|
|
sid = "WriteExecRoles"
|
|
effect = "Allow"
|
|
actions = [
|
|
"iam:DeleteRole",
|
|
"iam:DeleteRolePolicy",
|
|
"iam:DetachRolePolicy",
|
|
"iam:TagRole",
|
|
"iam:UntagRole",
|
|
"iam:UpdateAssumeRolePolicy",
|
|
"iam:UpdateRole",
|
|
"iam:UpdateRoleDescription",
|
|
]
|
|
resources = [
|
|
"arn:aws:iam::${local.account_id}:role/tf-managed/${local.stack_prefix}*",
|
|
]
|
|
}
|
|
|
|
statement {
|
|
sid = "PassExecRoles"
|
|
effect = "Allow"
|
|
actions = ["iam:PassRole"]
|
|
resources = ["arn:aws:iam::${local.account_id}:role/tf-managed/${local.stack_prefix}*"]
|
|
|
|
condition {
|
|
test = "StringEquals"
|
|
variable = "iam:PassedToService"
|
|
values = ["lambda.amazonaws.com", "ec2.amazonaws.com", "dlm.amazonaws.com"]
|
|
}
|
|
}
|
|
|
|
statement {
|
|
sid = "InstanceProfiles"
|
|
effect = "Allow"
|
|
actions = [
|
|
"iam:CreateInstanceProfile",
|
|
"iam:DeleteInstanceProfile",
|
|
"iam:AddRoleToInstanceProfile",
|
|
"iam:RemoveRoleFromInstanceProfile",
|
|
"iam:GetInstanceProfile",
|
|
"iam:TagInstanceProfile",
|
|
"iam:UntagInstanceProfile",
|
|
]
|
|
resources = [
|
|
"arn:aws:iam::${local.account_id}:instance-profile/tf-managed/${local.stack_prefix}*",
|
|
]
|
|
}
|
|
|
|
statement {
|
|
sid = "DropUploaderUser"
|
|
effect = "Allow"
|
|
actions = [
|
|
"iam:CreateUser",
|
|
"iam:DeleteUser",
|
|
"iam:GetUser",
|
|
"iam:TagUser",
|
|
"iam:UntagUser",
|
|
"iam:PutUserPolicy",
|
|
"iam:DeleteUserPolicy",
|
|
"iam:GetUserPolicy",
|
|
"iam:ListUserPolicies",
|
|
"iam:ListUserTags",
|
|
]
|
|
resources = ["arn:aws:iam::${local.account_id}:user/tf-managed/apm-wo-drop-uploader"]
|
|
}
|
|
|
|
statement {
|
|
sid = "CreateDeployRole"
|
|
effect = "Allow"
|
|
actions = ["iam:CreateRole"]
|
|
resources = ["arn:aws:iam::${local.account_id}:role/tf-managed/${local.deploy_role}"]
|
|
|
|
condition {
|
|
test = "Null"
|
|
variable = "iam:PermissionsBoundary"
|
|
values = ["true"]
|
|
}
|
|
}
|
|
|
|
statement {
|
|
sid = "WriteDeployRoles"
|
|
effect = "Allow"
|
|
actions = [
|
|
"iam:AttachRolePolicy",
|
|
"iam:DeleteRole",
|
|
"iam:DeleteRolePolicy",
|
|
"iam:DetachRolePolicy",
|
|
"iam:PutRolePolicy",
|
|
"iam:TagRole",
|
|
"iam:UntagRole",
|
|
"iam:UpdateAssumeRolePolicy",
|
|
"iam:UpdateRole",
|
|
"iam:UpdateRoleDescription",
|
|
]
|
|
resources = ["arn:aws:iam::${local.account_id}:role/tf-managed/${local.deploy_role}"]
|
|
}
|
|
|
|
statement {
|
|
sid = "IamReadOnly"
|
|
effect = "Allow"
|
|
actions = [
|
|
"iam:GetPolicy",
|
|
"iam:GetPolicyVersion",
|
|
"iam:GetRole",
|
|
"iam:GetRolePolicy",
|
|
"iam:ListAttachedRolePolicies",
|
|
"iam:ListInstanceProfilesForRole",
|
|
"iam:ListPolicies",
|
|
"iam:ListPolicyVersions",
|
|
"iam:ListRolePolicies",
|
|
"iam:ListRoleTags",
|
|
"iam:ListRoles",
|
|
]
|
|
resources = ["*"]
|
|
}
|
|
|
|
statement {
|
|
sid = "DenySelfMutation"
|
|
effect = "Deny"
|
|
actions = [
|
|
"iam:AttachRolePolicy",
|
|
"iam:DeleteRole",
|
|
"iam:DeleteRolePolicy",
|
|
"iam:DeleteRolePermissionsBoundary",
|
|
"iam:DetachRolePolicy",
|
|
"iam:PutRolePolicy",
|
|
"iam:PutRolePermissionsBoundary",
|
|
"iam:UpdateAssumeRolePolicy",
|
|
"iam:UpdateRole",
|
|
"iam:UpdateRoleDescription",
|
|
]
|
|
resources = [
|
|
"arn:aws:iam::${local.account_id}:role/hcptf-*",
|
|
"arn:aws:iam::${local.account_id}:role/github-cfn-execution-role",
|
|
"arn:aws:iam::${local.account_id}:role/githubdeploy-*",
|
|
"arn:aws:iam::${local.account_id}:role/cdk-hnb659fds-*",
|
|
"arn:aws:iam::${local.account_id}:role/OrganizationAccountAccessRole",
|
|
"arn:aws:iam::${local.account_id}:role/seahaven-*",
|
|
]
|
|
}
|
|
|
|
statement {
|
|
sid = "DenyBoundaryTampering"
|
|
effect = "Deny"
|
|
actions = [
|
|
"iam:DeleteRolePermissionsBoundary",
|
|
"iam:DeleteUserPermissionsBoundary",
|
|
]
|
|
resources = [
|
|
"arn:aws:iam::${local.account_id}:role/*",
|
|
"arn:aws:iam::${local.account_id}:user/*",
|
|
]
|
|
}
|
|
|
|
statement {
|
|
sid = "DenyBoundaryPolicyEdit"
|
|
effect = "Deny"
|
|
actions = [
|
|
"iam:CreatePolicyVersion",
|
|
"iam:DeletePolicy",
|
|
"iam:DeletePolicyVersion",
|
|
"iam:SetDefaultPolicyVersion",
|
|
]
|
|
resources = ["arn:aws:iam::${local.account_id}:policy/seahaven-*"]
|
|
}
|
|
}
|
|
|
|
data "aws_iam_policy_document" "hcptf_apply_services" {
|
|
statement {
|
|
sid = "LambdaAll"
|
|
effect = "Allow"
|
|
actions = [
|
|
"lambda:*",
|
|
]
|
|
resources = [
|
|
"arn:aws:lambda:${var.aws_region}:${local.account_id}:function:apm-wo-analysis-*",
|
|
]
|
|
}
|
|
|
|
statement {
|
|
sid = "PandasLayer"
|
|
effect = "Allow"
|
|
actions = [
|
|
"lambda:GetLayerVersion",
|
|
]
|
|
resources = [
|
|
local.pandas_layer_arn,
|
|
"arn:aws:lambda:${var.aws_region}:336392948345:layer:AWSSDKPandas-Python312-Arm64:*",
|
|
]
|
|
}
|
|
|
|
statement {
|
|
sid = "LambdaList"
|
|
effect = "Allow"
|
|
actions = [
|
|
"lambda:ListFunctions",
|
|
"lambda:ListLayers",
|
|
"lambda:GetAccountSettings",
|
|
]
|
|
resources = ["*"]
|
|
}
|
|
|
|
statement {
|
|
sid = "CloudWatchLogs"
|
|
effect = "Allow"
|
|
actions = [
|
|
"logs:CreateLogGroup",
|
|
"logs:DeleteLogGroup",
|
|
"logs:PutRetentionPolicy",
|
|
"logs:DeleteRetentionPolicy",
|
|
"logs:TagResource",
|
|
"logs:UntagResource",
|
|
"logs:ListTagsForResource",
|
|
"logs:PutMetricFilter",
|
|
"logs:DeleteMetricFilter",
|
|
"logs:DescribeMetricFilters",
|
|
]
|
|
resources = [
|
|
"arn:aws:logs:${var.aws_region}:${local.account_id}:log-group:/aws/lambda/apm-wo-analysis-*",
|
|
"arn:aws:logs:${var.aws_region}:${local.account_id}:log-group:/aws/apigateway/apm-wo-analysis",
|
|
"arn:aws:logs:${var.aws_region}:${local.account_id}:log-group:/aws/apigateway/apm-wo-analysis:*",
|
|
]
|
|
}
|
|
|
|
statement {
|
|
sid = "CloudWatchLogsDescribe"
|
|
effect = "Allow"
|
|
actions = ["logs:DescribeLogGroups"]
|
|
resources = ["*"]
|
|
}
|
|
|
|
statement {
|
|
sid = "ApiGwAccessLogDelivery"
|
|
effect = "Allow"
|
|
actions = [
|
|
"logs:CreateLogDelivery",
|
|
"logs:GetLogDelivery",
|
|
"logs:UpdateLogDelivery",
|
|
"logs:DeleteLogDelivery",
|
|
"logs:ListLogDeliveries",
|
|
"logs:PutResourcePolicy",
|
|
"logs:DescribeResourcePolicies",
|
|
]
|
|
resources = ["*"]
|
|
}
|
|
|
|
statement {
|
|
sid = "StackBuckets"
|
|
effect = "Allow"
|
|
actions = [
|
|
"s3:*",
|
|
]
|
|
resources = [
|
|
"arn:aws:s3:::${local.artifacts_bucket_name}",
|
|
"arn:aws:s3:::${local.artifacts_bucket_name}/*",
|
|
"arn:aws:s3:::${local.exports_bucket_name}",
|
|
"arn:aws:s3:::${local.exports_bucket_name}/*",
|
|
]
|
|
}
|
|
|
|
statement {
|
|
sid = "HttpApiManage"
|
|
effect = "Allow"
|
|
actions = [
|
|
"apigateway:*",
|
|
]
|
|
resources = [
|
|
"arn:aws:apigateway:${var.aws_region}::/apis",
|
|
"arn:aws:apigateway:${var.aws_region}::/apis/*",
|
|
"arn:aws:apigateway:${var.aws_region}::/tags/*",
|
|
"arn:aws:apigateway:${var.aws_region}::/vpclinks",
|
|
"arn:aws:apigateway:${var.aws_region}::/vpclinks/*",
|
|
"arn:aws:apigateway:${var.aws_region}::/domainnames",
|
|
"arn:aws:apigateway:${var.aws_region}::/domainnames/*",
|
|
]
|
|
}
|
|
}
|
|
|
|
data "aws_iam_policy_document" "hcptf_apply_data" {
|
|
statement {
|
|
sid = "Ssm"
|
|
effect = "Allow"
|
|
actions = [
|
|
"ssm:GetParameter",
|
|
"ssm:GetParameters",
|
|
"ssm:PutParameter",
|
|
"ssm:DeleteParameter",
|
|
"ssm:AddTagsToResource",
|
|
"ssm:RemoveTagsFromResource",
|
|
"ssm:ListTagsForResource",
|
|
]
|
|
resources = [
|
|
"arn:aws:ssm:${var.aws_region}:${local.account_id}:parameter${local.ssm_prefix}/*",
|
|
]
|
|
}
|
|
|
|
statement {
|
|
sid = "SsmDescribeParameters"
|
|
effect = "Allow"
|
|
actions = ["ssm:DescribeParameters"]
|
|
resources = ["*"]
|
|
}
|
|
|
|
statement {
|
|
sid = "SsmAmiLookup"
|
|
effect = "Allow"
|
|
actions = [
|
|
"ssm:GetParameter",
|
|
]
|
|
resources = [
|
|
"arn:aws:ssm:${var.aws_region}::parameter/aws/service/ami-amazon-linux-latest/*",
|
|
]
|
|
}
|
|
|
|
statement {
|
|
sid = "SecretsManagerReadAndManage"
|
|
effect = "Allow"
|
|
actions = [
|
|
"secretsmanager:CreateSecret",
|
|
"secretsmanager:DeleteSecret",
|
|
"secretsmanager:DescribeSecret",
|
|
"secretsmanager:GetResourcePolicy",
|
|
"secretsmanager:PutResourcePolicy",
|
|
"secretsmanager:DeleteResourcePolicy",
|
|
"secretsmanager:TagResource",
|
|
"secretsmanager:UntagResource",
|
|
"secretsmanager:UpdateSecret",
|
|
"secretsmanager:ListSecretVersionIds",
|
|
]
|
|
resources = [
|
|
"arn:aws:secretsmanager:${var.aws_region}:${local.account_id}:secret:apm-wo-analysis/*",
|
|
]
|
|
}
|
|
|
|
statement {
|
|
sid = "SecretsManagerCreateByName"
|
|
effect = "Allow"
|
|
actions = [
|
|
"secretsmanager:CreateSecret",
|
|
]
|
|
resources = ["*"]
|
|
|
|
condition {
|
|
test = "StringLike"
|
|
variable = "secretsmanager:Name"
|
|
values = ["apm-wo-analysis/*"]
|
|
}
|
|
}
|
|
|
|
statement {
|
|
sid = "SecretsManagerList"
|
|
effect = "Allow"
|
|
actions = ["secretsmanager:ListSecrets"]
|
|
resources = ["*"]
|
|
}
|
|
|
|
statement {
|
|
sid = "SqsDlq"
|
|
effect = "Allow"
|
|
actions = [
|
|
"sqs:*",
|
|
]
|
|
resources = [
|
|
"arn:aws:sqs:${var.aws_region}:${local.account_id}:apm-wo-analysis-classifier-dlq",
|
|
]
|
|
}
|
|
|
|
statement {
|
|
sid = "SqsList"
|
|
effect = "Allow"
|
|
actions = ["sqs:ListQueues"]
|
|
resources = ["*"]
|
|
}
|
|
|
|
statement {
|
|
sid = "Glue"
|
|
effect = "Allow"
|
|
actions = [
|
|
"glue:*",
|
|
]
|
|
resources = [
|
|
"arn:aws:glue:${var.aws_region}:${local.account_id}:catalog",
|
|
"arn:aws:glue:${var.aws_region}:${local.account_id}:database/${local.glue_database}",
|
|
"arn:aws:glue:${var.aws_region}:${local.account_id}:table/${local.glue_database}/*",
|
|
]
|
|
}
|
|
|
|
statement {
|
|
sid = "Athena"
|
|
effect = "Allow"
|
|
actions = [
|
|
"athena:*",
|
|
]
|
|
resources = [
|
|
"arn:aws:athena:${var.aws_region}:${local.account_id}:workgroup/${local.athena_workgroup}",
|
|
]
|
|
}
|
|
|
|
statement {
|
|
sid = "AthenaList"
|
|
effect = "Allow"
|
|
actions = ["athena:ListWorkGroups"]
|
|
resources = ["*"]
|
|
}
|
|
|
|
statement {
|
|
sid = "CloudWatchAlarms"
|
|
effect = "Allow"
|
|
actions = [
|
|
"cloudwatch:PutMetricAlarm",
|
|
"cloudwatch:DeleteAlarms",
|
|
"cloudwatch:DescribeAlarms",
|
|
"cloudwatch:TagResource",
|
|
"cloudwatch:UntagResource",
|
|
"cloudwatch:ListTagsForResource",
|
|
]
|
|
resources = [
|
|
"arn:aws:cloudwatch:${var.aws_region}:${local.account_id}:alarm:Lambda-*-apm-wo-analysis-*",
|
|
"arn:aws:cloudwatch:${var.aws_region}:${local.account_id}:alarm:apm-wo-analysis-*",
|
|
"arn:aws:cloudwatch:${var.aws_region}:${local.account_id}:alarm:ApiGateway-*",
|
|
]
|
|
}
|
|
|
|
statement {
|
|
sid = "CloudWatchDescribeAlarms"
|
|
effect = "Allow"
|
|
actions = ["cloudwatch:DescribeAlarms"]
|
|
resources = ["*"]
|
|
}
|
|
|
|
statement {
|
|
sid = "SnsPublishSiteAlerts"
|
|
effect = "Allow"
|
|
actions = [
|
|
"sns:Publish",
|
|
"sns:GetTopicAttributes",
|
|
"sns:ListTagsForResource",
|
|
]
|
|
resources = [local.site_alerts_arn]
|
|
}
|
|
|
|
statement {
|
|
sid = "ManageTfManagedBoundary"
|
|
effect = "Allow"
|
|
actions = [
|
|
"iam:GetPolicy",
|
|
"iam:GetPolicyVersion",
|
|
"iam:ListPolicyVersions",
|
|
"iam:ListPolicyTags",
|
|
"iam:TagPolicy",
|
|
"iam:UntagPolicy",
|
|
]
|
|
resources = [
|
|
"arn:aws:iam::${local.account_id}:policy/tf-managed/${local.stack_prefix}*",
|
|
]
|
|
}
|
|
}
|
|
|
|
# Split from hcptf_apply_services: IAM inline policies cap at 10240 bytes.
|
|
data "aws_iam_policy_document" "hcptf_apply_network" {
|
|
# checkov:skip=CKV_AWS_111: EC2/ELB describe and tagged-create APIs require Resource=*. Writes use RequestTag/ResourceTag Project=apm-wo-analysis.
|
|
statement {
|
|
sid = "Ec2Describe"
|
|
effect = "Allow"
|
|
actions = [
|
|
"ec2:DescribeAccountAttributes",
|
|
"ec2:DescribeAddresses",
|
|
"ec2:DescribeAddressesAttribute",
|
|
"ec2:DescribeAvailabilityZones",
|
|
"ec2:DescribeImages",
|
|
"ec2:DescribeInstanceAttribute",
|
|
"ec2:DescribeInstanceCreditSpecifications",
|
|
"ec2:DescribeInstanceStatus",
|
|
"ec2:DescribeInstanceTypes",
|
|
"ec2:DescribeInstances",
|
|
"ec2:DescribeInternetGateways",
|
|
"ec2:DescribeNatGateways",
|
|
"ec2:DescribeNetworkAcls",
|
|
"ec2:DescribeNetworkInterfaces",
|
|
"ec2:DescribePrefixLists",
|
|
"ec2:DescribeRouteTables",
|
|
"ec2:DescribeSecurityGroups",
|
|
"ec2:DescribeSecurityGroupRules",
|
|
"ec2:DescribeSnapshots",
|
|
"ec2:DescribeSubnets",
|
|
"ec2:DescribeTags",
|
|
"ec2:DescribeVolumes",
|
|
"ec2:DescribeVolumesModifications",
|
|
"ec2:DescribeVpcAttribute",
|
|
"ec2:DescribeVpcs",
|
|
]
|
|
resources = ["*"]
|
|
}
|
|
|
|
statement {
|
|
sid = "Ec2CreateTagged"
|
|
effect = "Allow"
|
|
actions = [
|
|
"ec2:CreateVpc",
|
|
"ec2:CreateSubnet",
|
|
"ec2:CreateInternetGateway",
|
|
"ec2:CreateNatGateway",
|
|
"ec2:AllocateAddress",
|
|
"ec2:CreateRouteTable",
|
|
"ec2:CreateSecurityGroup",
|
|
"ec2:RunInstances",
|
|
"ec2:CreateTags",
|
|
"ec2:CreateVolume",
|
|
]
|
|
resources = ["*"]
|
|
|
|
condition {
|
|
test = "StringEquals"
|
|
variable = "aws:RequestTag/Project"
|
|
values = [local.project]
|
|
}
|
|
}
|
|
|
|
statement {
|
|
sid = "Ec2CreateInTaggedVpc"
|
|
effect = "Allow"
|
|
actions = [
|
|
"ec2:CreateSubnet",
|
|
"ec2:CreateRouteTable",
|
|
"ec2:CreateSecurityGroup",
|
|
"ec2:CreateNatGateway",
|
|
"ec2:CreateNetworkInterface",
|
|
]
|
|
resources = ["*"]
|
|
|
|
condition {
|
|
test = "StringEquals"
|
|
variable = "ec2:ResourceTag/Project"
|
|
values = [local.project]
|
|
}
|
|
}
|
|
|
|
statement {
|
|
sid = "Ec2MutateTagged"
|
|
effect = "Allow"
|
|
actions = [
|
|
"ec2:DeleteVpc",
|
|
"ec2:DeleteSubnet",
|
|
"ec2:DeleteInternetGateway",
|
|
"ec2:DeleteNatGateway",
|
|
"ec2:ReleaseAddress",
|
|
"ec2:DeleteRouteTable",
|
|
"ec2:DeleteSecurityGroup",
|
|
"ec2:TerminateInstances",
|
|
"ec2:StopInstances",
|
|
"ec2:StartInstances",
|
|
"ec2:ModifyInstanceAttribute",
|
|
"ec2:DeleteVolume",
|
|
"ec2:DetachVolume",
|
|
"ec2:AttachVolume",
|
|
"ec2:DeleteTags",
|
|
"ec2:RevokeSecurityGroupIngress",
|
|
"ec2:RevokeSecurityGroupEgress",
|
|
"ec2:AuthorizeSecurityGroupIngress",
|
|
"ec2:AuthorizeSecurityGroupEgress",
|
|
"ec2:ModifySubnetAttribute",
|
|
]
|
|
resources = ["*"]
|
|
|
|
condition {
|
|
test = "StringEquals"
|
|
variable = "aws:ResourceTag/Project"
|
|
values = [local.project]
|
|
}
|
|
}
|
|
|
|
statement {
|
|
sid = "Ec2Networking"
|
|
effect = "Allow"
|
|
actions = [
|
|
"ec2:CreateRoute",
|
|
"ec2:DeleteRoute",
|
|
"ec2:AssociateRouteTable",
|
|
"ec2:DisassociateRouteTable",
|
|
"ec2:AttachInternetGateway",
|
|
"ec2:DetachInternetGateway",
|
|
"ec2:ModifyVpcAttribute",
|
|
"ec2:AssociateAddress",
|
|
"ec2:DisassociateAddress",
|
|
]
|
|
resources = ["*"]
|
|
}
|
|
|
|
statement {
|
|
sid = "RunInstancesSupportingResources"
|
|
effect = "Allow"
|
|
actions = [
|
|
"ec2:RunInstances",
|
|
]
|
|
resources = [
|
|
"arn:aws:ec2:${var.aws_region}:${local.account_id}:network-interface/*",
|
|
"arn:aws:ec2:${var.aws_region}:${local.account_id}:volume/*",
|
|
"arn:aws:ec2:${var.aws_region}::image/*",
|
|
"arn:aws:ec2:${var.aws_region}:${local.account_id}:subnet/*",
|
|
"arn:aws:ec2:${var.aws_region}:${local.account_id}:security-group/*",
|
|
]
|
|
}
|
|
}
|
|
|
|
data "aws_iam_policy_document" "hcptf_apply_elb" {
|
|
statement {
|
|
sid = "ElbDescribe"
|
|
effect = "Allow"
|
|
actions = [
|
|
"elasticloadbalancing:DescribeListenerAttributes",
|
|
"elasticloadbalancing:DescribeListeners",
|
|
"elasticloadbalancing:DescribeLoadBalancerAttributes",
|
|
"elasticloadbalancing:DescribeLoadBalancers",
|
|
"elasticloadbalancing:DescribeRules",
|
|
"elasticloadbalancing:DescribeTags",
|
|
"elasticloadbalancing:DescribeTargetGroupAttributes",
|
|
"elasticloadbalancing:DescribeTargetGroups",
|
|
"elasticloadbalancing:DescribeTargetHealth",
|
|
]
|
|
resources = ["*"]
|
|
}
|
|
|
|
statement {
|
|
sid = "ElbCreateTagged"
|
|
effect = "Allow"
|
|
actions = [
|
|
"elasticloadbalancing:CreateLoadBalancer",
|
|
"elasticloadbalancing:CreateTargetGroup",
|
|
"elasticloadbalancing:AddTags",
|
|
]
|
|
resources = ["*"]
|
|
|
|
condition {
|
|
test = "StringEquals"
|
|
variable = "aws:RequestTag/Project"
|
|
values = [local.project]
|
|
}
|
|
}
|
|
|
|
statement {
|
|
sid = "ElbMutateTagged"
|
|
effect = "Allow"
|
|
actions = [
|
|
"elasticloadbalancing:CreateListener",
|
|
"elasticloadbalancing:CreateRule",
|
|
"elasticloadbalancing:DeleteListener",
|
|
"elasticloadbalancing:DeleteLoadBalancer",
|
|
"elasticloadbalancing:DeleteRule",
|
|
"elasticloadbalancing:DeleteTargetGroup",
|
|
"elasticloadbalancing:DeregisterTargets",
|
|
"elasticloadbalancing:ModifyListener",
|
|
"elasticloadbalancing:ModifyLoadBalancerAttributes",
|
|
"elasticloadbalancing:ModifyRule",
|
|
"elasticloadbalancing:ModifyTargetGroup",
|
|
"elasticloadbalancing:ModifyTargetGroupAttributes",
|
|
"elasticloadbalancing:RegisterTargets",
|
|
"elasticloadbalancing:RemoveTags",
|
|
"elasticloadbalancing:SetSecurityGroups",
|
|
"elasticloadbalancing:SetSubnets",
|
|
]
|
|
resources = ["*"]
|
|
|
|
condition {
|
|
test = "StringEquals"
|
|
variable = "aws:ResourceTag/Project"
|
|
values = [local.project]
|
|
}
|
|
}
|
|
|
|
statement {
|
|
sid = "ElbPrefix"
|
|
effect = "Allow"
|
|
actions = [
|
|
"elasticloadbalancing:*",
|
|
]
|
|
resources = [
|
|
"arn:aws:elasticloadbalancing:${var.aws_region}:${local.account_id}:loadbalancer/app/apm-wo-analysis-*/*",
|
|
"arn:aws:elasticloadbalancing:${var.aws_region}:${local.account_id}:targetgroup/apm-wo-analysis-*/*",
|
|
"arn:aws:elasticloadbalancing:${var.aws_region}:${local.account_id}:listener/app/apm-wo-analysis-*/*",
|
|
"arn:aws:elasticloadbalancing:${var.aws_region}:${local.account_id}:listener-rule/app/apm-wo-analysis-*/*",
|
|
]
|
|
}
|
|
|
|
statement {
|
|
sid = "DlmCreate"
|
|
effect = "Allow"
|
|
actions = [
|
|
"dlm:CreateLifecyclePolicy",
|
|
]
|
|
resources = ["*"]
|
|
|
|
condition {
|
|
test = "StringEquals"
|
|
variable = "aws:RequestTag/Project"
|
|
values = [local.project]
|
|
}
|
|
}
|
|
|
|
statement {
|
|
sid = "Dlm"
|
|
effect = "Allow"
|
|
actions = [
|
|
"dlm:*",
|
|
]
|
|
resources = [
|
|
"arn:aws:dlm:${var.aws_region}:${local.account_id}:policy/*",
|
|
]
|
|
}
|
|
|
|
statement {
|
|
sid = "AcmRead"
|
|
effect = "Allow"
|
|
actions = [
|
|
"acm:DescribeCertificate",
|
|
"acm:GetCertificate",
|
|
"acm:ListCertificates",
|
|
"acm:ListTagsForCertificate",
|
|
]
|
|
resources = ["*"]
|
|
}
|
|
}
|
|
|
|
data "aws_iam_policy_document" "hcptf_plan_refresh" {
|
|
statement {
|
|
sid = "RefreshIamRoles"
|
|
effect = "Allow"
|
|
actions = [
|
|
"iam:GetRole",
|
|
"iam:GetRolePolicy",
|
|
"iam:ListRolePolicies",
|
|
"iam:ListAttachedRolePolicies",
|
|
"iam:ListRoleTags",
|
|
"iam:GetInstanceProfile",
|
|
"iam:GetUser",
|
|
"iam:GetUserPolicy",
|
|
"iam:ListUserPolicies",
|
|
"iam:ListUserTags",
|
|
]
|
|
resources = [
|
|
"arn:aws:iam::${local.account_id}:role/tf-managed/${local.stack_prefix}*",
|
|
"arn:aws:iam::${local.account_id}:role/tf-managed/${local.deploy_role}",
|
|
"arn:aws:iam::${local.account_id}:role/${local.apply_role}",
|
|
"arn:aws:iam::${local.account_id}:role/${local.plan_role}",
|
|
"arn:aws:iam::${local.account_id}:instance-profile/tf-managed/${local.stack_prefix}*",
|
|
"arn:aws:iam::${local.account_id}:user/tf-managed/apm-wo-drop-uploader",
|
|
]
|
|
}
|
|
|
|
statement {
|
|
sid = "RefreshManagedPolicies"
|
|
effect = "Allow"
|
|
actions = [
|
|
"iam:GetPolicy",
|
|
"iam:GetPolicyVersion",
|
|
]
|
|
resources = ["*"]
|
|
}
|
|
|
|
statement {
|
|
sid = "RefreshLambda"
|
|
effect = "Allow"
|
|
actions = [
|
|
"lambda:GetFunction",
|
|
"lambda:GetFunctionConfiguration",
|
|
"lambda:GetPolicy",
|
|
"lambda:GetFunctionCodeSigningConfig",
|
|
"lambda:GetFunctionConcurrency",
|
|
"lambda:GetFunctionEventInvokeConfig",
|
|
"lambda:GetFunctionUrlConfig",
|
|
"lambda:GetRuntimeManagementConfig",
|
|
"lambda:GetFunctionRecursionConfig",
|
|
"lambda:ListTags",
|
|
"lambda:ListVersionsByFunction",
|
|
"lambda:ListAliases",
|
|
]
|
|
resources = [
|
|
"arn:aws:lambda:${var.aws_region}:${local.account_id}:function:apm-wo-analysis-*",
|
|
]
|
|
}
|
|
|
|
statement {
|
|
sid = "RefreshPandasLayer"
|
|
effect = "Allow"
|
|
actions = [
|
|
"lambda:GetLayerVersion",
|
|
]
|
|
resources = [
|
|
local.pandas_layer_arn,
|
|
"arn:aws:lambda:${var.aws_region}:336392948345:layer:AWSSDKPandas-Python312-Arm64:*",
|
|
]
|
|
}
|
|
|
|
statement {
|
|
sid = "RefreshLambdaList"
|
|
effect = "Allow"
|
|
actions = [
|
|
"lambda:ListFunctions",
|
|
"lambda:ListLayers",
|
|
"lambda:GetAccountSettings",
|
|
]
|
|
resources = ["*"]
|
|
}
|
|
|
|
statement {
|
|
sid = "RefreshBuckets"
|
|
effect = "Allow"
|
|
actions = [
|
|
"s3:GetAccelerateConfiguration",
|
|
"s3:GetAnalyticsConfiguration",
|
|
"s3:GetBucketAcl",
|
|
"s3:GetBucketCORS",
|
|
"s3:GetBucketLifecycleConfiguration",
|
|
"s3:GetBucketLocation",
|
|
"s3:GetBucketLogging",
|
|
"s3:GetBucketNotification",
|
|
"s3:GetBucketObjectLockConfiguration",
|
|
"s3:GetBucketOwnershipControls",
|
|
"s3:GetBucketPolicy",
|
|
"s3:GetBucketPolicyStatus",
|
|
"s3:GetBucketPublicAccessBlock",
|
|
"s3:GetBucketReplication",
|
|
"s3:GetBucketRequestPayment",
|
|
"s3:GetBucketTagging",
|
|
"s3:GetBucketVersioning",
|
|
"s3:GetBucketWebsite",
|
|
"s3:GetEncryptionConfiguration",
|
|
"s3:GetIntelligentTieringConfiguration",
|
|
"s3:GetInventoryConfiguration",
|
|
"s3:GetLifecycleConfiguration",
|
|
"s3:GetMetricsConfiguration",
|
|
"s3:GetObject",
|
|
"s3:GetObjectTagging",
|
|
"s3:GetObjectVersion",
|
|
"s3:GetReplicationConfiguration",
|
|
"s3:ListBucket",
|
|
]
|
|
resources = [
|
|
"arn:aws:s3:::${local.artifacts_bucket_name}",
|
|
"arn:aws:s3:::${local.artifacts_bucket_name}/*",
|
|
"arn:aws:s3:::${local.exports_bucket_name}",
|
|
"arn:aws:s3:::${local.exports_bucket_name}/*",
|
|
]
|
|
}
|
|
|
|
statement {
|
|
sid = "RefreshLogs"
|
|
effect = "Allow"
|
|
actions = [
|
|
"logs:DescribeLogGroups",
|
|
"logs:ListTagsForResource",
|
|
]
|
|
resources = ["*"]
|
|
}
|
|
|
|
statement {
|
|
sid = "RefreshHttpApi"
|
|
effect = "Allow"
|
|
actions = [
|
|
"apigateway:GET",
|
|
]
|
|
resources = [
|
|
"arn:aws:apigateway:${var.aws_region}::/apis",
|
|
"arn:aws:apigateway:${var.aws_region}::/apis/*",
|
|
"arn:aws:apigateway:${var.aws_region}::/tags/*",
|
|
"arn:aws:apigateway:${var.aws_region}::/domainnames",
|
|
"arn:aws:apigateway:${var.aws_region}::/domainnames/*",
|
|
]
|
|
}
|
|
|
|
statement {
|
|
sid = "RefreshSsm"
|
|
effect = "Allow"
|
|
actions = [
|
|
"ssm:GetParameter",
|
|
"ssm:GetParameters",
|
|
"ssm:ListTagsForResource",
|
|
]
|
|
resources = [
|
|
"arn:aws:ssm:${var.aws_region}:${local.account_id}:parameter${local.ssm_prefix}/*",
|
|
"arn:aws:ssm:${var.aws_region}::parameter/aws/service/ami-amazon-linux-latest/*",
|
|
]
|
|
}
|
|
|
|
statement {
|
|
sid = "RefreshSsmDescribeParameters"
|
|
effect = "Allow"
|
|
actions = ["ssm:DescribeParameters"]
|
|
resources = ["*"]
|
|
}
|
|
|
|
statement {
|
|
sid = "RefreshSecrets"
|
|
effect = "Allow"
|
|
actions = [
|
|
"secretsmanager:DescribeSecret",
|
|
"secretsmanager:GetResourcePolicy",
|
|
"secretsmanager:ListSecretVersionIds",
|
|
]
|
|
resources = [
|
|
"arn:aws:secretsmanager:${var.aws_region}:${local.account_id}:secret:apm-wo-analysis/*",
|
|
]
|
|
}
|
|
|
|
statement {
|
|
sid = "RefreshSecretsList"
|
|
effect = "Allow"
|
|
actions = ["secretsmanager:ListSecrets"]
|
|
resources = ["*"]
|
|
}
|
|
|
|
statement {
|
|
sid = "RefreshSqs"
|
|
effect = "Allow"
|
|
actions = [
|
|
"sqs:GetQueueAttributes",
|
|
"sqs:GetQueueUrl",
|
|
"sqs:ListQueueTags",
|
|
]
|
|
resources = [
|
|
"arn:aws:sqs:${var.aws_region}:${local.account_id}:apm-wo-analysis-classifier-dlq",
|
|
]
|
|
}
|
|
|
|
statement {
|
|
sid = "RefreshGlue"
|
|
effect = "Allow"
|
|
actions = [
|
|
"glue:GetDatabase",
|
|
"glue:GetTable",
|
|
"glue:GetTables",
|
|
"glue:GetPartition",
|
|
"glue:GetPartitions",
|
|
]
|
|
resources = [
|
|
"arn:aws:glue:${var.aws_region}:${local.account_id}:catalog",
|
|
"arn:aws:glue:${var.aws_region}:${local.account_id}:database/${local.glue_database}",
|
|
"arn:aws:glue:${var.aws_region}:${local.account_id}:table/${local.glue_database}/*",
|
|
]
|
|
}
|
|
|
|
statement {
|
|
sid = "RefreshAthena"
|
|
effect = "Allow"
|
|
actions = [
|
|
"athena:GetWorkGroup",
|
|
]
|
|
resources = [
|
|
"arn:aws:athena:${var.aws_region}:${local.account_id}:workgroup/${local.athena_workgroup}",
|
|
]
|
|
}
|
|
|
|
statement {
|
|
sid = "RefreshAlarms"
|
|
effect = "Allow"
|
|
actions = [
|
|
"cloudwatch:DescribeAlarms",
|
|
"cloudwatch:ListTagsForResource",
|
|
]
|
|
resources = ["*"]
|
|
}
|
|
|
|
statement {
|
|
sid = "RefreshSns"
|
|
effect = "Allow"
|
|
actions = [
|
|
"sns:GetTopicAttributes",
|
|
"sns:ListTagsForResource",
|
|
]
|
|
resources = [local.site_alerts_arn]
|
|
}
|
|
|
|
statement {
|
|
sid = "RefreshEc2"
|
|
effect = "Allow"
|
|
actions = [
|
|
"ec2:DescribeAccountAttributes",
|
|
"ec2:DescribeAddresses",
|
|
"ec2:DescribeAddressesAttribute",
|
|
"ec2:DescribeAvailabilityZones",
|
|
"ec2:DescribeImages",
|
|
"ec2:DescribeInstanceAttribute",
|
|
"ec2:DescribeInstanceCreditSpecifications",
|
|
"ec2:DescribeInstances",
|
|
"ec2:DescribeInternetGateways",
|
|
"ec2:DescribeNatGateways",
|
|
"ec2:DescribeNetworkInterfaces",
|
|
"ec2:DescribeRouteTables",
|
|
"ec2:DescribeSecurityGroups",
|
|
"ec2:DescribeSecurityGroupRules",
|
|
"ec2:DescribeSubnets",
|
|
"ec2:DescribeTags",
|
|
"ec2:DescribeVolumes",
|
|
"ec2:DescribeVpcAttribute",
|
|
"ec2:DescribeVpcs",
|
|
]
|
|
resources = ["*"]
|
|
}
|
|
|
|
statement {
|
|
sid = "RefreshElb"
|
|
effect = "Allow"
|
|
actions = [
|
|
"elasticloadbalancing:DescribeListenerAttributes",
|
|
"elasticloadbalancing:DescribeListeners",
|
|
"elasticloadbalancing:DescribeLoadBalancerAttributes",
|
|
"elasticloadbalancing:DescribeLoadBalancers",
|
|
"elasticloadbalancing:DescribeRules",
|
|
"elasticloadbalancing:DescribeTags",
|
|
"elasticloadbalancing:DescribeTargetGroupAttributes",
|
|
"elasticloadbalancing:DescribeTargetGroups",
|
|
"elasticloadbalancing:DescribeTargetHealth",
|
|
]
|
|
resources = ["*"]
|
|
}
|
|
|
|
statement {
|
|
sid = "RefreshDlm"
|
|
effect = "Allow"
|
|
actions = [
|
|
"dlm:GetLifecyclePolicy",
|
|
"dlm:GetLifecyclePolicies",
|
|
]
|
|
resources = ["*"]
|
|
}
|
|
|
|
statement {
|
|
sid = "RefreshAcm"
|
|
effect = "Allow"
|
|
actions = [
|
|
"acm:DescribeCertificate",
|
|
"acm:GetCertificate",
|
|
"acm:ListCertificates",
|
|
"acm:ListTagsForCertificate",
|
|
]
|
|
resources = ["*"]
|
|
}
|
|
}
|
|
|
|
resource "aws_iam_role" "hcptf_apply" {
|
|
name = local.apply_role
|
|
assume_role_policy = data.aws_iam_policy_document.hcptf_apply_trust.json
|
|
max_session_duration = 3600
|
|
|
|
tags = {
|
|
Owner = "adam@seahavenind.com"
|
|
ManagedBy = "terraform"
|
|
}
|
|
}
|
|
|
|
resource "aws_iam_role" "hcptf_plan" {
|
|
name = local.plan_role
|
|
assume_role_policy = data.aws_iam_policy_document.hcptf_plan_trust.json
|
|
max_session_duration = 3600
|
|
|
|
tags = {
|
|
Owner = "adam@seahavenind.com"
|
|
ManagedBy = "terraform"
|
|
}
|
|
}
|
|
|
|
resource "aws_iam_role_policy" "hcptf_scoped_iam" {
|
|
name = "scoped-iam-management"
|
|
role = aws_iam_role.hcptf_apply.id
|
|
policy = data.aws_iam_policy_document.hcptf_scoped_iam.json
|
|
}
|
|
|
|
resource "aws_iam_policy" "hcptf_apply_services" {
|
|
name = "apm-wo-analysis-apply-services"
|
|
path = "/tf-managed/"
|
|
description = "HCP apply Lambda/API/S3 permissions for apm-wo-analysis"
|
|
policy = data.aws_iam_policy_document.hcptf_apply_services.json
|
|
}
|
|
|
|
resource "aws_iam_policy" "hcptf_apply_data" {
|
|
name = "apm-wo-analysis-apply-data"
|
|
path = "/tf-managed/"
|
|
description = "HCP apply Glue/Athena/SSM/Secrets/SQS permissions for apm-wo-analysis"
|
|
policy = data.aws_iam_policy_document.hcptf_apply_data.json
|
|
}
|
|
|
|
resource "aws_iam_policy" "hcptf_apply_network" {
|
|
name = "apm-wo-analysis-apply-network"
|
|
path = "/tf-managed/"
|
|
description = "HCP apply VPC/EC2 permissions for apm-wo-analysis"
|
|
policy = data.aws_iam_policy_document.hcptf_apply_network.json
|
|
}
|
|
|
|
resource "aws_iam_policy" "hcptf_apply_elb" {
|
|
name = "apm-wo-analysis-apply-elb"
|
|
path = "/tf-managed/"
|
|
description = "HCP apply ALB/DLM/ACM permissions for apm-wo-analysis"
|
|
policy = data.aws_iam_policy_document.hcptf_apply_elb.json
|
|
}
|
|
|
|
resource "aws_iam_role_policy_attachment" "hcptf_apply_services" {
|
|
role = aws_iam_role.hcptf_apply.name
|
|
policy_arn = aws_iam_policy.hcptf_apply_services.arn
|
|
}
|
|
|
|
resource "aws_iam_role_policy_attachment" "hcptf_apply_data" {
|
|
role = aws_iam_role.hcptf_apply.name
|
|
policy_arn = aws_iam_policy.hcptf_apply_data.arn
|
|
}
|
|
|
|
resource "aws_iam_role_policy_attachment" "hcptf_apply_network" {
|
|
role = aws_iam_role.hcptf_apply.name
|
|
policy_arn = aws_iam_policy.hcptf_apply_network.arn
|
|
}
|
|
|
|
resource "aws_iam_role_policy_attachment" "hcptf_apply_elb" {
|
|
role = aws_iam_role.hcptf_apply.name
|
|
policy_arn = aws_iam_policy.hcptf_apply_elb.arn
|
|
}
|
|
|
|
resource "aws_iam_role_policy" "hcptf_plan_refresh" {
|
|
name = "apm-wo-analysis-plan-refresh"
|
|
role = aws_iam_role.hcptf_plan.id
|
|
policy = data.aws_iam_policy_document.hcptf_plan_refresh.json
|
|
}
|
|
|
|
resource "aws_iam_role_policy_attachment" "hcptf_plan_view_only" {
|
|
role = aws_iam_role.hcptf_plan.name
|
|
policy_arn = "arn:aws:iam::aws:policy/job-function/ViewOnlyAccess"
|
|
}
|
|
|
|
resource "aws_iam_role_policy_attachments_exclusive" "hcptf_apply" {
|
|
role_name = aws_iam_role.hcptf_apply.name
|
|
policy_arns = [
|
|
aws_iam_policy.hcptf_apply_services.arn,
|
|
aws_iam_policy.hcptf_apply_data.arn,
|
|
aws_iam_policy.hcptf_apply_network.arn,
|
|
aws_iam_policy.hcptf_apply_elb.arn,
|
|
]
|
|
}
|
|
|
|
resource "aws_iam_role_policy_attachments_exclusive" "hcptf_plan" {
|
|
role_name = aws_iam_role.hcptf_plan.name
|
|
policy_arns = [
|
|
"arn:aws:iam::aws:policy/job-function/ViewOnlyAccess",
|
|
]
|
|
}
|