diff --git a/terraform/hcp_iam.tf b/terraform/hcp_iam.tf index 3da428d..8b6c918 100644 --- a/terraform/hcp_iam.tf +++ b/terraform/hcp_iam.tf @@ -8,7 +8,7 @@ # 2. Point this workspace's TFC_AWS_* at hcptf-bootstrap / # hcptf-bootstrap-plan (workspace vars, never a project set). # 3. One Manual apply (import + detach seahaven-hcptf-iam-management + -# put scoped inline). +# put scoped IAM as a customer-managed policy). # 4. Point TFC_AWS_* back at hcptf-procurement-ingest / hcptf-procurement-ingest-plan. # 5. Re-run the script without --allow-workspace to pin trust back to # iam-bootstrap-prod only. @@ -821,10 +821,14 @@ resource "aws_iam_role" "hcptf_apply" { } } -# Empty exclusive set keeps seahaven-hcptf-iam-management detached. +# Services inline is 6894 bytes; a second inline for scoped IAM exceeds the +# 10240 role quota. Attach scoped IAM as a customer-managed policy instead. +# Exclusive set keeps seahaven-hcptf-iam-management detached. resource "aws_iam_role_policy_attachments_exclusive" "hcptf_apply" { - role_name = aws_iam_role.hcptf_apply.name - policy_arns = [] + role_name = aws_iam_role.hcptf_apply.name + policy_arns = [ + aws_iam_policy.hcptf_scoped_iam.arn, + ] } resource "aws_iam_role" "hcptf_plan" { @@ -851,8 +855,19 @@ resource "aws_iam_role_policy_attachments_exclusive" "hcptf_plan" { ] } -resource "aws_iam_role_policy" "hcptf_scoped_iam" { - name = "scoped-iam-management" - role = aws_iam_role.hcptf_apply.id +resource "aws_iam_policy" "hcptf_scoped_iam" { + name = "hcptf-procurement-ingest-scoped-iam" + path = "/tf-managed/" policy = data.aws_iam_policy_document.hcptf_scoped_iam.json + + tags = { + Project = "procurement-ingest" + Owner = "adam@seahavenind.com" + ManagedBy = "terraform" + } +} + +resource "aws_iam_role_policy_attachment" "hcptf_scoped_iam" { + role = aws_iam_role.hcptf_apply.name + policy_arn = aws_iam_policy.hcptf_scoped_iam.arn }