File tree Expand file tree Collapse file tree 2 files changed +12
-11
lines changed Expand file tree Collapse file tree 2 files changed +12
-11
lines changed Original file line number Diff line number Diff line change 1
1
repos :
2
2
- repo : https://github.com/antonbabenko/pre-commit-terraform
3
- rev : v1.88.0
3
+ rev : v1.88.4
4
4
hooks :
5
5
- id : terraform_fmt
6
6
- id : terraform_docs
Original file line number Diff line number Diff line change @@ -6,20 +6,18 @@ data "aws_iam_policy_document" "sns_feedback" {
6
6
count = local. create_sns_feedback_role ? 1 : 0
7
7
8
8
statement {
9
- sid = " PermitDeliveryStatusMessagesToCloudWatchLogs "
9
+ sid = " SnsAssume "
10
10
effect = " Allow"
11
11
12
12
actions = [
13
- " logs:CreateLogGroup" ,
14
- " logs:CreateLogStream" ,
15
- " logs:PutLogEvents" ,
16
- " logs:PutMetricFilter" ,
17
- " logs:PutRetentionPolicy"
13
+ " sts:AssumeRole" ,
14
+ " sts:TagSession" ,
18
15
]
19
16
20
- resources = [
21
- " *"
22
- ]
17
+ principals {
18
+ type = " Service"
19
+ identifiers = [" sns.amazonaws.com" ]
20
+ }
23
21
}
24
22
}
25
23
@@ -33,5 +31,8 @@ resource "aws_iam_role" "sns_feedback_role" {
33
31
permissions_boundary = var. sns_topic_feedback_role_permissions_boundary
34
32
assume_role_policy = data. aws_iam_policy_document . sns_feedback [0 ]. json
35
33
36
- tags = merge (var. tags , var. sns_topic_feedback_role_tags )
34
+ tags = merge (
35
+ var. tags ,
36
+ var. sns_topic_feedback_role_tags ,
37
+ )
37
38
}
You can’t perform that action at this time.
0 commit comments