infra: add least-privilege iam role and instance profile
This commit is contained in:
@@ -0,0 +1,79 @@
|
|||||||
|
resource "aws_iam_role" "app" {
|
||||||
|
name = "cibello-app"
|
||||||
|
|
||||||
|
assume_role_policy = jsonencode({
|
||||||
|
Version = "2012-10-17"
|
||||||
|
Statement = [
|
||||||
|
{
|
||||||
|
Action = "sts:AssumeRole"
|
||||||
|
Effect = "Allow"
|
||||||
|
Principal = {
|
||||||
|
Service = "ec2.amazonaws.com"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
]
|
||||||
|
})
|
||||||
|
|
||||||
|
tags = {
|
||||||
|
Name = "cibello-app"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
resource "aws_iam_role_policy" "app" {
|
||||||
|
name = "cibello-app-policy"
|
||||||
|
role = aws_iam_role.app.id
|
||||||
|
|
||||||
|
policy = jsonencode({
|
||||||
|
Version = "2012-10-17"
|
||||||
|
Statement = [
|
||||||
|
{
|
||||||
|
Sid = "AllowProductionS3"
|
||||||
|
Effect = "Allow"
|
||||||
|
Action = [
|
||||||
|
"s3:ListBucket",
|
||||||
|
"s3:GetObject",
|
||||||
|
"s3:PutObject",
|
||||||
|
"s3:DeleteObject"
|
||||||
|
]
|
||||||
|
Resource = [
|
||||||
|
aws_s3_bucket.production.arn,
|
||||||
|
"${aws_s3_bucket.production.arn}/*"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
{
|
||||||
|
Sid = "AllowSSMParameters"
|
||||||
|
Effect = "Allow"
|
||||||
|
Action = [
|
||||||
|
"ssm:GetParameter",
|
||||||
|
"ssm:GetParameters",
|
||||||
|
"ssm:GetParametersByPath"
|
||||||
|
]
|
||||||
|
Resource = "arn:aws:ssm:eu-north-1:${data.aws_caller_identity.current.account_id}:parameter/cibello/prod/*"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
Sid = "AllowKMSDecrypt"
|
||||||
|
Effect = "Allow"
|
||||||
|
Action = [
|
||||||
|
"kms:Decrypt",
|
||||||
|
"kms:GenerateDataKey"
|
||||||
|
]
|
||||||
|
Resource = "*"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
resource "aws_iam_role_policy_attachment" "app_ssm" {
|
||||||
|
role = aws_iam_role.app.name
|
||||||
|
policy_arn = "arn:aws:iam::aws:policy/AmazonSSMManagedInstanceCore"
|
||||||
|
}
|
||||||
|
|
||||||
|
resource "aws_iam_instance_profile" "app" {
|
||||||
|
name = "cibello-prod-app-profile"
|
||||||
|
role = aws_iam_role.app.name
|
||||||
|
tags = {
|
||||||
|
Name = "cibello-prod-app-profile"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
data "aws_caller_identity" "current" {}
|
||||||
Reference in New Issue
Block a user