resource "aws_iam_role" "app" { name = "cibello-app" assume_role_policy = jsonencode({ Version = "2012-10-17" Statement = [ { Action = "sts:AssumeRole" Effect = "Allow" Principal = { Service = "ec2.amazonaws.com" } } ] }) tags = { Name = "cibello-app" } } resource "aws_iam_role_policy" "app" { name = "cibello-app-policy" role = aws_iam_role.app.id policy = jsonencode({ Version = "2012-10-17" Statement = [ { Sid = "AllowProductionS3" Effect = "Allow" Action = [ "s3:ListBucket", "s3:GetObject", "s3:PutObject", "s3:DeleteObject" ] Resource = [ aws_s3_bucket.production.arn, "${aws_s3_bucket.production.arn}/*" ] }, { Sid = "AllowSSMParameters" Effect = "Allow" Action = [ "ssm:GetParameter", "ssm:GetParameters", "ssm:GetParametersByPath" ] Resource = "arn:aws:ssm:eu-north-1:${data.aws_caller_identity.current.account_id}:parameter/cibello/prod/*" }, { Sid = "AllowKMSDecrypt" Effect = "Allow" Action = [ "kms:Decrypt", "kms:GenerateDataKey" ] Resource = "*" } ] }) } resource "aws_iam_role_policy_attachment" "app_ssm" { role = aws_iam_role.app.name policy_arn = "arn:aws:iam::aws:policy/AmazonSSMManagedInstanceCore" } resource "aws_iam_instance_profile" "app" { name = "cibello-prod-app-profile" role = aws_iam_role.app.name tags = { Name = "cibello-prod-app-profile" } } data "aws_caller_identity" "current" {}