Files
Cibello-app/infrastructure/terraform/iam.tf
T
2026-08-11 21:33:45 +07:00

80 lines
1.7 KiB
Terraform

resource "aws_iam_role" "app" {
name = "cibello-app"
assume_role_policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = "sts:AssumeRole"
Effect = "Allow"
Principal = {
Service = "ec2.amazonaws.com"
}
}
]
})
tags = {
Name = "cibello-app"
}
}
resource "aws_iam_role_policy" "app" {
name = "cibello-app-policy"
role = aws_iam_role.app.id
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Sid = "AllowProductionS3"
Effect = "Allow"
Action = [
"s3:ListBucket",
"s3:GetObject",
"s3:PutObject",
"s3:DeleteObject"
]
Resource = [
aws_s3_bucket.production.arn,
"${aws_s3_bucket.production.arn}/*"
]
},
{
Sid = "AllowSSMParameters"
Effect = "Allow"
Action = [
"ssm:GetParameter",
"ssm:GetParameters",
"ssm:GetParametersByPath"
]
Resource = "arn:aws:ssm:eu-north-1:${data.aws_caller_identity.current.account_id}:parameter/cibello/prod/*"
},
{
Sid = "AllowKMSDecrypt"
Effect = "Allow"
Action = [
"kms:Decrypt",
"kms:GenerateDataKey"
]
Resource = "*"
}
]
})
}
resource "aws_iam_role_policy_attachment" "app_ssm" {
role = aws_iam_role.app.name
policy_arn = "arn:aws:iam::aws:policy/AmazonSSMManagedInstanceCore"
}
resource "aws_iam_instance_profile" "app" {
name = "cibello-prod-app-profile"
role = aws_iam_role.app.name
tags = {
Name = "cibello-prod-app-profile"
}
}
data "aws_caller_identity" "current" {}