Skip to content

Commit 4f93a44

Browse files
committed
add missing data.tf file for data.aws_iam_policy_document.support_assume_policy
1 parent 2fc6d0e commit 4f93a44

File tree

2 files changed

+13
-0
lines changed

2 files changed

+13
-0
lines changed

modules/baseline_iam/data.tf

+12
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
data "aws_caller_identity" "current" {}
2+
3+
data "aws_iam_policy_document" "support_assume_policy" {
4+
statement {
5+
sid = "supportpolicy"
6+
actions = ["sts:AssumeRole"]
7+
principals {
8+
type = "AWS"
9+
identifiers = [data.aws_caller_identity.current.id]
10+
}
11+
}
12+
}

modules/baseline_iam/main.tf

+1
Original file line numberDiff line numberDiff line change
@@ -20,6 +20,7 @@ resource "aws_iam_account_password_policy" "default" {
2020
max_password_age = var.max_password_age
2121
}
2222

23+
# Moved to data.tf file
2324
# --------------------------------------------------------------------------------------------------
2425
# Support Role - https://us-east-1.console.aws.amazon.com/securityhub/home?region=us-east-1#/standards/cis-aws-foundations-benchmark-1.4.0/1.17
2526
# https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-cis-controls.html#cis-1.20-remediation

0 commit comments

Comments
 (0)