Skip to content

Commit a82560a

Browse files
author
Sanja Kosier
committed
remove depricated inline policy; use new resource instead
1 parent 5606c28 commit a82560a

File tree

1 file changed

+7
-5
lines changed
  • modules/integrations/cloud-logs

1 file changed

+7
-5
lines changed

modules/integrations/cloud-logs/main.tf

Lines changed: 7 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -43,12 +43,14 @@ resource "random_id" "suffix" {
4343
resource "aws_iam_role" "cloudlogs_s3_access" {
4444
name = local.role_name
4545
tags = var.tags
46-
4746
assume_role_policy = data.aws_iam_policy_document.assume_cloudlogs_s3_access_role.json
48-
inline_policy {
49-
name = "cloudlogs_s3_access_policy"
50-
policy = data.aws_iam_policy_document.cloudlogs_s3_access.json
51-
}
47+
}
48+
49+
// AWS IAM Role Policy that will be used by CloudIngestion to access the CloudTrail-associated s3 bucket
50+
resource "aws_iam_role_policy" "cloudlogs_s3_access_policy" {
51+
name = "cloudlogs_s3_access_policy"
52+
role = aws_iam_role.cloudlogs_s3_access.name
53+
policy = data.aws_iam_policy_document.cloudlogs_s3_access.json
5254
}
5355

5456
# IAM Policy Document used for the assume role policy

0 commit comments

Comments
 (0)