assume_role_policy-okta_saml.tf 466 B

12345678910111213141516171819202122
  1. data "aws_iam_policy_document" "okta_saml_assume_role_policy" {
  2. statement {
  3. sid = "AllowAssumeRoleViaOkta"
  4. effect = "Allow"
  5. principals {
  6. type = "Federated"
  7. identifiers = [aws_iam_saml_provider.okta.arn]
  8. }
  9. actions = [
  10. "sts:AssumeRoleWithSAML",
  11. ]
  12. condition {
  13. test = "StringEquals"
  14. variable = "SAML:aud"
  15. values = [
  16. local.saml_signin_page[local.aws_partition]
  17. ]
  18. }
  19. }
  20. }