assume_role_policy-non_saml.tf 370 B

12345678910111213141516
  1. data "aws_iam_policy_document" "non_saml_assume_role_policy" {
  2. statement {
  3. sid = "AllowAssumeRoleFromReadOnly"
  4. effect = "Allow"
  5. principals {
  6. type = "AWS"
  7. identifiers = [
  8. "arn:${local.aws_partition}:iam::${local.aws_account}:role/user/mdr_engineer_readonly"
  9. ]
  10. }
  11. actions = [
  12. "sts:AssumeRole",
  13. ]
  14. }
  15. }