role-mdr_iam_admin.tf 687 B

12345678910111213141516171819
  1. module "role-mdr_iam_admin" {
  2. source = "./modules/saml_linked_role"
  3. name = "mdr_iam_admin"
  4. account_friendly_name = aws_iam_account_alias.alias.account_alias
  5. path = "/user/"
  6. assume_role_policy = local.assume_role_policy
  7. okta_app_id = data.okta_app.awsapp.id
  8. }
  9. resource "aws_iam_role_policy_attachment" "mdr_iam_admin_IAMFullAccess" {
  10. role = module.role-mdr_iam_admin.name
  11. policy_arn = "arn:${local.aws_partition}:iam::aws:policy/IAMFullAccess"
  12. }
  13. resource "aws_iam_role_policy_attachment" "mdr_iam_admin-iam_admin_kms" {
  14. role = module.role-mdr_iam_admin.name
  15. policy_arn = aws_iam_policy.iam_admin_kms.arn
  16. }