123456789101112131415161718192021222324252627282930313233343536373839 |
- resource "aws_iam_policy" "fcm-lambda-base" {
- name = "fcm-lambda-base"
- path = "/fcm/"
- description = "FCM policy for EbsEncryptionByDefault Enforcement Analysis"
- policy = <<LAMBDABASE
- {
- "Version": "2012-10-17",
- "Statement": [
- {
- "Effect": "Allow",
- "Action": "logs:CreateLogGroup",
- "Resource": "arn:aws:logs:us-east-2:082012130604:log-group:*"
- },
- {
- "Effect": "Allow",
- "Action": [
- "logs:CreateLogStream",
- "logs:PutLogEvents"
- ],
- "Resource": "arn:aws:logs:us-east-2:082012130604:log-group:/aws/lambda/*"
- },
- {
- "Sid": "FCMRequiredAccess",
- "Effect": "Allow",
- "Action": [
- "kms:Decrypt",
- "kms:GenerateDataKey*",
- "sqs:ReceiveMessage",
- "sqs:DeleteMessage",
- "sqs:GetQueueAttributes"
- ],
- "Resource": "*"
- }
- ]
- }
- LAMBDABASE
- }
|