diff --git a/examples/full-cluster-tf-upgrade/1.29/role.tf b/examples/full-cluster-tf-upgrade/1.29/role.tf index df9de09..ffced71 100644 --- a/examples/full-cluster-tf-upgrade/1.29/role.tf +++ b/examples/full-cluster-tf-upgrade/1.29/role.tf @@ -153,12 +153,23 @@ data "aws_iam_policy_document" "allow_sts" { ] } } + ## statement { + ## sid = "AllowSTSAssumeFromSSO" + ## effect = "Allow" + ## actions = ["sts:AssumeRole"] + ## principals { + ## type = "AWS" + ## identifiers = [ + ## format(local.iam_arn, "root"), + ## ] + ## } + ## condition { + ## test = "ArnLike" + ## variable = "aws:PrincipalArn" + ## values = [ + ## format(local.iam_arn, "role/aws-reserved/sso.amazonaws.com/*/AWSReservedSSO_csvd-sa-sc-developer_*"), + ## format(local.iam_arn, "role/aws-reserved/sso.amazonaws.com/AWSReservedSSO_csvd-sa-sc-developer_*"), + ## ] + ## } + ## } } - -# data "aws_iam_policy_document" "cluster-admin_combined" -# source_policy_documents = [ -# data.aws_iam_policy_document.allow_sts.json -# data.aws_iam_policy_document.saml_assume.json, -# ] -# } -#