Skip to content

Commit

Permalink
update
Browse files Browse the repository at this point in the history
  • Loading branch information
badra001 committed Sep 6, 2023
1 parent 2f8a995 commit c04d8e1
Showing 1 changed file with 3 additions and 1 deletion.
4 changes: 3 additions & 1 deletion cloudtrail/cloudtrail.tf
Original file line number Diff line number Diff line change
Expand Up @@ -21,13 +21,14 @@ resource "aws_cloudtrail" "this" {
}

resource "aws_iam_role" "cloudtrail" {
count = var.enable_cloudwatch_logs ? 1 : 0
name = local.role_name
assume_role_policy = data.aws_iam_policy_document.cloudtrail_assume.json
description = "AWS CloudTrail Role for ${local.name}"
force_detach_policies = false
max_session_duration = 3600
# add deny billing
managed_policy_arns = [aws_iam_policy.cloudtrail_policy.arn]
managed_policy_arns = try([aws_iam_policy.cloudtrail_policy[0].arn], null)
path = "/"

tags = merge(
Expand All @@ -50,6 +51,7 @@ data "aws_iam_policy_document" "cloudtrail_assume" {
}

resource "aws_iam_policy" "cloudtrail_policy" {
count = var.enable_cloudwatch_logs ? 1 : 0
name = local.policy_name
policy = data.aws_iam_policy_document.cloudtrail_cloudwatch.json
}
Expand Down

0 comments on commit c04d8e1

Please sign in to comment.