Skip to content

Commit 12f5e13

Browse files
committed
NRL-1187 update kms reosurces
1 parent 8152f64 commit 12f5e13

File tree

2 files changed

+8
-3
lines changed

2 files changed

+8
-3
lines changed

terraform/infrastructure/modules/firehose/iam_firehose.tf

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -44,9 +44,7 @@ data "aws_iam_policy_document" "firehose" {
4444
"kms:Decrypt",
4545
]
4646

47-
resources = [
48-
aws_kms_key.firehose.arn,
49-
]
47+
resources = local.iam_kms_resources
5048
}
5149
statement {
5250
actions = [

terraform/infrastructure/modules/firehose/locals.tf

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -40,4 +40,11 @@ locals {
4040
firehose_reporting_stream_arn = var.reporting_infra_toggle ? aws_kinesis_firehose_delivery_stream.reporting_stream[0].arn : null
4141
}
4242

43+
iam_kms_resources = var.reporting_infra_toggle ? [
44+
aws_kms_key.firehose.arn,
45+
aws_kms_key.glue.arn,
46+
] : [
47+
aws_kms_key.firehose.arn,
48+
]
49+
4350
}

0 commit comments

Comments
 (0)