Skip to content

Commit 710dfeb

Browse files
committed
String interpolation for account id
1 parent 9630051 commit 710dfeb

File tree

5 files changed

+16
-16
lines changed

5 files changed

+16
-16
lines changed

infra_old/endpoints.tf

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -243,8 +243,8 @@ resource "aws_vpc_endpoint" "kms_endpoint" {
243243
"kms:GenerateDataKey*"
244244
],
245245
Resource = [
246-
"arn:aws:kms:eu-west-2:084828561157:key/4e643221-4cb8-49c5-9a78-ced991ff52ae",
247-
"arn:aws:kms:eu-west-2:084828561157:key/d7b3c213-3c05-4caf-bb95-fdb2a6e533b1"
246+
"arn:aws:kms:eu-west-2:${var.imms_account_id}:key/4e643221-4cb8-49c5-9a78-ced991ff52ae",
247+
"arn:aws:kms:eu-west-2:${var.imms_account_id}:key/d7b3c213-3c05-4caf-bb95-fdb2a6e533b1"
248248
]
249249
}
250250
]

infra_old/kms_dynamo.tf

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@ resource "aws_kms_key" "dynamodb_encryption" {
1010
{
1111
"Sid": "Allow administration of the key",
1212
"Effect": "Allow",
13-
"Principal": { "AWS": "arn:aws:iam::084828561157:root" },
13+
"Principal": { "AWS": "arn:aws:iam::${var.imms_account_id}:root" },
1414
"Action": [
1515
"kms:Create*",
1616
"kms:Describe*",
@@ -33,7 +33,7 @@ resource "aws_kms_key" "dynamodb_encryption" {
3333
{
3434
"Sid": "KMS KeyUser access",
3535
"Effect": "Allow",
36-
"Principal": { "AWS": ["arn:aws:iam::084828561157:role/auto-ops"] },
36+
"Principal": { "AWS": ["arn:aws:iam::${var.imms_account_id}:role/auto-ops"] },
3737
"Action": [
3838
"kms:Encrypt",
3939
"kms:GenerateDataKey*"
@@ -43,7 +43,7 @@ resource "aws_kms_key" "dynamodb_encryption" {
4343
{
4444
"Sid": "KMS KeyUser access for DevOps",
4545
"Effect": "Allow",
46-
"Principal": { "AWS": ["arn:aws:iam::084828561157:role/DevOps"] },
46+
"Principal": { "AWS": ["arn:aws:iam::${var.imms_account_id}:role/DevOps"] },
4747
"Action": [
4848
"kms:Encrypt",
4949
"kms:GenerateDataKey*"
@@ -53,7 +53,7 @@ resource "aws_kms_key" "dynamodb_encryption" {
5353
{
5454
"Sid": "KMS KeyUser access for Admin",
5555
"Effect": "Allow",
56-
"Principal": { "AWS": ["arn:aws:iam::084828561157:role/aws-reserved/sso.amazonaws.com/eu-west-2/AWSReservedSSO_PREPROD-IMMS-Admin_acce656dcacf6f4c"] },
56+
"Principal": { "AWS": ["arn:aws:iam::${var.imms_account_id}:role/aws-reserved/sso.amazonaws.com/eu-west-2/AWSReservedSSO_PREPROD-IMMS-Admin_acce656dcacf6f4c"] },
5757
"Action": [
5858
"kms:Encrypt",
5959
"kms:GenerateDataKey*"

infra_old/kms_kinesis.tf

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@ resource "aws_kms_key" "kinesis_stream_encryption" {
1010
{
1111
"Sid": "Allow administration of the key",
1212
"Effect": "Allow",
13-
"Principal": { "AWS": "arn:aws:iam::084828561157:root" },
13+
"Principal": { "AWS": "arn:aws:iam::${var.imms_account_id}:root" },
1414
"Action": [
1515
"kms:Create*",
1616
"kms:Describe*",
@@ -33,7 +33,7 @@ resource "aws_kms_key" "kinesis_stream_encryption" {
3333
{
3434
"Sid": "KMS KeyUser access",
3535
"Effect": "Allow",
36-
"Principal": {"AWS": ["arn:aws:iam::084828561157:role/auto-ops"]},
36+
"Principal": {"AWS": ["arn:aws:iam::${var.imms_account_id}:role/auto-ops"]},
3737
"Action": [
3838
"kms:Encrypt",
3939
"kms:GenerateDataKey*"
@@ -43,7 +43,7 @@ resource "aws_kms_key" "kinesis_stream_encryption" {
4343
{
4444
"Sid": "KMS KeyUser access for Devops",
4545
"Effect": "Allow",
46-
"Principal": {"AWS": ["arn:aws:iam::084828561157:role/DevOps"]},
46+
"Principal": {"AWS": ["arn:aws:iam::${var.imms_account_id}:role/DevOps"]},
4747
"Action": [
4848
"kms:Encrypt",
4949
"kms:GenerateDataKey*"
@@ -53,7 +53,7 @@ resource "aws_kms_key" "kinesis_stream_encryption" {
5353
{
5454
"Sid": "KMS KeyUser access for Admin",
5555
"Effect": "Allow",
56-
"Principal": { "AWS": ["arn:aws:iam::084828561157:role/aws-reserved/sso.amazonaws.com/eu-west-2/AWSReservedSSO_PREPROD-IMMS-Admin_acce656dcacf6f4c"] },
56+
"Principal": { "AWS": ["arn:aws:iam::${var.imms_account_id}:role/aws-reserved/sso.amazonaws.com/eu-west-2/AWSReservedSSO_PREPROD-IMMS-Admin_acce656dcacf6f4c"] },
5757
"Action": [
5858
"kms:Encrypt",
5959
"kms:GenerateDataKey*"

infra_old/kms_lambda.tf

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@ resource "aws_kms_key" "lambda_env_encryption" {
1010
{
1111
"Sid": "Allow administration of the key",
1212
"Effect": "Allow",
13-
"Principal": { "AWS": "arn:aws:iam::084828561157:root" },
13+
"Principal": { "AWS": "arn:aws:iam::${var.imms_account_id}:root" },
1414
"Action": [
1515
"kms:Create*",
1616
"kms:Describe*",
@@ -33,7 +33,7 @@ resource "aws_kms_key" "lambda_env_encryption" {
3333
{
3434
"Sid": "KMS KeyUser access",
3535
"Effect": "Allow",
36-
"Principal": {"AWS": ["arn:aws:iam::084828561157:role/auto-ops"]},
36+
"Principal": {"AWS": ["arn:aws:iam::${var.imms_account_id}:role/auto-ops"]},
3737
"Action": [
3838
"kms:Encrypt",
3939
"kms:GenerateDataKey*"
@@ -43,7 +43,7 @@ resource "aws_kms_key" "lambda_env_encryption" {
4343
{
4444
"Sid": "KMS KeyUser access for Devops",
4545
"Effect": "Allow",
46-
"Principal": {"AWS": ["arn:aws:iam::084828561157:role/DevOps"]},
46+
"Principal": {"AWS": ["arn:aws:iam::${var.imms_account_id}:role/DevOps"]},
4747
"Action": [
4848
"kms:Encrypt",
4949
"kms:GenerateDataKey*"
@@ -53,7 +53,7 @@ resource "aws_kms_key" "lambda_env_encryption" {
5353
{
5454
"Sid": "KMS KeyUser access for Admin",
5555
"Effect": "Allow",
56-
"Principal": { "AWS": ["arn:aws:iam::084828561157:role/aws-reserved/sso.amazonaws.com/eu-west-2/AWSReservedSSO_PREPROD-IMMS-Admin_acce656dcacf6f4c"] },
56+
"Principal": { "AWS": ["arn:aws:iam::${var.imms_account_id}:role/aws-reserved/sso.amazonaws.com/eu-west-2/AWSReservedSSO_PREPROD-IMMS-Admin_acce656dcacf6f4c"] },
5757
"Action": [
5858
"kms:Encrypt",
5959
"kms:GenerateDataKey*"

infra_old/kms_s3.tf

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ resource "aws_kms_key" "s3_shared_key" {
99
{
1010
"Sid": "Allow administration of the key",
1111
"Effect": "Allow",
12-
"Principal": { "AWS": "arn:aws:iam::084828561157:root" },
12+
"Principal": { "AWS": "arn:aws:iam::${var.imms_account_id}:root" },
1313
"Action": [
1414
"kms:Create*",
1515
"kms:Describe*",
@@ -45,7 +45,7 @@ resource "aws_kms_key" "s3_shared_key" {
4545
{
4646
"Sid": "KMS KeyUser access for Admin",
4747
"Effect": "Allow",
48-
"Principal": { "AWS": ["arn:aws:iam::084828561157:role/aws-reserved/sso.amazonaws.com/eu-west-2/AWSReservedSSO_PREPROD-IMMS-Admin_acce656dcacf6f4c"] },
48+
"Principal": { "AWS": ["arn:aws:iam::${var.imms_account_id}:role/aws-reserved/sso.amazonaws.com/eu-west-2/AWSReservedSSO_PREPROD-IMMS-Admin_acce656dcacf6f4c"] },
4949
"Action": [
5050
"kms:Encrypt",
5151
"kms:GenerateDataKey*"

0 commit comments

Comments
 (0)