Skip to content

Commit 89d011e

Browse files
authored
fix: Add missing condition role_session_name when assuming a role (#418)
1 parent 2ce2fd1 commit 89d011e

File tree

1 file changed

+9
-0
lines changed

1 file changed

+9
-0
lines changed

modules/iam-assumable-role/main.tf

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -55,6 +55,15 @@ data "aws_iam_policy_document" "assume_role" {
5555
values = local.role_sts_externalid
5656
}
5757
}
58+
59+
dynamic "condition" {
60+
for_each = var.role_requires_session_name ? [1] : []
61+
content {
62+
test = "StringEquals"
63+
variable = "sts:RoleSessionName"
64+
values = var.role_session_name
65+
}
66+
}
5867
}
5968
}
6069

0 commit comments

Comments
 (0)