Giter Club home page Giter Club logo

terraform-aws-secret's People

Contributors

dependabot[bot] avatar posquit0 avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar

terraform-aws-secret's Issues

Wrong output during terraform plan

Is there an existing issue for this?

  • I have searched the existing issues

Description of the bug

I am using following resource block:

resource "aws_kms_key_policy" "cmk" {
key_id = data.aws_kms_key.by_alias.id
policy = jsonencode({

"Version": "2012-10-17",
"Statement": [
    {
        "Sid": "SId#1",
        "Effect": "Allow",
        "Principal": {
            "AWS": "arn:aws:iam::123456789:root"
        },
        "Action": "kms:CreateGrant",
        "Resource": "*",
        "Condition": {
            "StringEquals": {
                "kms:CallerAccount": "123456789",
                "kms:GranteePrincipal": "arn:aws:iam::123456789:role/aws-service-role/mgn.amazonaws.com/AWSServiceRoleForApplicationMigrationService"
            },
            "ForAllValues:StringEquals": {
                "kms:GrantOperations": [
                    "CreateGrant",
                    "DescribeKey",
                    "Encrypt",
                    "Decrypt",
                    "GenerateDataKey",
                    "GenerateDataKeyWithoutPlaintext"
                ]
            },
            "Bool": {
                "aws:ViaAWSService": "true"
            }
        }
    },
    {
        "Sid": "Sid#2",
        "Effect": "Allow",
        "Principal": {
            "AWS": [
                "arn:aws:iam::123456789:root",
                "arn:aws:iam::123456789:role/aws-service-role/mgn.amazonaws.com/AWSServiceRoleForApplicationMigrationService"
            ]
        },
        "Action": [
            "kms:ReEncrypt*",
            "kms:GenerateDataKey*"
        ],
        "Resource": "*",
        "Condition": {
            "StringEquals": {
                "kms:CallerAccount": "123456789",
                "kms:ViaService": "ec2.us-east-1.amazonaws.com"
            }
        }
    }
]

}
)
}

terraform plan output

                          + "kms:CallerAccount"    = "123456789"
                          + "kms:GranteePrincipal" = "arn:aws:iam::123456789:role/aws-service-role/mgn.amazonaws.com/AWSServiceRoleForApplicationMigrationService"
                        }
                    }
                  + Effect    = "Allow"
                  + Principal = {
                      + AWS = "arn:aws:iam::123456789:root"
                    }
                  + Resource  = "*"
                  + Sid       = "Sid#2"
                },
              + {
                  + Action    = [
                      + "kms:ReEncrypt*",
                      + "kms:GenerateDataKey*",
                    ]
                  + Condition = {
                      + StringEquals = {
                          + "kms:CallerAccount" = "123456789"
                          + "kms:ViaService"    = "ec2.***.amazonaws.com"
                        }
                    }
                  + Effect    = "Allow"
                  + Principal = {
                      + AWS = [
                          + "arn:aws:iam::123456789:root",
                          + "arn:aws:iam::123456789:role/aws-service-role/mgn.amazonaws.com/AWSServiceRoleForApplicationMigrationService",
                        ]
                    }
                  + Resource  = "*"
                  + Sid       = "Sid#1"
                },
            ]
          + Version   = "2012-10-17"
        }
    )
}

I don't understand why the kms:ViaService = ec2..amazonaws.com in output with three star () rather than exact region name.

Steps To Reproduce

provider "aws" {
region = var.region
}

terraform {
required_providers {
aws = {
source = "hashicorp/aws"
version = "~> 4.0"
}
}

Which version of the app are you using?

1.0.0, 1.1.0, 1.2.0

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.