terraform { required_providers { aws = { source = "hashicorp/aws" version = "5.39.0" } } backend "s3" { encrypt = true } } provider "aws" { default_tags { tags = { Terraform = "true" } } } # s3 bucket - devops resource "aws_s3_bucket" "devops" { bucket = local.devops_s3_bucket_name tags = local.common_tags } resource "aws_s3_bucket_policy" "deny_insecure_communication" { bucket = aws_s3_bucket.devops.id policy = data.aws_iam_policy_document.deny_insecure_communication.json } # s3 bucket - raw-data-ingestion resource "aws_s3_bucket" "raw_data_ingestion" { bucket = local.raw_data_ingestion_s3_bucket_name tags = local.common_tags } resource "aws_s3_bucket_policy" "raw_data_ingestion_policy" { bucket = aws_s3_bucket.raw_data_ingestion.id policy = data.aws_iam_policy_document.raw_data_ingestion_deny_insecure_communication.json } # s3 bucket - mwaa_resources resource "aws_s3_bucket" "mwaa_resources" { bucket = local.mwaa_resources_s3_bucket_name tags = local.common_tags } resource "aws_s3_bucket_policy" "mwaa_resources_policy" { bucket = aws_s3_bucket.mwaa_resources.id policy = data.aws_iam_policy_document.mwaa_resources_deny_insecure_communication.json } # Deny insecure s3 bucket policy data "aws_iam_policy_document" "deny_insecure_communication" { statement { sid = "DenyInsecureCommunications" principals { type = "*" identifiers = ["*"] } condition { test = "Bool" variable = "aws:SecureTransport" values = ["false"] } effect = "Deny" actions = ["s3:*"] resources = [ aws_s3_bucket.devops.arn, "${aws_s3_bucket.devops.arn}/*", ] } } # Deny insecure s3 bucket policy - raw_data_ingestion data "aws_iam_policy_document" "raw_data_ingestion_deny_insecure_communication" { statement { sid = "DenyInsecureCommunications" principals { type = "*" identifiers = ["*"] } condition { test = "Bool" variable = "aws:SecureTransport" values = ["false"] } effect = "Deny" actions = ["s3:*"] resources = [ aws_s3_bucket.raw_data_ingestion.arn, "${aws_s3_bucket.raw_data_ingestion.arn}/*", ] } } # Deny insecure s3 bucket policy - mwaa_resources data "aws_iam_policy_document" "mwaa_resources_deny_insecure_communication" { statement { sid = "DenyInsecureCommunications" principals { type = "*" identifiers = ["*"] } condition { test = "Bool" variable = "aws:SecureTransport" values = ["false"] } effect = "Deny" actions = ["s3:*"] resources = [ aws_s3_bucket.mwaa_resources.arn, "${aws_s3_bucket.mwaa_resources.arn}/*", ] } } # IAM role - snowflake-integration-role resource "aws_iam_role" "snowflake_integration_role" { name = local.snowflake_integration_role_name assume_role_policy = jsonencode({ Version = "2012-10-17" Statement = [ { Action = "sts:AssumeRole" Effect = "Allow" Sid = "" Principal = { AWS = "arn:aws:iam::851725635820:user/3nmi0000-s" } Condition = { StringEquals = { "sts:ExternalId" = var.storage_integration_external_id } } }, ] }) } # Construct IAM Policy for snowflake-integration-role data "aws_iam_policy_document" "snowflake_integration_policy_document" { statement { effect = "Allow" actions = [ "s3:PutObject", "s3:GetObject", "s3:GetObjectVersion", "s3:DeleteObject", "s3:DeleteObjectVersion" ] resources = ["${aws_s3_bucket.raw_data_ingestion.arn}*"] } statement { effect = "Allow" actions = [ "s3:ListBucket", "s3:GetBucketLocation" ] resources = ["${aws_s3_bucket.raw_data_ingestion.arn}"] condition { test = "StringLike" variable = "s3:prefix" values = ["*"] } } } # IAM Policy for snowflake-integration-role resource "aws_iam_policy" "snowflake_integration_policy" { name = local.snowflake_integration_policy_name description = "Client textract permissions" policy = data.aws_iam_policy_document.snowflake_integration_policy_document.json } # Attach IAM Policy to snowflake-integration-role resource "aws_iam_role_policy_attachment" "snowflake_integration_policy_attachment" { role = aws_iam_role.snowflake_integration_role.name policy_arn = aws_iam_policy.snowflake_integration_policy.arn } # IAM role - cross-account-role resource "aws_iam_role" "cross_account_role" { count = var.environment != "dev"? 1 : 0 name = local.cross_account_role_name assume_role_policy = jsonencode({ Version = "2012-10-17" Statement = [ { Action = "sts:AssumeRole" Effect = "Allow" Sid = "" Principal = { AWS = "arn:aws:iam::${var.cross_account_target_account_id}:root" } }, ] }) } # Construct IAM Policy for cross-account-role data "aws_iam_policy_document" "cross_account_policy_document" { statement { effect = "Allow" actions = [ "s3:PutObject", "s3:GetObject", "s3:ListBucket", "s3:PutObjectAcl", "s3:GetObjectVersion" ] resources = [ "${aws_s3_bucket.raw_data_ingestion.arn}", "${aws_s3_bucket.raw_data_ingestion.arn}/*" ] } } # IAM Policy for cross-account-role resource "aws_iam_policy" "cross_account_policy" { count = var.environment != "dev"? 1 : 0 name = local.cross_account_policy_name description = "This role is used for other AWS account to assume inorder to drop files to our data ingestion bucket. At the time of creation, this is being used by CODE DEV to drop all clients list." policy = data.aws_iam_policy_document.cross_account_policy_document.json } # Attach IAM Policy to cross-account-role resource "aws_iam_role_policy_attachment" "cross_account_policy_attachment" { count = var.environment != "dev"? 1 : 0 role = aws_iam_role.cross_account_role[count.index].name policy_arn = aws_iam_policy.cross_account_policy[count.index].arn } # IAM role - mwaa-exec-role resource "aws_iam_role" "mwaa_exec_role" { name = local.mwaa_exec_role_role_name assume_role_policy = jsonencode({ Version = "2012-10-17" Statement = [ { Action = "sts:AssumeRole" Effect = "Allow" Sid = "" Principal = { Service = ["airflow-env.amazonaws.com","airflow.amazonaws.com"] } }, ] }) } # Construct IAM Policy for mwaa-exec-role data "aws_iam_policy_document" "mwaa_exec_policy_document" { statement { effect = "Allow" actions = ["s3:*"] resources = [ "${aws_s3_bucket.raw_data_ingestion.arn}/*" ] } statement { effect = "Allow" actions = ["airflow:CreateCliToken"] resources = [ "arn:aws:airflow:us-east-2:${var.aws_account_id}:environment/doczy-${var.environment}-infra-mwaa" ] } statement { effect = "Allow" actions = ["airflow:PublishMetrics"] resources = [ "arn:aws:airflow:us-east-2:${var.aws_account_id}:environment/doczy-${var.environment}-infra-mwaa" ] } statement { effect = "Deny" actions = ["s3:ListAllMyBuckets"] resources = [ "${aws_s3_bucket.mwaa_resources.arn}", "${aws_s3_bucket.mwaa_resources.arn}/*" ] } statement { effect = "Allow" actions = [ "s3:GetObject*", "s3:GetBucket*", "s3:List*", "s3:PutObject" ] resources = [ "${aws_s3_bucket.mwaa_resources.arn}", "${aws_s3_bucket.mwaa_resources.arn}/*" ] } statement { effect = "Allow" actions = [ "logs:CreateLogStream", "logs:CreateLogGroup", "logs:PutLogEvents", "logs:GetLogEvents", "logs:GetLogRecord", "logs:GetLogGroupFields", "logs:GetQueryResults" ] resources = [ "arn:aws:logs:us-east-2:${var.aws_account_id}:log-group:airflow-doczy-${var.environment}-infra-mwaa-*" ] } statement { effect = "Allow" actions = [ "logs:DescribeLogGroups" ] resources = ["*"] } statement { effect = "Allow" actions = [ "cloudwatch:PutMetricData" ] resources = ["*"] } } # IAM Policy for mwaa-exec-role resource "aws_iam_policy" "mwaa_exec_policy" { name = local.mwaa_exec_policy_name description = "" policy = data.aws_iam_policy_document.mwaa_exec_policy_document.json } # Attach IAM Policy to mwaa-exec-role resource "aws_iam_role_policy_attachment" "mwaa_exec_policy_attachment" { role = aws_iam_role.mwaa_exec_role.name policy_arn = aws_iam_policy.mwaa_exec_policy.arn }