resource "aws_iam_role" "ec2_role" { name = local.ec2_role_name assume_role_policy = jsonencode({ Version = "2012-10-17" Statement = [ { Action = "sts:AssumeRole" Effect = "Allow" Sid = "" Principal = { Service = "ec2.amazonaws.com" } } ] }) } # Attached all policies created here to the ec2 role # Combine all policy documents into a single document data "aws_iam_policy_document" "combined_policy_document" { statement { sid = "S3Permissions" effect = "Allow" actions = [ "s3:ListBucket", "s3:ListAllMyBuckets", "s3:GetObject", "s3:PutObject", "s3:GetObjectTagging", "s3:PutObjectTagging" ] resources = ["*"] } statement { sid = "SecretsManagerOperations" effect = "Allow" actions = [ "secretsmanager:GetResourcePolicy", "secretsmanager:GetSecretValue", "secretsmanager:DescribeSecret", "secretsmanager:PutSecretValue", "secretsmanager:ListSecretVersionIds", "secretsmanager:GetRandomPassword", "secretsmanager:ListSecrets", "secretsmanager:BatchGetSecretValue" ] # Need to restrict this to ARN of the secrets later resources = ["*"] } statement { sid = "SSMUpdateInstanceInformation" effect = "Allow" actions = ["ssm:UpdateInstanceInformation"] # Refernce the instance by its instance id resources = ["${aws_instance.streamlit_server.arn}"] } statement { sid = "BedrockPermissions" effect = "Allow" actions = [ "bedrock:InvokeAgent", "bedrock:InvokeModel", "bedrock:InvokeModelWithResponseStream", "bedrock:ListFoundationModels" ] resources = ["*"] } statement { sid = "APIGatewayInvokeFullAccess" effect = "Allow" actions = ["execute-api:Invoke", "execute-api:ManageConnections"] resources = ["arn:aws:execute-api:*:*:*"] } statement { sid = "AmazonSSMManagedInstanceCore" effect = "Allow" actions = [ "ssm:DescribeAssociation", "ssm:GetDeployablePatchSnapshotForInstance", "ssm:GetDocument", "ssm:DescribeDocument", "ssm:GetManifest", "ssm:GetParameter", "ssm:GetParameters", "ssm:ListAssociations", "ssm:ListInstanceAssociations", "ssm:PutInventory", "ssm:PutComplianceItems", "ssm:PutConfigurePackageResult", "ssm:UpdateAssociationStatus", "ssm:UpdateInstanceAssociationStatus", "ssm:UpdateInstanceInformation", "ssmmessages:CreateControlChannel", "ssmmessages:CreateDataChannel", "ssmmessages:OpenControlChannel", "ssmmessages:OpenDataChannel", "ec2messages:AcknowledgeMessage", "ec2messages:DeleteMessage", "ec2messages:FailMessage", "ec2messages:GetEndpoint", "ec2messages:GetMessages", "ec2messages:SendReply" ] resources = ["*"] } # statement for cli policy statement { effect = "Allow" actions = ["airflow:CreateCliToken"] resources = ["*"] } } # Attached the combined document to the ec2 role resource "aws_iam_policy" "combined_policy" { name = "${local.ec2_role_name}-combined-policy" description = "Combined policy for Bedrock, Secrets Manager, SSM, and S3" policy = data.aws_iam_policy_document.combined_policy_document.json } resource "aws_iam_role_policy_attachment" "combined_policy_attachment" { role = aws_iam_role.ec2_role.name policy_arn = aws_iam_policy.combined_policy.arn } output "ec2_role_name" { value = local.ec2_role_name }