Files
doczyai-pipelines/streamlit-server/iam.tf
T
2024-06-06 17:09:04 +02:00

137 lines
3.9 KiB
Terraform

resource "aws_iam_role" "ec2_role" {
name = local.ec2_role_name
assume_role_policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = "sts:AssumeRole"
Effect = "Allow"
Sid = ""
Principal = {
Service = "ec2.amazonaws.com"
}
}
]
})
}
# Attached all policies created here to the ec2 role
# Combine all policy documents into a single document
data "aws_iam_policy_document" "combined_policy_document" {
statement {
sid = "S3Permissions"
effect = "Allow"
actions = [
"s3:ListBucket",
"s3:ListAllMyBuckets",
"s3:GetObject",
"s3:PutObject",
"s3:GetObjectTagging",
"s3:PutObjectTagging"
]
resources = ["*"]
}
statement {
sid = "SecretsManagerOperations"
effect = "Allow"
actions = [
"secretsmanager:GetResourcePolicy",
"secretsmanager:GetSecretValue",
"secretsmanager:DescribeSecret",
"secretsmanager:PutSecretValue",
"secretsmanager:ListSecretVersionIds",
"secretsmanager:GetRandomPassword",
"secretsmanager:ListSecrets",
"secretsmanager:BatchGetSecretValue"
]
# Need to restrict this to ARN of the secrets later
resources = ["*"]
}
statement {
sid = "SSMUpdateInstanceInformation"
effect = "Allow"
actions = ["ssm:UpdateInstanceInformation"]
# Refernce the instance by its instance id
resources = ["${aws_instance.streamlit_server.arn}"]
}
statement {
sid = "BedrockPermissions"
effect = "Allow"
actions = [
"bedrock:InvokeAgent",
"bedrock:InvokeModel",
"bedrock:InvokeModelWithResponseStream",
"bedrock:ListFoundationModels"
]
resources = ["*"]
}
statement {
sid = "APIGatewayInvokeFullAccess"
effect = "Allow"
actions = ["execute-api:Invoke",
"execute-api:ManageConnections"]
resources = ["arn:aws:execute-api:*:*:*"]
}
statement {
sid = "AmazonSSMManagedInstanceCore"
effect = "Allow"
actions = [
"ssm:DescribeAssociation",
"ssm:GetDeployablePatchSnapshotForInstance",
"ssm:GetDocument",
"ssm:DescribeDocument",
"ssm:GetManifest",
"ssm:GetParameter",
"ssm:GetParameters",
"ssm:ListAssociations",
"ssm:ListInstanceAssociations",
"ssm:PutInventory",
"ssm:PutComplianceItems",
"ssm:PutConfigurePackageResult",
"ssm:UpdateAssociationStatus",
"ssm:UpdateInstanceAssociationStatus",
"ssm:UpdateInstanceInformation",
"ssmmessages:CreateControlChannel",
"ssmmessages:CreateDataChannel",
"ssmmessages:OpenControlChannel",
"ssmmessages:OpenDataChannel",
"ec2messages:AcknowledgeMessage",
"ec2messages:DeleteMessage",
"ec2messages:FailMessage",
"ec2messages:GetEndpoint",
"ec2messages:GetMessages",
"ec2messages:SendReply"
]
resources = ["*"]
}
# statement for cli policy
statement {
effect = "Allow"
actions = ["airflow:CreateCliToken"]
resources = ["*"]
}
}
# Attached the combined document to the ec2 role
resource "aws_iam_policy" "combined_policy" {
name = "${local.ec2_role_name}-combined-policy"
description = "Combined policy for Bedrock, Secrets Manager, SSM, and S3"
policy = data.aws_iam_policy_document.combined_policy_document.json
}
resource "aws_iam_role_policy_attachment" "combined_policy_attachment" {
role = aws_iam_role.ec2_role.name
policy_arn = aws_iam_policy.combined_policy.arn
}
output "ec2_role_name" {
value = local.ec2_role_name
}