【发布时间】:2020-11-11 17:57:34
【问题描述】:
我正在尝试创建多个 IAM 组,然后使用 terraform (v0.12) 将多个 AWS 策略附加到每个组。
目前我有:
resource "aws_iam_group" "group1" {
name = "group1"
path = "/"
}
resource "aws_iam_group" "group2" {
name = "group2"
path = "/"
}
resource "aws_iam_group_policy_attachment" "group1" {
for_each = toset([
"arn:aws:iam::aws:policy/AmazonS3FullAccess",
"arn:aws:iam::aws:policy/AmazonCodeGuruProfilerFullAccess",
"arn:aws:iam::aws:policy/job-function/Billing"
])
group = aws_iam_group.group1.name
policy_arn = each.value
}
有没有更简洁的方法可以做到这一点,这样我就不会使用那么多重复的代码。
【问题讨论】:
标签: amazon-web-services terraform amazon-iam