Files
dsk-iac/terraform/iam/policies/modules/dsk-lambda-execute.tf
2024-01-30 11:12:54 +09:00

35 lines
695 B
HCL

resource "aws_iam_policy" "policy" {
name = "DSK_LambdaExecute"
path = "/"
policy = jsonencode({
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"logs:CreateLogGroup",
"logs:CreateLogStream",
"logs:PutLogEvents"
],
"Resource": "arn:aws:logs:*:*:*"
},
{
"Effect": "Allow",
"Action": [
"ec2:Start*",
"ec2:Stop*"
],
"Resource": "*"
},
{
"Sid": "Invoke",
"Effect": "Allow",
"Action": [
"lambda:InvokeFunction"
],
"Resource": "*"
}
]
})
}