Skip to content

Commit db55ac7

Browse files
Support AWS partition for SSM resources (#148)
* Support AWS partition for SSM resources * Updated README.md Co-authored-by: actions-bot <[email protected]>
1 parent 7caab4b commit db55ac7

File tree

2 files changed

+4
-4
lines changed

2 files changed

+4
-4
lines changed

README.md

+1-1
Original file line numberDiff line numberDiff line change
@@ -455,7 +455,7 @@ In general, PRs are welcome. We follow the typical "fork-and-pull" Git workflow.
455455

456456
## Copyright
457457

458-
Copyright © 2017-2022 [Cloud Posse, LLC](https://cpco.io/copyright)
458+
Copyright © 2017-2023 [Cloud Posse, LLC](https://cpco.io/copyright)
459459

460460

461461

ssm_patch.tf

+3-3
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11

22
locals {
33
ssm_patch_log_bucket_enabled = local.ssm_enabled && var.ssm_patch_manager_s3_log_bucket != "" && var.ssm_patch_manager_s3_log_bucket != null
4-
ssm_policy_arn = var.ssm_patch_manager_iam_policy_arn == null || var.ssm_patch_manager_iam_policy_arn == "" ? "arn:aws:iam::aws:policy/AmazonSSMManagedInstanceCore" : var.ssm_patch_manager_iam_policy_arn
4+
ssm_policy_arn = var.ssm_patch_manager_iam_policy_arn == null || var.ssm_patch_manager_iam_policy_arn == "" ? "arn:${data.aws_partition.default.partition}:iam::aws:policy/AmazonSSMManagedInstanceCore" : var.ssm_patch_manager_iam_policy_arn
55
ssm_enabled = local.enabled && var.ssm_patch_manager_enabled
66
}
77

@@ -25,8 +25,8 @@ data "aws_iam_policy_document" "ssm_patch_s3_log_policy" {
2525
"s3:GetEncryptionConfiguration",
2626
]
2727
resources = [
28-
"arn:aws:s3:::${var.ssm_patch_manager_s3_log_bucket}/*",
29-
"arn:aws:s3:::${var.ssm_patch_manager_s3_log_bucket}",
28+
"arn:${data.aws_partition.default.partition}:s3:::${var.ssm_patch_manager_s3_log_bucket}/*",
29+
"arn:${data.aws_partition.default.partition}:s3:::${var.ssm_patch_manager_s3_log_bucket}",
3030
]
3131
}
3232
}

0 commit comments

Comments
 (0)