Are you still defining IAM policies using heredoc syntax (<<EOF ... EOF) or jsonencode()? You can do better! As a result, terraform validate can tell you about typos before you apply them, and you get better auto-complete support from your IDE. Read on to learn how to define IAM policies in Terraform safely.
When looking at Terraform code I still see the following two ways to define IAM policies:
resource "aws_iam_policy" "inline" { |
The second approach looks like this:
resource "aws_iam_policy" "jsonencode" { |
The problem with both approaches: If your policy is malformed, you have to terraform apply before you realize the mistake. Besides that, your IDE’s auto-complete can not help you much when using those approaches.
How can we do better? The following video demonstrates using the data source aws_iam_policy_document. This way, Terraform can validate your IAM policy (at least from a structural perspective), and your IDE can do a much better job of increasing your productivity.
resource "aws_iam_policy" "policydocument" { |
Discover more from Free Exam Prep By IT Professionals | CertificationTest | ExamTopics
Subscribe to get the latest posts sent to your email.
- CloudFormation cfn-init pitfall: Auto scaling and throttling error rate exceeded
- Have you replaced IAM Users with AWS SSO yet?
- Migrating CodePipeline to GitHub Actions to improve performance
- API Gateway Custom Authorization with Lambda, DynamoDB and CloudFormation
- Using DynamoDB Entity Store for cleaner TypeScript code

















