{"id":15156442,"url":"https://github.com/geekcell/terraform-aws-iam-policy","last_synced_at":"2026-01-21T12:02:00.124Z","repository":{"id":145007790,"uuid":"588079359","full_name":"geekcell/terraform-aws-iam-policy","owner":"geekcell","description":"Terraform module to provision an AWS IAM Policy.","archived":false,"fork":false,"pushed_at":"2024-04-04T10:26:08.000Z","size":78,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":3,"default_branch":"main","last_synced_at":"2025-10-01T22:56:49.144Z","etag":null,"topics":["aws","iam","iam-policy","terraform","terraform-module"],"latest_commit_sha":null,"homepage":"https://www.geekcell.io","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/geekcell.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2023-01-12T09:23:41.000Z","updated_at":"2023-05-16T13:08:03.000Z","dependencies_parsed_at":"2024-04-04T11:45:14.417Z","dependency_job_id":null,"html_url":"https://github.com/geekcell/terraform-aws-iam-policy","commit_stats":{"total_commits":4,"total_committers":4,"mean_commits":1.0,"dds":0.75,"last_synced_commit":"a0e7328f9eb16fabf17cb368b23f6f3657aa682c"},"previous_names":[],"tags_count":5,"template":false,"template_full_name":"geekcell/terraform-aws-module-template","purl":"pkg:github/geekcell/terraform-aws-iam-policy","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/geekcell%2Fterraform-aws-iam-policy","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/geekcell%2Fterraform-aws-iam-policy/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/geekcell%2Fterraform-aws-iam-policy/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/geekcell%2Fterraform-aws-iam-policy/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/geekcell","download_url":"https://codeload.github.com/geekcell/terraform-aws-iam-policy/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/geekcell%2Fterraform-aws-iam-policy/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28632781,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-01-21T04:47:28.174Z","status":"ssl_error","status_checked_at":"2026-01-21T04:47:22.943Z","response_time":86,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.5:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["aws","iam","iam-policy","terraform","terraform-module"],"created_at":"2024-09-26T19:21:36.537Z","updated_at":"2026-01-21T12:02:00.108Z","avatar_url":"https://github.com/geekcell.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003c!-- BEGIN_TF_DOCS --\u003e\n[![Geek Cell GmbH](https://raw.githubusercontent.com/geekcell/.github/main/geekcell-github-banner.png)](https://www.geekcell.io/)\n\n### Code Quality\n[![License](https://img.shields.io/github/license/geekcell/terraform-aws-iam-policy)](https://github.com/geekcell/terraform-aws-iam-policy/blob/master/LICENSE)\n[![GitHub release (latest tag)](https://img.shields.io/github/v/release/geekcell/terraform-aws-iam-policy?logo=github\u0026sort=semver)](https://github.com/geekcell/terraform-aws-iam-policy/releases)\n[![Release](https://github.com/geekcell/terraform-aws-iam-policy/actions/workflows/release.yaml/badge.svg)](https://github.com/geekcell/terraform-aws-iam-policy/actions/workflows/release.yaml)\n[![Validate](https://github.com/geekcell/terraform-aws-iam-policy/actions/workflows/validate.yaml/badge.svg)](https://github.com/geekcell/terraform-aws-iam-policy/actions/workflows/validate.yaml)\n[![Lint](https://github.com/geekcell/terraform-aws-iam-policy/actions/workflows/linter.yaml/badge.svg)](https://github.com/geekcell/terraform-aws-iam-policy/actions/workflows/linter.yaml)\n[![Test](https://github.com/geekcell/terraform-aws-iam-policy/actions/workflows/test.yaml/badge.svg)](https://github.com/geekcell/terraform-aws-iam-policy/actions/workflows/test.yaml)\n\n### Security\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-iam-policy/general)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-iam-policy\u0026benchmark=INFRASTRUCTURE+SECURITY)\n\n#### Cloud\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-iam-policy/cis_aws)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-iam-policy\u0026benchmark=CIS+AWS+V1.2)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-iam-policy/cis_aws_13)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-iam-policy\u0026benchmark=CIS+AWS+V1.3)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-iam-policy/cis_azure)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-iam-policy\u0026benchmark=CIS+AZURE+V1.1)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-iam-policy/cis_azure_13)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-iam-policy\u0026benchmark=CIS+AZURE+V1.3)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-iam-policy/cis_gcp)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-iam-policy\u0026benchmark=CIS+GCP+V1.1)\n\n##### Container\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-iam-policy/cis_kubernetes_16)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-iam-policy\u0026benchmark=CIS+KUBERNETES+V1.6)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-iam-policy/cis_eks_11)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-iam-policy\u0026benchmark=CIS+EKS+V1.1)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-iam-policy/cis_gke_11)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-iam-policy\u0026benchmark=CIS+GKE+V1.1)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-iam-policy/cis_kubernetes)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-iam-policy\u0026benchmark=CIS+KUBERNETES+V1.5)\n\n#### Data protection\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-iam-policy/soc2)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-iam-policy\u0026benchmark=SOC2)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-iam-policy/pci)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-iam-policy\u0026benchmark=PCI-DSS+V3.2)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-iam-policy/pci_dss_v321)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-iam-policy\u0026benchmark=PCI-DSS+V3.2.1)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-iam-policy/iso)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-iam-policy\u0026benchmark=ISO27001)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-iam-policy/nist)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-iam-policy\u0026benchmark=NIST-800-53)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-iam-policy/hipaa)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-iam-policy\u0026benchmark=HIPAA)\n[![Infrastructure Tests](https://www.bridgecrew.cloud/badges/github/geekcell/terraform-aws-iam-policy/fedramp_moderate)](https://www.bridgecrew.cloud/link/badge?vcs=github\u0026fullRepo=geekcell%2Fterraform-aws-iam-policy\u0026benchmark=FEDRAMP+%28MODERATE%29)\n\n# Terraform AWS IAM Policy\n\nIntroducing the AWS IAM Policy Collection Terraform Module, a comprehensive solution for managing your AWS Identity\nand Access Management (IAM) policies. This module has been carefully crafted to include the most commonly used\npolicies in our setups, making it easier for you to manage and secure your AWS resources.\n\nOur team of experts has worked with AWS IAM policies for years and has a deep understanding of the best practices\nand configurations. By using this Terraform module, you can be sure that your policies are created and managed in\na secure, efficient, and scalable manner.\n\nThis module offers a one-stop-shop for all your IAM policy needs, saving you time and effort in the process. Whether\nyou're looking to grant access to specific AWS services or to limit the actions that can be performed on your\nresources, this module has you covered.\n\nSo, if you're looking for a convenient and reliable solution for managing your IAM policies, look no further than\nthe AWS IAM Policy Collection Terraform Module. Give it a try and see the difference it can make in your AWS setup!\n\n## Inputs\n\n| Name | Description | Type | Default | Required |\n|------|-------------|------|---------|:--------:|\n| \u003ca name=\"input_create_policy\"\u003e\u003c/a\u003e [create\\_policy](#input\\_create\\_policy) | Whether to create the actual policy resource or to only render it. | `bool` | `true` | no |\n| \u003ca name=\"input_description\"\u003e\u003c/a\u003e [description](#input\\_description) | Description of the Security Group. | `string` | `null` | no |\n| \u003ca name=\"input_name\"\u003e\u003c/a\u003e [name](#input\\_name) | Name of the policy. | `string` | n/a | yes |\n| \u003ca name=\"input_path\"\u003e\u003c/a\u003e [path](#input\\_path) | Path in which to create the policy. | `string` | `\"/\"` | no |\n| \u003ca name=\"input_policy_id\"\u003e\u003c/a\u003e [policy\\_id](#input\\_policy\\_id) | ID for the policy document. | `string` | `null` | no |\n| \u003ca name=\"input_statements\"\u003e\u003c/a\u003e [statements](#input\\_statements) | A map of principals which can assume the role. | \u003cpre\u003elist(object({\u003cbr\u003e    sid    = optional(string)\u003cbr\u003e    effect = optional(string, \"Allow\")\u003cbr\u003e\u003cbr\u003e    actions     = optional(list(string))\u003cbr\u003e    not_actions = optional(list(string))\u003cbr\u003e\u003cbr\u003e    resources     = optional(list(string))\u003cbr\u003e    not_resources = optional(list(string))\u003cbr\u003e\u003cbr\u003e    conditions = optional(list(object({\u003cbr\u003e      test     = string\u003cbr\u003e      variable = string\u003cbr\u003e      values   = list(string)\u003cbr\u003e    })))\u003cbr\u003e\u003cbr\u003e    principals = optional(list(object({\u003cbr\u003e      type        = string\u003cbr\u003e      identifiers = list(string)\u003cbr\u003e    })))\u003cbr\u003e\u003cbr\u003e    not_principals = optional(list(object({\u003cbr\u003e      type        = string\u003cbr\u003e      identifiers = list(string)\u003cbr\u003e    })))\u003cbr\u003e  }))\u003c/pre\u003e | `[]` | no |\n| \u003ca name=\"input_tags\"\u003e\u003c/a\u003e [tags](#input\\_tags) | Tags to add to the Security Group. | `map(any)` | `{}` | no |\n| \u003ca name=\"input_templates\"\u003e\u003c/a\u003e [templates](#input\\_templates) | A list of templates. Multiple templates will be combined into a single policy. | \u003cpre\u003elist(object({\u003cbr\u003e    name = string\u003cbr\u003e    vars = optional(map(any))\u003cbr\u003e  }))\u003c/pre\u003e | `[]` | no |\n| \u003ca name=\"input_use_name_prefix\"\u003e\u003c/a\u003e [use\\_name\\_prefix](#input\\_use\\_name\\_prefix) | Use the `name` attribute as prefix for the role name. | `bool` | `true` | no |\n\n## Outputs\n\n| Name | Description |\n|------|-------------|\n| \u003ca name=\"output_arn\"\u003e\u003c/a\u003e [arn](#output\\_arn) | ARN of the IAM policy |\n| \u003ca name=\"output_id\"\u003e\u003c/a\u003e [id](#output\\_id) | ID of the IAM policy |\n| \u003ca name=\"output_json\"\u003e\u003c/a\u003e [json](#output\\_json) | Rendered JSON of the policy. |\n| \u003ca name=\"output_name\"\u003e\u003c/a\u003e [name](#output\\_name) | Name of the IAM policy |\n\n## Providers\n\n| Name | Version |\n|------|---------|\n| \u003ca name=\"provider_aws\"\u003e\u003c/a\u003e [aws](#provider\\_aws) | \u003e= 4.36 |\n\n## Resources\n\n- resource.aws_iam_policy.main (main.tf#101)\n- data source.aws_caller_identity.current (main.tf#40)\n- data source.aws_iam_policy_document.combined (main.tf#93)\n- data source.aws_iam_policy_document.statement (main.tf#48)\n- data source.aws_iam_policy_document.template (main.tf#44)\n- data source.aws_region.current (main.tf#36)\n\n# Examples\n### Statements\n```hcl\nmodule \"s3_policy\" {\n  source = \"../../\"\n\n  name = var.name\n  statements = [\n    {\n      effect = \"Allow\"\n      actions = [\n        \"s3:GetObject\",\n        \"s3:PutObject\",\n        \"s3:PutObjectAcl\",\n        \"s3:ListBucket\",\n        \"s3:DeleteObject\"\n      ]\n      resources = [\n        \"arn:aws:s3:::my-bucket\",\n        \"arn:aws:s3:::my-bucket/*\"\n      ]\n    }\n  ]\n}\n```\n\n### Templates\n```hcl\nmodule \"codedeploy_policy\" {\n  source = \"../../\"\n\n  name = var.name\n  templates = [\n    {\n      name = \"codedeploy/ecs-blue-green-deployment\"\n      vars = {\n        codedeploy_app_name              = \"my-project\"\n        codedeploy_deployment_group_name = \"web-app\"\n\n        ecs_cluster_name = \"my-project\"\n        ecs_service_name = \"web-app\"\n\n        task_definition_task_role_name      = \"web-app\"\n        task_definition_execution_role_name = \"web-app-exec\"\n      }\n    },\n    {\n      name = \"ecr/push-and-pull\"\n      vars = {\n        ecr_repository_name = \"web-app\"\n      }\n    }\n  ]\n}\n```\n\u003c!-- END_TF_DOCS --\u003e\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fgeekcell%2Fterraform-aws-iam-policy","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fgeekcell%2Fterraform-aws-iam-policy","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fgeekcell%2Fterraform-aws-iam-policy/lists"}