mirror of
https://github.com/terraform-aws-modules/terraform-aws-eks.git
synced 2025-09-09 19:32:58 +08:00
fix: Allow for both amazonaws.com.cn and amazonaws.com conditions in PassRole as required for AWS CN (#3422)
* Allow for both amazonaws.com.cn and amazonaws.com conditions as required for AWS CN * Allow for both amazonaws.com.cn and amazonaws.com conditions as required for AWS CN - set in correct policy --------- Co-authored-by: Oliver Smith <osmith@netvirta.com>
This commit is contained in:
@@ -585,7 +585,7 @@ data "aws_iam_policy_document" "v1" {
|
|||||||
condition {
|
condition {
|
||||||
test = "StringEquals"
|
test = "StringEquals"
|
||||||
variable = "iam:PassedToService"
|
variable = "iam:PassedToService"
|
||||||
values = ["ec2.${local.dns_suffix}"]
|
values = distinct(["ec2.${local.dns_suffix}", "ec2.amazonaws.com"])
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user