File tree Expand file tree Collapse file tree 1 file changed +13
-8
lines changed
modules/iam-role-for-service-accounts Expand file tree Collapse file tree 1 file changed +13
-8
lines changed Original file line number Diff line number Diff line change @@ -483,14 +483,19 @@ data "aws_iam_policy_document" "external_secrets" {
483483 resources = [" *" ]
484484 }
485485
486- statement {
487- actions = [
488- " secretsmanager:GetResourcePolicy" ,
489- " secretsmanager:GetSecretValue" ,
490- " secretsmanager:DescribeSecret" ,
491- " secretsmanager:ListSecretVersionIds"
492- ]
493- resources = var. external_secrets_secrets_manager_arns
486+ dynamic "statement" {
487+ for_each = length (var. external_secrets_secrets_manager_arns ) > 0 ? [1 ] : []
488+
489+ content {
490+ actions = [
491+ " secretsmanager:GetResourcePolicy" ,
492+ " secretsmanager:GetSecretValue" ,
493+ " secretsmanager:DescribeSecret" ,
494+ " secretsmanager:ListSecretVersionIds"
495+ ]
496+
497+ resources = var. external_secrets_secrets_manager_arns
498+ }
494499 }
495500
496501 dynamic "statement" {
You can’t perform that action at this time.
0 commit comments