controls-aws-iam-failing.tfplan.json
  1
  2
  3
  4
  5
  6
  7
  8
  9
 10
 11
 12
 13
 14
 15
 16
 17
 18
 19
 20
 21
 22
 23
 24
 25
 26
 27
 28
 29
 30
 31
 32
 33
 34
 35
 36
 37
 38
 39
 40
 41
 42
 43
 44
 45
 46
 47
 48
 49
 50
 51
 52
 53
 54
 55
 56
 57
 58
 59
 60
 61
 62
 63
 64
 65
 66
 67
 68
 69
 70
 71
 72
 73
 74
 75
 76
 77
 78
 79
 80
 81
 82
 83
 84
 85
 86
 87
 88
 89
 90
 91
 92
 93
 94
 95
 96
 97
 98
 99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
{
    "format_version": "1.2",
    "terraform_version": "1.15.6",
    "planned_values": {
        "root_module": {
            "resources": [
                {
                    "address": "aws_iam_access_key.bad_key",
                    "mode": "managed",
                    "type": "aws_iam_access_key",
                    "name": "bad_key",
                    "provider_name": "registry.terraform.io/hashicorp/aws",
                    "schema_version": 0,
                    "values": {
                        "pgp_key": null,
                        "status": "Active",
                        "user": "bad-user"
                    },
                    "sensitive_values": {
                        "secret": true,
                        "ses_smtp_password_v4": true
                    }
                },
                {
                    "address": "aws_iam_policy.bad_policy",
                    "mode": "managed",
                    "type": "aws_iam_policy",
                    "name": "bad_policy",
                    "provider_name": "registry.terraform.io/hashicorp/aws",
                    "schema_version": 0,
                    "values": {
                        "description": null,
                        "name": "bad-managed-policy",
                        "path": "/",
                        "policy": "{\"Statement\":[{\"Action\":[\"s3:GetObject\"],\"Effect\":\"Allow\",\"Resource\":\"*\"}],\"Version\":\"2012-10-17\"}",
                        "tags": null
                    },
                    "sensitive_values": {
                        "tags_all": {}
                    }
                },
                {
                    "address": "aws_iam_role.app_role",
                    "mode": "managed",
                    "type": "aws_iam_role",
                    "name": "app_role",
                    "provider_name": "registry.terraform.io/hashicorp/aws",
                    "schema_version": 0,
                    "values": {
                        "assume_role_policy": "{\"Statement\":[{\"Action\":\"sts:AssumeRole\",\"Effect\":\"Allow\",\"Principal\":{\"Service\":\"ec2.amazonaws.com\"}}],\"Version\":\"2012-10-17\"}",
                        "description": null,
                        "force_detach_policies": false,
                        "max_session_duration": 3600,
                        "name": "app-role",
                        "path": "/",
                        "permissions_boundary": null,
                        "tags": null
                    },
                    "sensitive_values": {
                        "inline_policy": [],
                        "managed_policy_arns": [],
                        "tags_all": {}
                    }
                },
                {
                    "address": "aws_iam_role.bad_cross_account",
                    "mode": "managed",
                    "type": "aws_iam_role",
                    "name": "bad_cross_account",
                    "provider_name": "registry.terraform.io/hashicorp/aws",
                    "schema_version": 0,
                    "values": {
                        "assume_role_policy": "{\"Statement\":[{\"Action\":\"sts:AssumeRole\",\"Effect\":\"Allow\",\"Principal\":\"*\"}],\"Version\":\"2012-10-17\"}",
                        "description": null,
                        "force_detach_policies": false,
                        "max_session_duration": 3600,
                        "name": "bad-cross-account-role",
                        "path": "/",
                        "permissions_boundary": null,
                        "tags": null
                    },
                    "sensitive_values": {
                        "inline_policy": [],
                        "managed_policy_arns": [],
                        "tags_all": {}
                    }
                },
                {
                    "address": "aws_iam_role_policy.bad_kms",
                    "mode": "managed",
                    "type": "aws_iam_role_policy",
                    "name": "bad_kms",
                    "provider_name": "registry.terraform.io/hashicorp/aws",
                    "schema_version": 0,
                    "values": {
                        "name": "bad-kms-policy",
                        "policy": "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Action\":[\"kms:Decrypt\"],\"Effect\":\"Allow\",\"Resource\":\"*\"}]}",
                        "role": "app-role"
                    },
                    "sensitive_values": {}
                },
                {
                    "address": "aws_iam_user.bad_user",
                    "mode": "managed",
                    "type": "aws_iam_user",
                    "name": "bad_user",
                    "provider_name": "registry.terraform.io/hashicorp/aws",
                    "schema_version": 0,
                    "values": {
                        "force_destroy": false,
                        "name": "bad-user",
                        "path": "/",
                        "permissions_boundary": null,
                        "tags": null
                    },
                    "sensitive_values": {
                        "tags_all": {}
                    }
                },
                {
                    "address": "aws_iam_user_policy.bad_inline",
                    "mode": "managed",
                    "type": "aws_iam_user_policy",
                    "name": "bad_inline",
                    "provider_name": "registry.terraform.io/hashicorp/aws",
                    "schema_version": 0,
                    "values": {
                        "name": "bad-inline-policy",
                        "policy": "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Action\":[\"s3:GetObject\"],\"Effect\":\"Allow\",\"Resource\":\"*\"}]}",
                        "user": "bad-user"
                    },
                    "sensitive_values": {}
                },
                {
                    "address": "aws_iam_user_policy_attachment.bad_attachment",
                    "mode": "managed",
                    "type": "aws_iam_user_policy_attachment",
                    "name": "bad_attachment",
                    "provider_name": "registry.terraform.io/hashicorp/aws",
                    "schema_version": 0,
                    "values": {
                        "user": "bad-user"
                    },
                    "sensitive_values": {}
                }
            ]
        }
    },
    "resource_changes": [
        {
            "address": "aws_iam_access_key.bad_key",
            "mode": "managed",
            "type": "aws_iam_access_key",
            "name": "bad_key",
            "provider_name": "registry.terraform.io/hashicorp/aws",
            "change": {
                "actions": [
                    "create"
                ],
                "before": null,
                "after": {
                    "pgp_key": null,
                    "status": "Active",
                    "user": "bad-user"
                },
                "after_unknown": {
                    "create_date": true,
                    "encrypted_secret": true,
                    "encrypted_ses_smtp_password_v4": true,
                    "id": true,
                    "key_fingerprint": true,
                    "secret": true,
                    "ses_smtp_password_v4": true
                },
                "before_sensitive": false,
                "after_sensitive": {
                    "secret": true,
                    "ses_smtp_password_v4": true
                }
            }
        },
        {
            "address": "aws_iam_policy.bad_policy",
            "mode": "managed",
            "type": "aws_iam_policy",
            "name": "bad_policy",
            "provider_name": "registry.terraform.io/hashicorp/aws",
            "change": {
                "actions": [
                    "create"
                ],
                "before": null,
                "after": {
                    "description": null,
                    "name": "bad-managed-policy",
                    "path": "/",
                    "policy": "{\"Statement\":[{\"Action\":[\"s3:GetObject\"],\"Effect\":\"Allow\",\"Resource\":\"*\"}],\"Version\":\"2012-10-17\"}",
                    "tags": null
                },
                "after_unknown": {
                    "arn": true,
                    "attachment_count": true,
                    "id": true,
                    "name_prefix": true,
                    "policy_id": true,
                    "tags_all": true
                },
                "before_sensitive": false,
                "after_sensitive": {
                    "tags_all": {}
                }
            }
        },
        {
            "address": "aws_iam_role.app_role",
            "mode": "managed",
            "type": "aws_iam_role",
            "name": "app_role",
            "provider_name": "registry.terraform.io/hashicorp/aws",
            "change": {
                "actions": [
                    "create"
                ],
                "before": null,
                "after": {
                    "assume_role_policy": "{\"Statement\":[{\"Action\":\"sts:AssumeRole\",\"Effect\":\"Allow\",\"Principal\":{\"Service\":\"ec2.amazonaws.com\"}}],\"Version\":\"2012-10-17\"}",
                    "description": null,
                    "force_detach_policies": false,
                    "max_session_duration": 3600,
                    "name": "app-role",
                    "path": "/",
                    "permissions_boundary": null,
                    "tags": null
                },
                "after_unknown": {
                    "arn": true,
                    "create_date": true,
                    "id": true,
                    "inline_policy": true,
                    "managed_policy_arns": true,
                    "name_prefix": true,
                    "tags_all": true,
                    "unique_id": true
                },
                "before_sensitive": false,
                "after_sensitive": {
                    "inline_policy": [],
                    "managed_policy_arns": [],
                    "tags_all": {}
                }
            }
        },
        {
            "address": "aws_iam_role.bad_cross_account",
            "mode": "managed",
            "type": "aws_iam_role",
            "name": "bad_cross_account",
            "provider_name": "registry.terraform.io/hashicorp/aws",
            "change": {
                "actions": [
                    "create"
                ],
                "before": null,
                "after": {
                    "assume_role_policy": "{\"Statement\":[{\"Action\":\"sts:AssumeRole\",\"Effect\":\"Allow\",\"Principal\":\"*\"}],\"Version\":\"2012-10-17\"}",
                    "description": null,
                    "force_detach_policies": false,
                    "max_session_duration": 3600,
                    "name": "bad-cross-account-role",
                    "path": "/",
                    "permissions_boundary": null,
                    "tags": null
                },
                "after_unknown": {
                    "arn": true,
                    "create_date": true,
                    "id": true,
                    "inline_policy": true,
                    "managed_policy_arns": true,
                    "name_prefix": true,
                    "tags_all": true,
                    "unique_id": true
                },
                "before_sensitive": false,
                "after_sensitive": {
                    "inline_policy": [],
                    "managed_policy_arns": [],
                    "tags_all": {}
                }
            }
        },
        {
            "address": "aws_iam_role_policy.bad_kms",
            "mode": "managed",
            "type": "aws_iam_role_policy",
            "name": "bad_kms",
            "provider_name": "registry.terraform.io/hashicorp/aws",
            "change": {
                "actions": [
                    "create"
                ],
                "before": null,
                "after": {
                    "name": "bad-kms-policy",
                    "policy": "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Action\":[\"kms:Decrypt\"],\"Effect\":\"Allow\",\"Resource\":\"*\"}]}",
                    "role": "app-role"
                },
                "after_unknown": {
                    "id": true,
                    "name_prefix": true
                },
                "before_sensitive": false,
                "after_sensitive": {}
            }
        },
        {
            "address": "aws_iam_user.bad_user",
            "mode": "managed",
            "type": "aws_iam_user",
            "name": "bad_user",
            "provider_name": "registry.terraform.io/hashicorp/aws",
            "change": {
                "actions": [
                    "create"
                ],
                "before": null,
                "after": {
                    "force_destroy": false,
                    "name": "bad-user",
                    "path": "/",
                    "permissions_boundary": null,
                    "tags": null
                },
                "after_unknown": {
                    "arn": true,
                    "id": true,
                    "tags_all": true,
                    "unique_id": true
                },
                "before_sensitive": false,
                "after_sensitive": {
                    "tags_all": {}
                }
            }
        },
        {
            "address": "aws_iam_user_policy.bad_inline",
            "mode": "managed",
            "type": "aws_iam_user_policy",
            "name": "bad_inline",
            "provider_name": "registry.terraform.io/hashicorp/aws",
            "change": {
                "actions": [
                    "create"
                ],
                "before": null,
                "after": {
                    "name": "bad-inline-policy",
                    "policy": "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Action\":[\"s3:GetObject\"],\"Effect\":\"Allow\",\"Resource\":\"*\"}]}",
                    "user": "bad-user"
                },
                "after_unknown": {
                    "id": true,
                    "name_prefix": true
                },
                "before_sensitive": false,
                "after_sensitive": {}
            }
        },
        {
            "address": "aws_iam_user_policy_attachment.bad_attachment",
            "mode": "managed",
            "type": "aws_iam_user_policy_attachment",
            "name": "bad_attachment",
            "provider_name": "registry.terraform.io/hashicorp/aws",
            "change": {
                "actions": [
                    "create"
                ],
                "before": null,
                "after": {
                    "user": "bad-user"
                },
                "after_unknown": {
                    "id": true,
                    "policy_arn": true
                },
                "before_sensitive": false,
                "after_sensitive": {}
            }
        }
    ],
    "configuration": {
        "provider_config": {
            "aws": {
                "name": "aws",
                "full_name": "registry.terraform.io/hashicorp/aws",
                "version_constraint": "~\u003e 5.0",
                "expressions": {
                    "access_key": {
                        "constant_value": "AKIAIOSFODNN7EXAMPLE"
                    },
                    "region": {
                        "constant_value": "ap-south-1"
                    },
                    "secret_key": {
                        "constant_value": "wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY"
                    }
                }
            }
        },
        "root_module": {
            "resources": [
                {
                    "address": "aws_iam_access_key.bad_key",
                    "mode": "managed",
                    "type": "aws_iam_access_key",
                    "name": "bad_key",
                    "provider_config_key": "aws",
                    "expressions": {
                        "user": {
                            "references": [
                                "aws_iam_user.bad_user.name",
                                "aws_iam_user.bad_user"
                            ]
                        }
                    },
                    "schema_version": 0
                },
                {
                    "address": "aws_iam_policy.bad_policy",
                    "mode": "managed",
                    "type": "aws_iam_policy",
                    "name": "bad_policy",
                    "provider_config_key": "aws",
                    "expressions": {
                        "name": {
                            "constant_value": "bad-managed-policy"
                        },
                        "policy": {}
                    },
                    "schema_version": 0
                },
                {
                    "address": "aws_iam_role.app_role",
                    "mode": "managed",
                    "type": "aws_iam_role",
                    "name": "app_role",
                    "provider_config_key": "aws",
                    "expressions": {
                        "assume_role_policy": {},
                        "name": {
                            "constant_value": "app-role"
                        }
                    },
                    "schema_version": 0
                },
                {
                    "address": "aws_iam_role.bad_cross_account",
                    "mode": "managed",
                    "type": "aws_iam_role",
                    "name": "bad_cross_account",
                    "provider_config_key": "aws",
                    "expressions": {
                        "assume_role_policy": {},
                        "name": {
                            "constant_value": "bad-cross-account-role"
                        }
                    },
                    "schema_version": 0
                },
                {
                    "address": "aws_iam_role_policy.bad_kms",
                    "mode": "managed",
                    "type": "aws_iam_role_policy",
                    "name": "bad_kms",
                    "provider_config_key": "aws",
                    "expressions": {
                        "name": {
                            "constant_value": "bad-kms-policy"
                        },
                        "policy": {},
                        "role": {
                            "references": [
                                "aws_iam_role.app_role.name",
                                "aws_iam_role.app_role"
                            ]
                        }
                    },
                    "schema_version": 0
                },
                {
                    "address": "aws_iam_user.bad_user",
                    "mode": "managed",
                    "type": "aws_iam_user",
                    "name": "bad_user",
                    "provider_config_key": "aws",
                    "expressions": {
                        "name": {
                            "constant_value": "bad-user"
                        }
                    },
                    "schema_version": 0
                },
                {
                    "address": "aws_iam_user_policy.bad_inline",
                    "mode": "managed",
                    "type": "aws_iam_user_policy",
                    "name": "bad_inline",
                    "provider_config_key": "aws",
                    "expressions": {
                        "name": {
                            "constant_value": "bad-inline-policy"
                        },
                        "policy": {},
                        "user": {
                            "references": [
                                "aws_iam_user.bad_user.name",
                                "aws_iam_user.bad_user"
                            ]
                        }
                    },
                    "schema_version": 0
                },
                {
                    "address": "aws_iam_user_policy_attachment.bad_attachment",
                    "mode": "managed",
                    "type": "aws_iam_user_policy_attachment",
                    "name": "bad_attachment",
                    "provider_config_key": "aws",
                    "expressions": {
                        "policy_arn": {
                            "references": [
                                "aws_iam_policy.bad_policy.arn",
                                "aws_iam_policy.bad_policy"
                            ]
                        },
                        "user": {
                            "references": [
                                "aws_iam_user.bad_user.name",
                                "aws_iam_user.bad_user"
                            ]
                        }
                    },
                    "schema_version": 0
                }
            ]
        }
    },
    "relevant_attributes": [
        {
            "resource": "aws_iam_policy.bad_policy",
            "attribute": [
                "arn"
            ]
        },
        {
            "resource": "aws_iam_role.app_role",
            "attribute": [
                "name"
            ]
        },
        {
            "resource": "aws_iam_user.bad_user",
            "attribute": [
                "name"
            ]
        }
    ],
    "timestamp": "2026-07-16T08:41:51Z",
    "applyable": true,
    "complete": true,
    "errored": false
}