controls-aws-iam-passing.tfplan.json
  1
  2
  3
  4
  5
  6
  7
  8
  9
 10
 11
 12
 13
 14
 15
 16
 17
 18
 19
 20
 21
 22
 23
 24
 25
 26
 27
 28
 29
 30
 31
 32
 33
 34
 35
 36
 37
 38
 39
 40
 41
 42
 43
 44
 45
 46
 47
 48
 49
 50
 51
 52
 53
 54
 55
 56
 57
 58
 59
 60
 61
 62
 63
 64
 65
 66
 67
 68
 69
 70
 71
 72
 73
 74
 75
 76
 77
 78
 79
 80
 81
 82
 83
 84
 85
 86
 87
 88
 89
 90
 91
 92
 93
 94
 95
 96
 97
 98
 99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
{
    "format_version": "1.2",
    "terraform_version": "1.15.6",
    "planned_values": {
        "root_module": {
            "resources": [
                {
                    "address": "aws_iam_group.app_group",
                    "mode": "managed",
                    "type": "aws_iam_group",
                    "name": "app_group",
                    "provider_name": "registry.terraform.io/hashicorp/aws",
                    "schema_version": 0,
                    "values": {
                        "name": "app-group",
                        "path": "/"
                    },
                    "sensitive_values": {}
                },
                {
                    "address": "aws_iam_group_policy.app_group_policy",
                    "mode": "managed",
                    "type": "aws_iam_group_policy",
                    "name": "app_group_policy",
                    "provider_name": "registry.terraform.io/hashicorp/aws",
                    "schema_version": 0,
                    "values": {
                        "group": "app-group",
                        "name": "app-group-policy",
                        "policy": "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Action\":[\"s3:GetObject\"],\"Effect\":\"Allow\",\"Resource\":\"arn:aws:s3:::my-bucket/*\"}]}"
                    },
                    "sensitive_values": {}
                },
                {
                    "address": "aws_iam_role.app_role",
                    "mode": "managed",
                    "type": "aws_iam_role",
                    "name": "app_role",
                    "provider_name": "registry.terraform.io/hashicorp/aws",
                    "schema_version": 0,
                    "values": {
                        "assume_role_policy": "{\"Statement\":[{\"Action\":\"sts:AssumeRole\",\"Effect\":\"Allow\",\"Principal\":{\"Service\":\"ec2.amazonaws.com\"}}],\"Version\":\"2012-10-17\"}",
                        "description": null,
                        "force_detach_policies": false,
                        "max_session_duration": 3600,
                        "name": "app-role",
                        "path": "/",
                        "permissions_boundary": "arn:aws:iam::123456789012:policy/boundary-policy",
                        "tags": null
                    },
                    "sensitive_values": {
                        "inline_policy": [],
                        "managed_policy_arns": [],
                        "tags_all": {}
                    }
                },
                {
                    "address": "aws_iam_role.cross_account_role",
                    "mode": "managed",
                    "type": "aws_iam_role",
                    "name": "cross_account_role",
                    "provider_name": "registry.terraform.io/hashicorp/aws",
                    "schema_version": 0,
                    "values": {
                        "assume_role_policy": "{\"Statement\":[{\"Action\":\"sts:AssumeRole\",\"Condition\":{\"StringEquals\":{\"sts:ExternalId\":\"unique-external-id\"}},\"Effect\":\"Allow\",\"Principal\":{\"AWS\":\"arn:aws:iam::999999999999:root\"}}],\"Version\":\"2012-10-17\"}",
                        "description": null,
                        "force_detach_policies": false,
                        "max_session_duration": 3600,
                        "name": "cross-account-role",
                        "path": "/",
                        "permissions_boundary": "arn:aws:iam::123456789012:policy/boundary-policy",
                        "tags": null
                    },
                    "sensitive_values": {
                        "inline_policy": [],
                        "managed_policy_arns": [],
                        "tags_all": {}
                    }
                },
                {
                    "address": "aws_iam_role_policy.scoped_kms",
                    "mode": "managed",
                    "type": "aws_iam_role_policy",
                    "name": "scoped_kms",
                    "provider_name": "registry.terraform.io/hashicorp/aws",
                    "schema_version": 0,
                    "values": {
                        "name": "scoped-kms-policy",
                        "policy": "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Action\":[\"kms:Decrypt\"],\"Effect\":\"Allow\",\"Resource\":\"arn:aws:kms:ap-south-1:123456789012:key/mrk-1234abcd\"}]}",
                        "role": "app-role"
                    },
                    "sensitive_values": {}
                }
            ]
        }
    },
    "resource_changes": [
        {
            "address": "aws_iam_group.app_group",
            "mode": "managed",
            "type": "aws_iam_group",
            "name": "app_group",
            "provider_name": "registry.terraform.io/hashicorp/aws",
            "change": {
                "actions": [
                    "create"
                ],
                "before": null,
                "after": {
                    "name": "app-group",
                    "path": "/"
                },
                "after_unknown": {
                    "arn": true,
                    "id": true,
                    "unique_id": true
                },
                "before_sensitive": false,
                "after_sensitive": {}
            }
        },
        {
            "address": "aws_iam_group_policy.app_group_policy",
            "mode": "managed",
            "type": "aws_iam_group_policy",
            "name": "app_group_policy",
            "provider_name": "registry.terraform.io/hashicorp/aws",
            "change": {
                "actions": [
                    "create"
                ],
                "before": null,
                "after": {
                    "group": "app-group",
                    "name": "app-group-policy",
                    "policy": "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Action\":[\"s3:GetObject\"],\"Effect\":\"Allow\",\"Resource\":\"arn:aws:s3:::my-bucket/*\"}]}"
                },
                "after_unknown": {
                    "id": true,
                    "name_prefix": true
                },
                "before_sensitive": false,
                "after_sensitive": {}
            }
        },
        {
            "address": "aws_iam_role.app_role",
            "mode": "managed",
            "type": "aws_iam_role",
            "name": "app_role",
            "provider_name": "registry.terraform.io/hashicorp/aws",
            "change": {
                "actions": [
                    "create"
                ],
                "before": null,
                "after": {
                    "assume_role_policy": "{\"Statement\":[{\"Action\":\"sts:AssumeRole\",\"Effect\":\"Allow\",\"Principal\":{\"Service\":\"ec2.amazonaws.com\"}}],\"Version\":\"2012-10-17\"}",
                    "description": null,
                    "force_detach_policies": false,
                    "max_session_duration": 3600,
                    "name": "app-role",
                    "path": "/",
                    "permissions_boundary": "arn:aws:iam::123456789012:policy/boundary-policy",
                    "tags": null
                },
                "after_unknown": {
                    "arn": true,
                    "create_date": true,
                    "id": true,
                    "inline_policy": true,
                    "managed_policy_arns": true,
                    "name_prefix": true,
                    "tags_all": true,
                    "unique_id": true
                },
                "before_sensitive": false,
                "after_sensitive": {
                    "inline_policy": [],
                    "managed_policy_arns": [],
                    "tags_all": {}
                }
            }
        },
        {
            "address": "aws_iam_role.cross_account_role",
            "mode": "managed",
            "type": "aws_iam_role",
            "name": "cross_account_role",
            "provider_name": "registry.terraform.io/hashicorp/aws",
            "change": {
                "actions": [
                    "create"
                ],
                "before": null,
                "after": {
                    "assume_role_policy": "{\"Statement\":[{\"Action\":\"sts:AssumeRole\",\"Condition\":{\"StringEquals\":{\"sts:ExternalId\":\"unique-external-id\"}},\"Effect\":\"Allow\",\"Principal\":{\"AWS\":\"arn:aws:iam::999999999999:root\"}}],\"Version\":\"2012-10-17\"}",
                    "description": null,
                    "force_detach_policies": false,
                    "max_session_duration": 3600,
                    "name": "cross-account-role",
                    "path": "/",
                    "permissions_boundary": "arn:aws:iam::123456789012:policy/boundary-policy",
                    "tags": null
                },
                "after_unknown": {
                    "arn": true,
                    "create_date": true,
                    "id": true,
                    "inline_policy": true,
                    "managed_policy_arns": true,
                    "name_prefix": true,
                    "tags_all": true,
                    "unique_id": true
                },
                "before_sensitive": false,
                "after_sensitive": {
                    "inline_policy": [],
                    "managed_policy_arns": [],
                    "tags_all": {}
                }
            }
        },
        {
            "address": "aws_iam_role_policy.scoped_kms",
            "mode": "managed",
            "type": "aws_iam_role_policy",
            "name": "scoped_kms",
            "provider_name": "registry.terraform.io/hashicorp/aws",
            "change": {
                "actions": [
                    "create"
                ],
                "before": null,
                "after": {
                    "name": "scoped-kms-policy",
                    "policy": "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Action\":[\"kms:Decrypt\"],\"Effect\":\"Allow\",\"Resource\":\"arn:aws:kms:ap-south-1:123456789012:key/mrk-1234abcd\"}]}",
                    "role": "app-role"
                },
                "after_unknown": {
                    "id": true,
                    "name_prefix": true
                },
                "before_sensitive": false,
                "after_sensitive": {}
            }
        }
    ],
    "configuration": {
        "provider_config": {
            "aws": {
                "name": "aws",
                "full_name": "registry.terraform.io/hashicorp/aws",
                "version_constraint": "~\u003e 5.0",
                "expressions": {
                    "region": {
                        "constant_value": "ap-south-1"
                    }
                }
            }
        },
        "root_module": {
            "resources": [
                {
                    "address": "aws_iam_group.app_group",
                    "mode": "managed",
                    "type": "aws_iam_group",
                    "name": "app_group",
                    "provider_config_key": "aws",
                    "expressions": {
                        "name": {
                            "constant_value": "app-group"
                        }
                    },
                    "schema_version": 0
                },
                {
                    "address": "aws_iam_group_policy.app_group_policy",
                    "mode": "managed",
                    "type": "aws_iam_group_policy",
                    "name": "app_group_policy",
                    "provider_config_key": "aws",
                    "expressions": {
                        "group": {
                            "references": [
                                "aws_iam_group.app_group.name",
                                "aws_iam_group.app_group"
                            ]
                        },
                        "name": {
                            "constant_value": "app-group-policy"
                        },
                        "policy": {}
                    },
                    "schema_version": 0
                },
                {
                    "address": "aws_iam_role.app_role",
                    "mode": "managed",
                    "type": "aws_iam_role",
                    "name": "app_role",
                    "provider_config_key": "aws",
                    "expressions": {
                        "assume_role_policy": {},
                        "name": {
                            "constant_value": "app-role"
                        },
                        "permissions_boundary": {
                            "constant_value": "arn:aws:iam::123456789012:policy/boundary-policy"
                        }
                    },
                    "schema_version": 0
                },
                {
                    "address": "aws_iam_role.cross_account_role",
                    "mode": "managed",
                    "type": "aws_iam_role",
                    "name": "cross_account_role",
                    "provider_config_key": "aws",
                    "expressions": {
                        "assume_role_policy": {},
                        "name": {
                            "constant_value": "cross-account-role"
                        },
                        "permissions_boundary": {
                            "constant_value": "arn:aws:iam::123456789012:policy/boundary-policy"
                        }
                    },
                    "schema_version": 0
                },
                {
                    "address": "aws_iam_role_policy.scoped_kms",
                    "mode": "managed",
                    "type": "aws_iam_role_policy",
                    "name": "scoped_kms",
                    "provider_config_key": "aws",
                    "expressions": {
                        "name": {
                            "constant_value": "scoped-kms-policy"
                        },
                        "policy": {},
                        "role": {
                            "references": [
                                "aws_iam_role.app_role.name",
                                "aws_iam_role.app_role"
                            ]
                        }
                    },
                    "schema_version": 0
                }
            ]
        }
    },
    "relevant_attributes": [
        {
            "resource": "aws_iam_group.app_group",
            "attribute": [
                "name"
            ]
        },
        {
            "resource": "aws_iam_role.app_role",
            "attribute": [
                "name"
            ]
        }
    ],
    "timestamp": "2026-07-16T09:14:03Z",
    "applyable": true,
    "complete": true,
    "errored": false
}