@@ -4,8 +4,6 @@ data "aws_iam_openid_connect_provider" "github" {
44
55data "aws_caller_identity" "current" {}
66
7- data "aws_region" "current" {}
8-
97data "aws_iam_policy_document" "update_lambda" {
108 # checkov:skip=CKV_AWS_356: Read only
119 statement {
@@ -32,7 +30,7 @@ data "aws_iam_policy_document" "update_lambda" {
3230 " lambda:PutProvisionedConcurrencyConfig" ,
3331 " lambda:DeleteProvisionedConcurrencyConfig" ,
3432 ]
35- resources = [" arn:aws:lambda:${ data . aws_region . current . region } :${ data . aws_caller_identity . current . account_id } :function:${ var . function_prefix } *" ]
33+ resources = [" arn:aws:lambda:${ var . region } :${ data . aws_caller_identity . current . account_id } :function:${ var . function_prefix } *" ]
3634 }
3735
3836 dynamic "statement" {
@@ -43,7 +41,7 @@ data "aws_iam_policy_document" "update_lambda" {
4341 " apigateway:POST" ,
4442 " apigateway:PUT" ,
4543 ]
46- resources = [" arn:aws:apigateway:${ data . aws_region . current . region } ::/restapis/${ var . apigw_id } /*" ]
44+ resources = [" arn:aws:apigateway:${ var . region } ::/restapis/${ var . apigw_id } /*" ]
4745 }
4846 }
4947
@@ -54,7 +52,7 @@ data "aws_iam_policy_document" "update_lambda" {
5452 actions = [
5553 " lambda:AddPermission" ,
5654 ]
57- resources = [" arn:aws:lambda:${ data . aws_region . current . region } :${ data . aws_caller_identity . current . account_id } :function:${ var . function_prefix } *" ]
55+ resources = [" arn:aws:lambda:${ var . region } :${ data . aws_caller_identity . current . account_id } :function:${ var . function_prefix } *" ]
5856 }
5957 }
6058
@@ -65,7 +63,7 @@ data "aws_iam_policy_document" "update_lambda" {
6563 actions = [
6664 " lambda:UpdateEventSourceMapping" ,
6765 ]
68- resources = [" arn:aws:lambda:${ data . aws_region . current . region } :${ data . aws_caller_identity . current . account_id } :event-source-mapping:*" ]
66+ resources = [" arn:aws:lambda:${ var . region } :${ data . aws_caller_identity . current . account_id } :event-source-mapping:*" ]
6967 }
7068 }
7169}
@@ -175,7 +173,7 @@ data "aws_iam_policy_document" "sign_code" {
175173 ]
176174
177175 resources = [
178- " arn:aws:signer:${ data . aws_region . current . region } :${ data . aws_caller_identity . current . account_id } :/signing-jobs/*" ,
176+ " arn:aws:signer:${ var . region } :${ data . aws_caller_identity . current . account_id } :/signing-jobs/*" ,
179177 ]
180178 }
181179
@@ -188,7 +186,7 @@ data "aws_iam_policy_document" "sign_code" {
188186 ]
189187
190188 resources = [
191- " arn:aws:signer:${ data . aws_region . current . region } :${ data . aws_caller_identity . current . account_id } :/signing-profiles/${ var . signing_profile_name } " ,
189+ " arn:aws:signer:${ var . region } :${ data . aws_caller_identity . current . account_id } :/signing-profiles/${ var . signing_profile_name } " ,
192190 ]
193191 }
194192}
0 commit comments