I am trying to set up an S3 bucket policy in Terraform. I have written the following code in a module core/main.tf:
resource "aws_s3_bucket_policy" "access_to_bucket" {
bucket = aws_s3_bucket.some_bucket.id
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = ["s3:GetObject", "s3:GetObjectAcl", "s3:ListBucket"]
Effect = "Allow"
Principal = "${var.some_variable_name}"
Resource = [
"${aws_s3_bucket.some_bucket.arn}",
"${aws_s3_bucket.some_bucket.arn}/*"
]
},
]
})
}
Which then gets instantiated in a local module which uses localstack to run locally.
This is the plan generated:
Terraform will perform the following actions:
# module.local.aws_s3_bucket_policy.access_to_bucket will be created
+ resource "aws_s3_bucket_policy" "access_to_bucket" {
+ bucket = "some_bucket"
+ id = (known after apply)
+ policy = jsonencode(
{
+ Statement = [
+ {
+ Action = [
+ "s3:GetObject",
+ "s3:GetObjectAcl",
+ "s3:ListBucket",
]
+ Effect = "Allow"
+ Principal = "arn:aws:iam::000000000000:role/test_role"
+ Resource = [
+ "arn:aws:s3:::some-bucket/*",
+ "arn:aws:s3:::some-bucket",
]
},
]
+ Version = "2012-10-17"
}
)
}
╷
│ Error: Error putting S3 policy: MalformedPolicy: Invalid policy syntax.
│ status code: 400, request id, host id
│
│ with module.local.aws_s3_bucket_policy.access_to_bucket,
│ on ../core/main.tf line 55, in resource "aws_s3_bucket_policy" "access_to_bucket":
│ 55: resource "aws_s3_bucket_policy" "access_to_bucket" {
│
Running it both locally and in AWS ends up with this error. I am guessing it's a syntax error somewhere but AFAIK this is correct. Any clue what's wrong?