How to update KMS Key policy using Terraform

Viewed 90

I have the following terraform code to create KMS Key. The My.tf file is using organization level common cmk core module that creates a key using aws_kms_key resource. This core module also attach a default key policy to the newly created Key.

my.tf file

//create key using core module
 module "cmk" {
      source = "git::https://company-repository-url/cmk?ref=v1.0.0"
      name                = "test"
      enable_key_rotation = true
    }

I don't have access to the core module. In My.tf file, after the Key is created I want to append the Key policy with the following policy document

data "aws_caller_identity" "current" {}

data "aws_iam_policy_document" "default" {

  statement {
    sid    = "Some Sid"
    effect = "Allow"
    principals {
      type = "AWS"
      identifiers = [
        "arn:aws:iam::123456789:root", //hardcoded. this is a cross account user
        "arn:aws:iam::${data.aws_caller_identity.current.id}:role/service-role/SomeAWSRole"]
    }
    actions = [
      "kms:CreateGrant",
      "kms:ListGrants",
      "kms:RevokeGrant"
    ]
    resources = ["arn:aws:kms:us-west-2:${data.aws_caller_identity.current.id}:key/*"]
    condition {
      test     = "Bool"
      variable = "kms:GrantIsForAWSResource"
      values   = ["true"]
    }
  }
}

Is it possible to attach this policy to Key using aws_iam_policy_attachment or some other way?

0 Answers
Related