I have the following terraform code to create KMS Key. The My.tf file is using organization level common cmk core module that creates a key using aws_kms_key resource. This core module also attach a default key policy to the newly created Key.
my.tf file
//create key using core module
module "cmk" {
source = "git::https://company-repository-url/cmk?ref=v1.0.0"
name = "test"
enable_key_rotation = true
}
I don't have access to the core module. In My.tf file, after the Key is created I want to append the Key policy with the following policy document
data "aws_caller_identity" "current" {}
data "aws_iam_policy_document" "default" {
statement {
sid = "Some Sid"
effect = "Allow"
principals {
type = "AWS"
identifiers = [
"arn:aws:iam::123456789:root", //hardcoded. this is a cross account user
"arn:aws:iam::${data.aws_caller_identity.current.id}:role/service-role/SomeAWSRole"]
}
actions = [
"kms:CreateGrant",
"kms:ListGrants",
"kms:RevokeGrant"
]
resources = ["arn:aws:kms:us-west-2:${data.aws_caller_identity.current.id}:key/*"]
condition {
test = "Bool"
variable = "kms:GrantIsForAWSResource"
values = ["true"]
}
}
}
Is it possible to attach this policy to Key using aws_iam_policy_attachment or some other way?