Q: How do you use Terraform to create IAM policies without hardcoding JSON?
Use the aws_iam_policy_document data source:
#Terraform #Use VPC ID from another module #L2 #IaC #Cloud Infrastructure #S3
🎙️ Candidate Opening & Architectural Context
""In our enterprise Terraform repository, we designed reusable modules and remote backends to prevent this exact issue. When addressing this question, I walk the interviewer through our production incident runbook: isolating the blast radius, checking diagnostic logs and metrics, and applying a safe fix.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Production Solution & Architecture
Use the aws_iam_policy_document data source: Clean HCL instead of embedded JSON strings. Properly interpolates ARNs.
data "aws_iam_policy_document" "s3_read" {
statement {
effect = "Allow"
actions = ["s3:GetObject"]
resources = ["${aws_s3_bucket.data.arn}/*"]
}
}
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Use the aws_iam_policy_document data source:."
⚡ 60-Second Elevator Pitch Talking Points
- Immediate Triage: Use the aws_iam_policy_document data source:
- Run targeted verification commands before modifying configuration.
- Automate permanent guardrails (CI check, alerts, IaC policy) to prevent recurrence.
Advertisement