@@ -17,7 +17,7 @@ data "aws_iam_policy_document" "cert_manager" {
17
17
18
18
statement {
19
19
actions = [" route53:GetChange" ]
20
- resources = [" arn:aws :route53:::change/*" ]
20
+ resources = [" arn:${ local . partition } :route53:::change/*" ]
21
21
}
22
22
23
23
statement {
@@ -550,9 +550,9 @@ data "aws_iam_policy_document" "karpenter_controller" {
550
550
statement {
551
551
actions = [" ec2:RunInstances" ]
552
552
resources = [
553
- " arn:aws :ec2:*:${ local . account_id } :launch-template/*" ,
554
- " arn:aws :ec2:*:${ local . account_id } :security-group/*" ,
555
- " arn:aws :ec2:*:${ local . account_id } :subnet/*" ,
553
+ " arn:${ local . partition } :ec2:*:${ local . account_id } :launch-template/*" ,
554
+ " arn:${ local . partition } :ec2:*:${ local . account_id } :security-group/*" ,
555
+ " arn:${ local . partition } :ec2:*:${ local . account_id } :subnet/*" ,
556
556
]
557
557
558
558
condition {
@@ -565,10 +565,10 @@ data "aws_iam_policy_document" "karpenter_controller" {
565
565
statement {
566
566
actions = [" ec2:RunInstances" ]
567
567
resources = [
568
- " arn:aws :ec2:*::image/*" ,
569
- " arn:aws :ec2:*:${ local . account_id } :instance/*" ,
570
- " arn:aws :ec2:*:${ local . account_id } :volume/*" ,
571
- " arn:aws :ec2:*:${ local . account_id } :network-interface/*" ,
568
+ " arn:${ local . partition } :ec2:*::image/*" ,
569
+ " arn:${ local . partition } :ec2:*:${ local . account_id } :instance/*" ,
570
+ " arn:${ local . partition } :ec2:*:${ local . account_id } :volume/*" ,
571
+ " arn:${ local . partition } :ec2:*:${ local . account_id } :network-interface/*" ,
572
572
]
573
573
}
574
574
@@ -1144,7 +1144,7 @@ resource "aws_iam_role_policy_attachment" "node_termination_handler" {
1144
1144
data "aws_iam_policy_document" "vpc_cni" {
1145
1145
count = var. create_role && var. attach_vpc_cni_policy ? 1 : 0
1146
1146
1147
- # arn:aws :iam::aws:policy/AmazonEKS_CNI_Policy
1147
+ # arn:${local.partition} :iam::aws:policy/AmazonEKS_CNI_Policy
1148
1148
dynamic "statement" {
1149
1149
for_each = var. vpc_cni_enable_ipv4 ? [1 ] : []
1150
1150
content {
0 commit comments