## Module functionality
Creates an IAM policy that allows readonly access to a buckets that fall under the provided list of bucket_masks
