data "aws_iam_policy_document" "sme-gen-custom" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  #checkov:skip=CKV_AWS_110: Ensure IAM policies does not allow privilege escalation
  #checkov:skip=CKV_AWS_109: Ensure IAM policies does not allow permissions management / resource exposure without constraints
  #checkov:skip=CKV_AWS_108: Ensure IAM policies does not allow data exfiltration
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "lambda:CreateFunction",
      "iam:GetAccountPasswordPolicy",
      "cloudwatch:PutMetricData",
      "iam:ListRoleTags",
      "iam:GenerateServiceLastAccessedDetails",
      "iam:ListServiceSpecificCredentials",
      "iam:ListSigningCertificates",
      "iam:SimulateCustomPolicy",
      "ec2:StartInstances",
      "lambda:DeleteFunction",
      "iam:ListRolePolicies",
      "iam:GetCredentialReport",
      "ecs:DeregisterContainerInstance",
      "iam:ListPolicies",
      "iam:GetRole",
      "iam:ListSAMLProviders",
      "iam:GetPolicy",
      "config:PutConfigRule",
      "iam:ListEntitiesForPolicy",
      "ecr:GetAuthorizationToken",
      "ec2messages:AcknowledgeMessage",
      "ec2:StopInstances",
      "lambda:UpdateFunctionCode",
      "ecs:StartTelemetrySession",
      "config:PutConfigurationAggregator",
      "lambda:PublishVersion",
      "ec2messages:SendReply",
      "iam:GetOpenIDConnectProvider",
      "ce:*",
      "iam:GetRolePolicy",
      "iam:GenerateCredentialReport",
      "iam:UntagRole",
      "ec2messages:GetEndpoint",
      "iam:TagRole",
      "ecs:Submit*",
      "iam:GetServiceLastAccessedDetails",
      "iam:GetServiceLinkedRoleDeletionStatus",
      "iam:ListInstanceProfilesForRole",
      "ec2messages:DeleteMessage",
      "ec2:CreateSnapshot",
      "iam:ListAttachedGroupPolicies",
      "ec2:DescribeInstanceStatus",
      "iam:ListAccessKeys",
      "config:PutConfigurationRecorder",
      "s3:*",
      "iam:ListGroupPolicies",
      "iam:GetSSHPublicKey",
      "lambda:UpdateFunctionConfiguration",
      "iam:ListRoles",
      "config:StopConfigurationRecorder",
      "iam:GetContextKeysForCustomPolicy",
      "ssm:*",
      "iam:ListAccountAliases",
      "iam:GetUser",
      "iam:ListGroups",
      "iam:GetLoginProfile",
      "iam:GetPolicyVersion",
      "iam:ListServerCertificates",
      "ds:CreateComputer",
      "config:StartConfigurationRecorder",
      "config:PutDeliveryChannel",
      "iam:ListVirtualMFADevices",
      "ec2:DeleteVolume",
      "logs:CreateLogStream",
      "iam:ListSSHPublicKeys",
      "iam:SimulatePrincipalPolicy",
      "iam:ListAttachedRolePolicies",
      "iam:GetAccountAuthorizationDetails",
      "ecr:BatchCheckLayerAvailability",
      "iam:GetServerCertificate",
      "lambda:InvokeFunction",
      "ecs:CreateCluster",
      "ecr:GetDownloadUrlForLayer",
      "iam:GetAccessKeyLastUsed",
      "config:PutEvaluations",
      "logs:CreateLogGroup",
      "config:StartConfigRulesEvaluation",
      "rds:StartDBInstance",
      "glacier:*",
      "iam:GetUserPolicy",
      "iam:ListGroupsForUser",
      "ecr:BatchGetImage",
      "iam:GetGroupPolicy",
      "eks:*",
      "iam:GetAccountSummary",
      "ec2:DeleteSnapshot",
      "iam:GetServiceLastAccessedDetailsWithEntities",
      "logs:DescribeLogStreams",
      "iam:ListPoliciesGrantingServiceAccess",
      "ecs:RegisterContainerInstance",
      "ec2messages:GetMessages",
      "iam:ListMFADevices",
      "iam:GetGroup",
      "iam:GetContextKeysForPrincipalPolicy",
      "ecs:Poll",
      "ec2messages:FailMessage",
      "iam:ListAttachedUserPolicies",
      "iam:GetSAMLProvider",
      "ecs:DiscoverPollEndpoint",
      "iam:GetInstanceProfile",
      "logs:DescribeLogGroups",
      "iam:ListUserPolicies",
      "config:PutAggregationAuthorization",
      "iam:ListInstanceProfiles",
      "rds:StopDBInstance",
      "iam:TagUser",
      "logs:PutLogEvents",
      "support:*",
      "iam:UntagUser",
      "lambda:AddPermission",
      "iam:ListPolicyVersions",
      "iam:ListOpenIDConnectProviders",
      "config:PutRetentionConfiguration",
      "ds:DescribeDirectories",
      "iam:ListUsers",
      "iam:ListUserTags",
      "secretsmanager:GetSecretValue",
      "dynamodb:*",
      "kafka-cluster:Connect",
      "kafka-cluster:AlterCluster",
      "kafka-cluster:DescribeCluster",
      "kafka-cluster:DescribeTopic",
      "kafka-cluster:CreateTopic",
      "kafka-cluster:WriteData",
      "kafka-cluster:ReadData"
    ]
  }

  statement {
    sid    = "VisualEditor1"
    effect = "Allow"
    resources = [
      "arn:aws:kafka:eu-central-1:504436705349:cluster/maxffp-msk01/6fa3e304-d396-4767-b1fd-299bf8c9f1b0-4",
      "arn:aws:kafka:eu-central-1:504436705349:topic/maxffp-msk01/6fa3e304-d396-4767-b1fd-299bf8c9f1b0-4/DSRV_STATUS_CHANGES"
    ]

    actions = [
      "kafka-cluster:Connect",
      "kafka-cluster:AlterCluster",
      "kafka-cluster:DescribeCluster",
      "kafka-cluster:DescribeTopic",
      "kafka-cluster:CreateTopic",
      "kafka-cluster:WriteData",
      "kafka-cluster:ReadData"
    ]
  }

  statement {
    sid    = "VisualEditor9"
    effect = "Allow"

    resources = ["arn:aws:iam::019963779799:role/MSK-role"]

    actions = [
      "sts:AssumeRole"
    ]
  }

  statement {
    sid    = ""
    effect = "Allow"

    resources = [
      "arn:aws:kms:eu-central-1:023180329437:key/7fcf7089-a08e-4de9-8177-1a3026ed3a1c",
      "arn:aws:kms:eu-central-1:023180329437:key/c43c70ed-018c-40b0-b70b-5d7fd4a5f58d",
    ]

    actions = [
      "kms:Decrypt",
    ]
  }

}

data "aws_iam_policy_document" "delp2-service-discovery-ECSInstance-DynamoDB" {
  statement {
    sid    = "VisualEditor0"
    effect = "Allow"

    resources = [
      "arn:aws:dynamodb:eu-central-1:023180329437:table/eom-bb-group-store",
      "arn:aws:dynamodb:eu-central-1:023180329437:table/delivery-package-creator",
      "arn:aws:dynamodb:eu-central-1:023180329437:table/delivery-status-publisher-Max",
      "arn:aws:dynamodb:eu-central-1:023180329437:table/delivery-status-publisher",
    ]

    actions = [
      "dynamodb:BatchGetItem",
      "dynamodb:BatchWriteItem",
      "dynamodb:PutItem",
      "dynamodb:DeleteItem",
      "dynamodb:Scan",
      "dynamodb:DescribeStream",
      "dynamodb:Query",
      "dynamodb:UpdateItem",
      "dynamodb:DeleteTable",
      "dynamodb:CreateTable",
      "dynamodb:DescribeTable",
      "dynamodb:GetShardIterator",
      "dynamodb:GetItem",
      "dynamodb:UpdateTable",
      "dynamodb:GetRecords",
    ]
  }

  statement {
    sid       = "VisualEditor1"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "dynamodb:DescribeReservedCapacityOfferings",
      "dynamodb:TagResource",
      "dynamodb:UntagResource",
      "dynamodb:DescribeReservedCapacity",
      "dynamodb:PurchaseReservedCapacityOfferings",
      "dynamodb:ListTagsOfResource",
      "dynamodb:DescribeTimeToLive",
      "dynamodb:DescribeLimits",
      "dynamodb:ListStreams",
    ]
  }

  statement {
    sid    = ""
    effect = "Allow"

    resources = [
      "arn:aws:secretsmanager:eu-central-1:023180329437:secret:PROD/EOM-pY1NZ7",
      "arn:aws:secretsmanager:eu-central-1:023180329437:secret:PROD/RabbitMQ-04CUZl",
      "arn:aws:secretsmanager:eu-central-1:023180329437:secret:PROD/DeliveryPackageCreator/PostgreSql-RDS-DB-b4hkOA",
      "arn:aws:kinesis:eu-central-1:023180329437:stream/StatusUpdateStream",
      "arn:aws:kinesis:eu-central-1:023180329437:stream/EmailStream",
    ]

    actions = [
      "secretsmanager:GetSecretValue",
      "kinesis:*",
    ]
  }
}

data "aws_iam_policy_document" "SES_send_email_only" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "ses:SendEmail",
      "ses:SendRawEmail",
    ]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:sns:eu-west-2:${var.account_id}:LibraryDataResponseTopic"]
    actions   = ["sns:*"]
  }
}

data "aws_iam_policy_document" "Dynamodb_MGSRVAWSConsumers_table_access" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:dynamodb:eu-central-1:${var.account_id}:table/MGSRVAWSConsumers"]

    actions = [
      "dynamodb:BatchGetItem",
      "dynamodb:BatchWriteItem",
      "dynamodb:DeleteItem",
      "dynamodb:DescribeTable",
      "dynamodb:GetItem",
      "dynamodb:GetRecords",
      "dynamodb:ListStreams",
      "dynamodb:ListTagsOfResource",
      "dynamodb:PutItem",
      "dynamodb:Query",
      "dynamodb:Scan",
      "dynamodb:TagResource",
      "dynamodb:UpdateItem",
      "dynamodb:UpdateTable",
      "dynamodb:UntagResource",
    ]
  }
}

data "aws_iam_policy_document" "delivery-package-archiver-policy" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:logs:*:*:*"]
    actions   = ["logs:*"]
  }

  statement {
    sid    = "Stmt1498113445000"
    effect = "Allow"

    resources = [
      "arn:aws:kinesis:eu-central-1:${var.account_id}:stream/ArchivePackageStream",
      "arn:aws:kinesis:eu-central-1:${var.account_id}:stream/EmailStream",
      "arn:aws:kinesis:eu-central-1:${var.account_id}:stream/StatusUpdateStream",
    ]

    actions = ["kinesis:*"]
  }

  statement {
    sid    = "Stmt1486461263700"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delivery-target/*",
      "arn:aws:s3:::sme-delivery-target",
    ]

    actions = ["s3:*"]
  }

  statement {
    sid       = "SecretmanagerRead"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "secretsmanager:DescribeSecret",
      "secretsmanager:List*",
    ]
  }

  statement {
    sid    = "SecretmanagerAccess"
    effect = "Allow"

    resources = [
      "arn:aws:secretsmanager:eu-central-1:${var.account_id}:secret:PROD/DeliveryPackageArchiverLambda-Read/PostgreSql-RDS-DB-yUtkcr",
      "arn:aws:secretsmanager:eu-central-1:${var.account_id}:secret:PROD/DeliveryPackageArchiverLambda-Write/PostgreSql-RDS-DB-C7zZlF",
      "arn:aws:secretsmanager:eu-central-1:${var.account_id}:secret:PROD/EOM-pY1NZ7",
    ]

    actions = ["secretsmanager:*"]
  }
}

data "aws_iam_policy_document" "delp2-delivery-util-ec2-policy" {
  statement {
    sid    = "Stmt1549438521793"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delivery-target",
      "arn:aws:s3:::sme-delivery-target/*",
      "arn:aws:s3:::sme-delivery-messages-prod/*",
      "arn:aws:s3:::sme-delivery-messages-prod"


    ]

    actions = ["s3:*"]
  }

  statement {
    sid    = "Stmt1549438568635"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-conversion-shelf",
      "arn:aws:s3:::sme-conversion-shelf/*",
    ]

    actions = ["s3:*"]
  }

  statement {
    sid    = "Stmt1549438653093"
    effect = "Allow"

    resources = [
      "arn:aws:sqs:eu-central-1:023180329437:SFTPMsDeliveryQueue",
      "arn:aws:sqs:eu-central-1:023180329437:S3v2DeliveryQ.fifo",
      "arn:aws:sqs:eu-central-1:023180329437:S3v2DeliveryDLQ.fifo",
    ]

    actions = ["sqs:*"]
  }

  statement {
    sid       = "Stmt1549438685546"
    effect    = "Allow"
    resources = ["arn:aws:sqs:eu-central-1:023180329437:S3MsDeliveryQueue"]
    actions   = ["sqs:*"]
  }

  statement {
    sid       = "Stmt1549438719887"
    effect    = "Allow"
    resources = ["arn:aws:sqs:eu-central-1:023180329437:TransporterMsDeliveryQueue"]
    actions   = ["sqs:*"]
  }

  statement {
    sid       = "Stmt1549438747237"
    effect    = "Allow"
    resources = ["arn:aws:sqs:eu-central-1:023180329437:AsperaMsDeliveryQueue"]
    actions   = ["sqs:*"]
  }

  statement {
    sid       = "Stmt1498113445000"
    effect    = "Allow"
    resources = ["arn:aws:kinesis:eu-central-1:023180329437:stream/EmailStream"]
    actions   = ["kinesis:PutRecord"]
  }

  statement {
    sid    = "KMSAccess"
    effect = "Allow"
    resources = [
      "arn:aws:kms:us-east-1:505950216627:key/82a0a889-eba8-4c5c-92ff-2a72e8b1f78b",
      "arn:aws:kms:us-east-1:522970592647:key/mrk-1dc52a5518e34c28b10eeb32130f6b71",
    ]

    actions = [
      "kms:Decrypt",
      "kms:GenerateDataKey",
    ]
  }
}

data "aws_iam_policy_document" "universal-email-notifier-policy" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:kinesis:eu-central-1:${var.account_id}:stream/EmailStream"]

    actions = [
      "kinesis:DescribeStream",
      "kinesis:GetRecords",
      "kinesis:GetShardIterator",
      "kinesis:ListStreams",
      "logs:CreateLogGroup",
      "logs:CreateLogStream",
      "logs:PutLogEvents",
    ]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "ses:SendEmail",
      "ses:SendRawEmail",
      "logs:CreateLogGroup",
      "logs:CreateLogStream",
      "logs:PutLogEvents",
    ]
  }

  statement {
    sid    = ""
    effect = "Allow"

    resources = [
      "arn:aws:dynamodb:eu-central-1:${var.account_id}:table/email_notifications",
      "arn:aws:dynamodb:eu-central-1:${var.account_id}:table/email_notification_config",
    ]

    actions = [
      "dynamodb:*",
      "dax:*",
      "application-autoscaling:DeleteScalingPolicy",
      "application-autoscaling:DeregisterScalableTarget",
      "application-autoscaling:DescribeScalableTargets",
      "application-autoscaling:DescribeScalingActivities",
      "application-autoscaling:DescribeScalingPolicies",
      "application-autoscaling:PutScalingPolicy",
      "application-autoscaling:RegisterScalableTarget",
      "cloudwatch:DeleteAlarms",
      "cloudwatch:DescribeAlarmHistory",
      "cloudwatch:DescribeAlarms",
      "cloudwatch:DescribeAlarmsForMetric",
      "cloudwatch:GetMetricStatistics",
      "cloudwatch:ListMetrics",
      "cloudwatch:PutMetricAlarm",
      "datapipeline:ActivatePipeline",
      "datapipeline:CreatePipeline",
      "datapipeline:DeletePipeline",
      "datapipeline:DescribeObjects",
      "datapipeline:DescribePipelines",
      "datapipeline:GetPipelineDefinition",
      "datapipeline:ListPipelines",
      "datapipeline:PutPipelineDefinition",
      "datapipeline:QueryObjects",
      "ec2:DescribeVpcs",
      "ec2:DescribeSubnets",
      "ec2:DescribeSecurityGroups",
      "iam:GetRole",
      "iam:ListRoles",
      "sns:CreateTopic",
      "sns:DeleteTopic",
      "sns:ListSubscriptions",
      "sns:ListSubscriptionsByTopic",
      "sns:ListTopics",
      "sns:Subscribe",
      "sns:Unsubscribe",
      "sns:SetTopicAttributes",
      "lambda:CreateFunction",
      "lambda:ListFunctions",
      "lambda:ListEventSourceMappings",
      "lambda:CreateEventSourceMapping",
      "lambda:DeleteEventSourceMapping",
      "lambda:GetFunctionConfiguration",
      "lambda:DeleteFunction",
    ]
  }

  statement {
    sid    = ""
    effect = "Allow"

    resources = [
      "arn:aws:dynamodb:eu-central-1:${var.account_id}:table/email_notifications",
      "arn:aws:dynamodb:eu-central-1:${var.account_id}:table/email_notification_config",
    ]

    actions = ["iam:PassRole"]

    condition {
      test     = "StringLike"
      variable = "iam:PassedToService"

      values = [
        "application-autoscaling.amazonaws.com",
        "dax.amazonaws.com",
      ]
    }
  }
}

data "aws_iam_policy_document" "sme-delivery-pkg-creator-policy" {
  statement {
    sid    = ""
    effect = "Allow"

    resources = [
      "arn:aws:kinesis:eu-central-1:${var.account_id}:stream/OrderStream",
      "arn:aws:kinesis:eu-central-1:${var.account_id}:stream/EmailStream",
    ]

    actions = ["kinesis:*"]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]
    actions   = ["cloudwatch:PutMetricData"]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:dynamodb:eu-central-1:${var.account_id}:table/delivery-package-creator"]
    actions   = ["dynamodb:*"]
  }
}

data "aws_iam_policy_document" "AWSLambdaS3ExecutionRole-2abec43b-af07-4025-af5f-a2dc6865c49c" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:s3:::*"]
    actions   = ["s3:GetObject"]
  }
}

data "aws_iam_policy_document" "StatesExecutionPolicy-us-east-1" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]
    actions   = ["lambda:InvokeFunction"]
  }
}

data "aws_iam_policy_document" "prod-packager-policy" {
  #checkov:skip=CKV_AWS_108: Ensure IAM policies does not allow data exfiltration
  statement {
    sid    = "VisualEditor0"
    effect = "Allow"

    resources = [
      "arn:aws:sqs:eu-central-1:023180329437:SonyCiDeliveryQueue",
      "arn:aws:kinesis:eu-central-1:023180329437:stream/EmailStream",
    ]

    actions = [
      "sqs:*",
      "kinesis:PutRecord",
    ]
  }

  statement {
    sid       = "VisualEditor1"
    effect    = "Allow"
    resources = ["*"]
    actions   = ["sqs:ListQueues"]
  }

  statement {
    sid    = "VisualEditor2"
    effect = "Allow"

    resources = [
      "arn:aws:sqs:eu-central-1:023180329437:TransporterMsDeliveryQueue",
      "arn:aws:sqs:eu-central-1:023180329437:TransporterDeliveryQueue",
      "arn:aws:sqs:eu-central-1:023180329437:SftpDeliveryQueue",
      "arn:aws:sqs:eu-central-1:023180329437:SFTPMsDeliveryQueue",
      "arn:aws:sqs:eu-central-1:023180329437:S3MsDeliveryQueue",
      "arn:aws:sqs:eu-central-1:023180329437:S3DeliveryQueue",
      "arn:aws:sqs:eu-central-1:023180329437:GcsDeliveryQ.fifo",
      "arn:aws:sqs:eu-central-1:023180329437:AsperaMsDeliveryQueue",
      "arn:aws:sqs:eu-central-1:023180329437:AsperaDeliveryQueue",
      "arn:aws:sqs:eu-central-1:023180329437:S3v2DeliveryQ.fifo",
      "arn:aws:sqs:eu-central-1:023180329437:S3v2DeliveryDLQ.fifo",
    ]

    actions = ["sqs:*"]
  }

  statement {
    sid    = "VisualEditor3"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delivery-target/*",
      "arn:aws:s3:::sme-delivery-target",
      "arn:aws:s3:::sme-delivery-messages-prod/*",
      "arn:aws:s3:::sme-delivery-messages-prod",
      "arn:aws:s3:::sme-delivery-messages-prod/*",
      "arn:aws:s3:::sme-conversion-shelf/*",
      "arn:aws:s3:::sme-conversion-shelf",
    ]

    actions = ["s3:*"]
  }

  statement {
    sid       = "VisualEditor4"
    effect    = "Allow"
    resources = ["*"]
    actions   = ["secretsmanager:GetSecretValue"]
  }
}

data "aws_iam_policy_document" "StatesExecutionPolicy-eu-central-1" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]
    actions   = ["lambda:InvokeFunction"]
  }
}

data "aws_iam_policy_document" "policy-gen-scops" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:s3:::*"]

    actions = [
      "s3:GetBucketLocation",
      "s3:ListAllMyBuckets",
    ]
  }

  statement {
    sid    = ""
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delivery-target",
      "arn:aws:s3:::sme-media-production",
    ]

    actions = ["s3:ListBucket"]
  }

  statement {
    sid    = ""
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delivery-target/*",
      "arn:aws:s3:::sme-media-production/*",
    ]

    actions = [
      "s3:GetObject",
      "s3:PutObject",
      "s3:DeleteObject",
    ]
  }
}

data "aws_iam_policy_document" "delivery_package_purge_execution_policy" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "logs:CreateLogGroup",
      "logs:CreateLogStream",
      "logs:PutLogEvents",
      "ec2:CreateNetworkInterface",
      "ec2:DescribeNetworkInterfaces",
      "ec2:DeleteNetworkInterface",
    ]
  }

  statement {
    sid    = ""
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delivery-target",
      "arn:aws:s3:::sme-delivery-target/*",
    ]

    actions = [
      "s3:DeleteObject",
      "s3:List*",
    ]
  }
}

data "aws_iam_policy_document" "GSIRT_AWS_S3AccessLog_Collection" {
  statement {
    sid    = ""
    effect = "Allow"

    resources = [
      "arn:aws:sqs:eu-west-2:${var.account_id}:delp-LBAccessLogs-ln",
      "arn:aws:sqs:eu-central-1:${var.account_id}:delp-LBAccessLogs-ff",
      "arn:aws:sqs:us-east-1:${var.account_id}:delp-CFAccessLogs",
      "arn:aws:sqs:eu-central-1:${var.account_id}:delp-S3AccessLogs-ff",
      "arn:aws:sqs:eu-west-2:${var.account_id}:delp-S3AccessLogs-ln",
      "arn:aws:sqs:us-east-1:${var.account_id}:delp-S3AccessLogs-va",
      "arn:aws:sqs:us-east-1:${var.account_id}:delp-LBAccessLogs-va",
      "arn:aws:s3:::delp-frankfurt-elb-logs/*",
      "arn:aws:s3:::delp-frankfurt-elb-logs",
      "arn:aws:s3:::delp-london-elb-logs/*",
      "arn:aws:s3:::delp-london-elb-logs",
      "arn:aws:s3:::sme-delivery-cf-logs/*",
      "arn:aws:s3:::sme-delivery-cf-logs",
      "arn:aws:s3:::sme-aoma-delivery-prod-eu-central-1-logs/*",
      "arn:aws:s3:::sme-aoma-delivery-prod-eu-central-1-logs",
      "arn:aws:s3:::sme-aoma-delivery-prod-eu-west-2-logs/*",
      "arn:aws:s3:::sme-aoma-delivery-prod-eu-west-2-logs",
      "arn:aws:s3:::sme-aoma-delivery-prod-us-east-1-logs/*",
      "arn:aws:s3:::sme-aoma-delivery-prod-us-east-1-logs",
      "arn:aws:s3:::sme-aoma-delivery-prod-us-west-2-logs",
      "arn:aws:s3:::sme-aoma-delivery-prod-us-west-2-logs/*",
      "arn:aws:s3:::delp-virginia-elb-logs",
      "arn:aws:s3:::delp-virginia-elb-logs/*",
    ]

    actions = [
      "sqs:GetQueueUrl",
      "sqs:ReceiveMessage",
      "sqs:SendMessage",
      "sqs:DeleteMessage",
      "sqs:ChangeMessageVisibility",
      "sqs:GetQueueAttributes",
      "sqs:ListQueues",
      "s3:GetObject",
      "s3:GetObjectVersion",
      "kms:Decrypt",
    ]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]
    actions   = ["sqs:ListQueues"]
  }
}

data "aws_iam_policy_document" "CloudOpsDenyIAM" {
  statement {
    sid       = "VisualEditor0"
    effect    = "Deny"
    resources = ["*"]

    actions = [
      "iam:UpdateAssumeRolePolicy",
      "iam:DeactivateMFADevice",
      "iam:CreateServiceSpecificCredential",
      "iam:DeleteAccessKey",
      "iam:DeleteGroup",
      "iam:UpdateOpenIDConnectProviderThumbprint",
      "iam:RemoveRoleFromInstanceProfile",
      "iam:UpdateGroup",
      "iam:CreateRole",
      "iam:AttachRolePolicy",
      "iam:PutRolePolicy",
      "iam:AddRoleToInstanceProfile",
      "iam:CreateLoginProfile",
      "iam:DetachRolePolicy",
      "iam:CreateAccountAlias",
      "iam:DeleteServerCertificate",
      "iam:UploadSSHPublicKey",
      "iam:DetachGroupPolicy",
      "iam:DetachUserPolicy",
      "iam:DeleteOpenIDConnectProvider",
      "iam:ChangePassword",
      "iam:PutGroupPolicy",
      "iam:UpdateLoginProfile",
      "iam:UpdateServiceSpecificCredential",
      "iam:CreateGroup",
      "iam:RemoveClientIDFromOpenIDConnectProvider",
      "iam:UpdateUser",
      "iam:DeleteUserPolicy",
      "iam:AttachUserPolicy",
      "iam:DeleteRole",
      "iam:UpdateRoleDescription",
      "iam:UpdateAccessKey",
      "iam:UpdateSSHPublicKey",
      "iam:UpdateServerCertificate",
      "iam:DeleteSigningCertificate",
      "iam:UpdateAccountPasswordPolicy",
      "iam:DeleteServiceLinkedRole",
      "iam:CreateInstanceProfile",
      "iam:UntagRole",
      "iam:PutRolePermissionsBoundary",
      "iam:TagRole",
      "iam:ResetServiceSpecificCredential",
      "iam:DeletePolicy",
      "iam:DeleteSSHPublicKey",
      "iam:CreateVirtualMFADevice",
      "iam:CreateSAMLProvider",
      "iam:DeleteRolePermissionsBoundary",
      "iam:CreateUser",
      "iam:CreateAccessKey",
      "iam:AddUserToGroup",
      "iam:RemoveUserFromGroup",
      "iam:DeleteRolePolicy",
      "iam:EnableMFADevice",
      "iam:ResyncMFADevice",
      "iam:DeleteAccountAlias",
      "iam:CreatePolicyVersion",
      "iam:UpdateSAMLProvider",
      "iam:DeleteLoginProfile",
      "iam:DeleteInstanceProfile",
      "iam:UploadSigningCertificate",
      "iam:DeleteAccountPasswordPolicy",
      "iam:PutUserPermissionsBoundary",
      "iam:DeleteUser",
      "iam:DeleteUserPermissionsBoundary",
      "iam:TagUser",
      "iam:CreateOpenIDConnectProvider",
      "iam:UploadServerCertificate",
      "iam:CreatePolicy",
      "iam:UntagUser",
      "iam:CreateServiceLinkedRole",
      "iam:DeleteVirtualMFADevice",
      "iam:AttachGroupPolicy",
      "iam:PutUserPolicy",
      "iam:UpdateRole",
      "iam:UpdateSigningCertificate",
      "iam:DeleteGroupPolicy",
      "iam:AddClientIDToOpenIDConnectProvider",
      "iam:DeleteServiceSpecificCredential",
      "iam:DeletePolicyVersion",
      "iam:SetDefaultPolicyVersion",
      "iam:DeleteSAMLProvider",
    ]
  }
}

data "aws_iam_policy_document" "ytclaims-ecsInstancePolicy" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  #checkov:skip=CKV_AWS_109: Ensure IAM policies does not allow permissions management / resource exposure without constraints
  #checkov:skip=CKV_AWS_108: Ensure IAM policies does not allow data exfiltration
  statement {
    sid       = "Stmt1505834883174"
    effect    = "Allow"
    resources = ["arn:aws:dynamodb:eu-west-2:${var.account_id}:table/ytcms_db"]
    actions   = ["dynamodb:*"]
  }

  statement {
    sid       = "Stmt1505835163078"
    effect    = "Allow"
    resources = ["*"]
    actions   = ["ses:*"]
  }

  statement {
    sid    = ""
    effect = "Allow"

    resources = [
      "arn:aws:sqs:eu-central-1:${var.account_id}:LibraryDataRequestQueue",
      "arn:aws:sqs:eu-central-1:${var.account_id}:LibraryDataResponseProdQueue",
    ]

    actions = ["sqs:*"]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "cloudwatch:PutMetricData",
      "logs:CreateLogStream",
      "logs:PutLogEvents",
      "s3:*",
    ]
  }
}

data "aws_iam_policy_document" "delivery-order-lambda-function-execution-policy" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:logs:*:*:*"]

    actions = [
      "logs:CreateLogGroup",
      "logs:CreateLogStream",
      "logs:PutLogEvents",
    ]
  }

  statement {
    sid    = ""
    effect = "Allow"

    resources = [
      "arn:aws:kinesis:eu-central-1:${var.account_id}:stream/OrderStream",
      "arn:aws:kinesis:eu-central-1:${var.account_id}:stream/OrderStream-Orchard",
      "arn:aws:kinesis:eu-central-1:${var.account_id}:stream/OrderStream-TEST",
    ]

    actions = ["kinesis:*"]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "ec2:CreateNetworkInterface",
      "ec2:DescribeNetworkInterfaces",
      "ec2:DescribeSubnets",
      "ec2:DeleteNetworkInterface",
      "ec2:AssignPrivateIpAddresses",
      "ec2:UnassignPrivateIpAddresses"
    ]
  }
}

data "aws_iam_policy_document" "observable-policy" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "autoscaling:Describe*",
      "cloudtrail:LookupEvents",
      "ec2:Describe*",
      "elasticache:Describe*",
      "elasticache:List*",
      "elasticloadbalancing:Describe*",
      "iam:Get*",
      "iam:List*",
      "inspector:*",
      "rds:Describe*",
      "rds:List*",
      "redshift:Describe*",
      "workspaces:Describe*",
      "route53:List*",
    ]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "logs:Describe*",
      "logs:GetLogEvents",
      "logs:FilterLogEvents",
      "logs:PutSubscriptionFilter",
      "logs:DeleteSubscriptionFilter",
    ]
  }
}

data "aws_iam_policy_document" "S3-delivery-target" {
  statement {
    sid    = "Stmt1500930890000"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delivery-target/",
      "arn:aws:s3:::sme-delivery-target/*",
    ]

    actions = ["s3:*"]
  }
}
data "aws_iam_policy_document" "warner-ada-s3" {
  statement {
    sid       = "VisualEdior1"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "s3:ListStorageLensConfigurations",
      "s3:ListAccessPointsForObjectLambda",
      "s3:GetAccessPoint",
      "s3:PutAccountPublicAccessBlock",
      "s3:GetAccountPublicAccessBlock",
      "s3:ListAllMyBuckets",
      "s3:ListAccessPoints",
      "s3:ListJobs",
      "s3:PutStorageLensConfiguration",
      "s3:CreateJob",
    ]
  }
  statement {
    sid    = "Stmt150093000"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-media-production/",
      "arn:aws:s3:::sme-media-production/dBpm_Records_Assets/*",
    ]

    actions = [
      "s3:ListAccessPointsForObjectLambda",
      "s3:GetObjectVersionTagging",
      "s3:GetStorageLensConfigurationTagging",
      "s3:ReplicateObject",
      "s3:GetObjectAcl",
      "s3:GetBucketObjectLockConfiguration",
      "s3:GetIntelligentTieringConfiguration",
      "s3:GetObjectVersionAcl",
      "s3:DeleteObject",
      "s3:GetBucketPolicyStatus",
      "s3:GetObjectRetention",
      "s3:GetBucketWebsite",
      "s3:GetJobTagging",
      "s3:ListJobs",
      "s3:GetMultiRegionAccessPoint",
      "s3:GetObjectAttributes",
      "s3:GetObjectLegalHold",
      "s3:GetBucketNotification",
      "s3:DescribeMultiRegionAccessPointOperation",
      "s3:GetReplicationConfiguration",
      "s3:ListMultipartUploadParts",
      "s3:PutObject",
      "s3:GetObject",
      "s3:DescribeJob",
      "s3:PutObjectVersionAcl",
      "s3:GetAnalyticsConfiguration",
      "s3:GetObjectVersionForReplication",
      "s3:GetAccessPointForObjectLambda",
      "s3:GetStorageLensDashboard",
      "s3:GetLifecycleConfiguration",
      "s3:GetAccessPoint",
      "s3:GetInventoryConfiguration",
      "s3:GetBucketTagging",
      "s3:GetAccessPointPolicyForObjectLambda",
      "s3:GetBucketLogging",
      "s3:ListBucketVersions",
      "s3:RestoreObject",
      "s3:ListBucket",
      "s3:GetAccelerateConfiguration",
      "s3:GetObjectVersionAttributes",
      "s3:GetBucketPolicy",
      "s3:GetEncryptionConfiguration",
      "s3:GetObjectVersionTorrent",
      "s3:GetBucketRequestPayment",
      "s3:GetAccessPointPolicyStatus",
      "s3:GetObjectTagging",
      "s3:GetMetricsConfiguration",
      "s3:GetBucketOwnershipControls",
      "s3:PutObjectAcl",
      "s3:GetBucketPublicAccessBlock",
      "s3:GetMultiRegionAccessPointPolicyStatus",
      "s3:ListBucketMultipartUploads",
      "s3:GetMultiRegionAccessPointPolicy",
      "s3:GetAccessPointPolicyStatusForObjectLambda",
      "s3:ListAccessPoints",
      "s3:PutMetricsConfiguration",
      "s3:GetBucketVersioning",
      "s3:ListMultiRegionAccessPoints",
      "s3:GetBucketAcl",
      "s3:GetAccessPointConfigurationForObjectLambda",
      "s3:ListStorageLensConfigurations",
      "s3:GetObjectTorrent",
      "s3:GetMultiRegionAccessPointRoutes",
      "s3:GetStorageLensConfiguration",
      "s3:GetAccountPublicAccessBlock",
      "s3:ListAllMyBuckets",
      "s3:PutObjectRetention",
      "s3:GetBucketCORS",
      "s3:GetBucketLocation",
      "s3:GetAccessPointPolicy",
      "s3:ReplicateDelete",
      "s3:GetObjectVersion"
    ]
  }
}
data "aws_iam_policy_document" "AWSLambdaBasicExecutionRole-d4de3375-ed2f-4ce1-bb66-43b8d21ac6be" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:logs:eu-central-1:${var.account_id}:*"]
    actions   = ["logs:CreateLogGroup"]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:logs:eu-central-1:${var.account_id}:log-group:/aws/lambda/s3-logs:*"]

    actions = [
      "logs:CreateLogStream",
      "logs:PutLogEvents",
    ]
  }
}

data "aws_iam_policy_document" "ScOps-S3" {
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["arn:aws:s3:::*"]
    actions   = ["s3:GetObject"]
  }

  statement {
    sid       = "VisualEditor1"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "s3:ListStorageLensConfigurations",
      "s3:ListAccessPointsForObjectLambda",
      "s3:GetAccessPoint",
      "s3:PutAccountPublicAccessBlock",
      "s3:GetAccountPublicAccessBlock",
      "s3:ListAllMyBuckets",
      "s3:ListAccessPoints",
      "s3:ListJobs",
      "s3:PutStorageLensConfiguration",
      "s3:CreateJob",
    ]
  }

  statement {
    sid    = "VisualEditor2"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delivery-uat-target",
      "arn:aws:s3:::sme-delivery-uat-target/*",
    ]

    actions = ["s3:*"]
  }

  statement {
    sid       = "VisualEditor3"
    effect    = "Allow"
    resources = ["arn:aws:sqs:eu-central-1:058029036333:BBSmartSftpDeliveryQueue"]
    actions   = ["sqs:*"]
  }
}

data "aws_iam_policy_document" "ecs_create_service" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  #checkov:skip=CKV_AWS_109: Ensure IAM policies does not allow permissions management / resource exposure without constraints
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "application-autoscaling:Describe*",
      "application-autoscaling:PutScalingPolicy",
      "application-autoscaling:RegisterScalableTarget",
      "cloudwatch:DescribeAlarms",
      "cloudwatch:PutMetricAlarm",
      "ecs:List*",
      "ecs:Describe*",
      "ecs:CreateService",
      "ecs:UpdateService",
      "elasticloadbalancing:Describe*",
      "iam:AttachRolePolicy",
      "iam:CreateRole",
      "iam:GetPolicy",
      "iam:GetPolicyVersion",
      "iam:GetRole",
      "iam:ListAttachedRolePolicies",
      "iam:ListRoles",
      "iam:ListGroups",
      "iam:ListUsers",
      "SecretsManager:*",
    ]
  }
}

data "aws_iam_policy_document" "tagging_policy" {
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "s3:DeleteObjectTagging",
      "rds:AddTagsToResource",
      "redshift:DeleteTags",
      "s3:ListBucketByTags",
      "redshift:CreateTags",
      "s3:GetBucketTagging",
      "ec2:DeleteTags",
      "s3:GetObjectVersionTagging",
      "elasticloadbalancing:DescribeTags",
      "ec2:DescribeTags",
      "ec2:CreateTags",
      "s3:ReplicateTags",
      "s3:PutObjectVersionTagging",
      "redshift:DescribeTags",
      "s3:DeleteObjectVersionTagging",
      "elasticloadbalancing:RemoveTags",
      "rds:ListTagsForResource",
      "s3:PutBucketTagging",
      "elasticloadbalancing:AddTags",
      "s3:GetObjectTagging",
      "s3:PutObjectTagging",
      "rds:RemoveTagsFromResource",
    ]
  }
}

data "aws_iam_policy_document" "ECR-Access" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  #checkov:skip=CKV_AWS_109: Ensure IAM policies does not allow permissions management / resource exposure without constraints
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "ecr:*",
      "eks:DescribeCluster",
    ]
  }
}

data "aws_iam_policy_document" "DatadogAWSIntegrationPolicy" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  #checkov:skip=CKV_AWS_107: Ensure IAM policies does not allow credentials exposure
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "autoscaling:Describe*",
      "budgets:ViewBudget",
      "cloudtrail:DescribeTrails",
      "cloudtrail:GetTrailStatus",
      "cloudwatch:Describe*",
      "cloudwatch:Get*",
      "cloudwatch:List*",
      "codedeploy:List*",
      "codedeploy:BatchGet*",
      "directconnect:Describe*",
      "dynamodb:List*",
      "dynamodb:Describe*",
      "ec2:Describe*",
      "ec2:Get*",
      "ecs:Describe*",
      "ecs:List*",
      "elasticache:Describe*",
      "elasticache:List*",
      "elasticfilesystem:DescribeFileSystems",
      "elasticfilesystem:DescribeTags",
      "elasticloadbalancing:Describe*",
      "elasticmapreduce:List*",
      "elasticmapreduce:Describe*",
      "es:ListTags",
      "es:ListDomainNames",
      "es:DescribeElasticsearchDomains",
      "kinesis:List*",
      "kinesis:Describe*",
      "lambda:List*",
      "lambda:ListFunctions",
      "lambda:ListTags",
      "logs:Get*",
      "logs:Describe*",
      "logs:FilterLogEvents",
      "logs:TestMetricFilter",
      "rds:Describe*",
      "rds:List*",
      "route53:List*",
      "s3:GetBucketTagging",
      "s3:ListAllMyBuckets",
      "ses:Get*",
      "sns:List*",
      "sns:Publish",
      "sqs:ListQueues",
      "support:*",
      "tag:getResources",
      "tag:getTagKeys",
      "tag:getTagValues",
    ]
  }
}

data "aws_iam_policy_document" "ecs_task_definition" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "ecs:RegisterTaskDefinition",
      "ecs:ListTaskDefinitions",
      "ecs:DescribeTaskDefinition",
    ]
  }
}

data "aws_iam_policy_document" "AthenaRO" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "athena:GetQueryResultsStream",
      "athena:GetNamespace",
      "athena:GetQueryResults",
      "athena:GetQueryExecutions",
      "athena:ListWorkGroups",
      "athena:GetNamedQuery",
      "athena:GetCatalogs",
      "athena:ListQueryExecutions",
      "athena:ListNamedQueries",
      "athena:GetNamespaces",
      "athena:GetWorkGroup",
      "athena:GetExecutionEngine",
      "athena:GetQueryExecution",
      "athena:GetExecutionEngines",
      "athena:GetTables",
      "athena:GetTable",
      "athena:BatchGetNamedQuery",
      "athena:BatchGetQueryExecution",
      "athena:StartQueryExecution",
      "athena:CreateNamedQuery",
    ]
  }
}

data "aws_iam_policy_document" "AWS_ECR_Access" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  #checkov:skip=CKV_AWS_109: Ensure IAM policies does not allow permissions management / resource exposure without constraints
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]
    actions = [
      "ecr:*",
      "ec2:CreateNetworkInterface",
      "ec2:DescribeNetworkInterfaces",
      "ec2:DeleteNetworkInterface",
      "apigateway:DELETE",
      "apigateway:GET",
      "wafv2:ListWebACLs",
      "wafv2:GetWebACLForResource",
      "wafv2:GetWebACL",
      "apigateway:DELETE",
      "apigateway:UpdateRestApiPolicy",
      "apigateway:SetWebACL",
      "ec2:CreateVpcEndpoint",
      "apigateway:POST",
      "wafv2:AssociateWebACL",
    ]
  }

  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "kinesis:ListStreams",
      "kinesis:EnableEnhancedMonitoring",
      "kinesis:ListShards",
      "kinesis:UpdateShardCount",
      "kinesis:DescribeLimits",
      "kinesis:ListStreamConsumers",
      "kinesis:DisableEnhancedMonitoring",
    ]
  }

  statement {
    sid    = "VisualEditor2"
    effect = "Allow"

    resources = [
      "arn:aws:sqs:eu-central-1:023180329437:AzureDeliveryQ.fifo",
      "arn:aws:sqs:eu-central-1:023180329437:AomaRequestQueue",
    ]

    actions = [
      "sqs:SendMessage",
      "sqs:DeleteMessage",
    ]
  }

  statement {
    sid       = "VisualEditor1"
    effect    = "Allow"
    resources = ["arn:aws:kinesis:eu-central-1:023180329437:stream/StatusUpdateStream"]
    actions   = ["kinesis:*"]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]
    actions   = ["eks:DescribeCluster"]
  }

  statement {
    sid    = "VisualEditor3"
    effect = "Allow"
    resources = [
      "arn:aws:kafka:us-east-1:019963779799:cluster/order-history-prod/81ba30ef-9861-4004-b945-cbbfb1654b18-6",
      "arn:aws:kafka:us-east-1:019963779799:topic/order-history-prod/81ba30ef-9861-4004-b945-cbbfb1654b18-6/dsrv-conversion-metadata"
    ]

    actions = [
      "kafka-cluster:Connect",
      "kafka-cluster:AlterCluster",
      "kafka-cluster:DescribeCluster",
      "kafka-cluster:DescribeTopic",
      "kafka-cluster:CreateTopic",
      "kafka-cluster:WriteData",
      "kafka-cluster:ReadData"
    ]
  }
}

data "aws_iam_policy_document" "lambda_elasticsearch_execution_policy" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:es:eu-central-1:${var.account_id}:domain/delivery-prod-dockers/*"]
    actions   = ["es:*"]
  }
}

data "aws_iam_policy_document" "sme-delivery-test-target" {
  statement {
    sid    = "Stmt1476951673001"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delivery-test-target/",
      "arn:aws:s3:::sme-delivery-test-target/*",
    ]

    actions = ["s3:*"]
  }
}

data "aws_iam_policy_document" "oneClick_CloudTrail_CloudWatchLogs_Role_1540805881069" {
  statement {
    sid       = "AWSCloudTrailCreateLogStream20141101"
    effect    = "Allow"
    resources = ["arn:aws:logs:ap-south-1:${var.account_id}:log-group:CloudTrail/AlertLogicCT:log-stream:${var.account_id}_CloudTrail_ap-south-1*"]
    actions   = ["logs:CreateLogStream"]
  }

  statement {
    sid       = "AWSCloudTrailPutLogEvents20141101"
    effect    = "Allow"
    resources = ["arn:aws:logs:ap-south-1:${var.account_id}:log-group:CloudTrail/AlertLogicCT:log-stream:${var.account_id}_CloudTrail_ap-south-1*"]
    actions   = ["logs:PutLogEvents"]
  }
}

data "aws_iam_policy_document" "oneClick_lambda_basic_execution_1542093202278" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:logs:*:*:*"]

    actions = [
      "logs:CreateLogGroup",
      "logs:CreateLogStream",
      "logs:PutLogEvents",
    ]
  }
}

data "aws_iam_policy_document" "CWLogs-Put" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]
    actions   = ["logs:PutLogEvents"]
  }
}

data "aws_iam_policy_document" "delp-dsrv-prod-eks-ns-delivery-prod-sony-ci-transfer-policy" {
  statement {
    sid    = "VisualEditor0"
    effect = "Allow"
    resources = [
      "arn:aws:s3:::sme-delivery-target",
      "arn:aws:s3:::sme-delivery-aoma-upload",
      "arn:aws:s3:::sme-delivery-user-upload"
    ]

    actions = [
      "s3:ListBucketMultipartUploads",
      "s3:ListBucket",
      "s3:ListMultipartUploadParts",
      "s3:PutEncryptionConfiguration",
      "s3:PutObject",
      "s3:GetObject",
      "s3:AbortMultipartUpload",
      "s3:DeleteObject",
      "s3:ListObjectsV2",
      "s3:ListAllMyBuckets",
      "s3:ListObjects",
      "s3:CopyObject",
    ]
  }

  statement {
    sid       = "VisualEditor1"
    effect    = "Allow"
    resources = ["arn:aws:kinesis:eu-central-1:023180329437:stream/EmailStream"]

    actions = [
      "sts:AssumeRoleWithWebIdentity",
      "kinesis:DescribeStream",
      "kinesis:GetShardIterator",
      "kinesis:GetRecords",
      "kinesis:PutRecord",
      "kinesis:PutRecords",
    ]
  }

  statement {
    sid       = "VisualEditor3"
    effect    = "Allow"
    resources = ["arn:aws:sqs:eu-central-1:023180329437:SonyCiDeliveryQueue"]

    actions = [
      "sqs:ListQueues",
      "sqs:SendMessageBatch",
      "sqs:DeleteMessage",
      "sqs:GetQueueUrl",
      "sqs:ReceiveMessage",
      "sqs:SendMessage",
      "sqs:GetQueueAttributes",
      "sqs:ListQueueTags",
      "sqs:PurgeQueue",
      "sqs:DeleteQueue",
      "sqs:CreateQueue",
      "sqs:SetQueueAttributes",
    ]
  }

  statement {
    sid    = "VisualEditor4"
    effect = "Allow"

    resources = [
      "arn:aws:sqs:eu-central-1:023180329437:S3v2DeliveryDLQ.fifo",
      "arn:aws:sqs:eu-central-1:023180329437:S3v2DeliveryQ.fifo",
    ]

    actions = ["sqs:*"]
  }
}

data "aws_iam_policy_document" "iam-pass-policy" {
  #checkov:skip=CKV_AWS_109: Ensure IAM policies does not allow permissions management / resource exposure without constraints
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]
    actions   = ["iam:PassRole"]
  }
}

data "aws_iam_policy_document" "oneClick_Cognito_ytcp_ytclaimsUnauth_Role_1599458257462" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "mobileanalytics:PutEvents",
      "cognito-sync:*",
    ]
  }
}

data "aws_iam_policy_document" "AWSLambdaBasicExecutionRole-9d455ba9-bc54-4811-967b-c1e90c6e83cc" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:logs:eu-central-1:${var.account_id}:*"]
    actions   = ["logs:CreateLogGroup"]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:logs:eu-central-1:${var.account_id}:log-group:/aws/lambda/domain_resolve_test:*"]

    actions = [
      "logs:CreateLogStream",
      "logs:PutLogEvents",
    ]
  }
}

data "aws_iam_policy_document" "oneClick_CloudTrail_CloudWatchLogs_Role_1540806989651" {
  statement {
    sid       = "AWSCloudTrailCreateLogStream20141101"
    effect    = "Allow"
    resources = ["arn:aws:logs:ca-central-1:${var.account_id}:log-group:CloudTrail/AlertLogicCT:log-stream:${var.account_id}_CloudTrail_ca-central-1*"]
    actions   = ["logs:CreateLogStream"]
  }

  statement {
    sid       = "AWSCloudTrailPutLogEvents20141101"
    effect    = "Allow"
    resources = ["arn:aws:logs:ca-central-1:${var.account_id}:log-group:CloudTrail/AlertLogicCT:log-stream:${var.account_id}_CloudTrail_ca-central-1*"]
    actions   = ["logs:PutLogEvents"]
  }
}

data "aws_iam_policy_document" "lambda-pitch-app-track-loader-lambda-function" {
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "lambda:ListFunctions",
      "lambda:ListEventSourceMappings",
      "lambda:ListLayerVersions",
      "lambda:ListLayers",
      "lambda:GetAccountSettings",
      "lambda:CreateEventSourceMapping",
    ]
  }

  statement {
    sid       = "VisualEditor1"
    effect    = "Allow"
    resources = ["arn:aws:lambda:us-west-2:${var.account_id}:function:pitch-app-track-loader-lambda-function"]
    actions   = ["lambda:*"]
  }
}

data "aws_iam_policy_document" "waf-kinesis-policy" {
  statement {
    sid    = "VisualEditor0"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-core-cloud-compliance-waf-logs",
      "arn:aws:s3:::sme-core-cloud-compliance-waf-logs/*",
    ]

    actions = [
      "s3:AbortMultipartUpload",
      "s3:GetBucketLocation",
      "s3:GetObject",
      "s3:ListBucket",
      "s3:ListBucketMultipartUploads",
      "s3:PutObjectAcl",
      "s3:PutObject",
    ]
  }
}

data "aws_iam_policy_document" "aws-lambda-es-access-policy" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:es:eu-west-2:${var.account_id}:domain/dynamodbindexing/*"]
    actions   = ["es:ESHttpPost"]
  }
}

data "aws_iam_policy_document" "mlib-conversion-policy" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  #checkov:skip=CKV_AWS_109: Ensure IAM policies does not allow permissions management / resource exposure without constraints
  #checkov:skip=CKV_AWS_108: Ensure IAM policies does not allow data exfiltration
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "sqs:ListQueues",
      "ssm:*",
    ]
  }

  statement {
    sid       = "VisualEditor1"
    effect    = "Allow"
    resources = ["arn:aws:sqs:eu-central-1:${var.account_id}:MlibConversionCompletionQueue"]
    actions   = ["sqs:*"]
  }

  statement {
    sid       = "VisualEditor2"
    effect    = "Allow"
    resources = ["arn:aws:iam::613871678587:role/aomap-sa-msk-mlib-prod"]
    actions   = ["sts:AssumeRole"]
  }
}


data "aws_iam_policy_document" "cloudops-instance-policy" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  #checkov:skip=CKV_AWS_110: Ensure IAM policies does not allow privilege escalation
  #checkov:skip=CKV_AWS_109: Ensure IAM policies does not allow permissions management / resource exposure without constraints
  #checkov:skip=CKV_AWS_108: Ensure IAM policies does not allow data exfiltration
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "autoscaling:Describe*",
      "autoscaling:Describe*",
      "cloudtrail:DescribeTrails",
      "cloudtrail:GetEventSelectors",
      "cloudtrail:GetInsightSelectors",
      "cloudtrail:GetTrail",
      "cloudtrail:GetTrailStatus",
      "cloudtrail:ListPublicKeys",
      "cloudtrail:ListTags",
      "cloudtrail:ListTrails",
      "cloudtrail:LookupEvents",
      "cloudwatch:Describe*",
      "cloudwatch:Get*",
      "cloudwatch:GetMetricStatistics",
      "cloudwatch:List*",
      "cloudwatch:ListMetrics",
      "cloudwatch:PutMetricData",
      "ec2:Describe*",
      "ec2:DescribeAccountAttributes",
      "ec2:DescribeAddresses",
      "ec2:DescribeAvailabilityZones",
      "ec2:DescribeClassicLinkInstances",
      "ec2:DescribeCustomerGateways",
      "ec2:DescribeDhcpOptions",
      "ec2:DescribeEgressOnlyInternetGateways",
      "ec2:DescribeFlowLogs",
      "ec2:DescribeInternetGateways",
      "ec2:DescribeMovingAddresses",
      "ec2:DescribeNatGateways",
      "ec2:DescribeNetworkAcls",
      "ec2:DescribeNetworkInterfaceAttribute",
      "ec2:DescribeNetworkInterfacePermissions",
      "ec2:DescribeNetworkInterfaces",
      "ec2:DescribePrefixLists",
      "ec2:DescribeRouteTables",
      "ec2:DescribeSecurityGroupReferences",
      "ec2:DescribeSecurityGroups",
      "ec2:DescribeStaleSecurityGroups",
      "ec2:DescribeSubnets",
      "ec2:DescribeTags",
      "ec2:DescribeVpcAttribute",
      "ec2:DescribeVpcClassicLink",
      "ec2:DescribeVpcClassicLinkDnsSupport",
      "ec2:DescribeVpcEndpointConnectionNotifications",
      "ec2:DescribeVpcEndpointConnections",
      "ec2:DescribeVpcEndpoints",
      "ec2:DescribeVpcEndpointServiceConfigurations",
      "ec2:DescribeVpcEndpointServicePermissions",
      "ec2:DescribeVpcEndpointServices",
      "ec2:DescribeVpcPeeringConnections",
      "ec2:DescribeVpcs",
      "ec2:DescribeVpnConnections",
      "ec2:DescribeVpnGateways",
      "ec2messages:AcknowledgeMessage",
      "ec2messages:DeleteMessage",
      "ec2messages:FailMessage",
      "ec2messages:GetEndpoint",
      "ec2messages:GetMessages",
      "ec2messages:SendReply",
      "elasticloadbalancing:Describe*",
      "lambda:ListFunctions",
      "logs:CreateLogGroup",
      "logs:CreateLogStream",
      "logs:Describe*",
      "logs:DescribeLogGroups",
      "logs:DescribeLogStreams",
      "logs:FilterLogEvents",
      "logs:Get*",
      "logs:GetLogEvents",
      "logs:List*",
      "logs:PutLogEvents",
      "logs:TestMetricFilter",
      "rds:Describe*",
      "rds:ListTagsForResource",
      "s3:Get*",
      "s3:GetBucketLocation",
      "s3:GetObject",
      "s3:List*",
      "s3:ListAllMyBuckets",
      "sns:Get*",
      "sns:List*",
      "ssm:DescribeAssociation",
      "ssm:DescribeDocument",
      "ssm:GetDeployablePatchSnapshotForInstance",
      "ssm:GetDocument",
      "ssm:GetManifest",
      "ssm:GetParameter",
      "ssm:GetParameters",
      "ssm:ListAssociations",
      "ssm:ListInstanceAssociations",
      "ssmmessages:CreateControlChannel",
      "ssmmessages:CreateDataChannel",
      "ssmmessages:OpenControlChannel",
      "ssmmessages:OpenDataChannel",
      "ssm:PutComplianceItems",
      "ssm:PutConfigurePackageResult",
      "ssm:PutInventory",
      "ssm:UpdateAssociationStatus",
      "ssm:UpdateInstanceAssociationStatus",
      "ssm:UpdateInstanceInformation",
      "lambda:CreateFunction",
      "iam:GetAccountPasswordPolicy",
      "cloudwatch:PutMetricData",
      "iam:ListRoleTags",
      "iam:GenerateServiceLastAccessedDetails",
      "iam:ListServiceSpecificCredentials",
      "iam:ListSigningCertificates",
      "iam:SimulateCustomPolicy",
      "ec2:StartInstances",
      "lambda:DeleteFunction",
      "iam:ListRolePolicies",
      "iam:GetCredentialReport",
      "ecs:DeregisterContainerInstance",
      "iam:ListPolicies",
      "iam:GetRole",
      "iam:ListSAMLProviders",
      "iam:GetPolicy",
      "config:PutConfigRule",
      "iam:ListEntitiesForPolicy",
      "ecr:GetAuthorizationToken",
      "ec2messages:AcknowledgeMessage",
      "ec2:StopInstances",
      "lambda:UpdateFunctionCode",
      "ecs:StartTelemetrySession",
      "config:PutConfigurationAggregator",
      "lambda:PublishVersion",
      "ec2messages:SendReply",
      "iam:GetOpenIDConnectProvider",
      "ce:*",
      "iam:GetRolePolicy",
      "iam:GenerateCredentialReport",
      "iam:UntagRole",
      "ec2messages:GetEndpoint",
      "iam:TagRole",
      "ecs:Submit*",
      "iam:GetServiceLastAccessedDetails",
      "iam:GetServiceLinkedRoleDeletionStatus",
      "iam:ListInstanceProfilesForRole",
      "ec2messages:DeleteMessage",
      "ec2:CreateSnapshot",
      "iam:ListAttachedGroupPolicies",
      "ec2:DescribeInstanceStatus",
      "iam:ListAccessKeys",
      "config:PutConfigurationRecorder",
      "s3:*",
      "iam:ListGroupPolicies",
      "iam:GetSSHPublicKey",
      "lambda:UpdateFunctionConfiguration",
      "iam:ListRoles",
      "config:StopConfigurationRecorder",
      "iam:GetContextKeysForCustomPolicy",
      "ssm:*",
      "iam:ListAccountAliases",
      "iam:GetUser",
      "iam:ListGroups",
      "iam:GetLoginProfile",
      "iam:GetPolicyVersion",
      "iam:ListServerCertificates",
      "ds:CreateComputer",
      "config:StartConfigurationRecorder",
      "config:PutDeliveryChannel",
      "iam:ListVirtualMFADevices",
      "ec2:DeleteVolume",
      "logs:CreateLogStream",
      "iam:ListSSHPublicKeys",
      "iam:SimulatePrincipalPolicy",
      "iam:ListAttachedRolePolicies",
      "iam:GetAccountAuthorizationDetails",
      "ecr:BatchCheckLayerAvailability",
      "iam:GetServerCertificate",
      "lambda:InvokeFunction",
      "ecs:CreateCluster",
      "ecr:GetDownloadUrlForLayer",
      "iam:GetAccessKeyLastUsed",
      "config:PutEvaluations",
      "logs:CreateLogGroup",
      "config:StartConfigRulesEvaluation",
      "rds:StartDBInstance",
      "glacier:*",
      "iam:GetUserPolicy",
      "iam:ListGroupsForUser",
      "ecr:BatchGetImage",
      "iam:GetGroupPolicy",
      "eks:*",
      "iam:GetAccountSummary",
      "ec2:DeleteSnapshot",
      "iam:GetServiceLastAccessedDetailsWithEntities",
      "logs:DescribeLogStreams",
      "iam:ListPoliciesGrantingServiceAccess",
      "ecs:RegisterContainerInstance",
      "ec2messages:GetMessages",
      "iam:ListMFADevices",
      "iam:GetGroup",
      "iam:GetContextKeysForPrincipalPolicy",
      "ecs:Poll",
      "ec2messages:FailMessage",
      "iam:ListAttachedUserPolicies",
      "iam:GetSAMLProvider",
      "ecs:DiscoverPollEndpoint",
      "iam:GetInstanceProfile",
      "logs:DescribeLogGroups",
      "iam:ListUserPolicies",
      "config:PutAggregationAuthorization",
      "iam:ListInstanceProfiles",
      "rds:StopDBInstance",
      "iam:TagUser",
      "logs:PutLogEvents",
      "support:*",
      "iam:UntagUser",
      "lambda:AddPermission",
      "iam:ListPolicyVersions",
      "iam:ListOpenIDConnectProviders",
      "config:PutRetentionConfiguration",
      "ds:DescribeDirectories",
      "iam:ListUsers",
      "iam:ListUserTags",
      "sqs:listqueues",
      "secretsmanager:ListSecrets",
      "secretsmanager:GetSecretValue",
      "kinesis:*",
      "cloudfront:ListDistributions",
    ]
  }

  statement {
    sid    = ""
    effect = "Allow"
    resources = [
      "arn:aws:ssm:*:*:parameter/AmazonCloudWatch-*",
      "arn:aws:kms:eu-central-1:${var.account_id}:key/7fcf7089-a08e-4de9-8177-1a3026ed3a1c",
    ]

    actions = [
      "ssm:GetParameter",
      "ssm:PutParameter",
      "kms:*",
    ]
  }
}

data "aws_iam_policy_document" "oneClick_CloudTrail_CloudWatchLogs_Role_1540805922309" {
  statement {
    sid       = "AWSCloudTrailCreateLogStream20141101"
    effect    = "Allow"
    resources = ["arn:aws:logs:ap-northeast-2:${var.account_id}:log-group:CloudTrail/AlertLogicCT:log-stream:${var.account_id}_CloudTrail_ap-northeast-2*"]
    actions   = ["logs:CreateLogStream"]
  }

  statement {
    sid       = "AWSCloudTrailPutLogEvents20141101"
    effect    = "Allow"
    resources = ["arn:aws:logs:ap-northeast-2:${var.account_id}:log-group:CloudTrail/AlertLogicCT:log-stream:${var.account_id}_CloudTrail_ap-northeast-2*"]
    actions   = ["logs:PutLogEvents"]
  }
}

data "aws_iam_policy_document" "kinesis-stream-orderstream-bbox" {
  statement {
    sid       = "Stmt1509030747000"
    effect    = "Allow"
    resources = ["arn:aws:kinesis:eu-central-1:${var.account_id}:stream/OrderStream-Bbox"]
    actions   = ["kinesis:*"]
  }
}

data "aws_iam_policy_document" "For_RDS_Enhanced_Monitoring" {
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["arn:aws:iam::${var.account_id}:role/rds-monitoring-role"]
    actions   = ["iam:PassRole"]
  }
}

data "aws_iam_policy_document" "oneClick_firehose_delivery_role_1591852573061" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "glue:GetTable",
      "glue:GetTableVersion",
      "glue:GetTableVersions",
    ]
  }

  statement {
    sid    = ""
    effect = "Allow"

    resources = [
      "arn:aws:s3:::delp-aws-waf-logs",
      "arn:aws:s3:::delp-aws-waf-logs/*",
      "arn:aws:s3:::%FIREHOSE_BUCKET_NAME%",
      "arn:aws:s3:::%FIREHOSE_BUCKET_NAME%/*",
    ]

    actions = [
      "s3:AbortMultipartUpload",
      "s3:GetBucketLocation",
      "s3:GetObject",
      "s3:ListBucket",
      "s3:ListBucketMultipartUploads",
      "s3:PutObject",
    ]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:lambda:eu-central-1:${var.account_id}:function:%FIREHOSE_DEFAULT_FUNCTION%:%FIREHOSE_DEFAULT_VERSION%"]

    actions = [
      "lambda:InvokeFunction",
      "lambda:GetFunctionConfiguration",
    ]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:logs:eu-central-1:${var.account_id}:log-group:/aws/kinesisfirehose/aws-waf-logs-delp:log-stream:*"]
    actions   = ["logs:PutLogEvents"]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:kinesis:eu-central-1:${var.account_id}:stream/%FIREHOSE_STREAM_NAME%"]

    actions = [
      "kinesis:DescribeStream",
      "kinesis:GetShardIterator",
      "kinesis:GetRecords",
      "kinesis:ListShards",
    ]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:kms:eu-central-1:${var.account_id}:key/%SSE_KEY_ID%"]
    actions   = ["kms:Decrypt"]

    condition {
      test     = "StringEquals"
      variable = "kms:ViaService"
      values   = ["kinesis.%REGION_NAME%.amazonaws.com"]
    }

    condition {
      test     = "StringLike"
      variable = "kms:EncryptionContext:aws:kinesis:arn"
      values   = ["arn:aws:kinesis:%REGION_NAME%:${var.account_id}:stream/%FIREHOSE_STREAM_NAME%"]
    }
  }
}

data "aws_iam_policy_document" "delivery-bulk-operation-policy" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["arn:aws:logs:eu-central-1:${var.account_id}:log-group:/aws/lambda/delivery-bulk-operation"]

    actions = [
      "logs:CreateLogStream",
      "logs:DescribeLogStreams",
      "logs:PutLogEvents",
    ]
  }

  statement {
    sid       = "VisualEditor1"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "sqs:ListQueues",
      "kinesis:EnableEnhancedMonitoring",
      "secretsmanager:DescribeSecret",
      "kinesis:ListShards",
      "logs:CreateLogGroup",
      "s3:ListObjects",
      "kinesis:ListStreams",
      "s3:ListAllMyBuckets",
      "kinesis:UpdateShardCount",
      "kinesis:GetRecords",
      "secretsmanager:List*",
      "s3:HeadBucket",
      "kinesis:DescribeLimits",
      "kinesis:ListStreamConsumers",
      "kinesis:DisableEnhancedMonitoring",
      "kinesis:PutRecord"
    ]
  }

  statement {
    sid    = "VisualEditor2"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delivery-target",
      "arn:aws:s3:::sme-conversion-shelf",
      "arn:aws:s3:::sme-delivery-target/*",
      "arn:aws:s3:::sme-conversion-shelf/*",
      "arn:aws:s3:::sme-delivery-aoma-upload",
      "arn:aws:s3:::sme-delivery-user-upload",
      "arn:aws:s3:::sme-delivery-aoma-upload/*",
      "arn:aws:s3:::sme-delivery-user-upload/*"
    ]

    actions = ["s3:*"]
  }

  statement {
    sid       = "VisualEditor3"
    effect    = "Allow"
    resources = ["arn:aws:sqs:eu-central-1:${var.account_id}:AomaExternalConvRequestCancelQueue"]
    actions   = ["sqs:*"]
  }

  statement {
    sid       = "VisualEditor4"
    effect    = "Allow"
    resources = ["arn:aws:kinesis:eu-central-1:${var.account_id}:stream/EmailStream"]
    actions   = ["kinesis:*"]
  }

  statement {
    sid       = "VisualEditor5"
    effect    = "Allow"
    resources = ["arn:aws:kinesis:eu-central-1:${var.account_id}:stream/StatusUpdateStream"]
    actions   = ["kinesis:*"]
  }

  statement {
    sid    = "VisualEditor6"
    effect = "Allow"

    resources = [
      "arn:aws:secretsmanager:eu-central-1:${var.account_id}:secret:PROD/GLOBALDS/USERINFO-lTe98D",
      "arn:aws:secretsmanager:eu-central-1:${var.account_id}:secret:PROD/DeliveryBulkOperationLambda/PostgreSql-RDS-DB-txnw0j",
      "arn:aws:secretsmanager:eu-central-1:${var.account_id}:secret:PROD/RabbitMQ-04CUZl",
      "arn:aws:secretsmanager:eu-central-1:${var.account_id}:secret:PROD/EOM-pY1NZ7",
    ]

    actions = ["secretsmanager:*"]
  }
}

data "aws_iam_policy_document" "CloudabilityMonitorResourcesPolicy" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "cloudwatch:GetMetricStatistics",
      "dynamodb:DescribeTable",
      "dynamodb:ListTables",
      "ec2:DescribeImages",
      "ec2:DescribeInstances",
      "ec2:DescribeRegions",
      "ec2:DescribeReservedInstances",
      "ec2:DescribeReservedInstancesModifications",
      "ec2:DescribeSnapshots",
      "ec2:DescribeVolumes",
      "ec2:GetReservedInstancesExchangeQuote",
      "ecs:DescribeClusters",
      "ecs:DescribeContainerInstances",
      "ecs:ListClusters",
      "ecs:ListContainerInstances",
      "elasticache:DescribeCacheClusters",
      "elasticache:DescribeReservedCacheNodes",
      "elasticache:ListTagsForResource",
      "elasticmapreduce:DescribeCluster",
      "elasticmapreduce:ListClusters",
      "elasticmapreduce:ListInstances",
      "rds:DescribeDBClusters",
      "rds:DescribeDBInstances",
      "rds:DescribeReservedDBInstances",
      "rds:ListTagsForResource",
      "redshift:DescribeClusters",
      "redshift:DescribeReservedNodes",
      "redshift:DescribeTags",
    ]
  }
}

data "aws_iam_policy_document" "s3RAforspecificbuckets" {
  statement {
    sid    = "VisualEditor0"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delivery-dev-source",
      "arn:aws:s3:::sme-delivery-dev-target",
      "arn:aws:s3:::sme-delivery-stage-source",
      "arn:aws:s3:::sme-delivery-stage-target",
      "arn:aws:s3:*:*:job/*",
      "arn:aws:s3:::sme-delivery-dev-source/*",
      "arn:aws:s3:::sme-delivery-dev-target/*",
      "arn:aws:s3:::sme-delivery-stage-source/*",
      "arn:aws:s3:::sme-delivery-stage-target/*",
    ]

    actions = [
      "s3:ListBucketByTags",
      "s3:GetLifecycleConfiguration",
      "s3:GetBucketTagging",
      "s3:GetInventoryConfiguration",
      "s3:GetObjectVersionTagging",
      "s3:ListBucketVersions",
      "s3:GetBucketLogging",
      "s3:ListBucket",
      "s3:GetAccelerateConfiguration",
      "s3:GetBucketPolicy",
      "s3:GetObjectVersionTorrent",
      "s3:GetObjectAcl",
      "s3:GetEncryptionConfiguration",
      "s3:GetBucketRequestPayment",
      "s3:GetObjectVersionAcl",
      "s3:GetObjectTagging",
      "s3:GetMetricsConfiguration",
      "s3:GetBucketPublicAccessBlock",
      "s3:GetBucketPolicyStatus",
      "s3:ListBucketMultipartUploads",
      "s3:GetBucketWebsite",
      "s3:GetBucketVersioning",
      "s3:GetBucketAcl",
      "s3:GetBucketNotification",
      "s3:GetReplicationConfiguration",
      "s3:ListMultipartUploadParts",
      "s3:GetObject",
      "s3:GetObjectTorrent",
      "s3:DescribeJob",
      "s3:GetBucketCORS",
      "s3:GetAnalyticsConfiguration",
      "s3:GetObjectVersionForReplication",
      "s3:GetBucketLocation",
      "s3:GetObjectVersion",
    ]
  }

  statement {
    sid       = "VisualEditor1"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "s3:GetAccountPublicAccessBlock",
      "s3:ListAllMyBuckets",
      "s3:ListJobs",
      "s3:HeadBucket",
    ]
  }

  statement {
    sid       = "VisualEditor2"
    effect    = "Allow"
    resources = ["arn:aws:s3:::*/*"]

    actions = [
      "s3:ListBucketByTags",
      "s3:GetLifecycleConfiguration",
      "s3:GetBucketTagging",
      "s3:GetInventoryConfiguration",
      "s3:GetObjectVersionTagging",
      "s3:ListBucketVersions",
      "s3:GetBucketLogging",
      "s3:GetAccelerateConfiguration",
      "s3:GetBucketPolicy",
      "s3:GetObjectVersionTorrent",
      "s3:GetObjectAcl",
      "s3:GetEncryptionConfiguration",
      "s3:GetBucketRequestPayment",
      "s3:GetObjectVersionAcl",
      "s3:GetObjectTagging",
      "s3:GetMetricsConfiguration",
      "s3:GetBucketPublicAccessBlock",
      "s3:GetBucketPolicyStatus",
      "s3:ListBucketMultipartUploads",
      "s3:GetBucketWebsite",
      "s3:GetBucketVersioning",
      "s3:GetBucketAcl",
      "s3:GetBucketNotification",
      "s3:GetReplicationConfiguration",
      "s3:ListMultipartUploadParts",
      "s3:GetObject",
      "s3:GetObjectTorrent",
      "s3:DescribeJob",
      "s3:GetBucketCORS",
      "s3:GetAnalyticsConfiguration",
      "s3:GetObjectVersionForReplication",
      "s3:GetBucketLocation",
      "s3:GetObjectVersion",
    ]
  }
}

data "aws_iam_policy_document" "delp-eks-dsrv-prod-eks-cluster-ns-delivery-prod-sa-aoma-master-export-service-policy" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  #checkov:skip=CKV_AWS_108: Ensure IAM policies does not allow data exfiltration
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "kinesis:PutRecord",
      "kinesis:PutRecords",
      "secretsmanager:GetSecretValue",
    ]
  }
}

data "aws_iam_policy_document" "sme-delivery-stage-bb-target" {
  statement {
    sid    = "Stmt1476951673001"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delivery-stage-bb-target/",
      "arn:aws:s3:::sme-delivery-stage-bb-target/*",
    ]

    actions = ["s3:*"]
  }
}

data "aws_iam_policy_document" "delp-aws-config-policy" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-aoma-delivery-prod-awsconfig-prod/*"]
    actions   = ["s3:PutObject*"]

    condition {
      test     = "StringLike"
      variable = "s3:x-amz-acl"
      values   = ["bucket-owner-full-control"]
    }
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-aoma-delivery-prod-awsconfig-prod"]
    actions   = ["s3:GetBucketAcl"]
  }
}

data "aws_iam_policy_document" "s3-sme-conversion-shelf" {
  statement {
    sid       = "Stmt1415223369001"
    effect    = "Allow"
    resources = ["arn:aws:s3:::*"]

    actions = [
      "s3:GetBucketLocation",
      "s3:ListAllMyBuckets",
    ]
  }

  statement {
    sid    = "Stmt1415223369000"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-conversion-shelf/*",
      "arn:aws:s3:::sme-conversion-shelf",
    ]

    actions = [
      "s3:GetObject",
      "s3:ListBucket",
    ]
  }
}

data "aws_iam_policy_document" "mlib-prod-ecs-kinesis-stream-policy" {
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["arn:aws:kinesis:eu-central-1:${var.account_id}:stream/EmailStream"]

    actions = [
      "kinesis:StopStreamEncryption",
      "kinesis:DeregisterStreamConsumer",
      "kinesis:SubscribeToShard",
      "kinesis:DecreaseStreamRetentionPeriod",
      "kinesis:PutRecords",
      "kinesis:DescribeStreamConsumer",
      "kinesis:GetShardIterator",
      "kinesis:DescribeStream",
      "kinesis:RegisterStreamConsumer",
      "kinesis:ListTagsForStream",
      "kinesis:PutRecord",
      "kinesis:DescribeStreamSummary",
      "kinesis:MergeShards",
      "kinesis:AddTagsToStream",
      "kinesis:IncreaseStreamRetentionPeriod",
      "kinesis:GetRecords",
      "kinesis:StartStreamEncryption",
    ]
  }

  statement {
    sid       = "VisualEditor1"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "kinesis:ListStreams",
      "kinesis:EnableEnhancedMonitoring",
      "kinesis:DescribeLimits",
      "kinesis:DisableEnhancedMonitoring",
    ]
  }
}

data "aws_iam_policy_document" "sme-media-production-03302017" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  #checkov:skip=CKV_AWS_109: Ensure IAM policies does not allow permissions management / resource exposure without constraints
  #checkov:skip=CKV_AWS_108: Ensure IAM policies does not allow data exfiltration
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "s3:*",
    ]
  }

  statement {
    sid       = "VisualEditor1"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-media-production"]
    actions   = ["s3:ListBucket"]
  }

  statement {
    sid       = "VisualEditor2"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-media-production/*"]

    actions = [
      "s3:PutObject",
      "s3:GetObject",
      "s3:DeleteObject",
      "s3:ListMultipartUploadParts",
    ]
  }

  statement {
    sid       = "VisualEditor3"
    effect    = "Allow"
    resources = ["*"]
    actions   = ["s3:ListAllMyBuckets"]
  }

  statement {
    sid    = "VisualEditorS3"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delivery-stage-source",
      "arn:aws:s3:::sme-delivery-stage-target",
      "arn:aws:s3:::sme-delivery-stage-source/*",
      "arn:aws:s3:::sme-delivery-stage-target/*",
    ]

    actions = [
      "s3:ListBucket",
      "s3:ListAllMyBuckets",
      "s3:Get*",
    ]
  }
}

data "aws_iam_policy_document" "S3-Athena-Full-Access" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  #checkov:skip=CKV_AWS_109: Ensure IAM policies does not allow permissions management / resource exposure without constraints
  #checkov:skip=CKV_AWS_108: Ensure IAM policies does not allow data exfiltration
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "s3:List*",
      "s3:Describe*",
      "s3:Get*",
      "s3:AbortMultipartUpload",
      "s3:Create*",
      "s3:Delete*",
      "s3:InitiateReplication",
      "s3:PauseReplication",
      "s3:Put*",
      "s3:Replicate*",
      "s3:RestoreObject",
      "s3:SubmitMultiRegionAccessPointRoutes",
      "s3:Update*",
      "s3:AssociateAccessGrantsIdentityCenter",
      "s3:BypassGovernanceRetention",
      "s3:DissociateAccessGrantsIdentityCenter",
      "s3:ObjectOwnerOverrideToBucketOwner",
      "s3:TagResource",
      "s3:UntagResource",
      "athena:List*",
      "athena:Batch*",
      "athena:Get*",
      "athena:Cancel*",
      "athena:Create*",
      "athena:Delete*",
      "athena:ExportNotebook",
      "athena:ImportNotebook",
      "athena:PutCapacityAssignmentConfiguration",
      "athena:RunQuery",
      "athena:Start*",
      "athena:Stop*",
      "athena:TerminateSession",
      "athena:Update*",
      "athena:TagResource",
      "athena:UntagResource"
    ]
  }
}

data "aws_iam_policy_document" "cost-explore-ro" {
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "ce:DescribeCostCategoryDefinition",
      "ce:GetRightsizingRecommendation",
      "ce:GetCostAndUsage",
      "ce:GetSavingsPlansUtilization",
      "ce:GetReservationPurchaseRecommendation",
      "ce:ListCostCategoryDefinitions",
      "ce:GetCostForecast",
      "ce:GetReservationUtilization",
      "ce:GetSavingsPlansPurchaseRecommendation",
      "ce:GetDimensionValues",
      "ce:GetSavingsPlansUtilizationDetails",
      "ce:GetCostAndUsageWithResources",
      "ce:GetReservationCoverage",
      "ce:GetSavingsPlansCoverage",
      "ce:GetTags",
      "ce:GetUsageForecast",
    ]
  }
}

data "aws_iam_policy_document" "Billing-RO" {
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "account:GetAccountInformation",
      "account:GetAlternateContact",
      "account:GetChallengeQuestions",
      "account:GetContactInformation",
      "account:GetAccountInformation",
      "billing:GetContractInformation",
      "billing:GetIAMAccessPreference",
      "billing:GetSellerOfRecord",
      "billing:GetBillingData",
      "billing:GetBillingDetails",
      "billing:GetBillingNotifications",
      "billing:GetBillingPreferences",
      "billing:GetContractInformation",
      "billing:GetCredits",
      "billing:GetIAMAccessPreference",
      "billing:GetSellerOfRecord",
      "billing:ListBillingViews",
      "payments:ListPaymentPreferences",
      "ce:DescribeNotificationSubscription",
      "ce:DescribeReport",
      "ce:GetAnomalies",
      "ce:GetAnomalyMonitors",
      "ce:GetAnomalySubscriptions",
      "ce:GetCostAndUsage",
      "ce:GetCostAndUsageWithResources",
      "ce:GetCostCategories",
      "ce:GetCostForecast",
      "ce:GetDimensionValues",
      "ce:GetPreferences",
      "ce:GetReservationCoverage",
      "ce:GetReservationPurchaseRecommendation",
      "ce:GetReservationUtilization",
      "ce:GetRightsizingRecommendation",
      "ce:GetSavingsPlansCoverage",
      "ce:GetSavingsPlansPurchaseRecommendation",
      "ce:GetSavingsPlansUtilization",
      "ce:GetSavingsPlansUtilizationDetails",
      "ce:GetTags",
      "ce:GetUsageForecast",
      "ce:ListCostAllocationTags",
      "ce:ListSavingsPlansPurchaseRecommendationGeneration",
      "consolidatedbilling:GetAccountBillingRole",
      "consolidatedbilling:ListLinkedAccounts",
      "cur:GetClassicReport",
      "cur:GetClassicReportPreferences",
      "cur:ValidateReportDestination",
      "cur:GetUsageReport",
      "freetier:GetFreeTierAlertPreference",
      "freetier:GetFreeTierUsage",
      "invoicing:GetInvoiceEmailDeliveryPreferences",
      "invoicing:GetInvoicePDF",
      "invoicing:ListInvoiceSummaries",
      "payments:GetPaymentInstrument",
      "payments:GetPaymentStatus",
      "payments:ListPaymentPreferences",
      "tax:GetTaxInheritance",
      "tax:GetTaxRegistrationDocument",
      "tax:ListTaxRegistrations"
    ]
  }
}

data "aws_iam_policy_document" "sme-netezza-delivery-01" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]
    actions   = ["s3:ListAllMyBuckets"]
  }

  statement {
    sid    = ""
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-netezza-delivery-01",
      "arn:aws:s3:::sme-netezza-delivery-01/*",
    ]

    actions = ["s3:*"]
  }
}

data "aws_iam_policy_document" "KinesisFirehoseServicePolicy-aws-waf-logs-eu-west-2-eu-west-2" {
  statement {
    sid    = ""
    effect = "Allow"

    resources = [
      "arn:aws:glue:eu-west-2:${var.account_id}:catalog",
      "arn:aws:glue:eu-west-2:${var.account_id}:database/%FIREHOSE_POLICY_TEMPLATE_PLACEHOLDER%",
      "arn:aws:glue:eu-west-2:${var.account_id}:table/%FIREHOSE_POLICY_TEMPLATE_PLACEHOLDER%/%FIREHOSE_POLICY_TEMPLATE_PLACEHOLDER%",
    ]

    actions = [
      "glue:GetTable",
      "glue:GetTableVersion",
      "glue:GetTableVersions",
    ]
  }

  statement {
    sid    = ""
    effect = "Allow"

    resources = [
      "arn:aws:s3:::delp-aws-waf-logs-eu-west-2",
      "arn:aws:s3:::delp-aws-waf-logs-eu-west-2/*",
    ]

    actions = [
      "s3:AbortMultipartUpload",
      "s3:GetBucketLocation",
      "s3:GetObject",
      "s3:ListBucket",
      "s3:ListBucketMultipartUploads",
      "s3:PutObject",
    ]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:lambda:eu-west-2:${var.account_id}:function:%FIREHOSE_POLICY_TEMPLATE_PLACEHOLDER%"]

    actions = [
      "lambda:InvokeFunction",
      "lambda:GetFunctionConfiguration",
    ]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:kms:eu-west-2:${var.account_id}:key/%FIREHOSE_POLICY_TEMPLATE_PLACEHOLDER%"]

    actions = [
      "kms:GenerateDataKey",
      "kms:Decrypt",
    ]

    condition {
      test     = "StringEquals"
      variable = "kms:ViaService"
      values   = ["s3.eu-west-2.amazonaws.com"]
    }

    condition {
      test     = "StringLike"
      variable = "kms:EncryptionContext:aws:s3:arn"
      values   = ["arn:aws:s3:::%FIREHOSE_POLICY_TEMPLATE_PLACEHOLDER%/*"]
    }
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:logs:eu-west-2:${var.account_id}:log-group:/aws/kinesisfirehose/aws-waf-logs-eu-west-2:log-stream:*"]
    actions   = ["logs:PutLogEvents"]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:kinesis:eu-west-2:${var.account_id}:stream/%FIREHOSE_POLICY_TEMPLATE_PLACEHOLDER%"]

    actions = [
      "kinesis:DescribeStream",
      "kinesis:GetShardIterator",
      "kinesis:GetRecords",
      "kinesis:ListShards",
    ]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:kms:eu-west-2:${var.account_id}:key/%FIREHOSE_POLICY_TEMPLATE_PLACEHOLDER%"]
    actions   = ["kms:Decrypt"]

    condition {
      test     = "StringEquals"
      variable = "kms:ViaService"
      values   = ["kinesis.eu-west-2.amazonaws.com"]
    }

    condition {
      test     = "StringLike"
      variable = "kms:EncryptionContext:aws:kinesis:arn"
      values   = ["arn:aws:kinesis:eu-west-2:${var.account_id}:stream/%FIREHOSE_POLICY_TEMPLATE_PLACEHOLDER%"]
    }
  }
}

data "aws_iam_policy_document" "oneClick_CloudTrail_CloudWatchLogs_Role_1540806938711" {
  statement {
    sid       = "AWSCloudTrailCreateLogStream20141101"
    effect    = "Allow"
    resources = ["arn:aws:logs:ap-northeast-1:${var.account_id}:log-group:CloudTrail/AlertLogicCT:log-stream:${var.account_id}_CloudTrail_ap-northeast-1*"]
    actions   = ["logs:CreateLogStream"]
  }

  statement {
    sid       = "AWSCloudTrailPutLogEvents20141101"
    effect    = "Allow"
    resources = ["arn:aws:logs:ap-northeast-1:${var.account_id}:log-group:CloudTrail/AlertLogicCT:log-stream:${var.account_id}_CloudTrail_ap-northeast-1*"]
    actions   = ["logs:PutLogEvents"]
  }
}

data "aws_iam_policy_document" "oneClick_lambda_basic_execution_1528107322323" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:logs:*:*:*"]

    actions = [
      "logs:CreateLogGroup",
      "logs:CreateLogStream",
      "logs:PutLogEvents",
    ]
  }
}

data "aws_iam_policy_document" "oneClick_CloudTrail_CloudWatchLogs_Role_1540806472333" {
  statement {
    sid       = "AWSCloudTrailCreateLogStream20141101"
    effect    = "Allow"
    resources = ["arn:aws:logs:ap-southeast-2:${var.account_id}:log-group:CloudTrail/AlertLogicCT:log-stream:${var.account_id}_CloudTrail_ap-southeast-2*"]
    actions   = ["logs:CreateLogStream"]
  }

  statement {
    sid       = "AWSCloudTrailPutLogEvents20141101"
    effect    = "Allow"
    resources = ["arn:aws:logs:ap-southeast-2:${var.account_id}:log-group:CloudTrail/AlertLogicCT:log-stream:${var.account_id}_CloudTrail_ap-southeast-2*"]
    actions   = ["logs:PutLogEvents"]
  }
}

data "aws_iam_policy_document" "grpsd_dudi001_secretsmanager_read" {
  statement {
    sid    = "AllowSecretsManagerRead"
    effect = "Allow"

    actions = [
      "secretsmanager:GetSecretValue",
      "secretsmanager:DescribeSecret",
      "secretsmanager:GetResourcePolicy",
      "secretsmanager:ListSecretVersionIds",
    ]

    resources = [
      "arn:aws:secretsmanager:eu-central-1:${var.account_id}:secret:rdx/usm-client-secret-dev-vSxivs",
    ]
  }

}

data "aws_iam_policy_document" "delp-ecs-mlib-prod-task-def-task-policy" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  #checkov:skip=CKV_AWS_109: Ensure IAM policies does not allow permissions management / resource exposure without constraints
  #checkov:skip=CKV_AWS_108: Ensure IAM policies does not allow data exfiltration
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["arn:aws:iam::*:role/aws-service-role/events.amazonaws.com/AWSServiceRoleForCloudWatchEvents*"]
    actions   = ["iam:CreateServiceLinkedRole"]

    condition {
      test     = "StringLike"
      variable = "iam:AWSServiceName"
      values   = ["events.amazonaws.com"]
    }
  }

  statement {
    sid       = "VisualEditor1"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "iam:GetRole",
      "iam:GetPolicyVersion",
      "autoscaling:Describe*",
      "iam:GetPolicy",
      "cloudwatch:*",
      "ssm:*",
      "logs:*",
      "sqs:*",
    ]
  }

  statement {
    sid    = "VisualEditor2"
    effect = "Allow"

    resources = [
      "arn:aws:secretsmanager:eu-central-1:023180329437:secret:db/mlib/prod/media_library_app-X8lFdu",
      "arn:aws:kms:eu-central-1:023180329437:key/7fcf7089-a08e-4de9-8177-1a3026ed3a1c",
      "arn:aws:secretsmanager:eu-central-1:023180329437:secret:PROD/RabbitMQ-04CUZl",
      "arn:aws:kms:eu-central-1:023180329437:key/c43c70ed-018c-40b0-b70b-5d7fd4a5f58d",
    ]

    actions = [
      "secretsmanager:GetResourcePolicy",
      "secretsmanager:GetSecretValue",
      "secretsmanager:DescribeSecret",
      "secretsmanager:RestoreSecret",
      "secretsmanager:PutSecretValue",
      "secretsmanager:CreateSecret",
      "secretsmanager:UpdateSecretVersionStage",
      "secretsmanager:RotateSecret",
      "secretsmanager:CancelRotateSecret",
      "secretsmanager:ListSecretVersionIds",
      "secretsmanager:UpdateSecret",
      "kms:*",
    ]
  }

  statement {
    sid       = "VisualEditor3"
    effect    = "Allow"
    resources = ["arn:aws:iam::613871678587:role/aomap-sa-msk-mlib-prod"]
    actions   = ["sts:AssumeRole"]
  }

}

data "aws_iam_policy_document" "sme-delivery-stage-source-s3-access" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  #checkov:skip=CKV_AWS_109: Ensure IAM policies does not allow permissions management / resource exposure without constraints
  #checkov:skip=CKV_AWS_108: Ensure IAM policies does not allow data exfiltration
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["arn:aws:s3:::*"]
    actions   = ["s3:GetBucketLocation"]
  }

  statement {
    sid       = "VisualEditor1"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "s3:*"
    ]
  }

  statement {
    sid    = "VisualEditor2"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delivery-uat-target",
      "arn:aws:s3:::sme-delivery-uat-target/*",
      "arn:aws:s3:::delivery-s3-logs",
      "arn:aws:s3:::delivery-s3-logs/*",
      "arn:aws:s3:::sme-delivery-uat-shelf",
      "arn:aws:s3:::sme-delivery-uat-shelf/*",
    ]

    actions = ["s3:*"]
  }

  statement {
    sid    = "VisualEditor3"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delivery-uat-shelf",
      "arn:aws:s3:::sme-delivery-uat-shelf/*",
      "arn:aws:s3:::delivery-s3-logs",
      "arn:aws:s3:::delivery-s3-logs/*",
    ]

    actions = ["s3:*"]
  }

  statement {
    sid    = "VisualEditor4"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delivery-uat-source",
      "arn:aws:s3:::sme-delivery-uat-source/*",
    ]

    actions = ["s3:*"]
  }

  statement {
    sid       = "VisualEditor5"
    effect    = "Allow"
    resources = ["arn:aws:s3:::*"]
    actions   = ["s3:ListAllMyBuckets"]
  }

  statement {
    sid    = "VisualEditor6"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delivery-stage-source/*",
      "arn:aws:s3:::sme-delivery-stage-target/*",
      "arn:aws:s3:::sme.conversion.shelf.test/*",
      "arn:aws:s3:::sme-mc-stage-hash/*",
      "arn:aws:s3:::sme-delivery-stage-source",
      "arn:aws:s3:::sme-delivery-stage-target",
      "arn:aws:s3:::sme.conversion.shelf.test",
      "arn:aws:s3:::sme-mc-stage-hash",
      "arn:aws:s3:::sme-mc-stage-migration",
      "arn:aws:s3:::sme-mc-stage-migration/*",
      "arn:aws:s3:::sme-mc-dev-source",
      "arn:aws:s3:::sme-mc-dev-source/*",
      "arn:aws:s3:::sme-mc-dev-target",
      "arn:aws:s3:::sme-mc-dev-target/*",
      "arn:aws:s3:::sme-mc-stage-source",
      "arn:aws:s3:::sme-mc-stage-source/*",
      "arn:aws:s3:::sme-mc-stage-target/*",
      "arn:aws:s3:::sme-mc-stage-target",
      "arn:aws:s3:::sme-delivery-uat-shelf",
      "arn:aws:s3:::sme-delivery-uat-shelf/*",
    ]

    actions = ["s3:*"]
  }
}

data "aws_iam_policy_document" "s3-sme-delivery-source-ro" {
  #checkov:skip=CKV_AWS_108: Ensure IAM policies does not allow data exfiltration
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "s3:ListBucketByTags",
      "s3:GetLifecycleConfiguration",
      "s3:GetBucketTagging",
      "s3:GetInventoryConfiguration",
      "s3:GetObjectVersionTagging",
      "s3:ListBucketVersions",
      "s3:GetBucketLogging",
      "s3:ListBucket",
      "s3:GetAccelerateConfiguration",
      "s3:GetBucketPolicy",
      "s3:GetObjectVersionTorrent",
      "s3:GetObjectAcl",
      "s3:GetEncryptionConfiguration",
      "s3:GetBucketRequestPayment",
      "s3:GetObjectVersionAcl",
      "s3:GetObjectTagging",
      "s3:GetMetricsConfiguration",
      "s3:HeadBucket",
      "s3:GetBucketPublicAccessBlock",
      "s3:GetBucketPolicyStatus",
      "s3:ListBucketMultipartUploads",
      "s3:GetBucketWebsite",
      "s3:ListJobs",
      "s3:GetBucketVersioning",
      "s3:GetBucketAcl",
      "s3:GetBucketNotification",
      "s3:GetReplicationConfiguration",
      "s3:ListMultipartUploadParts",
      "s3:GetObject",
      "s3:GetObjectTorrent",
      "s3:GetAccountPublicAccessBlock",
      "s3:ListAllMyBuckets",
      "s3:GetBucketCORS",
      "s3:GetAnalyticsConfiguration",
      "s3:GetObjectVersionForReplication",
      "s3:GetBucketLocation",
      "s3:GetObjectVersion",
    ]
  }
}

data "aws_iam_policy_document" "dporcp1-delivery-service01" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:sqs:eu-central-1:${var.account_id}:SmeOrchardS3DeliveryQueue"]
    actions   = ["sqs:*"]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:kinesis:eu-central-1:${var.account_id}:stream/EmailStream"]
    actions   = ["kinesis:PutRecord"]
  }

  statement {
    sid    = "Stmt1486461269756"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delivery-messages-prod",
      "arn:aws:s3:::sme-delivery-orchard-target",
      "arn:aws:s3:::sme-delivery-orchard-target/*",
    ]

    actions = ["s3:*"]
  }
}

data "aws_iam_policy_document" "sme-delivery-dashboard-policy" {
  statement {
    sid       = "Stmt1498115283000"
    effect    = "Allow"
    resources = ["arn:aws:kinesis:eu-central-1:${var.account_id}:stream/EmailStream"]
    actions   = ["kinesis:PutRecord"]
  }

  statement {
    sid    = "Stmt1498115339000"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delivery-target",
      "arn:aws:s3:::sme-delivery-target/*",
    ]

    actions = ["s3:*"]
  }

  statement {
    sid    = "Stmt1498115374000"
    effect = "Allow"

    resources = [
      "arn:aws:sqs:eu-central-1:${var.account_id}:AomaExternalConvRequestCancelQueue",
      "arn:aws:sqs:eu-central-1:${var.account_id}:AomaRequestQueue",
    ]

    actions = ["sqs:*"]
  }

  statement {
    sid    = "Stmt1498113638020"
    effect = "Allow"

    resources = [
      "arn:aws:kinesis:eu-central-1:${var.account_id}:stream/DeliveryBulkOperationStream",
      "arn:aws:kinesis:eu-central-1:${var.account_id}:stream/DeliveryRecordsPurgeStream",
    ]

    actions = ["kinesis:*"]
  }
}

data "aws_iam_policy_document" "sme-aoma-delivery-prod-waf-logging-policy" {
  statement {
    sid    = "VisualEditor0"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-core-cloud-compliance-waf-logs",
      "arn:aws:s3:::sme-core-cloud-compliance-waf-logs/*",
    ]

    actions = [
      "s3:AbortMultipartUpload",
      "s3:GetBucketLocation",
      "s3:GetObject",
      "s3:ListBucket",
      "s3:ListBucketMultipartUploads",
      "s3:PutObjectAcl",
      "s3:PutObject",
    ]
  }
}

data "aws_iam_policy_document" "partner-dropoff-bucket-policy" {
  statement {
    sid    = "VisualEditor0"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::*/*",
      "arn:aws:s3:::*",
    ]

    actions = [
      "s3:PutObjectAcl",
      "s3:PutObject",
      "s3:PutBucketAcl",
      "s3:ListBucket",
      "s3:GetObject",
      "s3:DeleteObject",
      "s3:ListBucketMultipartUploads",
      "s3:AbortMultipartUpload",
      "s3:ListMultipartUploadParts",
    ]
  }


  statement {
    sid    = "CLOUDOPS14503"
    effect = "Allow"
    resources = ["arn:aws:kms:eu-west-1:795266304504:key/1fb6632d-c094-4a2f-a9a9-d46d5fe70cd1",
    "arn:aws:kms:ap-northeast-1:055122944979:key/6549745b-6bf3-4ca9-8d72-95c972f911de"]

    actions = [
      "kms:Decrypt",
      "kms:GenerateDataKey",
      "kms:Encrypt",
      "kms:ReEncrypt*",
      "kms:DescribeKey",
    ]
  }
}

data "aws_iam_policy_document" "partner-dropoff-bucket-policy-extended" {
  statement {
    sid    = "VisualEditor0"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::qobuz-eu-west-1-supplychain-exchange",
      "arn:aws:s3:::qobuz-eu-west-1-supplychain-exchange/*",
      "arn:aws:s3:::content-delivery",
      "arn:aws:s3:::content-delivery/*"
    ]

    actions = [
      "s3:PutObjectAcl",
      "s3:PutObject",
      "s3:PutBucketAcl",
      "s3:ListBucket",
      "s3:GetObject",
      "s3:DeleteObject",
      "s3:ListBucketMultipartUploads",
      "s3:AbortMultipartUpload",
      "s3:ListMultipartUploadParts",
    ]
  }


  statement {
    sid    = "CLOUDOPS14503"
    effect = "Allow"
    resources = ["arn:aws:kms:eu-west-1:795266304504:key/1fb6632d-c094-4a2f-a9a9-d46d5fe70cd1",
    "arn:aws:kms:ap-northeast-1:055122944979:key/6549745b-6bf3-4ca9-8d72-95c972f911de"]

    actions = [
      "kms:Decrypt",
      "kms:GenerateDataKey",
      "kms:Encrypt",
      "kms:ReEncrypt*",
      "kms:DescribeKey",
    ]
  }
}
data "aws_iam_policy_document" "sme-logs-policy" {
  version = "2012-10-17"

  statement {
    sid    = "logs"
    effect = "Allow"

    actions = [
      "logs:PutLogEvents",
      "logs:CreateLogStream",
      "logs:DescribeLogStreams",
      "logs:CreateLogGroup",
    ]

    resources = [
      "arn:aws:logs:*:*:*",
    ]
  }

  statement {
    sid    = "metrics"
    effect = "Allow"

    actions = [
      "cloudwatch:PutMetricData",
    ]

    resources = [
      "*",
    ]
  }
}
data "aws_iam_policy_document" "partner-dropoff-bucket-assume-role-policy" {

  statement {
    sid    = "VisualEditor1"
    effect = "Allow"
    resources = [
      "arn:aws:iam::614263107061:role/sony_access_role",
      "arn:aws:iam::623159496745:role/sarmady-to-sony-s3",
      "arn:aws:iam::272327601909:role/kkbox-metadata-vendor-sony_v2",
      "arn:aws:iam::089660437765:role/delp2-delivery-util-ec2-role",
      "arn:aws:iam::827541288795:role/ihr_sony_S3CARole",
      "arn:aws:iam::783874086758:role/kkbox-metadata-vendor-sony_v2",
      "arn:aws:iam::023180329437:role/delp2-delivery-util-ec2-role",
      "arn:aws:iam::289987588205:role/sony-music-catalog-transfer-iam-role"
    ]
    actions = ["sts:AssumeRole"]
  }

  statement {
    sid    = "VisualEditor2"
    effect = "Allow"
    resources = [
      "arn:aws:s3:::sme-delivery-target/KBX/*",
      "arn:aws:s3:::sme-delivery-target/KBX",
      "arn:aws:s3:::sme-delivery-target/KBH/*",
      "arn:aws:s3:::sme-delivery-target/KBH",
      "arn:aws:s3:::sme-delivery-target/M31/*",
      "arn:aws:s3:::sme-delivery-target/M31",
      "arn:aws:s3:::sme-delivery-target/tmp/*",
      "arn:aws:s3:::sme-delivery-target/tmp",
      "arn:aws:s3:::sme-delivery-target/test/*",
      "arn:aws:s3:::sme-delivery-target/test",
      "arn:aws:s3:::sme-delivery-target/*",
      "arn:aws:s3:::sme-delivery-target",
    ]

    actions = [
      "s3:GetObject",
      "s3:GetObjectVersion",
      "s3:AbortMultipartUpload",
      "s3:ListBucketMultipartUploads",
      "s3:ListBucket",
    ]
  }
}

data "aws_iam_policy_document" "mlib-prod-ecs-s3-policy" {
  statement {
    sid    = "VisualEditor0"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-origin-medialib",
      "arn:aws:s3:::sme-origin-medialib/*",
    ]

    actions = [
      "s3:PutAnalyticsConfiguration",
      "s3:GetObjectVersionTagging",
      "s3:CreateBucket",
      "s3:ReplicateObject",
      "s3:GetObjectAcl",
      "s3:GetBucketObjectLockConfiguration",
      "s3:PutLifecycleConfiguration",
      "s3:GetObjectVersionAcl",
      "s3:DeleteObject",
      "s3:GetBucketPolicyStatus",
      "s3:GetObjectRetention",
      "s3:GetBucketWebsite",
      "s3:GetJobTagging",
      "s3:PutReplicationConfiguration",
      "s3:PutObjectLegalHold",
      "s3:GetObjectLegalHold",
      "s3:GetBucketNotification",
      "s3:PutBucketCORS",
      "s3:GetReplicationConfiguration",
      "s3:ListMultipartUploadParts",
      "s3:PutObject",
      "s3:GetObject",
      "s3:PutBucketNotification",
      "s3:DescribeJob",
      "s3:PutBucketLogging",
      "s3:GetAnalyticsConfiguration",
      "s3:PutBucketObjectLockConfiguration",
      "s3:GetObjectVersionForReplication",
      "s3:CreateAccessPoint",
      "s3:GetLifecycleConfiguration",
      "s3:GetInventoryConfiguration",
      "s3:GetBucketTagging",
      "s3:PutAccelerateConfiguration",
      "s3:DeleteObjectVersion",
      "s3:GetBucketLogging",
      "s3:ListBucketVersions",
      "s3:RestoreObject",
      "s3:ListBucket",
      "s3:GetAccelerateConfiguration",
      "s3:GetBucketPolicy",
      "s3:PutEncryptionConfiguration",
      "s3:GetEncryptionConfiguration",
      "s3:GetObjectVersionTorrent",
      "s3:AbortMultipartUpload",
      "s3:GetBucketRequestPayment",
      "s3:GetAccessPointPolicyStatus",
      "s3:UpdateJobPriority",
      "s3:GetObjectTagging",
      "s3:GetMetricsConfiguration",
      "s3:PutBucketVersioning",
      "s3:GetBucketPublicAccessBlock",
      "s3:ListBucketMultipartUploads",
      "s3:PutMetricsConfiguration",
      "s3:UpdateJobStatus",
      "s3:GetBucketVersioning",
      "s3:GetBucketAcl",
      "s3:PutInventoryConfiguration",
      "s3:GetObjectTorrent",
      "s3:PutBucketWebsite",
      "s3:PutBucketRequestPayment",
      "s3:PutObjectRetention",
      "s3:GetBucketCORS",
      "s3:GetBucketLocation",
      "s3:GetAccessPointPolicy",
      "s3:ReplicateDelete",
      "s3:GetObjectVersion",
    ]
  }
}

data "aws_iam_policy_document" "sme-delivery-jboss-worker-policy" {
  statement {
    sid    = "Stmt1486461269700"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delivery-target",
      "arn:aws:s3:::sme-delivery-target/*",
      "arn:aws:s3:::sme-conversion-shelf",
      "arn:aws:s3:::sme-conversion-shelf/*",
      "arn:aws:s3:::sme-delivery-source",
      "arn:aws:s3:::sme-delivery-source/*",
      "arn:aws:s3:::sme-delivery-messages-prod",
      "arn:aws:s3:::sme-delivery-messages-prod/*",
    ]

    actions = ["s3:*"]
  }

  statement {
    sid    = "Stmt1498113445000"
    effect = "Allow"

    resources = [
      "arn:aws:kinesis:eu-central-1:${var.account_id}:stream/EmailStream",
      "arn:aws:kinesis:eu-central-1:${var.account_id}:stream/ArchivePackageStream",
    ]

    actions = ["kinesis:PutRecord"]
  }

  statement {
    sid    = "Stmt1498113601000"
    effect = "Allow"

    resources = [
      "arn:aws:sqs:eu-central-1:${var.account_id}:AomaRequestQueue",
      "arn:aws:sqs:eu-central-1:${var.account_id}:AomaResponseQueue",
      "arn:aws:sqs:eu-central-1:${var.account_id}:AssetSourceDeleteQueue",
      "arn:aws:sqs:eu-central-1:${var.account_id}:AomaExternalConvRequestQueue",
      "arn:aws:sqs:eu-central-1:${var.account_id}:AomaExternalConvResponseQueue",
      "arn:aws:sqs:eu-central-1:${var.account_id}:SftpDeliveryQueue",
      "arn:aws:sqs:eu-central-1:${var.account_id}:S3DeliveryQueue",
      "arn:aws:sqs:eu-central-1:${var.account_id}:AsperaDeliveryQueue",
      "arn:aws:sqs:eu-central-1:${var.account_id}:TransporterDeliveryQueue",
    ]

    actions = ["sqs:*"]
  }
}

data "aws_iam_policy_document" "dd-agent-ecs" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "ecs:RegisterContainerInstance",
      "ecs:DeregisterContainerInstance",
      "ecs:DiscoverPollEndpoint",
      "ecs:Submit*",
      "ecs:Poll",
      "ecs:StartTask",
      "ecs:StartTelemetrySession",
    ]
  }
}

data "aws_iam_policy_document" "sme-delivery-scheduler-role-policy" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  #checkov:skip=CKV_AWS_109: Ensure IAM policies does not allow permissions management / resource exposure without constraints
  statement {
    sid       = "Stmt1486459983000"
    effect    = "Allow"
    resources = ["*"]
    actions   = ["ses:*"]
  }

  statement {
    sid    = "Stmt1486460004000"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delivery-target",
      "arn:aws:s3:::sme-delivery-target/*",
    ]

    actions = [
      "s3:AbortMultipartUpload",
      "s3:DeleteObject",
      "s3:Get*",
      "s3:ListBucket",
      "s3:ListBucketMultipartUploads",
      "s3:Put*",
    ]
  }

  statement {
    sid    = "Stmt1486460005000"
    effect = "Allow"

    resources = [
      "arn:aws:kinesis:eu-central-1:${var.account_id}:stream/EmailStream",
      "arn:aws:kinesis:eu-central-1:${var.account_id}:stream/ArchivePackageStream",
    ]

    actions = ["kinesis:PutRecord"]
  }
}

data "aws_iam_policy_document" "sme-mps-datastore-to-sme-mps-datastore" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme.mps.datastore"]

    actions = [
      "s3:GetReplicationConfiguration",
      "s3:ListBucket",
    ]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme.mps.datastore/*"]

    actions = [
      "s3:GetObjectVersion",
      "s3:GetObjectVersionAcl",
      "s3:GetObjectVersionTagging",
    ]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-mps-datastore/*"]

    actions = [
      "s3:ReplicateObject",
      "s3:ReplicateDelete",
      "s3:ReplicateTags",
    ]
  }
}

data "aws_iam_policy_document" "DynamoDBFullAccess_ytcms_db" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:dynamodb:eu-west-2:${var.account_id}:table/ytcms_db"]
    actions   = ["dynamodb:*"]
  }
}

data "aws_iam_policy_document" "secret_manager_access_policy" {
  #checkov:skip=CKV_AWS_108: Ensure IAM policies does not allow data exfiltration
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "secretsmanager:GetRandomPassword",
      "secretsmanager:GetResourcePolicy",
      "secretsmanager:GetSecretValue",
      "secretsmanager:DescribeSecret",
      "secretsmanager:ListSecretVersionIds",
      "secretsmanager:ListSecrets",
    ]
  }
}

data "aws_iam_policy_document" "DeepSecurity" {
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "ec2:DescribeInstances",
      "ec2:DescribeTags",
      "ec2:DescribeRegions",
      "workspaces:DescribeWorkspaceBundles",
      "ec2:DescribeSecurityGroups",
      "ec2:DescribeImages",
      "ec2:DescribeAvailabilityZones",
      "workspaces:DescribeTags",
      "ec2:DescribeVpcs",
      "iam:ListAccountAliases",
      "ec2:DescribeSubnets",
      "workspaces:DescribeWorkspaces",
      "workspaces:DescribeWorkspaceDirectories",
    ]
  }

  statement {
    sid       = "VisualEditor1"
    effect    = "Allow"
    resources = ["arn:aws:iam::*:role/DeepSecurity*"]

    actions = [
      "iam:GetRole",
      "iam:GetRolePolicy",
    ]
  }
}

data "aws_iam_policy_document" "AWS_Allow_Inspector_Assessment" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]
    actions   = ["inspector:StartAssessmentRun"]
  }
}

data "aws_iam_policy_document" "sme-delivery-smartutil-policy" {
  statement {
    sid    = "Stmt1498115496000"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delivery-target",
      "arn:aws:s3:::sme-delivery-target/*",
      "arn:aws:s3:::sme-delivery-messages-prod",
      "arn:aws:s3:::sme-delivery-messages-prod/*",
    ]

    actions = ["s3:*"]
  }

  statement {
    sid    = "Stmt1499318283000"
    effect = "Allow"

    resources = [
      "arn:aws:sqs:eu-central-1:${var.account_id}:SftpDeliveryQueue",
      "arn:aws:sqs:eu-central-1:${var.account_id}:S3DeliveryQueue",
      "arn:aws:sqs:eu-central-1:${var.account_id}:AsperaDeliveryQueue",
      "arn:aws:sqs:eu-central-1:${var.account_id}:TransporterDeliveryQueue",
    ]

    actions = ["sqs:*"]
  }
}

data "aws_iam_policy_document" "RDSProxyIAMpolicy" {
  #checkov:skip=CKV_AWS_108: Ensure IAM policies does not allow data exfiltration
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["arn:aws:kms:eu-central-1:${var.account_id}:key/7fcf7089-a08e-4de9-8177-1a3026ed3a1c"]
    actions   = ["kms:Decrypt"]

    condition {
      test     = "StringEquals"
      variable = "kms:ViaService"
      values   = ["secretsmanager.eu-central-1.amazonaws.com"]
    }
  }

  statement {
    sid       = "VisualEditor1"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "secretsmanager:GetRandomPassword",
      "secretsmanager:GetResourcePolicy",
      "secretsmanager:GetSecretValue",
      "secretsmanager:DescribeSecret",
      "secretsmanager:ListSecretVersionIds",
      "secretsmanager:ListSecrets",
    ]
  }
}

data "aws_iam_policy_document" "systems_manager_parameters" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  statement {
    sid    = "VisualEditor0"
    effect = "Allow"

    resources = [
      "arn:aws:ssm:*:${var.account_id}:patchbaseline/*",
      "arn:aws:ssm:*:${var.account_id}:maintenancewindow/*",
      "arn:aws:ssm:*:${var.account_id}:document/*",
      "arn:aws:ssm:*:${var.account_id}:parameter/*",
      "arn:aws:ssm:*:${var.account_id}:servicesetting/*",
      "arn:aws:ssm:*:${var.account_id}:resource-data-sync/*",
    ]

    actions = [
      "ssm:LabelParameterVersion",
      "ssm:DescribeDocument",
      "ssm:UpdateAssociation",
      "ssm:GetParameter",
      "ssm:DeletePatchBaseline",
      "ssm:GetMaintenanceWindowTask",
      "ssm:DeleteParameter",
      "ssm:RemoveTagsFromResource",
      "ssm:DeleteResourceDataSync",
      "ssm:AddTagsToResource",
      "ssm:GetDocument",
      "ssm:GetParametersByPath",
      "ssm:GetMaintenanceWindow",
      "ssm:UpdateDocument",
      "ssm:UpdatePatchBaseline",
      "ssm:DescribeAssociation",
      "ssm:GetParameterHistory",
      "ssm:GetParameters",
      "ssm:DeleteParameters",
      "ssm:UpdateServiceSetting",
      "ssm:PutParameter",
      "ssm:UpdateResourceDataSync",
      "ssm:ListTagsForResource",
      "ssm:DescribeDocumentParameters",
      "ssm:DescribeDocumentPermission",
      "ssm:GetCalendarState",
    ]
  }

  statement {
    sid       = "VisualEditor1"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "ssm:CancelCommand",
      "ssm:GetAutomationExecution",
      "ssm:ListCommands",
      "ssm:DescribeInstancePatches",
      "ssm:CreateActivation",
      "ssm:DescribePatchGroupState",
      "ssm:PutConfigurePackageResult",
      "ssm:GetMaintenanceWindowExecutionTaskInvocation",
      "ssm:DescribeAutomationExecutions",
      "ssm:GetManifest",
      "ssm:DescribeAutomationStepExecutions",
      "ssm:UpdateInstanceInformation",
      "ssm:DescribeInstancePatchStates",
      "ssm:DescribeInstancePatchStatesForPatchGroup",
      "ssm:DescribeParameters",
      "ssm:GetInventorySchema",
      "ssm:DescribeAssociationExecutionTargets",
      "ssm:DescribeInstanceProperties",
      "ssm:GetConnectionStatus",
      "ssm:GetMaintenanceWindowExecutionTask",
      "ssm:GetDeployablePatchSnapshotForInstance",
      "ssm:GetOpsItem",
      "ssm:GetMaintenanceWindowExecution",
      "ssm:DescribeInventoryDeletions",
      "ssm:DescribeActivations",
      "ssm:GetInventory",
      "ssm:DescribeOpsItems",
      "ssm:GetCommandInvocation",
      "ssm:UpdateOpsItem",
      "ssm:PutInventory",
      "ssm:DescribeInstanceInformation",
      "ssm:DescribeAssociationExecutions",
      "ssm:ListCommandInvocations",
      "ssm:DescribeAvailablePatches",
    ]
  }

  statement {
    sid    = "VisualEditor2"
    effect = "Allow"

    resources = [
      "arn:aws:ssm:*:${var.account_id}:maintenancewindow/*",
      "arn:aws:ssm:*:${var.account_id}:document/*",
      "arn:aws:ssm:*:${var.account_id}:servicesetting/*",
      "arn:aws:ssm:*:${var.account_id}:resource-data-sync/*",
    ]

    actions = [
      "ssm:GetMaintenanceWindowTask",
      "ssm:DescribeAssociation",
      "ssm:DescribeDocument",
      "ssm:ListTagsForResource",
      "ssm:DescribeDocumentParameters",
      "ssm:GetDocument",
      "ssm:GetServiceSetting",
      "ssm:GetMaintenanceWindow",
      "ssm:DescribeDocumentPermission",
      "ssm:GetOpsSummary",
      "ssm:GetCalendarState",
    ]
  }
}

data "aws_iam_policy_document" "ELB_Access" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]
    actions   = ["elasticloadbalancing:*"]
  }
}

data "aws_iam_policy_document" "delp2-ecs-service-discovery-LambdaServiceRole" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:logs:*:*:*"]

    actions = [
      "logs:CreateLogGroup",
      "logs:CreateLogStream",
      "logs:PutLogEvents",
    ]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:route53:::hostedzone/Z1BGWPD0HCIVKF"]
    actions   = ["route53:ChangeResourceRecordSets"]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]
    actions   = ["elasticloadbalancing:DescribeLoadBalancers"]
  }
}

data "aws_iam_policy_document" "CloudabilityVerificationPolicy" {
  statement {
    sid       = "VerifyRolePermissions"
    effect    = "Allow"
    resources = ["arn:aws:iam::*:role/CloudabilityRole"]
    actions   = ["iam:SimulatePrincipalPolicy"]
  }
}

data "aws_iam_policy_document" "sme-delivery-util-policy" {
  statement {
    sid    = "Stmt1498115497003"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delivery-target",
      "arn:aws:s3:::sme-delivery-target/*",
    ]

    actions = ["s3:*"]
  }
}

data "aws_iam_policy_document" "AzureDeliveryQ-sqs-policy" {
  statement {
    sid    = ""
    effect = "Allow"

    resources = [
      "arn:aws:sqs:eu-central-1:${var.account_id}:AzureDeliveryQ.fifo",
      "arn:aws:sqs:eu-central-1:${var.account_id}:AzureDeliveryDLQ.fifo",
      "arn:aws:sqs:eu-central-1:${var.account_id}:GcsDeliveryDLQ.fifo",
      "arn:aws:sqs:eu-central-1:${var.account_id}:GcsDeliveryQ.fifo",
    ]

    actions = ["sqs:*"]
  }
}

data "aws_iam_policy_document" "sme-amps-rw" {
  statement {
    sid    = "VisualEditor1"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::amp-asset-usr-ust-s",
      "arn:aws:s3:::amp-asset-usr-ust-s/*",
    ]

    actions = ["s3:*"]
  }
}

data "aws_iam_policy_document" "policygen-media-conversion-aws-prod-201509011315" {
  statement {
    sid       = "Stmt1441127694000"
    effect    = "Allow"
    resources = ["*"]
    actions   = ["sts:DecodeAuthorizationMessage"]
  }
}

data "aws_iam_policy_document" "delp-portal-policy" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  #checkov:skip=CKV_AWS_107: Ensure IAM policies does not allow credentials exposure
  #checkov:skip=CKV_AWS_110: Ensure IAM policies does not allow privilege escalation
  #checkov:skip=CKV_AWS_109: Ensure IAM policies does not allow permissions management / resource exposure without constraints
  #checkov:skip=CKV_AWS_108: Ensure IAM policies does not allow data exfiltration
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      #      "lambda:*",
      #      "wafv2:*",
      #      "support:*",
      "ssm:SendCommand",
      # "waf-regional:GetRuleGroup",
      # "waf-regional:GetRateBasedRuleManagedKeys",
      # "waf-regional:GetRateBasedRule",
      "iam:ListServiceSpecificCredentials",
      "iam:ListSigningCertificates",
      "s3:List*",
      "s3:Get*",
      # "waf-regional:GetRegexMatchSet",
      # "waf-regional:UpdateSqlInjectionMatchSet",
      "ec2:CreateRoute",
      # "waf-regional:GetWebACL",
      "ec2:DescribeVolumes",
      "config:DescribeConfigRules",
      "ec2:DescribeKeyPairs",
      "iam:ListRolePolicies",
      # "waf-regional:GetXssMatchSet",
      "iam:ListPolicies",
      "cloudtrail:LookupEvents",
      "iam:GetRole",
      "iam:ListSAMLProviders",
      "lambda:ListFunctions",
      "inspector:ListFindings",
      "glacier:ListVaults",
      "ec2:ModifyVpcEndpoint",
      "ssm:DescribePatchGroups",
      "s3:GetBucketTagging",
      "ec2:DescribeFlowLogs",
      "ecs:ListServices",
      "iam:ListInstanceProfilesForRole",
      # "waf-regional:DeleteGeoMatchSet",
      # "waf-regional:GetGeoMatchSet",
      # "waf-regional:GetRegexPatternSet",
      "ssm:DescribeInstancePatchStatesForPatchGroup",
      "ec2:CreateSnapshot",
      # "waf-regional:GetSampledRequests",
      "es:DescribeElasticsearchDomains",
      "ec2:ReleaseAddress",
      "inspector:ListAssessmentTargets",
      # "waf-regional:DeleteRateBasedRule",
      "iam:ListRoles",
      # "waf-regional:DeleteRegexMatchSet",
      # "waf-regional:DeleteLoggingConfiguration",
      # "waf-regional:UpdateByteMatchSet",
      "ec2:DescribeSecurityGroups",
      "s3:PutInventoryConfiguration",
      "es:ListDomainNames",
      "rds:ListTagsForResource",
      "elasticloadbalancing:DescribeTargetGroups",
      "iam:ListGroups",
      "iam:UpdateAssumeRolePolicy",
      "iam:GetPolicyVersion",
      # "waf-regional:GetChangeToken",
      # "waf-regional:UpdateXssMatchSet",
      "iam:ListServerCertificates",
      "ssm:DescribeInstancePatches",
      # "waf-regional:UpdateIPSet",
      "iam:ListVirtualMFADevices",
      # "waf-regional:GetSqlInjectionMatchSet",
      "elasticloadbalancing:DescribeLoadBalancers",
      # "waf-regional:ListTagsForResource",
      # "waf-regional:UpdateRegexMatchSet",
      "iam:ListSSHPublicKeys",
      "iam:ListOpenIDConnectProviderTags",
      "route53:ListResourceRecordSets",
      "ec2:DescribeReservedInstances",
      "trustedadvisor:Describe*",
      # "waf-regional:PutLoggingConfiguration",
      "rds:DescribeDBSnapshots",
      "ec2:DescribeVpcPeeringConnections",
      "glacier:ListTagsForVault",
      "iam:GetAccessKeyLastUsed",
      # "waf-regional:CreateSqlInjectionMatchSet",
      # "waf-regional:CreateRateBasedRule",
      "eks:DescribeCluster",
      "elasticache:DescribeCacheClusters",
      # "waf-regional:CreateRegexPatternSet",
      "ec2:DescribeVpnGateways",
      "iam:GetAccountSummary",
      "ec2:DescribeAddresses",
      "kafka:ListClusters",
      # "waf-regional:GetByteMatchSet",
      "s3:GetBucketLogging",
      "iam:ListMFADevices",
      # "waf-regional:GetRule",
      "s3:PutEncryptionConfiguration",
      "s3:GetEncryptionConfiguration",
      "directconnect:DescribeVirtualInterfaces",
      # "waf-regional:UpdateSizeConstraintSet",
      # "waf-regional:CreateSizeConstraintSet",
      "ecs:DescribeServices",
      "ecr:DescribeRepositories",
      "ecs:ListClusters",
      "health:DescribeEvents",
      "sqs:ListQueues",
      # "waf-regional:CreateGeoMatchSet",
      "iam:ListUserPolicies",
      # "waf-regional:UpdateRule",
      "iam:ListPolicyVersions",
      "iam:ListOpenIDConnectProviders",
      # "waf-regional:DeleteIPSet",
      "elasticloadbalancing:DescribeTargetHealth",
      "iam:ListUsers",
      "iam:ListUserTags",
      # "waf-regional:CreateRule",
      "iam:DeleteAccessKey",
      "ec2:DescribeInstances",
      "iam:ListRoleTags",
      "ec2:DescribeSnapshots",
      "ecs:DescribeTaskDefinition",
      # "waf-regional:DeleteByteMatchSet",
      # "waf-regional:GetWebACLForResource",
      "iam:GetCredentialReport",
      # "waf-regional:ListWebACLs",
      "ec2:CreateTags",
      # "waf-regional:UpdateRegexPatternSet",
      "iam:ListEntitiesForPolicy",
      "kafka:DescribeCluster",
      "cloudwatch:GetMetricStatistics",
      # "waf-regional:ListRules",
      "cloudtrail:DescribeTrails",
      "eks:ListClusters",
      "ec2:DescribeSubnets",
      "iam:GenerateCredentialReport",
      "waf-regional:AssociateWebACL",
      "ce:GetCostAndUsage",
      "kms:ListResourceTags",
      "s3:AbortMultipartUpload",
      "s3:PutBucketTagging",
      "rds:DescribeDBInstances",
      "iam:ListAttachedGroupPolicies",
      "iam:ListPolicyTags",
      "iam:ListAccessKeys",
      "iam:ListGroupPolicies",
      "route53:ListHostedZones",
      # "waf-regional:DeleteSizeConstraintSet",
      "es:DescribeElasticsearchDomainConfig",
      # "waf-regional:CreateRegexMatchSet",
      "inspector:ListAssessmentRuns",
      # "waf-regional:DeleteXssMatchSet",
      "ec2:DescribeVpcs",
      "kms:ListAliases",
      "iam:ListServerCertificateTags",
      "iam:ListAccountAliases",
      "iam:GetLoginProfile",
      # "waf-regional:UpdateRateBasedRule",
      # "waf-regional:DeleteRegexPatternSet",
      # "waf-regional:GetPermissionPolicy",
      # "waf-regional:GetLoggingConfiguration",
      "ec2:DescribeInternetGateways",
      "ec2:DeleteVolume",
      "iam:ListAttachedRolePolicies",
      "elasticloadbalancing:DescribeLoadBalancerPolicies",
      "iam:ListSAMLProviderTags",
      # "waf-regional:GetIPSet",
      "ec2:DescribeNetworkAcls",
      "ec2:DescribeRouteTables",
      # "waf-regional:DeleteRuleGroup",
      # "waf-regional:GetChangeTokenStatus",
      "ec2:DescribeVpnConnections",
      "ec2:CreateRouteTable",
      "iam:UpdateAccessKey",
      "ecs:DescribeClusters",
      "elasticloadbalancing:DescribeLoadBalancerAttributes",
      # "waf-regional:CreateIPSet",
      "acm:DescribeCertificate",
      "s3:PutBucketLogging",
      "iam:ListGroupsForUser",
      "ecr:DescribeImages",
      # "waf-regional:CreateXssMatchSet",
      "ec2:DescribeVpcEndpoints",
      # "waf-regional:DeleteRule",
      # "waf-regional:CreateRuleGroup",
      "ec2:DeleteSnapshot",
      "ec2:DescribeInstanceAttribute",
      "iam:ListPoliciesGrantingServiceAccess",
      "iam:ListInstanceProfileTags",
      "iam:CreateAccessKey",
      # "waf-regional:GetSizeConstraintSet",
      # "waf-regional:CreateByteMatchSet",
      "elasticloadbalancing:DescribeListeners",
      "ec2:DescribeNetworkInterfaces",
      "es:DescribeElasticsearchDomain",
      "iam:ListAttachedUserPolicies",
      "acm:ListCertificates",
      "kms:DescribeKey",
      "elasticfilesystem:DescribeFileSystems",
      "inspector:DescribeFindings",
      "s3:PutBucketPublicAccessBlock",
      # "waf-regional:DisassociateWebACL",
      "elasticloadbalancing:DescribeTags",
      # "waf-regional:DeleteSqlInjectionMatchSet",
      "ec2:DescribeNatGateways",
      "ec2:DescribeCustomerGateways",
      "iam:ListInstanceProfiles",
      "support:Describe*",
      "support:GetInteraction",
      "support:List*",
      "support:SearchForCases",
      "support:Add*",
      "support:CreateCase",
      "support:Initiate*",
      "support:PutCaseAttributes",
      "support:RateCaseCommunication",
      "support:RefreshTrustedAdvisorCheck",
      "support:Resolve*",
      "support:StartInteraction",
      "support:Update*",
      "ec2:DescribeImages",
      "redshift:DescribeClusters",
      "cloudfront:ListDistributions",
      # "waf-regional:UpdateGeoMatchSet",
      # "waf-regional:UpdateRuleGroup",
      "iam:ListMFADeviceTags",
      "s3:GetBucketLocation",
      "iam:ListAccountAliases",
      "firehose:CreateDeliveryStream",
      "iam:PassRole",
      "apigateway:GET",
      "lambda:List*",
      "lambda:Get*",
      "lambda:CheckpointDurableExecution",
      "lambda:Create*",
      "lambda:Delete*",
      "lambda:Invoke*",
      "lambda:PassCapacityProvider",
      "lambda:Publish*",
      "lambda:Put*",
      "lambda:Send*",
      "lambda:StopDurableExecution",
      "lambda:Update*",
      "lambda:Add*",
      "lambda:DisableReplication",
      "lambda:EnableReplication",
      "lambda:Remove*",
      "lambda:TagResource",
      "lambda:UntagResource",
      "elasticmapreduce:ListClusters",
      "ssm:SendCommand",
      "ssm:DescribeInstanceInformation",
      "ssm:GetCommandInvocation",
    ]
  }
}

data "aws_iam_policy_document" "oneClick_CloudTrail_CloudWatchLogs_Role_1540805758929" {
  statement {
    sid       = "AWSCloudTrailCreateLogStream20141101"
    effect    = "Allow"
    resources = ["arn:aws:logs:eu-central-1:${var.account_id}:log-group:CloudTrail/GSIRT-Monitoring-Trail:log-stream:${var.account_id}_CloudTrail_eu-central-1*"]
    actions   = ["logs:CreateLogStream"]
  }

  statement {
    sid       = "AWSCloudTrailPutLogEvents20141101"
    effect    = "Allow"
    resources = ["arn:aws:logs:eu-central-1:${var.account_id}:log-group:CloudTrail/GSIRT-Monitoring-Trail:log-stream:${var.account_id}_CloudTrail_eu-central-1*"]
    actions   = ["logs:PutLogEvents"]
  }
}

data "aws_iam_policy_document" "mlib-prod-ecs-secretmanager-policy" {
  statement {
    sid    = "VisualEditor0"
    effect = "Allow"

    resources = [
      "arn:aws:secretsmanager:eu-central-1:${var.account_id}:secret:PROD/MLIB-DB/PostgreSql-RDS-DB-dks3l0",
      "arn:aws:secretsmanager:eu-central-1:${var.account_id}:secret:PROD/MLIB/MSRV-ArzROT",
      "arn:aws:secretsmanager:eu-central-1:${var.account_id}:secret:PROD/MLIB/GraphQl-D8t6KW",
      "arn:aws:secretsmanager:eu-central-1:${var.account_id}:secret:db/mlib/prod/media_library_app-X8lFdu",
    ]

    actions = [
      "secretsmanager:GetResourcePolicy",
      "secretsmanager:GetSecretValue",
      "secretsmanager:DescribeSecret",
      "secretsmanager:RestoreSecret",
      "secretsmanager:PutSecretValue",
      "secretsmanager:CreateSecret",
      "secretsmanager:UpdateSecretVersionStage",
      "secretsmanager:RotateSecret",
      "secretsmanager:CancelRotateSecret",
      "secretsmanager:ListSecretVersionIds",
      "secretsmanager:UpdateSecret",
    ]
  }

  statement {
    sid       = "VisualEditor1"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "secretsmanager:GetRandomPassword",
      "secretsmanager:ListSecrets",
    ]
  }
}

data "aws_iam_policy_document" "ALBIngressControllerIAMPolicy" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  statement {
    effect    = "Allow"
    resources = ["*"]
    actions   = ["iam:CreateServiceLinkedRole"]

    condition {
      test     = "StringEquals"
      variable = "iam:AWSServiceName"
      values   = ["elasticloadbalancing.amazonaws.com"]
    }
  }

  statement {
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "ec2:DescribeAccountAttributes",
      "ec2:DescribeAddresses",
      "ec2:DescribeAvailabilityZones",
      "ec2:DescribeInternetGateways",
      "ec2:DescribeVpcs",
      "ec2:DescribeVpcPeeringConnections",
      "ec2:DescribeSubnets",
      "ec2:DescribeSecurityGroups",
      "ec2:DescribeInstances",
      "ec2:DescribeNetworkInterfaces",
      "ec2:DescribeTags",
      "ec2:GetCoipPoolUsage",
      "ec2:DescribeCoipPools",
      "ec2:GetSecurityGroupsForVpc",
      "elasticloadbalancing:DescribeLoadBalancers",
      "elasticloadbalancing:DescribeLoadBalancerAttributes",
      "elasticloadbalancing:DescribeListeners",
      "elasticloadbalancing:DescribeListenerCertificates",
      "elasticloadbalancing:DescribeSSLPolicies",
      "elasticloadbalancing:DescribeRules",
      "elasticloadbalancing:DescribeTargetGroups",
      "elasticloadbalancing:DescribeTargetGroupAttributes",
      "elasticloadbalancing:DescribeTargetHealth",
      "elasticloadbalancing:DescribeTags",
      "elasticloadbalancing:DescribeTrustStores",
      "elasticloadbalancing:DescribeListenerAttributes",
      "elasticloadbalancing:DescribeCapacityReservation",
    ]
  }

  statement {
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "cognito-idp:DescribeUserPoolClient",
      "acm:ListCertificates",
      "acm:DescribeCertificate",
      "iam:ListServerCertificates",
      "iam:GetServerCertificate",
      "waf-regional:GetWebACL",
      "waf-regional:GetWebACLForResource",
      "waf-regional:AssociateWebACL",
      "waf-regional:DisassociateWebACL",
      "wafv2:GetWebACL",
      "wafv2:GetWebACLForResource",
      "wafv2:AssociateWebACL",
      "wafv2:DisassociateWebACL",
      "shield:GetSubscriptionState",
      "shield:DescribeProtection",
      "shield:CreateProtection",
      "shield:DeleteProtection",
    ]
  }

  statement {
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "ec2:AuthorizeSecurityGroupIngress",
      "ec2:RevokeSecurityGroupIngress",
    ]
  }

  statement {
    effect    = "Allow"
    resources = ["*"]
    actions   = ["ec2:CreateSecurityGroup"]
  }

  statement {
    effect    = "Allow"
    resources = ["arn:aws:ec2:*:*:security-group/*"]
    actions   = ["ec2:CreateTags"]

    condition {
      test     = "StringEquals"
      variable = "ec2:CreateAction"
      values   = ["CreateSecurityGroup"]
    }

    condition {
      test     = "Null"
      variable = "aws:RequestTag/elbv2.k8s.aws/cluster"
      values   = ["false"]
    }
  }

  statement {
    effect    = "Allow"
    resources = ["arn:aws:ec2:*:*:security-group/*"]

    actions = [
      "ec2:CreateTags",
      "ec2:DeleteTags",
    ]

    condition {
      test     = "Null"
      variable = "aws:RequestTag/elbv2.k8s.aws/cluster"
      values   = ["true"]
    }

    condition {
      test     = "Null"
      variable = "aws:ResourceTag/elbv2.k8s.aws/cluster"
      values   = ["false"]
    }
  }

  statement {
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "ec2:AuthorizeSecurityGroupIngress",
      "ec2:RevokeSecurityGroupIngress",
      "ec2:DeleteSecurityGroup",
    ]

    condition {
      test     = "Null"
      variable = "aws:ResourceTag/elbv2.k8s.aws/cluster"
      values   = ["false"]
    }
  }

  statement {
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "elasticloadbalancing:CreateLoadBalancer",
      "elasticloadbalancing:CreateTargetGroup",
    ]

    condition {
      test     = "Null"
      variable = "aws:RequestTag/elbv2.k8s.aws/cluster"
      values   = ["false"]
    }
  }

  statement {
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "elasticloadbalancing:CreateListener",
      "elasticloadbalancing:DeleteListener",
      "elasticloadbalancing:CreateRule",
      "elasticloadbalancing:DeleteRule",
    ]
  }

  statement {
    effect = "Allow"

    resources = [
      "arn:aws:elasticloadbalancing:*:*:targetgroup/*/*",
      "arn:aws:elasticloadbalancing:*:*:loadbalancer/net/*/*",
      "arn:aws:elasticloadbalancing:*:*:loadbalancer/app/*/*",
    ]

    actions = [
      "elasticloadbalancing:AddTags",
      "elasticloadbalancing:RemoveTags",
    ]

    condition {
      test     = "Null"
      variable = "aws:RequestTag/elbv2.k8s.aws/cluster"
      values   = ["true"]
    }

    condition {
      test     = "Null"
      variable = "aws:ResourceTag/elbv2.k8s.aws/cluster"
      values   = ["false"]
    }
  }

  statement {
    effect = "Allow"

    resources = [
      "arn:aws:elasticloadbalancing:*:*:listener/net/*/*/*",
      "arn:aws:elasticloadbalancing:*:*:listener/app/*/*/*",
      "arn:aws:elasticloadbalancing:*:*:listener-rule/net/*/*/*",
      "arn:aws:elasticloadbalancing:*:*:listener-rule/app/*/*/*",
    ]

    actions = [
      "elasticloadbalancing:AddTags",
      "elasticloadbalancing:RemoveTags",
    ]
  }

  statement {
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "elasticloadbalancing:ModifyLoadBalancerAttributes",
      "elasticloadbalancing:SetIpAddressType",
      "elasticloadbalancing:SetSecurityGroups",
      "elasticloadbalancing:SetSubnets",
      "elasticloadbalancing:DeleteLoadBalancer",
      "elasticloadbalancing:ModifyTargetGroup",
      "elasticloadbalancing:ModifyTargetGroupAttributes",
      "elasticloadbalancing:DeleteTargetGroup",
      "elasticloadbalancing:ModifyListenerAttributes",
      "elasticloadbalancing:ModifyCapacityReservation",
    ]

    condition {
      test     = "Null"
      variable = "aws:ResourceTag/elbv2.k8s.aws/cluster"
      values   = ["false"]
    }
  }

  statement {
    effect = "Allow"

    resources = [
      "arn:aws:elasticloadbalancing:*:*:targetgroup/*/*",
      "arn:aws:elasticloadbalancing:*:*:loadbalancer/net/*/*",
      "arn:aws:elasticloadbalancing:*:*:loadbalancer/app/*/*",
    ]

    actions = ["elasticloadbalancing:AddTags"]

    condition {
      test     = "StringEquals"
      variable = "elasticloadbalancing:CreateAction"

      values = [
        "CreateTargetGroup",
        "CreateLoadBalancer",
      ]
    }

    condition {
      test     = "Null"
      variable = "aws:RequestTag/elbv2.k8s.aws/cluster"
      values   = ["false"]
    }
  }

  statement {
    effect    = "Allow"
    resources = ["arn:aws:elasticloadbalancing:*:*:targetgroup/*/*"]

    actions = [
      "elasticloadbalancing:RegisterTargets",
      "elasticloadbalancing:DeregisterTargets",
    ]
  }

  statement {
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "elasticloadbalancing:SetWebAcl",
      "elasticloadbalancing:ModifyListener",
      "elasticloadbalancing:AddListenerCertificates",
      "elasticloadbalancing:RemoveListenerCertificates",
      "elasticloadbalancing:ModifyRule",
    ]
  }
}

data "aws_iam_policy_document" "kinesis-statusupdatestream" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "kinesis:ListStreams",
      "kinesis:EnableEnhancedMonitoring",
      "kinesis:ListShards",
      "kinesis:UpdateShardCount",
      "kinesis:DescribeLimits",
      "kinesis:ListStreamConsumers",
      "kinesis:DisableEnhancedMonitoring",
      "kinesis:PutRecord",
    ]
  }

  statement {
    sid    = "VisualEditor1"
    effect = "Allow"
    resources = [
      "arn:aws:kinesis:eu-central-1:${var.account_id}:stream/StatusUpdateStream",
      "arn:aws:kinesis:eu-central-1:${var.account_id}:stream/ArchivePackageStream",
    ]
    actions = ["kinesis:*"]
  }
}

data "aws_iam_policy_document" "policygen-sme-gen-dynamodb" {
  statement {
    sid       = "Stmt1497344965000"
    effect    = "Allow"
    resources = ["arn:aws:dynamodb:us-east-1:361463692799:table/mpub_media"]
    actions   = ["dynamodb:*"]
  }
}

data "aws_iam_policy_document" "KinesisFirehoseServicePolicy-aws-waf-logs-delp-us-east-1-us-east-1" {
  statement {
    sid    = ""
    effect = "Allow"

    resources = [
      "arn:aws:glue:us-east-1:${var.account_id}:catalog",
      "arn:aws:glue:us-east-1:${var.account_id}:database/%FIREHOSE_POLICY_TEMPLATE_PLACEHOLDER%",
      "arn:aws:glue:us-east-1:${var.account_id}:table/%FIREHOSE_POLICY_TEMPLATE_PLACEHOLDER%/%FIREHOSE_POLICY_TEMPLATE_PLACEHOLDER%",
    ]

    actions = [
      "glue:GetTable",
      "glue:GetTableVersion",
      "glue:GetTableVersions",
    ]
  }

  statement {
    sid    = ""
    effect = "Allow"

    resources = [
      "arn:aws:s3:::delp-aws-waf-logs-us-east-1",
      "arn:aws:s3:::delp-aws-waf-logs-us-east-1/*",
    ]

    actions = [
      "s3:AbortMultipartUpload",
      "s3:GetBucketLocation",
      "s3:GetObject",
      "s3:ListBucket",
      "s3:ListBucketMultipartUploads",
      "s3:PutObject",
    ]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:lambda:us-east-1:${var.account_id}:function:%FIREHOSE_POLICY_TEMPLATE_PLACEHOLDER%"]

    actions = [
      "lambda:InvokeFunction",
      "lambda:GetFunctionConfiguration",
    ]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:kms:us-east-1:${var.account_id}:key/%FIREHOSE_POLICY_TEMPLATE_PLACEHOLDER%"]

    actions = [
      "kms:GenerateDataKey",
      "kms:Decrypt",
    ]

    condition {
      test     = "StringEquals"
      variable = "kms:ViaService"
      values   = ["s3.us-east-1.amazonaws.com"]
    }

    condition {
      test     = "StringLike"
      variable = "kms:EncryptionContext:aws:s3:arn"
      values   = ["arn:aws:s3:::%FIREHOSE_POLICY_TEMPLATE_PLACEHOLDER%/*"]
    }
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:logs:us-east-1:${var.account_id}:log-group:/aws/kinesisfirehose/aws-waf-logs-delp-us-east-1:log-stream:*"]
    actions   = ["logs:PutLogEvents"]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:kinesis:us-east-1:${var.account_id}:stream/%FIREHOSE_POLICY_TEMPLATE_PLACEHOLDER%"]

    actions = [
      "kinesis:DescribeStream",
      "kinesis:GetShardIterator",
      "kinesis:GetRecords",
      "kinesis:ListShards",
    ]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:kms:us-east-1:${var.account_id}:key/%FIREHOSE_POLICY_TEMPLATE_PLACEHOLDER%"]
    actions   = ["kms:Decrypt"]

    condition {
      test     = "StringEquals"
      variable = "kms:ViaService"
      values   = ["kinesis.us-east-1.amazonaws.com"]
    }

    condition {
      test     = "StringLike"
      variable = "kms:EncryptionContext:aws:kinesis:arn"
      values   = ["arn:aws:kinesis:us-east-1:${var.account_id}:stream/%FIREHOSE_POLICY_TEMPLATE_PLACEHOLDER%"]
    }
  }
}

data "aws_iam_policy_document" "AWSLambdaBasicExecutionRole-20b39b37-313a-446f-9d00-0dbef3901a76" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:logs:us-west-2:${var.account_id}:*"]
    actions   = ["logs:CreateLogGroup"]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:logs:us-west-2:${var.account_id}:log-group:/aws/lambda/pitch-app-track-loader-lambda-function:*"]

    actions = [
      "logs:CreateLogStream",
      "logs:PutLogEvents",
    ]
  }

  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "lambda:ListFunctions",
      "lambda:ListVersionsByFunction",
      "lambda:GetLayerVersion",
      "lambda:GetEventSourceMapping",
      "lambda:GetFunction",
      "lambda:ListAliases",
      "lambda:GetAccountSettings",
      "lambda:GetFunctionConfiguration",
      "lambda:GetLayerVersionPolicy",
      "lambda:ListTags",
      "lambda:ListEventSourceMappings",
      "lambda:ListLayerVersions",
      "lambda:ListLayers",
      "lambda:GetAlias",
      "lambda:GetPolicy",
    ]
  }
}

data "aws_iam_policy_document" "policy-ddexws-role-25mar2017" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  #checkov:skip=CKV_AWS_109: Ensure IAM policies does not allow permissions management / resource exposure without constraints
  statement {
    sid       = "Stmt1490413318000"
    effect    = "Allow"
    resources = ["arn:aws:sqs:eu-central-1:${var.account_id}:DdexWebserviceStatusRequestStorageQueue"]
    actions   = ["sqs:*"]
  }

  statement {
    sid       = "Stmt1490413423000"
    effect    = "Allow"
    resources = ["*"]
    actions = [
      "ses:*",
      "kms:Decrypt",
    ]
  }

  statement {
    sid    = "Stmt1490413454000"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delivery-target",
      "arn:aws:s3:::sme-delivery-target/*",
    ]

    actions = [
      "s3:DeleteObject",
      "s3:GetBucketNotification",
      "s3:GetBucketPolicy",
      "s3:GetObject",
      "s3:GetObjectAcl",
      "s3:GetObjectVersion",
      "s3:ListBucket",
      "s3:ListBucketMultipartUploads",
      "s3:ListMultipartUploadParts",
      "s3:PutBucketNotification",
      "s3:PutObject",
      "s3:PutObjectAcl",
      "s3:PutObjectVersionAcl",
      "s3:RestoreObject",
    ]
  }

  statement {
    sid    = "Stmt1498113445000"
    effect = "Allow"

    resources = [
      "arn:aws:kinesis:eu-central-1:${var.account_id}:stream/EmailStream",
      "arn:aws:kinesis:eu-central-1:${var.account_id}:stream/ArchivePackageStream",
    ]

    actions = ["kinesis:PutRecord"]
  }
}

data "aws_iam_policy_document" "dsrv-prod-eks-cluster-ns-delivery-prod-sa-del-svc-gateway" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "kinesis:PutRecord",
      "kinesis:PutRecords",
      "secretsmanager:ListSecrets",
    ]
  }

  statement {
    sid    = "VisualEditor1"
    effect = "Allow"

    resources = [
      "arn:aws:secretsmanager:eu-central-1:023180329437:secret:PROD/DeliveryGatewayService/PostgreSql-RDS-DB-xT6CzS",
      "arn:aws:secretsmanager:eu-central-1:023180329437:secret:PROD/GATEWAY/KEY-OZhX9x",
      "arn:aws:secretsmanager:eu-central-1:023180329437:secret:PROD/DB/JASYPT/KEY-a618y3"
    ]

    actions = [
      "secretsmanager:*",
      "rds:*",
    ]
  }
}

data "aws_iam_policy_document" "queue-cwlogs-policy" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:logs:*:*:*"]

    actions = [
      "logs:CreateLogGroup",
      "logs:CreateLogStream",
      "logs:PutLogEvents",
      "logs:DescribeLogStreams",
    ]
  }
}

data "aws_iam_policy_document" "promo-prod-s3-star-1" {
  statement {
    sid    = "Stmt1491478039001"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::promo.prod.aoma.export",
      "arn:aws:s3:::promo.prod.campaigns",
      "arn:aws:s3:::promo.prod.customimagetemplate",
      "arn:aws:s3:::promo.prod.distributions",
      "arn:aws:s3:::promo.prod.hotfolders",
      "arn:aws:s3:::promo.prod.user.workbenches",
      "arn:aws:s3:::promo.prod.aoma.export/*",
      "arn:aws:s3:::promo.prod.campaigns/*",
      "arn:aws:s3:::promo.prod.customimagetemplate/*",
      "arn:aws:s3:::promo.prod.distributions/*",
      "arn:aws:s3:::promo.prod.hotfolders/*",
      "arn:aws:s3:::promo.prod.user.workbenches/*",
    ]

    actions = ["s3:*"]
  }
}

data "aws_iam_policy_document" "promo-dev-campaigns-distribution" {
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "s3:ListStorageLensConfigurations",
      "s3:ListAccessPointsForObjectLambda",
      "s3:GetAccessPoint",
      "s3:PutAccountPublicAccessBlock",
      "s3:GetAccountPublicAccessBlock",
      "s3:ListAllMyBuckets",
      "s3:ListAccessPoints",
      "s3:ListJobs",
      "s3:PutStorageLensConfiguration",
      "s3:CreateJob",
    ]
  }

  statement {
    sid    = "VisualEditor1"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delivery-uat-source",
      "arn:aws:s3:::sme-delivery-uat-source/*",
    ]

    actions = ["s3:*"]
  }

  statement {
    sid    = "VisualEditor2"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::promo.dev.campaigns/*",
      "arn:aws:s3:::promo.dev.distributions/*",
      "arn:aws:s3:::promo.dev.aoma.export/*",
      "arn:aws:s3:::promo.dev.customimagetemplate/*",
      "arn:aws:s3:::promo.dev.hotfolders/*",
      "arn:aws:s3:::promo.dev.user.workbenches/*",
      "arn:aws:s3:::vantage-test-media/*",
      "arn:aws:s3:::promo.dev.campaigns",
      "arn:aws:s3:::promo.dev.distributions",
      "arn:aws:s3:::promo.dev.aoma.export",
      "arn:aws:s3:::promo.dev.customimagetemplate",
      "arn:aws:s3:::promo.dev.hotfolders",
      "arn:aws:s3:::promo.dev.user.workbenches",
      "arn:aws:s3:::vantage-test-media",
    ]

    actions = ["s3:*"]
  }
}

data "aws_iam_policy_document" "eks-fargate-logging-policy" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "logs:CreateLogStream",
      "logs:CreateLogGroup",
      "logs:DescribeLogStreams",
      "logs:PutLogEvents",
    ]
  }
}

data "aws_iam_policy_document" "delp-sqs" {
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]
    actions   = ["sqs:ListQueues"]
  }

  statement {
    sid    = "VisualEditor1"
    effect = "Allow"

    resources = [
      "arn:aws:sqs:eu-central-1:023180329437:SFTPMsDeliveryQueue",
      "arn:aws:sqs:eu-central-1:023180329437:S3MsDeliveryQueue",
      "arn:aws:sqs:eu-central-1:023180329437:AsperaMsDeliveryQueue",
      "arn:aws:sqs:eu-central-1:023180329437:TransporterMsDeliveryQueue",
      "arn:aws:sqs:eu-central-1:023180329437:SonyCiDeliveryQueue",
      "arn:aws:sqs:eu-central-1:023180329437:GcsDeliveryQ.fifo",
      "arn:aws:sqs:eu-central-1:023180329437:AzureDeliveryQ.fifo",
      "arn:aws:sqs:eu-central-1:023180329437:S3v2DeliveryDLQ.fifo",
      "arn:aws:sqs:eu-central-1:023180329437:S3v2DeliveryQ.fifo",
    ]

    actions = ["sqs:*"]
  }
}

data "aws_iam_policy_document" "GSIRT_AWS_Monitoring_Role-DescribePolicy" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "sqs:GetQueueAttributes",
      "sqs:ListQueues",
      "sqs:GetQueueUrl",
      "s3:ListBucket",
      "s3:GetBucketLocation",
      "s3:ListAllMyBuckets",
      "s3:GetBucketTagging",
      "s3:GetAccelerateConfiguration",
      "s3:GetBucketLogging",
      "s3:GetLifecycleConfiguration",
      "s3:GetBucketCORS",
      "config:DeliverConfigSnapshot",
      "config:DescribeConfigRules",
      "config:DescribeConfigRuleEvaluationStatus",
      "config:GetComplianceDetailsByConfigRule",
      "config:GetComplianceSummaryByConfigRule",
      "iam:GetUser",
      "iam:ListUsers",
      "iam:GetAccountPasswordPolicy",
      "iam:ListAccessKeys",
      "iam:GetAccessKeyLastUsed",
      "autoscaling:Describe*",
      "cloudwatch:Describe*",
      "cloudwatch:Get*",
      "cloudwatch:List*",
      "sns:Get*",
      "sns:List*",
      "logs:DescribeLogGroups",
      "logs:DescribeLogStreams",
      "logs:GetLogEvents",
      "ec2:DescribeInstances",
      "ec2:DescribeReservedInstances",
      "ec2:DescribeSnapshots",
      "ec2:DescribeRegions",
      "ec2:DescribeKeyPairs",
      "ec2:DescribeNetworkAcls",
      "ec2:DescribeSecurityGroups",
      "ec2:DescribeSubnets",
      "ec2:DescribeVolumes",
      "ec2:DescribeVpcs",
      "ec2:DescribeImages",
      "ec2:DescribeAddresses",
      "lambda:ListFunctions",
      "rds:DescribeDBInstances",
      "cloudfront:ListDistributions",
      "elasticloadbalancing:DescribeLoadBalancers",
      "elasticloadbalancing:DescribeInstanceHealth",
      "elasticloadbalancing:DescribeTags",
      "elasticloadbalancing:DescribeTargetGroups",
      "elasticloadbalancing:DescribeTargetHealth",
      "elasticloadbalancing:DescribeListeners",
      "inspector:Describe*",
      "inspector:List*",
      "kinesis:DescribeStream",
      "kinesis:ListStreams",
      "eks:ListAddons",
      "eks:DescribeAddon",
      "eks:ListIdentityProviderConfigs",
      "eks:DescribeIdentityProviderConfig",
      "eks:DescribeAddonVersions",
      "eks:DescribeUpdate",
      "eks:ListTagsForResource",
      "network-firewall:ListTagsForResource",
      "logs:ListLogDeliveries",
      "logs:GetLogDelivery"
    ]
  }
}

data "aws_iam_policy_document" "media-conversion-s3-stage-access" {
  statement {
    sid    = "Stmt1402333240000"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme.delivery.master.dev/*",
      "arn:aws:s3:::sme.delivery.service.content/*",
    ]

    actions = [
      "s3:GetObject",
      "s3:PutObject",
    ]
  }
}

data "aws_iam_policy_document" "oneClick_CloudTrail_CloudWatchLogs_Role_1503402361310" {
  statement {
    sid       = "AWSCloudTrailCreateLogStream20141101"
    effect    = "Allow"
    resources = ["arn:aws:logs:eu-central-1:${var.account_id}:log-group:cloudtrail-traildash:log-stream:${var.account_id}_CloudTrail_eu-central-1*"]
    actions   = ["logs:CreateLogStream"]
  }

  statement {
    sid       = "AWSCloudTrailPutLogEvents20141101"
    effect    = "Allow"
    resources = ["arn:aws:logs:eu-central-1:${var.account_id}:log-group:cloudtrail-traildash:log-stream:${var.account_id}_CloudTrail_eu-central-1*"]
    actions   = ["logs:PutLogEvents"]
  }
}

data "aws_iam_policy_document" "AWSLambdaBasicExecutionRole-e1f9ab51-da25-409a-8807-e6ea0a256547" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:logs:eu-central-1:${var.account_id}:*"]
    actions   = ["logs:CreateLogGroup"]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:logs:eu-central-1:${var.account_id}:log-group:/aws/lambda/DeliveryShelfStageFileRecopyLambda:*"]

    actions = [
      "logs:CreateLogStream",
      "logs:PutLogEvents",
    ]
  }
}

data "aws_iam_policy_document" "delp-prod-wfdash" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "kinesis:ListStreams",
      "kinesis:EnableEnhancedMonitoring",
      "kinesis:ListShards",
      "kinesis:UpdateShardCount",
      "kinesis:DescribeLimits",
      "kinesis:ListStreamConsumers",
      "kinesis:DisableEnhancedMonitoring",
      "kinesis:PutRecord",
      "secretsmanager:DescribeSecret",
    ]
  }

  statement {
    sid    = "VisualEditor1"
    effect = "Allow"

    resources = [
      "arn:aws:ssm:eu-central-1:${var.account_id}:parameter/config/dashboard-PROD/dashboard.api.password",
      "arn:aws:kinesis:eu-central-1:${var.account_id}:stream/EmailStream",
    ]

    actions = [
      "ssm:PutParameter",
      "kinesis:PutRecord",
      "ssm:GetParametersByPath",
      "ssm:GetParameters",
      "ssm:GetParameter",
    ]
  }

  statement {
    sid       = "VisualEditor2"
    effect    = "Allow"
    resources = ["arn:aws:kinesis:eu-central-1:${var.account_id}:stream/StatusUpdateStream"]
    actions   = ["kinesis:*"]
  }

  statement {
    sid       = "VisualEditor3"
    effect    = "Allow"
    resources = ["arn:aws:dynamodb:eu-central-1:${var.account_id}:table/MGSRVAWSConsumers"]
    actions   = ["dynamodb:*"]
  }

  statement {
    sid    = "VisualEditor4"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delivery-target",
      "arn:aws:s3:::sme-delivery-target/*",
      "arn:aws:s3:::sme-delivery-user-upload",
      "arn:aws:s3:::sme-delivery-user-upload/*",
      "arn:aws:s3:::sme-conversion-shelf",
      "arn:aws:s3:::sme-conversion-shelf/*",
      "arn:aws:s3:::sme-media-production",
      "arn:aws:s3:::sme-media-production/*",
    ]

    actions = ["s3:*"]
  }

  statement {
    sid    = "VisualEditor5"
    effect = "Allow"

    resources = [
      "arn:aws:sqs:eu-central-1:${var.account_id}:AomaExternalConvRequestCancelQueue",
      "arn:aws:sqs:eu-central-1:${var.account_id}:AomaRequestQueue",
    ]

    actions = ["sqs:*"]
  }

  statement {
    sid    = "VisualEditor6"
    effect = "Allow"

    resources = [
      "arn:aws:kinesis:eu-central-1:${var.account_id}:stream/DeliveryBulkOperationStream",
      "arn:aws:kinesis:eu-central-1:${var.account_id}:stream/DeliveryRecordsPurgeStream",
    ]

    actions = ["kinesis:*"]
  }

  statement {
    sid    = "VisualEditor7"
    effect = "Allow"
    resources = [
      "arn:aws:kafka:eu-central-1:504436705349:cluster/maxffp-msk01/6fa3e304-d396-4767-b1fd-299bf8c9f1b0-4",
      "arn:aws:kafka:eu-central-1:504436705349:topic/maxffp-msk01/6fa3e304-d396-4767-b1fd-299bf8c9f1b0-4/DSRV-DSP-INFO"
    ]

    actions = [
      "kafka-cluster:Connect",
      "kafka-cluster:AlterCluster",
      "kafka-cluster:DescribeCluster",
      "kafka-cluster:DescribeTopic",
      "kafka-cluster:CreateTopic",
      "kafka-cluster:WriteData",
      "kafka-cluster:ReadData"
    ]
  }
}

data "aws_iam_policy_document" "sme-amp-rw" {
  statement {
    sid    = "VisualEditor0"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::amp-asset-usr-ust-p",
      "arn:aws:s3:::amp-asset-usr-ust-p/*",
    ]

    actions = ["s3:*"]
  }
}

data "aws_iam_policy_document" "AccessToDBtable" {
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["arn:aws:dynamodb:eu-central-1:${var.account_id}:table/MGSRVAWSConsumers"]
    actions   = ["dynamodb:*"]
  }
}

data "aws_iam_policy_document" "oneClick_CloudTrail_CloudWatchLogs_Role_1503402382534" {
  statement {
    sid       = "AWSCloudTrailCreateLogStream20141101"
    effect    = "Allow"
    resources = ["arn:aws:logs:eu-central-1:${var.account_id}:log-group:cloudtrail-traildash:log-stream:${var.account_id}_CloudTrail_eu-central-1*"]
    actions   = ["logs:CreateLogStream"]
  }

  statement {
    sid       = "AWSCloudTrailPutLogEvents20141101"
    effect    = "Allow"
    resources = ["arn:aws:logs:eu-central-1:${var.account_id}:log-group:cloudtrail-traildash:log-stream:${var.account_id}_CloudTrail_eu-central-1*"]
    actions   = ["logs:PutLogEvents"]
  }
}

data "aws_iam_policy_document" "AWSLambdaBasicExecutionRole-35ffda93-8e0f-4535-b500-ccad53c94c7a" {
  statement {
    sid    = "VisualEditor0"
    effect = "Allow"

    resources = [
      "arn:aws:logs:us-east-1:${var.account_id}:*",
      "arn:aws:s3:::sme-core-cloud-compliance-r53-public-logs",
      "arn:aws:s3:::sme-core-cloud-compliance-r53-public-logs/*",
    ]

    actions = [
      "s3:*",
      "logs:CreateLogGroup",
    ]
  }

  statement {
    sid       = "VisualEditor1"
    effect    = "Allow"
    resources = ["arn:aws:logs:us-east-1:${var.account_id}:log-group:/aws/lambda/R53-Public-logs-CC-COM-S3:*"]

    actions = [
      "logs:CreateLogStream",
      "logs:PutLogEvents",
    ]
  }

  statement {
    sid       = "VisualEditor2"
    effect    = "Allow"
    resources = ["arn:aws:logs:us-east-1:${var.account_id}:log-group:/aws/route53/sme-aoma-delivery-prod:*"]
    actions   = ["logs:CreateExportTask"]
  }

  statement {
    sid       = "VisualEditor3"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "s3:ListStorageLensConfigurations",
      "s3:ListAccessPointsForObjectLambda",
      "s3:GetAccessPoint",
      "s3:PutAccountPublicAccessBlock",
      "s3:GetAccountPublicAccessBlock",
      "s3:ListAllMyBuckets",
      "s3:ListAccessPoints",
      "s3:PutAccessPointPublicAccessBlock",
      "s3:ListJobs",
      "s3:PutStorageLensConfiguration",
      "s3:ListMultiRegionAccessPoints",
      "s3:CreateJob",
    ]
  }

  statement {
    sid       = "VisualEditor4"
    effect    = "Allow"
    resources = ["arn:aws:logs:us-east-1:${var.account_id}:log-group:/aws/route53/sme-aoma-delivery-prod:*"]
    actions   = ["logs:CancelExportTask"]
  }
}

data "aws_iam_policy_document" "delfd-policy" {
  statement {
    sid    = "Stmt1486461269700"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delivery-test-target",
      "arn:aws:s3:::sme-delivery-test-target/*",
      "arn:aws:s3:::sme-conversion-shelf",
      "arn:aws:s3:::sme-conversion-shelf/*",
      "arn:aws:s3:::sme-delivery-source",
      "arn:aws:s3:::sme-delivery-source/*",
      "arn:aws:s3:::sme-delivery-messages-prod",
      "arn:aws:s3:::sme-delivery-messages-prod/*",
    ]

    actions = ["s3:*"]
  }

  statement {
    sid    = "Stmt1498113445000"
    effect = "Allow"

    resources = [
      "arn:aws:kinesis:eu-central-1:${var.account_id}:stream/EmailStream",
      "arn:aws:kinesis:eu-central-1:${var.account_id}:stream/OrderStream-TEST",
    ]

    actions = ["kinesis:*"]
  }

  statement {
    sid    = "Stmt1498113601000"
    effect = "Allow"

    resources = [
      "arn:aws:sqs:eu-central-1:${var.account_id}:AomaRequestQueue-TEST",
      "arn:aws:sqs:eu-central-1:${var.account_id}:AomaResponseQueue-TEST",
      "arn:aws:sqs:eu-central-1:${var.account_id}:AssetSourceDeleteQueue-TEST",
      "arn:aws:sqs:eu-central-1:${var.account_id}:SftpDeliveryQueue-TEST",
      "arn:aws:sqs:eu-central-1:${var.account_id}:S3DeliveryQueue-TEST",
      "arn:aws:sqs:eu-central-1:${var.account_id}:AsperaDeliveryQueue-TEST",
      "arn:aws:sqs:eu-central-1:${var.account_id}:TransporterDeliveryQueue-TEST",
    ]

    actions = ["sqs:*"]
  }
}

data "aws_iam_policy_document" "wafv2" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  #checkov:skip=CKV_AWS_109: Ensure IAM policies does not allow permissions management / resource exposure without constraints
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "wafv2:List*",
      "wafv2:CheckCapacity",
      "wafv2:Describe*",
      "wafv2:GenerateMobileSdkReleaseUrl",
      "wafv2:Get*",
      "wafv2:AssociateWebACL",
      "wafv2:Create*",
      "wafv2:Delete*",
      "wafv2:Disassociate*",
      "wafv2:Put*",
      "wafv2:Update*",
      "wafv2:TagResource",
      "wafv2:UntagResource",
      "waf:ListByteMatchSets",
      "waf:ListWebACLs",
      "waf:ListSubscribedRuleGroups",
      "waf:ListRegexMatchSets",
      "waf:ListIPSets",
      "waf:ListRateBasedRules",
      "waf:ListSqlInjectionMatchSets",
      "waf:ListRuleGroups",
      "waf:ListSizeConstraintSets",
      "waf:ListActivatedRulesInRuleGroup",
      "kinesis:ListStreams",
      "iam:PassRole",
      "waf:ListLoggingConfigurations",
      "waf:ListXssMatchSets",
      "waf:ListGeoMatchSets",
      "waf-regional:Associate*",
      "waf-regional:Create*",
      "waf-regional:Delete*",
      "waf-regional:Get*",
      "waf-regional:List*",
      "waf-regional:Put*",
      "waf-regional:Tag*",
      "waf-regional:Untag*",
      "waf-regional:Update*",
      "waf:ListRules",
      "waf:ListRegexPatternSets",
      "firehose:CreateDeliveryStream",
    ]
  }
}

data "aws_iam_policy_document" "sme-content-protection" {
  statement {
    sid    = "VisualEditor0"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-content-protection*",
      "arn:aws:s3:::sme-content-protection/*",
    ]

    actions = [
      "s3:GetLifecycleConfiguration",
      "s3:ListBucketByTags",
      "s3:GetBucketTagging",
      "s3:GetInventoryConfiguration",
      "s3:GetObjectVersionTagging",
      "s3:GetBucketLogging",
      "s3:ListBucketVersions",
      "s3:GetAccelerateConfiguration",
      "s3:ListBucket",
      "s3:GetBucketPolicy",
      "s3:GetEncryptionConfiguration",
      "s3:GetObjectAcl",
      "s3:GetObjectVersionTorrent",
      "s3:GetBucketRequestPayment",
      "s3:GetObjectVersionAcl",
      "s3:GetObjectTagging",
      "s3:GetMetricsConfiguration",
      "s3:DeleteObject",
      "s3:GetBucketPolicyStatus",
      "s3:GetBucketPublicAccessBlock",
      "s3:ListBucketMultipartUploads",
      "s3:GetBucketWebsite",
      "s3:GetBucketVersioning",
      "s3:GetBucketAcl",
      "s3:GetBucketNotification",
      "s3:GetReplicationConfiguration",
      "s3:ListMultipartUploadParts",
      "s3:GetObject",
      "s3:PutObject",
      "s3:GetObjectTorrent",
      "s3:DescribeJob",
      "s3:GetBucketCORS",
      "s3:GetAnalyticsConfiguration",
      "s3:GetObjectVersionForReplication",
      "s3:GetBucketLocation",
      "s3:GetObjectVersion",
    ]
  }

  statement {
    sid       = "VisualEditor1"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "s3:GetAccountPublicAccessBlock",
      "s3:ListAllMyBuckets",
      "s3:ListJobs",
      "s3:HeadBucket",
    ]
  }
}

data "aws_iam_policy_document" "delivery-fire-drill-01" {
  statement {
    sid    = "Stmt1486461269700"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delivery-test-target",
      "arn:aws:s3:::sme-delivery-test-target/*",
      "arn:aws:s3:::sme-conversion-shelf",
      "arn:aws:s3:::sme-conversion-shelf/*",
      "arn:aws:s3:::sme-delivery-source",
      "arn:aws:s3:::sme-delivery-source/*",
      "arn:aws:s3:::sme-delivery-messages-prod",
      "arn:aws:s3:::sme-delivery-messages-prod/*",
    ]

    actions = ["s3:*"]
  }

  statement {
    sid    = "Stmt1498113445000"
    effect = "Allow"

    resources = [
      "arn:aws:kinesis:eu-central-1:${var.account_id}:stream/EmailStream",
      "arn:aws:kinesis:eu-central-1:${var.account_id}:stream/OrderStream-TEST",
    ]

    actions = ["kinesis:*"]
  }

  statement {
    sid    = "Stmt1498113601000"
    effect = "Allow"

    resources = [
      "arn:aws:sqs:eu-central-1:${var.account_id}:AomaRequestQueue-TEST",
      "arn:aws:sqs:eu-central-1:${var.account_id}:AomaResponseQueue-TEST",
      "arn:aws:sqs:eu-central-1:${var.account_id}:AssetSourceDeleteQueue-TEST",
      "arn:aws:sqs:eu-central-1:${var.account_id}:SftpDeliveryQueue-TEST",
      "arn:aws:sqs:eu-central-1:${var.account_id}:S3DeliveryQueue-TEST",
      "arn:aws:sqs:eu-central-1:${var.account_id}:AsperaDeliveryQueue-TEST",
      "arn:aws:sqs:eu-central-1:${var.account_id}:TransporterDeliveryQueue-TEST",
    ]

    actions = ["sqs:*"]
  }
}

data "aws_iam_policy_document" "oneClick_flowlogsRole_1448212171727" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "logs:CreateLogGroup",
      "logs:CreateLogStream",
      "logs:DescribeLogGroups",
      "logs:DescribeLogStreams",
      "logs:PutLogEvents",
    ]
  }
}

data "aws_iam_policy_document" "s3-shelf-test-policy" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:logs:*:*:*"]

    actions = [
      "logs:CreateLogGroup",
      "logs:CreateLogStream",
      "logs:PutLogEvents",
    ]
  }

  statement {
    sid    = ""
    effect = "Allow"

    resources = [
      "arn:aws:s3:::my-python-lambda/*",
      "arn:aws:s3:::sme.conversion.shelf.test/*",
    ]

    actions = [
      "s3:GetObject",
      "s3:PutObject",
    ]
  }

  statement {
    sid    = ""
    effect = "Allow"

    resources = [
      "arn:aws:s3:::my-python-lambda",
      "arn:aws:s3:::sme.conversion.shelf.test",
    ]

    actions = ["s3:ListBucket"]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "rds:DescribeDBLogFiles",
      "rds:DownloadDBLogFilePortion",
    ]
  }
}

data "aws_iam_policy_document" "oneClick_CloudTrail_CloudWatchLogs_Role_1540806198579" {
  statement {
    sid       = "AWSCloudTrailCreateLogStream20141101"
    effect    = "Allow"
    resources = ["arn:aws:logs:ap-southeast-1:${var.account_id}:log-group:CloudTrail/AlertLogicCT:log-stream:${var.account_id}_CloudTrail_ap-southeast-1*"]
    actions   = ["logs:CreateLogStream"]
  }

  statement {
    sid       = "AWSCloudTrailPutLogEvents20141101"
    effect    = "Allow"
    resources = ["arn:aws:logs:ap-southeast-1:${var.account_id}:log-group:CloudTrail/AlertLogicCT:log-stream:${var.account_id}_CloudTrail_ap-southeast-1*"]
    actions   = ["logs:PutLogEvents"]
  }
}

data "aws_iam_policy_document" "oneClick_flowlogsRole_1447447555661" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "logs:CreateLogGroup",
      "logs:CreateLogStream",
      "logs:DescribeLogGroups",
      "logs:DescribeLogStreams",
      "logs:PutLogEvents",
    ]
  }
}

data "aws_iam_policy_document" "media-conversion-aws-prod" {
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "s3:ListStorageLensConfigurations",
      "s3:GetAccessPoint",
      "s3:PutAccountPublicAccessBlock",
      "s3:GetAccountPublicAccessBlock",
      "s3:ListAllMyBuckets",
      "s3:ListAccessPoints",
      "s3:ListJobs",
      "s3:PutStorageLensConfiguration",
      "s3:CreateJob",
    ]
  }

  statement {
    sid    = "VisualEditor1"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delivery-target/*",
      "arn:aws:s3:::sme-conversion-shelf/*",
      "arn:aws:s3:::sme-mc-hash/*",
      "arn:aws:s3:::sme-delivery-target",
      "arn:aws:s3:::sme-conversion-shelf",
      "arn:aws:s3:::sme-mc-hash",
    ]

    actions = ["s3:*"]
  }

  statement {
    sid       = "VisualEditor2"
    effect    = "Allow"
    resources = ["arn:aws:ec2:eu-central-1:account:subnet/*"]
    actions   = ["ec2:*"]
  }
}

data "aws_iam_policy_document" "MasterAdmin" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  #checkov:skip=CKV_AWS_107: Ensure IAM policies does not allow credentials exposure
  #checkov:skip=CKV_AWS_109: Ensure IAM policies does not allow permissions management / resource exposure without constraints
  #checkov:skip=CKV_AWS_108: Ensure IAM policies does not allow data exfiltration
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "rds:Describe*",
      "rds:DownloadCompleteDBLogFile",
      "rds:DownloadDBLogFilePortion",
      "rds:BacktrackDBCluster",
      "rds:ListTagsForResource",
      "rds:Add*",
      "rds:Apply*",
      "rds:Cancel*",
      "rds:Copy*",
      "rds:Create*",
      "rds:CrossRegionCommunication",
      "rds:Delete*",
      "rds:DeregisterDBProxyTargets",
      "rds:DisableHttpEndpoint",
      "rds:EnableHttpEndpoint",
      "rds:Failover*",
      "rds:Modify*",
      "rds:Promote*",
      "rds:PurchaseReservedDBInstancesOffering",
      "rds:Reboot*",
      "rds:RegisterDBProxyTargets",
      "rds:Remove*",
      "rds:Reset*",
      "rds:Restore*",
      "rds:RevokeDBSecurityGroupIngress",
      "rds:Start*",
      "rds:Stop*",
      "rds:Switchover*",
      "rds:AuthorizeDBSecurityGroupIngress",
      "rds:AddTagsToResource",
      "rds:RemoveTagsFromResource",
      "redshift:Describe*",
      "redshift:List*",
      "redshift:View*",
      "redshift:Get*",
      "redshift:AcceptReservedNodeExchange",
      "redshift:AddPartner",
      "redshift:AssociateDataShareConsumer",
      "redshift:Authorize*",
      "redshift:Batch*",
      "redshift:Cancel*",
      "redshift:CopyClusterSnapshot",
      "redshift:Create*",
      "redshift:Delete*",
      "redshift:DeregisterNamespace",
      "redshift:Disable*",
      "redshift:DisassociateDataShareConsumer",
      "redshift:Enable*",
      "redshift:ExecuteQuery",
      "redshift:FailoverPrimaryCompute",
      "redshift:FetchResults",
      "redshift:Modify*",
      "redshift:PauseCluster",
      "redshift:PurchaseReservedNodeOffering",
      "redshift:RebootCluster",
      "redshift:RegisterNamespace",
      "redshift:ResetClusterParameterGroup",
      "redshift:ResizeCluster",
      "redshift:Restore*",
      "redshift:ResumeCluster",
      "redshift:RotateEncryptionKey",
      "redshift:UpdatePartnerStatus",
      "redshift:DeauthorizeDataShare",
      "redshift:JoinGroup",
      "redshift:PutResourcePolicy",
      "redshift:RejectDataShare",
      "redshift:Revoke*",
      "redshift:CreateTags",
      "redshift:DeleteTags",
      "s3:List*",
      "s3:Describe*",
      "s3:Get*",
      "s3:AbortMultipartUpload",
      "s3:Create*",
      "s3:Delete*",
      "s3:InitiateReplication",
      "s3:PauseReplication",
      "s3:Put*",
      "s3:Replicate*",
      "s3:RestoreObject",
      "s3:SubmitMultiRegionAccessPointRoutes",
      "s3:Update*",
      "s3:AssociateAccessGrantsIdentityCenter",
      "s3:BypassGovernanceRetention",
      "s3:DissociateAccessGrantsIdentityCenter",
      "s3:ObjectOwnerOverrideToBucketOwner",
      "s3:TagResource",
      "s3:UntagResource",
      "secretsmanager:CancelRotateSecret",
      "secretsmanager:DeleteSecret",
      "secretsmanager:DescribeSecret",
      "secretsmanager:GetRandomPassword",
      "secretsmanager:GetResourcePolicy",
      "secretsmanager:GetSecretValue",
      "secretsmanager:ListSecretVersionIds",
      "secretsmanager:PutSecretValue",
      "secretsmanager:RestoreSecret",
      "secretsmanager:RotateSecret",
      "secretsmanager:UpdateSecret",
      "secretsmanager:UpdateSecretVersionStage",
      "sns:List*",
      "sns:CheckIfPhoneNumberIsOptedOut",
      "sns:Get*",
      "sns:ConfirmSubscription",
      "sns:Create*",
      "sns:Delete*",
      "sns:OptInPhoneNumber",
      "sns:Publish",
      "sns:PutDataProtectionPolicy",
      "sns:Set*",
      "sns:Subscribe",
      "sns:Unsubscribe",
      "sns:VerifySMSSandboxPhoneNumber",
      "sns:AddPermission",
      "sns:RemovePermission",
      "sns:TagResource",
      "sns:UntagResource",
      "sqs:Get*",
      "sqs:List*",
      "sqs:ReceiveMessage",
      "sqs:CancelMessageMoveTask",
      "sqs:ChangeMessageVisibility",
      "sqs:CreateQueue",
      "sqs:Delete*",
      "sqs:PurgeQueue",
      "sqs:SendMessage",
      "sqs:SetQueueAttributes",
      "sqs:StartMessageMoveTask",
      "sqs:AddPermission",
      "sqs:RemovePermission",
      "sqs:TagQueue",
      "sqs:UntagQueue",
      "apigateway:GET",
      "apigateway:POST",
      "apigateway:PUT",
      "apigateway:PATCH",
      "apigateway:DELETE",
      "tax:GetTaxInheritance",
      "tax:GetTaxRegistrationDocument",
      "tax:ListTaxRegistrations",
      "apigateway:PUT",
      "apigateway:POST",
      "apigateway:PATCH",
      "apigateway:GET",
      "apigateway:DELETE"
    ]
  }

  statement {
    sid       = "VisualEditor1a"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "application-autoscaling:RegisterScalableTarget",
      "application-autoscaling:PutScalingPolicy",
      "application-autoscaling:DeregisterScalableTarget",
    ]
  }
}

data "aws_iam_policy_document" "MasterAdmin-2" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  #checkov:skip=CKV_AWS_107: Ensure IAM policies does not allow credentials exposure
  #checkov:skip=CKV_AWS_109: Ensure IAM policies does not allow permissions management / resource exposure without constraints
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "account:GetAccountInformation",
      "athena:List*",
      "athena:Batch*",
      "athena:Get*",
      "athena:Cancel*",
      "athena:Create*",
      "athena:Delete*",
      "athena:ExportNotebook",
      "athena:ImportNotebook",
      "athena:PutCapacityAssignmentConfiguration",
      "athena:RunQuery",
      "athena:Start*",
      "athena:Stop*",
      "athena:TerminateSession",
      "athena:Update*",
      "athena:TagResource",
      "athena:UntagResource",
      "billing:GetBillingData",
      "billing:GetBillingDetails",
      "billing:GetBillingNotifications",
      "billing:GetBillingPreferences",
      "billing:GetContractInformation",
      "billing:GetCredits",
      "billing:GetIAMAccessPreference",
      "billing:GetSellerOfRecord",
      "billing:ListBillingViews",
      "ce:DescribeNotificationSubscription",
      "ce:DescribeReport",
      "ce:GetAnomalies",
      "ce:GetAnomalyMonitors",
      "ce:GetAnomalySubscriptions",
      "ce:GetCostAndUsage",
      "ce:GetCostAndUsageWithResources",
      "ce:GetCostCategories",
      "ce:GetCostForecast",
      "ce:GetDimensionValues",
      "ce:GetPreferences",
      "ce:GetReservationCoverage",
      "ce:GetReservationPurchaseRecommendation",
      "ce:GetReservationUtilization",
      "ce:GetRightsizingRecommendation",
      "ce:GetSavingsPlansCoverage",
      "ce:GetSavingsPlansPurchaseRecommendation",
      "ce:GetSavingsPlansUtilization",
      "ce:GetSavingsPlansUtilizationDetails",
      "ce:GetTags",
      "ce:GetUsageForecast",
      "ce:ListCostAllocationTags",
      "ce:ListSavingsPlansPurchaseRecommendationGeneration",
      "cloudwatch:List*",
      "cloudwatch:Batch*",
      "cloudwatch:Describe*",
      "cloudwatch:Generate*",
      "cloudwatch:Get*",
      "cloudwatch:CreateServiceLevelObjective",
      "cloudwatch:Delete*",
      "cloudwatch:Disable*",
      "cloudwatch:Enable*",
      "cloudwatch:Link",
      "cloudwatch:Put*",
      "cloudwatch:SetAlarmState",
      "cloudwatch:StartMetricStreams",
      "cloudwatch:StopMetricStreams",
      "cloudwatch:UpdateServiceLevelObjective",
      "cloudwatch:TagResource",
      "cloudwatch:UntagResource",
      "consolidatedbilling:GetAccountBillingRole",
      "consolidatedbilling:ListLinkedAccounts",
      "cur:GetClassicReport",
      "cur:GetClassicReportPreferences",
      "cur:GetUsageReport",
      "cur:ValidateReportDestination",
      "dynamodb:List*",
      "dynamodb:Batch*",
      "dynamodb:ConditionCheckItem",
      "dynamodb:Describe*",
      "dynamodb:Get*",
      "dynamodb:PartiQL*",
      "dynamodb:Query",
      "dynamodb:Scan",
      "dynamodb:Create*",
      "dynamodb:Delete*",
      "dynamodb:DisableKinesisStreamingDestination",
      "dynamodb:EnableKinesisStreamingDestination",
      "dynamodb:ExportTableToPointInTime",
      "dynamodb:ImportTable",
      "dynamodb:PurchaseReservedCapacityOfferings",
      "dynamodb:Put*",
      "dynamodb:Restore*",
      "dynamodb:StartAwsBackupJob",
      "dynamodb:Update*",
      "dynamodb:TagResource",
      "dynamodb:UntagResource",
      "ec2:Describe*",
      "ec2:Get*",
      "ec2:List*",
      "ec2:Search*",
      "ec2:Export*",
      "ec2:Accept*",
      "ec2:AdvertiseByoipCidr",
      "ec2:Allocate*",
      "ec2:ApplySecurityGroupsToClientVpnTargetNetwork",
      "ec2:Assign*",
      "ec2:Associate*",
      "ec2:Attach*",
      "ec2:Authorize*",
      "ec2:BundleInstance",
      "ec2:Cancel*",
      "ec2:ConfirmProductInstance",
      "ec2:Copy*",
      "ec2:Create*",
      "ec2:Delete*",
      "ec2:Deprovision*",
      "ec2:Deregister*",
      "ec2:Detach*",
      "ec2:Disable*",
      "ec2:Disassociate*",
      "ec2:Enable*",
      "ec2:Import*",
      "ec2:InjectApiError",
      "ec2:LockSnapshot",
      "ec2:Modify*",
      "ec2:MonitorInstances",
      "ec2:Move*",
      "ec2:PauseVolumeIO",
      "ec2:Provision*",
      "ec2:Purchase*",
      "ec2:RebootInstances",
      "ec2:Register*",
      "ec2:Reject*",
      "ec2:Release*",
      "ec2:Replace*",
      "ec2:ReportInstanceStatus",
      "ec2:Request*",
      "ec2:Reset*",
      "ec2:Restore*",
      "ec2:Revoke*",
      "ec2:Run*",
      "ec2:Send*",
      "ec2:Start*",
      "ec2:StopInstances",
      "ec2:Terminate*",
      "ec2:Unassign*",
      "ec2:UnlockSnapshot",
      "ec2:UnmonitorInstances",
      "ec2:Update*",
      "ec2:WithdrawByoipCidr",
      "ec2:PutResourcePolicy"
    ]
  }
}

data "aws_iam_policy_document" "MasterAdmin-3" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  #checkov:skip=CKV_AWS_110: Ensure IAM policies does not allow privilege escalation
  #checkov:skip=CKV_AWS_109: Ensure IAM policies does not allow permissions management / resource exposure without constraints
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "ecr:Describe*",
      "ecr:List*",
      "ecr:Batch*",
      "ecr:Get*",
      "ecr:ValidatePullThroughCacheRule",
      "ecr:CompleteLayerUpload",
      "ecr:Create*",
      "ecr:Delete*",
      "ecr:DeregisterPullTimeUpdateExclusion",
      "ecr:InitiateLayerUpload",
      "ecr:Put*",
      "ecr:RegisterPullTimeUpdateExclusion",
      "ecr:ReplicateImage",
      "ecr:Start*",
      "ecr:Update*",
      "ecr:UploadLayerPart",
      "ecr:SetRepositoryPolicy",
      "ecr:TagResource",
      "ecr:UntagResource",
      "ecs:List*",
      "ecs:Describe*",
      "ecs:GetTaskProtection",
      "ecs:Create*",
      "ecs:Delete*",
      "ecs:Deregister*",
      "ecs:DiscoverPollEndpoint",
      "ecs:ExecuteCommand",
      "ecs:Poll",
      "ecs:Put*",
      "ecs:Register*",
      "ecs:RunTask",
      "ecs:Start*",
      "ecs:Stop*",
      "ecs:Submit*",
      "ecs:Update*",
      "ecs:TagResource",
      "ecs:UntagResource",
      "eks:List*",
      "eks:AccessKubernetesApi",
      "eks:Describe*",
      "eks:Associate*",
      "eks:Create*",
      "eks:Delete*",
      "eks:DeregisterCluster",
      "eks:Disassociate*",
      "eks:MutateViaKubernetesApi",
      "eks:RegisterCluster",
      "eks:StartInsightsRefresh",
      "eks:Update*",
      "eks:TagResource",
      "eks:UntagResource",
      "elasticache:Describe*",
      "elasticache:List*",
      "elasticache:AuthorizeCacheSecurityGroupIngress",
      "elasticache:Batch*",
      "elasticache:CompleteMigration",
      "elasticache:Connect",
      "elasticache:Copy*",
      "elasticache:Create*",
      "elasticache:Decrease*",
      "elasticache:Delete*",
      "elasticache:DisassociateGlobalReplicationGroup",
      "elasticache:ExportServerlessCacheSnapshot",
      "elasticache:FailoverGlobalReplicationGroup",
      "elasticache:Increase*",
      "elasticache:InterruptClusterAzPower",
      "elasticache:Modify*",
      "elasticache:PurchaseReservedCacheNodesOffering",
      "elasticache:RebalanceSlotsInGlobalReplicationGroup",
      "elasticache:RebootCacheCluster",
      "elasticache:ResetCacheParameterGroup",
      "elasticache:RevokeCacheSecurityGroupIngress",
      "elasticache:StartMigration",
      "elasticache:Test*",
      "elasticache:AddTagsToResource",
      "elasticache:RemoveTagsFromResource",
      "elasticloadbalancing:Describe*",
      "elasticloadbalancing:ApplySecurityGroupsToLoadBalancer",
      "elasticloadbalancing:AttachLoadBalancerToSubnets",
      "elasticloadbalancing:ConfigureHealthCheck",
      "elasticloadbalancing:Create*",
      "elasticloadbalancing:Delete*",
      "elasticloadbalancing:DeregisterInstancesFromLoadBalancer",
      "elasticloadbalancing:DetachLoadBalancerFromSubnets",
      "elasticloadbalancing:DisableAvailabilityZonesForLoadBalancer",
      "elasticloadbalancing:EnableAvailabilityZonesForLoadBalancer",
      "elasticloadbalancing:ModifyLoadBalancerAttributes",
      "elasticloadbalancing:RegisterInstancesWithLoadBalancer",
      "elasticloadbalancing:Set*",
      "elasticloadbalancing:AddTags",
      "elasticloadbalancing:RemoveTags",
      "freetier:GetFreeTierAlertPreference",
      "freetier:GetFreeTierUsage",
      "invoicing:GetInvoiceEmailDeliveryPreferences",
      "invoicing:GetInvoicePDF",
      "invoicing:ListInvoiceSummaries",
      "kinesis:List*",
      "kinesis:Describe*",
      "kinesis:Get*",
      "kinesis:SubscribeToShard",
      "kinesis:CreateStream",
      "kinesis:DecreaseStreamRetentionPeriod",
      "kinesis:Delete*",
      "kinesis:DeregisterStreamConsumer",
      "kinesis:DisableEnhancedMonitoring",
      "kinesis:EnableEnhancedMonitoring",
      "kinesis:IncreaseStreamRetentionPeriod",
      "kinesis:InjectApiError",
      "kinesis:MergeShards",
      "kinesis:Put*",
      "kinesis:RegisterStreamConsumer",
      "kinesis:SplitShard",
      "kinesis:StartStreamEncryption",
      "kinesis:StopStreamEncryption",
      "kinesis:Update*",
      "kinesis:AddTagsToStream",
      "kinesis:RemoveTagsFromStream",
      "kinesis:TagResource",
      "kinesis:UntagResource",
      "lambda:List*",
      "lambda:Get*",
      "lambda:CheckpointDurableExecution",
      "lambda:Create*",
      "lambda:Delete*",
      "lambda:Invoke*",
      "lambda:PassCapacityProvider",
      "lambda:Publish*",
      "lambda:Put*",
      "lambda:Send*",
      "lambda:StopDurableExecution",
      "lambda:Update*",
      "lambda:Add*",
      "lambda:DisableReplication",
      "lambda:EnableReplication",
      "lambda:Remove*",
      "lambda:TagResource",
      "lambda:UntagResource",
      "payments:GetPaymentInstrument",
      "payments:GetPaymentStatus",
      "payments:ListPaymentMethods",
      "payments:ListPaymentPreferences"
    ]
  }
}

data "aws_iam_policy_document" "mcond-s3-fsx" {
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "s3:GetAccessPoint",
      "s3:PutAccountPublicAccessBlock",
      "s3:GetAccountPublicAccessBlock",
      "s3:ListAllMyBuckets",
      "s3:ListAccessPoints",
      "s3:ListJobs",
      "s3:CreateJob",
      "s3:HeadBucket",
    ]
  }

  statement {
    sid    = "VisualEditor1"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delivery-source",
      "arn:aws:s3:::sme-delivery-source/*",
    ]

    actions = ["s3:*"]
  }
}

data "aws_iam_policy_document" "AWSGlueServiceRole-waf" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:s3:::aws-waf-logs-us-east-1/*"]

    actions = [
      "s3:GetObject",
      "s3:PutObject",
    ]
  }
}

data "aws_iam_policy_document" "oneClick_Cognito_ytcp_ytclaimsAuth_Role_1599458257458" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  #checkov:skip=CKV_AWS_107: Ensure IAM policies does not allow credentials exposure
  #checkov:skip=CKV_AWS_109: Ensure IAM policies does not allow permissions management / resource exposure without constraints
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "mobileanalytics:PutEvents",
      "cognito-sync:*",
      "cognito-identity:*",
    ]
  }
}

data "aws_iam_policy_document" "RDS_Snapshots_Export_To_S3_lambda" {
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "lambda:ListFunctions",
      "lambda:ListEventSourceMappings",
      "lambda:ListLayerVersions",
      "lambda:ListLayers",
      "lambda:GetAccountSettings",
      "lambda:CreateEventSourceMapping",
      "lambda:ListCodeSigningConfigs",
    ]
  }

  statement {
    sid       = "VisualEditor1"
    effect    = "Allow"
    resources = ["arn:aws:lambda:eu-central-1:${var.account_id}:function:RDS_Snapshots_Export_To_S3"]
    actions   = ["lambda:*"]
  }

  statement {
    sid    = "VisualEditor2"
    effect = "Allow"
    resources = [
      "arn:aws:secretsmanager:eu-central-1:023180329437:secret:Delivery/Nexus/Cred-qlB2Eu",
      "arn:aws:secretsmanager:eu-central-1:023180329437:secret:Delivery/Github/Token-YB7S8W",
    ]
    actions = ["secretsmanager:*"]
  }
}

data "aws_iam_policy_document" "dsrv-prod-eks-cluster-ns-delivery-prod-sa-ddex-exchange-policy" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "kinesis:PutRecord",
      "kinesis:PutRecords",
      "secretsmanager:ListSecrets",
    ]
  }

  statement {
    sid    = "VisualEditor1"
    effect = "Allow"

    resources = [
      "arn:aws:secretsmanager:eu-central-1:${var.account_id}:secret:PROD/DDEX/PostgreSql-RDS-DB-oiM418",
      "arn:aws:rds:eu-central-1:058029036333:cluster:del-rds-db-02",
    ]

    actions = [
      "secretsmanager:*",
      "rds:*",
    ]
  }

  statement {
    sid    = "VisualEditor2"
    effect = "Allow"

    resources = [
      "arn:aws:secretsmanager:eu-central-1:023180329437:secret:PROD/DeliveryOnixPackager/PostgreSql-RDS-DB-QOEAQV",
      "arn:aws:secretsmanager:eu-central-1:023180329437:secret:PROD/EOM-pY1NZ7",
      "arn:aws:secretsmanager:eu-central-1:023180329437:secret:PROD/RabbitMQ-04CUZl",
      "arn:aws:secretsmanager:eu-central-1:023180329437:secret:db/del/prod/delivery_packager-l9rZWR",
    ]

    actions = [
      "secretsmanager:*",

    ]
  }

  statement {
    sid    = "VisualEditor3"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delivery-target/*",
      "arn:aws:s3:::sme-delivery-target",
    ]

    actions = [
      "s3:*",

    ]
  }

  statement {
    sid    = "VisualEditor4"
    effect = "Allow"
    resources = [
      "arn:aws:kms:eu-central-1:023180329437:key/7fcf7089-a08e-4de9-8177-1a3026ed3a1c",
      "arn:aws:kms:eu-central-1:023180329437:key/c43c70ed-018c-40b0-b70b-5d7fd4a5f58d"
    ]

    actions = [
      "kms:DescribeKey",
      "kms:Decrypt",
    ]
  }

  statement {
    sid    = "globaldsdassumerole"
    effect = "Allow"

    resources = ["arn:aws:iam::635220336377:role/globaldsp-sa-msk-delivery-role"]

    actions = [
      "sts:AssumeRole"
    ]
  }
}

data "aws_iam_policy_document" "Redlock-IAM-ReadOnly-Policy" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "acm:List*",
      "apigateway:GET",
      "appstream:Describe*",
      "cloudtrail:GetEventSelectors",
      "cloudtrail:LookupEvents",
      "cloudsearch:Describe*",
      "dynamodb:DescribeTable",
      "ds:Describe*",
      "elasticache:List*",
      "eks:List*",
      "eks:Describe*",
      "elasticfilesystem:Describe*",
      "elasticmapreduce:Describe*",
      "elasticmapreduce:List*",
      "inspector:Describe*",
      "inspector:List*",
      "glacier:List*",
      "glacier:Get*",
      "glue:getConnections",
      "guardduty:List*",
      "guardduty:Get*",
      "iam:SimulatePrincipalPolicy",
      "iam:SimulateCustomPolicy",
      "kinesis:Describe*",
      "kinesis:List*",
      "rds:ListTagsForResource",
      "sns:List*",
      "sns:Get*",
      "sqs:SendMessage",
      "logs:FilterLogEvents",
      "logs:Get*",
      "logs:Describe*",
      "secretsmanager:List*",
      "secretsmanager:Describe*",
      "airflow:GetEnvironment",
      "lakeformation:GetDataLakeSettings",
    ]
  }
}

data "aws_iam_policy_document" "AWSGlueServiceRole-waf-eu-west-2" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:s3:::aws-waf-logs-eu-west-2/*"]

    actions = [
      "s3:GetObject",
      "s3:PutObject",
    ]
  }
}

data "aws_iam_policy_document" "mlib-prod-ecs-cloudwatch-policy" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:logs:*:*:*"]

    actions = [
      "logs:CreateLogGroup",
      "logs:CreateLogStream",
      "logs:PutLogEvents",
      "logs:DescribeLogStreams",
    ]
  }
}

data "aws_iam_policy_document" "S3-delivery-target-dev" {
  statement {
    sid    = "Stmt1500930890000"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delivery-dev-target/",
      "arn:aws:s3:::sme-delivery-dev-target/*",
    ]

    actions = ["s3:*"]
  }
}

data "aws_iam_policy_document" "ast-srv-bulk-ingest-lambda-policy" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  statement {
    sid    = "VisualEditor0"
    effect = "Allow"

    resources = [
      "arn:aws:secretsmanager:eu-central-1:${var.account_id}:secret:stage/assetserviceapi/credentials-9PYb93",
      "arn:aws:secretsmanager:eu-central-1:${var.account_id}:secret:prod/assetserviceapi/credentials-mGHUm1",
      "arn:aws:s3:::sme-delivery-stage-source",
      "arn:aws:s3:::sme-delivery-source",
      "arn:aws:s3:::sme-delivery-dev-source",
    ]

    actions = [
      "s3:GetLifecycleConfiguration",
      "s3:GetBucketTagging",
      "s3:GetInventoryConfiguration",
      "secretsmanager:DescribeSecret",
      "s3:DeleteObjectVersion",
      "s3:GetObjectVersionTagging",
      "s3:ListBucketVersions",
      "s3:GetBucketLogging",
      "s3:RestoreObject",
      "s3:ListBucket",
      "s3:GetAccelerateConfiguration",
      "s3:GetBucketPolicy",
      "secretsmanager:ListSecretVersionIds",
      "s3:GetObjectVersionTorrent",
      "s3:GetObjectAcl",
      "s3:GetEncryptionConfiguration",
      "s3:GetBucketObjectLockConfiguration",
      "secretsmanager:GetSecretValue",
      "s3:GetBucketRequestPayment",
      "s3:GetObjectVersionAcl",
      "s3:GetObjectTagging",
      "s3:GetMetricsConfiguration",
      "s3:DeleteObject",
      "s3:GetBucketPublicAccessBlock",
      "s3:GetBucketPolicyStatus",
      "s3:ListBucketMultipartUploads",
      "s3:GetObjectRetention",
      "s3:GetBucketWebsite",
      "s3:GetBucketVersioning",
      "s3:GetBucketAcl",
      "s3:GetObjectLegalHold",
      "s3:GetBucketNotification",
      "s3:GetReplicationConfiguration",
      "s3:ListMultipartUploadParts",
      "s3:PutObject",
      "s3:GetObject",
      "secretsmanager:GetResourcePolicy",
      "s3:GetObjectTorrent",
      "s3:PutObjectRetention",
      "s3:GetBucketCORS",
      "s3:GetAnalyticsConfiguration",
      "s3:GetObjectVersionForReplication",
      "s3:GetBucketLocation",
      "s3:GetObjectVersion",
    ]
  }

  statement {
    sid       = "VisualEditor1"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "secretsmanager:GetRandomPassword",
      "s3:GetAccessPoint",
      "s3:GetAccountPublicAccessBlock",
      "dynamodb:PutItem",
      "s3:ListAllMyBuckets",
      "s3:ListAccessPoints",
      "dynamodb:DeleteItem",
      "s3:ListJobs",
      "dynamodb:GetItem",
      "s3:HeadBucket",
    ]
  }
}

data "aws_iam_policy_document" "S3-delivery-target-stage" {
  statement {
    sid    = "Stmt1500930890000"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delivery-stage-target/",
      "arn:aws:s3:::sme-delivery-stage-target/*",
      "arn:aws:s3:::sme-delivery-stage-bb-target/",
      "arn:aws:s3:::sme-delivery-stage-bb-target/*",
    ]

    actions = ["s3:*"]
  }
}

data "aws_iam_policy_document" "ELB_register_target" {
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["arn:aws:elasticloadbalancing:eu-central-1:${var.account_id}:loadbalancer/app/delp2-media-gateway/99109cc3907a1abf"]

    actions = [
      "elasticloadbalancing:AttachLoadBalancerToSubnets",
      "elasticloadbalancing:EnableAvailabilityZonesForLoadBalancer",
      "elasticloadbalancing:DeregisterInstancesFromLoadBalancer",
      "elasticloadbalancing:ModifyLoadBalancerAttributes",
      "elasticloadbalancing:RegisterInstancesWithLoadBalancer",
      "elasticloadbalancing:DisableAvailabilityZonesForLoadBalancer",
    ]
  }

  statement {
    sid       = "VisualEditor1"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "elasticloadbalancing:DescribeLoadBalancerAttributes",
      "elasticloadbalancing:DescribeLoadBalancers",
      "elasticloadbalancing:DescribeTags",
      "elasticloadbalancing:DescribeLoadBalancerPolicies",
      "elasticloadbalancing:DescribeLoadBalancerPolicyTypes",
      "elasticloadbalancing:DescribeInstanceHealth",
    ]
  }
}

data "aws_iam_policy_document" "conversion-service-role-inline-policy" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:kinesis:eu-central-1:${var.account_id}:stream/EmailStream"]
    actions   = ["kinesis:PutRecord"]
  }

  statement {
    sid    = "Stmt1486461269700"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-conversion-shelf",
      "arn:aws:s3:::sme-conversion-shelf/*",
      "arn:aws:s3:::sme-delivery-target",
      "arn:aws:s3:::sme-delivery-target/*",
      "arn:aws:s3:::sme-delivery-source",
      "arn:aws:s3:::sme-delivery-source/*",
    ]

    actions = ["s3:*"]
  }

  statement {
    sid    = ""
    effect = "Allow"

    resources = [
      "arn:aws:secretsmanager:eu-central-1:${var.account_id}:secret:PROD/DeliveryConversionRequestor/PostgreSql-RDS-DB-kv1ogd",
      "arn:aws:secretsmanager:eu-central-1:${var.account_id}:secret:PROD/EOM-pY1NZ7",
      "arn:aws:secretsmanager:eu-central-1:${var.account_id}:secret:PROD/RabbitMQ-04CUZl",
    ]

    actions = ["secretsmanager:GetSecretValue"]
  }
}

data "aws_iam_policy_document" "sme-origin-mediapublisher-to-sme-origin-mediapublisher" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme.origin.mediapublisher"]

    actions = [
      "s3:GetReplicationConfiguration",
      "s3:ListBucket",
    ]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme.origin.mediapublisher/*"]

    actions = [
      "s3:GetObjectVersion",
      "s3:GetObjectVersionAcl",
      "s3:GetObjectVersionTagging",
    ]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-origin-mediapublisher/*"]

    actions = [
      "s3:ReplicateObject",
      "s3:ReplicateDelete",
      "s3:ReplicateTags",
    ]
  }
}

data "aws_iam_policy_document" "delp-sqs-policy" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "sqs:ReceiveMessage",
      "sqs:DeleteMessage",
      "sqs:SendMessage",
    ]
  }
}

data "aws_iam_policy_document" "delp2-reports01" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  #checkov:skip=CKV_AWS_109: Ensure IAM policies does not allow permissions management / resource exposure without constraints
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]
    actions   = ["ses:*"]
  }
}

data "aws_iam_policy_document" "eom-p-api-execute" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:execute-api:eu-central-1:*:*"]
    actions   = ["execute-api:Invoke"]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:kinesis:eu-central-1:${var.account_id}:stream/ArchivePackageStream"]
    actions   = ["kinesis:PutRecord"]
  }
}

data "aws_iam_policy_document" "orchard-bucket-sqs-access" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:sqs:eu-central-1:${var.account_id}:SmeOrchardS3DeliveryQueue"]
    actions   = ["sqs:*"]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:kinesis:eu-central-1:${var.account_id}:stream/EmailStream"]
    actions   = ["kinesis:PutRecord"]
  }

  statement {
    sid    = "Stmt1486461269756"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delivery-messages-prod",
      "arn:aws:s3:::sme-delivery-orchard-target",
      "arn:aws:s3:::sme-delivery-orchard-target/*",
    ]

    actions = ["s3:*"]
  }
}

data "aws_iam_policy_document" "sme-delivery-target" {
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "s3:ListStorageLensConfigurations",
      "s3:ListAccessPointsForObjectLambda",
      "s3:GetAccessPoint",
      "s3:PutAccountPublicAccessBlock",
      "s3:GetAccountPublicAccessBlock",
      "s3:ListAllMyBuckets",
      "s3:ListAccessPoints",
      "s3:ListJobs",
      "s3:PutStorageLensConfiguration",
      "s3:CreateJob",
    ]
  }

  statement {
    sid       = "VisualEditor1"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-delivery-uat-shelf"]
    actions   = ["s3:*"]
  }

  statement {
    sid    = "VisualEditor2"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delivery-target/",
      "arn:aws:s3:::sme-delivery-target/*",
      "arn:aws:s3:::sme-mc-source/",
      "arn:aws:s3:::sme-mc-source/*",
      "arn:aws:s3:::sme-mc-target/",
      "arn:aws:s3:::sme-mc-target/*",
    ]

    actions = ["s3:*"]
  }
}

data "aws_iam_policy_document" "delivery-records-purge-lambda" {
  statement {
    sid    = "VisualEditor0"
    effect = "Allow"
    resources = [
      "arn:aws:secretsmanager:eu-central-1:${var.account_id}:secret:PROD/DeliveryRecordPurgeService/PostgreSql-RDS-DB-s5Pbeh",
      "arn:aws:secretsmanager:eu-central-1:023180329437:secret:PROD/RabbitMQ*"
    ]
    actions = ["secretsmanager:*"]
  }

  statement {
    sid    = "VisualEditor1"
    effect = "Allow"

    resources = [
      "arn:aws:kinesis:eu-central-1:${var.account_id}:stream/DeliveryRecordsPurgeStream",
      "arn:aws:kinesis:eu-central-1:${var.account_id}:stream/EmailStream",
    ]

    actions = ["kinesis:*"]
  }

  statement {
    sid    = "VisualEditor2"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delivery-target",
      "arn:aws:s3:::sme-delivery-target/*"
    ]

    actions = ["s3:*"]
  }
}

data "aws_iam_policy_document" "BatchOperationsLambdaFunctions" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  #checkov:skip=CKV_AWS_108: Ensure IAM policies does not allow data exfiltration
  statement {
    sid       = "BatchOperationsLambdaPolicy"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "s3:GetObject",
      "s3:GetObjectVersion",
      "s3:PutObject",
      "lambda:InvokeFunction",
    ]
  }
}

data "aws_iam_policy_document" "s3-sme-delivery-dev-target" {
  statement {
    sid    = "Stmt1500930890000"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delivery-dev-target/",
      "arn:aws:s3:::sme-delivery-dev-target/*",
    ]

    actions = ["s3:*"]
  }
}

data "aws_iam_policy_document" "sme-delivery-dev-source-policy" {
  statement {
    sid    = "programmatically"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delivery-dev-source",
      "arn:aws:s3:::sme-delivery-dev-source/*",
      "arn:aws:s3:::sme-delivery-stage-source",
      "arn:aws:s3:::sme-delivery-stage-source/*",
    ]

    actions = [
      "s3:ListBucket",
      "s3:GetObject",
      "s3:PutObject",
      "s3:DeleteObject",
    ]
  }
}

data "aws_iam_policy_document" "delp-prod-cache" {
  statement {
    sid       = "Stmt1497344965000"
    effect    = "Allow"
    resources = ["arn:aws:dynamodb:us-east-1:361463692799:table/mpub_media"]
    actions   = ["dynamodb:*"]
  }
}

data "aws_iam_policy_document" "AWSLambdaBasicExecutionRole-4b27a209-85d2-4ce5-ac84-f1af015362b5" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:logs:eu-central-1:${var.account_id}:*"]
    actions   = ["logs:CreateLogGroup"]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:logs:eu-central-1:${var.account_id}:log-group:/aws/lambda/DeliveryShelfStageFileRecopyLambda:*"]

    actions = [
      "logs:CreateLogStream",
      "logs:PutLogEvents",
    ]
  }
}

data "aws_iam_policy_document" "aoma-RDS_snapshot_lambda-policy" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  statement {
    sid    = "VisualEditor0"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-aoma-delivery-prod-rds-backups",
      "arn:aws:s3:::sme-aoma-delivery-prod-rds-backups/*",
      "arn:aws:iam::${var.account_id}:role/aoma-RDS_snapshot_lambda-role",
      "arn:aws:kms:eu-central-1:${var.account_id}:key/7fcf7089-a08e-4de9-8177-1a3026ed3a1c",
    ]

    actions = [
      "s3:PutObject",
      "s3:GetObject",
      "iam:PassRole",
      "kms:Decrypt",
      "s3:ListBucket",
      "s3:DeleteObject",
      "s3:GetBucketLocation",
    ]
  }

  statement {
    sid       = "VisualEditor1"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "kms:ListKeys",
      "logs:CreateLogStream",
      "rds:DescribeDBSnapshots",
      "rds:CopyDBSnapshot",
      "rds:DescribeExportTasks",
      "rds:StartExportTask",
      "rds:DescribeDBClusterSnapshots",
      "logs:PutDestination",
      "logs:CreateLogGroup",
      "logs:PutLogEvents",
      "rds:DescribeDBSnapshotAttributes",
      "logs:ListLogDeliveries",
      "sns:ListTopics",
    ]
  }

  statement {
    sid       = "VisualEditor2"
    effect    = "Allow"
    resources = ["arn:aws:sns:eu-central-1:${var.account_id}:DB-TEAM"]
    actions   = ["sns:Publish"]
  }
}

data "aws_iam_policy_document" "logstash-elk-straeming" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]
    actions   = ["es:ESHttpPost"]
  }
}

data "aws_iam_policy_document" "aws-lambda-execution-policy" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  statement {
    sid    = "VisualEditor0"
    effect = "Allow"

    resources = [
      "arn:aws:sqs:us-west-2:788668825590:sonymusic_request_prd.fifo",
      "arn:aws:logs:us-west-2:${var.account_id}:log-group:/aws/lambda/pitch-app-track-loader-prod-lambda-function:*",
    ]

    actions = [
      "logs:CreateLogStream",
      "sqs:*",
      "logs:PutLogEvents",
    ]
  }

  statement {
    sid       = "VisualEditor1"
    effect    = "Allow"
    resources = ["*"]
    actions = [
      "sqs:ListQueues",
      "ec2:CreateNetworkInterface",
      "ec2:DescribeNetworkInterfaces",
      "ec2:DeleteNetworkInterface"
    ]
  }

  statement {
    sid       = "VisualEditor2"
    effect    = "Allow"
    resources = ["arn:aws:logs:us-west-2:${var.account_id}:*"]
    actions   = ["logs:CreateLogGroup"]
  }
}

data "aws_iam_policy_document" "delivery-package-archiver-s3policy" {
  statement {
    sid    = ""
    effect = "Allow"

    resources = [
      "arn:aws:s3:::dsrv-dsp-package-xml-prod/*",
      "arn:aws:s3:::dsrv-dsp-package-xml-prod",
      "arn:aws:s3:::sme-delivery-aoma-upload",
      "arn:aws:s3:::sme-delivery-user-upload",
      "arn:aws:s3:::sme-delivery-aoma-upload/*",
      "arn:aws:s3:::sme-delivery-user-upload/*"
    ]

    actions = [
      "s3:ListBucket",
      "s3:CopyObject",
      "s3:ListAllMyBuckets",
      "s3:DeleteObject",
      "s3:PutObject",
      "s3:GetObject",
      "s3:PutEncryptionConfiguration",
      "s3:ListBucketMultipartUploads",
      "s3:AbortMultipartUpload",
      "s3:ListMultipartUploadParts",
      "s3:List*",
      "s3:Get*",
      "s3:Put*",
    ]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:kinesis:eu-central-1:${var.account_id}:stream/StatusUpdateStream"]
    actions   = ["kinesis:PutRecords"]
  }
}

data "aws_iam_policy_document" "CloudFormerPolicy" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  #checkov:skip=CKV_AWS_108: Ensure IAM policies does not allow data exfiltration
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "autoscaling:Describe*",
      "cloudfront:List*",
      "cloudwatch:Describe*",
      "dynamodb:List*",
      "dynamodb:Describe*",
      "ec2:Describe*",
      "elasticloadbalancing:Describe*",
      "elasticache:Describe*",
      "rds:Describe*",
      "rds:List*",
      "route53:List*",
      "s3:List*",
      "s3:Get*",
      "s3:PutObject",
      "sdb:Get*",
      "sdb:List*",
      "sns:Get*",
      "sns:List*",
      "sqs:Get*",
      "sqs:List*",
    ]
  }
}

data "aws_iam_policy_document" "sme-delivery-pkg-creator" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:kinesis:eu-central-1:${var.account_id}:stream/OrderStream"]
    actions   = ["kinesis:*"]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]
    actions   = ["cloudwatch:PutMetricData"]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:dynamodb:eu-central-1:${var.account_id}:table/delivery-package-creator"]
    actions   = ["dynamodb:*"]
  }
}

data "aws_iam_policy_document" "ECS-Policy" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "ecs:PutAttributes",
      "ecs:UpdateContainerInstancesState",
      "ecs:StartTask",
      "ecs:DescribeTaskSets",
      "ecr:BatchGetRepositoryScanningConfiguration",
      "ecs:DescribeTaskDefinition",
      "ecs:UpdateService",
      "ecs:RegisterTaskDefinition",
      "ecs:StopTask",
      "ecs:DeregisterContainerInstance",
      "ecr:BatchCheckLayerAvailability",
      "ecs:CreateTaskSet",
      "ecr:GetLifecyclePolicy",
      "ecs:SubmitTaskStateChange",
      "ecr:DescribeImageScanFindings",
      "ecs:CreateCluster",
      "ecr:CreateRepository",
      "ecr:GetDownloadUrlForLayer",
      "ecr:DescribePullThroughCacheRules",
      "ecs:DeleteService",
      "ecs:DeleteCluster",
      "ecr:GetAuthorizationToken",
      "ecs:DeleteTaskSet",
      "ecs:DescribeClusters",
      "ecs:PutAccountSetting",
      "ecs:StartTelemetrySession",
      "ecs:DeleteAccountSetting",
      "ecr:BatchGetImage",
      "ecr:DescribeImages",
      "ecr:DescribeImageReplicationStatus",
      "ecs:RegisterContainerInstance",
      "ecs:DeleteAttributes",
      "ecr:ListTagsForResource",
      "ecr:ListImages",
      "ecr:GetRegistryScanningConfiguration",
      "ecs:SubmitAttachmentStateChanges",
      "ecs:DeregisterTaskDefinition",
      "ecs:Poll",
      "ecs:CreateService",
      "ecs:RunTask",
      "ecs:DescribeServices",
      "ecs:SubmitContainerStateChange",
      "ecr:DescribeRepositories",
      "ecs:DescribeContainerInstances",
      "ecs:DescribeTasks",
      "ecs:UpdateTaskSet",
      "ecs:DiscoverPollEndpoint",
      "ecr:GetRegistryPolicy",
      "ecs:PutAccountSettingDefault",
      "ecr:GetLifecyclePolicyPreview",
      "ecr:DescribeRegistry",
      "ecs:UpdateContainerAgent",
      "ecs:UpdateServicePrimaryTaskSet",
      "ecr:GetRepositoryPolicy",
    ]
  }
}

data "aws_iam_policy_document" "ytcp-ytclaims-logs-es-policy" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:es:eu-west-2:${var.account_id}:domain/ytcp-ytclaims-logs/*"]
    actions   = ["es:ESHttpPost"]
  }
}

data "aws_iam_policy_document" "policygen-media-conversion-default-201406091300" {
  statement {
    sid    = "VisualEditor0"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme.origin.medialib/*",
      "arn:aws:s3:::sme.origin.dx3/*",
      "arn:aws:s3:::sme.origin.promommx/*",
      "arn:aws:s3:::sme.conversion.shelf/*",
      "arn:aws:s3:::sme.delivery.master.test/*",
      "arn:aws:s3:::sme.delivery.master.*/*",
      "arn:aws:s3:::sme-delivery-source/*",
      "arn:aws:s3:::sme-conversion-shelf/*",
      "arn:aws:s3:::sme-delivery-stage-source/*",
    ]

    actions = [
      "s3:PutObject",
      "s3:GetObject",
    ]
  }

  statement {
    sid       = "VisualEditor1"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-delivery-source/*"]

    actions = [
      "s3:GetObjectAcl",
      "s3:PutObjectAcl",
    ]
  }
}

data "aws_iam_policy_document" "media-conversion-S3-stage-shelf-access" {
  statement {
    sid       = "Stmt1402333240000"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme.conversion.shelf.test/*"]
    actions   = ["s3:*"]
  }
}

data "aws_iam_policy_document" "AWSLambdaBasicExecutionRole-19d3b7c0-40d2-4401-ae91-bab58c714de9" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:logs:eu-central-1:${var.account_id}:*"]
    actions   = ["logs:CreateLogGroup"]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:logs:eu-central-1:${var.account_id}:log-group:/aws/lambda/DeliveryShelfStageFileRecopyLambda:*"]

    actions = [
      "logs:CreateLogStream",
      "logs:PutLogEvents",
    ]
  }
}

data "aws_iam_policy_document" "eks-fargate-logging-secret-access-policy" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  #checkov:skip=CKV_AWS_108: Ensure IAM policies does not allow data exfiltration
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "logs:CreateLogStream",
      "logs:CreateLogGroup",
      "logs:DescribeLogStreams",
      "logs:PutLogEvents",
    ]
  }

  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "kinesis:PutRecord",
      "kinesis:PutRecords",
      "secretsmanager:GetSecretValue",
    ]
  }
}

data "aws_iam_policy_document" "policygen-media-conversion-aws-stage-201511191654" {
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["arn:aws:s3:::*"]
    actions   = ["s3:ListBucket"]
  }

  statement {
    sid    = "VisualEditor1"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme.conversion.shelf.test",
      "arn:aws:s3:::sme-delivery-source",
      "arn:aws:s3:::sme-conversion-shelf",
      "arn:aws:s3:::sme-delivery-stage-bb-target",
      "arn:aws:s3:::sme-delivery-stage-source",
      "arn:aws:s3:::sme-mc-stage-source",
      "arn:aws:s3:::sme-mc-stage-target",
      "arn:aws:s3:::sme-delivery-dev-source",
      "arn:aws:s3:::sme-conversion-shelf-stage/",
      "arn:aws:s3:::sme-conversion-shelf-stage/*",
      "arn:aws:s3:::sme-delivery-stage-target/",
      "arn:aws:s3:::sme-delivery-stage-target/*",
      "arn:aws:s3:::sme.conversion.shelf.test/*",
      "arn:aws:s3:::sme-delivery-source/*",
      "arn:aws:s3:::sme-conversion-shelf/*",
      "arn:aws:s3:::sme-delivery-stage-bb-target/*",
      "arn:aws:s3:::sme-delivery-stage-source/*",
      "arn:aws:s3:::sme-mc-stage-source/*",
      "arn:aws:s3:::sme-mc-stage-target/*",
      "arn:aws:s3:::sme-delivery-dev-source/*",
    ]

    actions = [
      "s3:PutObject",
      "s3:GetObject",
      "s3:ListBucket",
      "s3:DeleteObject",
    ]
  }

  statement {
    sid       = "VisualEditor2"
    effect    = "Allow"
    resources = ["arn:aws:s3:::*"]
    actions   = ["s3:ListAllMyBuckets"]
  }
}

data "aws_iam_policy_document" "sme-dsp-cache-origin-licensing" {
  statement {
    sid    = "Stmt1486459417000"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-origin-licensing",
      "arn:aws:s3:::sme-origin-licensing/*",
    ]

    actions = [
      "s3:DeleteObject",
      "s3:Get*",
      "s3:ListBucket",
      "s3:ListBucketMultipartUploads",
      "s3:Put*",
    ]
  }
}

data "aws_iam_policy_document" "sme-pitch-user-role" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  statement {
    sid    = "programmatically"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-pitch-content-dropoff",
      "arn:aws:s3:::sme-pitch-content-dropoff/*",
    ]

    actions = ["s3:*"]
  }

  statement {
    sid       = "Stmt1566823043583"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "lambda:InvokeFunction",
      "lambda:ListFunctions",
    ]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:iam::788668825590:role/pitch-sm_process_prd_sme"]
    actions   = ["sts:AssumeRole"]
  }
}

data "aws_iam_policy_document" "deld-dynamodb-eom-group-cache" {
  statement {
    sid       = "Stmt1509030747000"
    effect    = "Allow"
    resources = ["arn:aws:dynamodb:eu-central-1:058029036333:table/eom_group_cache"]

    actions = [
      "dynamodb:BatchGetItem",
      "dynamodb:BatchWriteItem",
      "dynamodb:DeleteItem",
      "dynamodb:DescribeTable",
      "dynamodb:GetItem",
      "dynamodb:GetRecords",
      "dynamodb:ListStreams",
      "dynamodb:ListTagsOfResource",
      "dynamodb:PutItem",
      "dynamodb:Query",
      "dynamodb:Scan",
      "dynamodb:TagResource",
      "dynamodb:UpdateItem",
      "dynamodb:UpdateTable",
      "dynamodb:UntagResource",
    ]
  }
}

data "aws_iam_policy_document" "AWSLambdaBasicExecutionRole-f81e9d49-ce96-4c89-ab74-3925858440ff" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:logs:eu-central-1:${var.account_id}:*"]
    actions   = ["logs:CreateLogGroup"]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:logs:eu-central-1:${var.account_id}:log-group:/aws/lambda/delivery-prod-ecr-repo-cleanup:*"]

    actions = [
      "logs:CreateLogStream",
      "logs:PutLogEvents",
    ]
  }
}

data "aws_iam_policy_document" "aws-opsworks-service-policy" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  #checkov:skip=CKV_AWS_107: Ensure IAM policies does not allow credentials exposure
  #checkov:skip=CKV_AWS_110: Ensure IAM policies does not allow privilege escalation
  #checkov:skip=CKV_AWS_109: Ensure IAM policies does not allow permissions management / resource exposure without constraints
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "ec2:Describe*",
      "ec2:Get*",
      "ec2:List*",
      "ec2:Search*",
      "ec2:Export*",
      "ec2:Accept*",
      "ec2:AdvertiseByoipCidr",
      "ec2:Allocate*",
      "ec2:ApplySecurityGroupsToClientVpnTargetNetwork",
      "ec2:Assign*",
      "ec2:Associate*",
      "ec2:Attach*",
      "ec2:Authorize*",
      "ec2:BundleInstance",
      "ec2:Cancel*",
      "ec2:ConfirmProductInstance",
      "ec2:Copy*",
      "ec2:Create*",
      "ec2:Delete*",
      "ec2:Deprovision*",
      "ec2:Deregister*",
      "ec2:Detach*",
      "ec2:Disable*",
      "ec2:Disassociate*",
      "ec2:Enable*",
      "ec2:Import*",
      "ec2:InjectApiError",
      "ec2:LockSnapshot",
      "ec2:Modify*",
      "ec2:MonitorInstances",
      "ec2:Move*",
      "ec2:PauseVolumeIO",
      "ec2:Provision*",
      "ec2:Purchase*",
      "ec2:RebootInstances",
      "ec2:Register*",
      "ec2:Reject*",
      "ec2:Release*",
      "ec2:Replace*",
      "ec2:ReportInstanceStatus",
      "ec2:Request*",
      "ec2:Reset*",
      "ec2:Restore*",
      "ec2:Revoke*",
      "ec2:Run*",
      "ec2:Send*",
      "ec2:Start*",
      "ec2:StopInstances",
      "ec2:Terminate*",
      "ec2:Unassign*",
      "ec2:UnlockSnapshot",
      "ec2:UnmonitorInstances",
      "ec2:Update*",
      "ec2:WithdrawByoipCidr",
      "ec2:PutResourcePolicy",
      "iam:PassRole",
      "cloudwatch:GetMetricStatistics",
      "cloudwatch:DescribeAlarms",
      "elasticloadbalancing:Describe*",
      "elasticloadbalancing:ApplySecurityGroupsToLoadBalancer",
      "elasticloadbalancing:AttachLoadBalancerToSubnets",
      "elasticloadbalancing:ConfigureHealthCheck",
      "elasticloadbalancing:Create*",
      "elasticloadbalancing:Delete*",
      "elasticloadbalancing:DeregisterInstancesFromLoadBalancer",
      "elasticloadbalancing:DetachLoadBalancerFromSubnets",
      "elasticloadbalancing:DisableAvailabilityZonesForLoadBalancer",
      "elasticloadbalancing:EnableAvailabilityZonesForLoadBalancer",
      "elasticloadbalancing:ModifyLoadBalancerAttributes",
      "elasticloadbalancing:RegisterInstancesWithLoadBalancer",
      "elasticloadbalancing:Set*",
      "elasticloadbalancing:AddTags",
      "elasticloadbalancing:RemoveTags",
      "rds:Describe*",
      "rds:DownloadCompleteDBLogFile",
      "rds:DownloadDBLogFilePortion",
      "rds:BacktrackDBCluster",
      "rds:ListTagsForResource",
      "rds:Add*",
      "rds:Apply*",
      "rds:Cancel*",
      "rds:Copy*",
      "rds:Create*",
      "rds:CrossRegionCommunication",
      "rds:Delete*",
      "rds:DeregisterDBProxyTargets",
      "rds:DisableHttpEndpoint",
      "rds:EnableHttpEndpoint",
      "rds:Failover*",
      "rds:Modify*",
      "rds:Promote*",
      "rds:PurchaseReservedDBInstancesOffering",
      "rds:Reboot*",
      "rds:RegisterDBProxyTargets",
      "rds:Remove*",
      "rds:Reset*",
      "rds:Restore*",
      "rds:RevokeDBSecurityGroupIngress",
      "rds:Start*",
      "rds:Stop*",
      "rds:Switchover*",
      "rds:AuthorizeDBSecurityGroupIngress",
      "rds:AddTagsToResource",
      "rds:RemoveTagsFromResource"
    ]
  }
}

data "aws_iam_policy_document" "delivery-blackbox-order-capture-policy" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:logs:*:*:*"]

    actions = [
      "logs:CreateLogGroup",
      "logs:CreateLogStream",
      "logs:PutLogEvents",
    ]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:kinesis:eu-central-1:${var.account_id}:stream/OrderStream"]
    actions   = ["kinesis:*"]
  }

  statement {
    sid    = ""
    effect = "Allow"

    resources = [
      "arn:aws:s3:::eom-group-store",
      "arn:aws:s3:::eom-group-store/*",
    ]

    actions = ["s3:*"]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:dynamodb:eu-central-1:058029036333:table/eom_group_cache"]
    actions   = ["dynamodb:*"]
  }
}

data "aws_iam_policy_document" "aws-lambda-dynamodb-access-policy" {
  statement {
    sid       = "Stmt1497610036000"
    effect    = "Allow"
    resources = ["arn:aws:dynamodb:eu-west-2:${var.account_id}:table/ytcms_db/stream/2017-06-16T09:59:16.956"]

    actions = [
      "dynamodb:DescribeStream",
      "dynamodb:GetRecords",
      "dynamodb:GetShardIterator",
      "dynamodb:ListStreams",
    ]
  }
}

data "aws_iam_policy_document" "sme-conversion-shelf-test" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "s3:ListAccessPointsForObjectLambda",
      "s3:GetAccessPoint",
      "s3:PutAccountPublicAccessBlock",
      "logs:DescribeLogGroups",
      "s3:ListAccessPoints",
      "logs:DescribeLogStreams",
      "s3:ListJobs",
      "s3:PutStorageLensConfiguration",
      "logs:CreateLogGroup",
      "logs:PutLogEvents",
      "s3:ListStorageLensConfigurations",
      "logs:CreateLogStream",
      "s3:GetAccountPublicAccessBlock",
      "s3:ListAllMyBuckets",
      "logs:GetLogEvents",
      "s3:CreateJob",
    ]
  }

  statement {
    sid       = "VisualEditor1"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-delivery-uat-shelf"]
    actions   = ["s3:*"]
  }

  statement {
    sid    = "VisualEditor2"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme.conversion.shelf.test/",
      "arn:aws:s3:::sme.conversion.shelf.test/*",
      "arn:aws:s3:::sme-mc-source/*",
      "arn:aws:s3:::sme-mc-source",
      "arn:aws:s3:::sme-mc-target/*",
      "arn:aws:s3:::sme-mc-target"
    ]

    actions = ["s3:*"]
  }
}

data "aws_iam_policy_document" "sqs-custom-pitch" {
  statement {
    sid       = "AllowSQSMessageSend"
    effect    = "Allow"
    resources = ["arn:aws:sqs:us-west-2:788668825590:sonymusic_request_prd.fifo"]
    actions   = ["sqs:SendMessage"]
  }

  statement {
    sid       = "AllowSQSMessageReceiveDelete"
    effect    = "Allow"
    resources = ["arn:aws:sqs:us-west-2:788668825590:sonymusic_response_prd"]

    actions = [
      "sqs:DeleteMessage",
      "sqs:ReceiveMessage",
    ]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:kinesis:eu-central-1:023180329437:stream/EmailStream"]

    actions = [
      "kinesis:PutRecord",
      "kinesis:PutRecords",
    ]
  }
}

data "aws_iam_policy_document" "oneClick_lambda_basic_execution_1494406367508" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:logs:*:*:*"]

    actions = [
      "logs:CreateLogGroup",
      "logs:CreateLogStream",
      "logs:PutLogEvents",
    ]
  }
}

data "aws_iam_policy_document" "sme-netezza-delivery-02" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]
    actions   = ["s3:ListAllMyBuckets"]
  }

  statement {
    sid    = ""
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-netezza-delivery-02",
      "arn:aws:s3:::sme-netezza-delivery-02/*",
    ]

    actions = ["s3:*"]
  }
}

data "aws_iam_policy_document" "sme-s3-inventory-access" {
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-s3-inventory/*"]

    actions = [
      "s3:PutAnalyticsConfiguration",
      "s3:GetObjectVersionTagging",
      "s3:CreateBucket",
      "s3:ReplicateObject",
      "s3:GetObjectAcl",
      "s3:DeleteBucketWebsite",
      "s3:PutLifecycleConfiguration",
      "s3:GetObjectVersionAcl",
      "s3:PutObjectTagging",
      "s3:DeleteObject",
      "s3:DeleteObjectTagging",
      "s3:GetBucketPolicyStatus",
      "s3:GetBucketWebsite",
      "s3:PutReplicationConfiguration",
      "s3:DeleteObjectVersionTagging",
      "s3:GetBucketNotification",
      "s3:PutBucketCORS",
      "s3:GetReplicationConfiguration",
      "s3:ListMultipartUploadParts",
      "s3:GetObject",
      "s3:PutBucketNotification",
      "s3:PutObject",
      "s3:PutBucketLogging",
      "s3:GetAnalyticsConfiguration",
      "s3:GetObjectVersionForReplication",
      "s3:GetLifecycleConfiguration",
      "s3:ListBucketByTags",
      "s3:GetBucketTagging",
      "s3:GetInventoryConfiguration",
      "s3:PutAccelerateConfiguration",
      "s3:DeleteObjectVersion",
      "s3:GetBucketLogging",
      "s3:ListBucketVersions",
      "s3:ReplicateTags",
      "s3:RestoreObject",
      "s3:GetAccelerateConfiguration",
      "s3:ListBucket",
      "s3:GetBucketPolicy",
      "s3:PutEncryptionConfiguration",
      "s3:GetEncryptionConfiguration",
      "s3:GetObjectVersionTorrent",
      "s3:AbortMultipartUpload",
      "s3:GetBucketRequestPayment",
      "s3:PutBucketTagging",
      "s3:GetObjectTagging",
      "s3:GetMetricsConfiguration",
      "s3:DeleteBucket",
      "s3:PutBucketVersioning",
      "s3:GetBucketPublicAccessBlock",
      "s3:ListBucketMultipartUploads",
      "s3:PutMetricsConfiguration",
      "s3:PutObjectVersionTagging",
      "s3:GetBucketVersioning",
      "s3:GetBucketAcl",
      "s3:PutInventoryConfiguration",
      "s3:GetObjectTorrent",
      "s3:PutBucketRequestPayment",
      "s3:PutBucketWebsite",
      "s3:GetBucketCORS",
      "s3:GetBucketLocation",
      "s3:GetObjectVersion",
      "s3:ReplicateDelete",
    ]
  }

  statement {
    sid       = "VisualEditor1"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "s3:GetAccountPublicAccessBlock",
      "s3:ListAllMyBuckets",
      "s3:HeadBucket",
    ]
  }

  statement {
    sid    = "VisualEditor2"
    effect = "Allow"
    resources = [
      "arn:aws:s3:::dsrv-dsp-package-xml-prod",
      "arn:aws:s3:::dsrv-dsp-package-xml-prod/*"
    ]

    actions = [
      "s3:GetObject",
      "s3:PutObject",
      "s3:ListBucket",
      "s3:DeleteObject",
      "s3:GetObjectMetadata"
    ]
  }
}

data "aws_iam_policy_document" "oneClick_CloudTrail_CloudWatchLogs_Role_1528028433696" {
  statement {
    sid       = "AWSCloudTrailCreateLogStream20141101"
    effect    = "Allow"
    resources = ["arn:aws:logs:eu-central-1:${var.account_id}:log-group:Delivery-Prod-Log-Group:log-stream:${var.account_id}_CloudTrail_eu-central-1*"]
    actions   = ["logs:CreateLogStream"]
  }

  statement {
    sid       = "AWSCloudTrailPutLogEvents20141101"
    effect    = "Allow"
    resources = ["arn:aws:logs:eu-central-1:${var.account_id}:log-group:Delivery-Prod-Log-Group:log-stream:${var.account_id}_CloudTrail_eu-central-1*"]
    actions   = ["logs:PutLogEvents"]
  }
}

data "aws_iam_policy_document" "delp-trendmicro_esdomain_policy" {
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["arn:aws:es:us-east-1:991283851267:domain/trend-micro-logs/*"]

    actions = [
      "es:ESHttpGet",
      "es:ESHttpHead",
      "es:ESHttpPost",
      "es:ESHttpPut",
      "es:ESHttpPatch",
      "es:Describe*",
      "es:List*",
      "es:AddTags",
    ]
  }
}

data "aws_iam_policy_document" "delp-ecr-clean-up-access-policy" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "ecs:ListClusters",
      "ecs:ListServices",
      "ecs:DescribeServices",
      "ecs:DescribeTaskDefinition",
      "ecr:DescribeRepositories",
      "ecr:DescribeImages",
      "ecr:BatchDeleteImage",
    ]
  }
}

data "aws_iam_policy_document" "s3-media-production" {
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "s3:GetAccessPoint",
      "s3:PutAccountPublicAccessBlock",
      "s3:GetAccountPublicAccessBlock",
      "s3:ListAllMyBuckets",
      "s3:ListAccessPoints",
      "s3:ListJobs",
      "s3:CreateJob",
      "s3:HeadBucket",
    ]
  }

  statement {
    sid    = "VisualEditor1"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-media-production",
      "arn:aws:s3:*:*:accesspoint/*",
      "arn:aws:s3:*:*:job/*",
      "arn:aws:s3:::sme-media-production/*",
    ]

    actions = ["s3:*"]
  }
}

data "aws_iam_policy_document" "utilities-cwlogs-policy" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:logs:*:*:*"]

    actions = [
      "logs:CreateLogGroup",
      "logs:CreateLogStream",
      "logs:PutLogEvents",
      "logs:DescribeLogStreams",
    ]
  }
}

data "aws_iam_policy_document" "AmazonS3ReadOnlyAccess-origin-201312111536" {
  #checkov:skip=CKV_AWS_108: Ensure IAM policies does not allow data exfiltration
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "s3:Get*",
      "s3:List*",
    ]
  }
}

data "aws_iam_policy_document" "PostgreSQL-Credentials-Rotation-Policy" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  #checkov:skip=CKV_AWS_108: Ensure IAM policies does not allow data exfiltration
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["arn:aws:kms:eu-central-1:${var.account_id}:key/7fcf7089-a08e-4de9-8177-1a3026ed3a1c"]

    actions = [
      "kms:Decrypt",
      "kms:Encrypt",
      "kms:GenerateDataKey",
    ]

    condition {
      test     = "StringEquals"
      variable = "kms:ViaService"
      values   = ["secretsmanager.eu-central-1.amazonaws.com"]
    }
  }

  statement {
    sid       = "VisualEditor1"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "secretsmanager:UntagResource",
      "secretsmanager:DescribeSecret",
      "secretsmanager:PutSecretValue",
      "secretsmanager:CreateSecret",
      "secretsmanager:DeleteSecret",
      "secretsmanager:ListSecretVersionIds",
      "ses:SendEmail",
      "secretsmanager:GetRandomPassword",
      "logs:CreateLogStream",
      "ses:SendTemplatedEmail",
      "secretsmanager:GetSecretValue",
      "ec2:DescribeNetworkInterfaces",
      "secretsmanager:RestoreSecret",
      "secretsmanager:RotateSecret",
      "ec2:UnassignPrivateIpAddresses",
      "ses:SendRawEmail",
      "ec2:DeleteNetworkInterface",
      "secretsmanager:CancelRotateSecret",
      "ec2:AssignPrivateIpAddresses",
      "logs:CreateLogGroup",
      "logs:PutLogEvents",
      "secretsmanager:UpdateSecret",
      "ec2:CreateNetworkInterface",
      "secretsmanager:GetResourcePolicy",
      "ses:SendBulkTemplatedEmail",
      "secretsmanager:UpdateSecretVersionStage",
      "ses:SendBulkEmail",
      "secretsmanager:ListSecrets",
      "secretsmanager:TagResource",
    ]
  }

  statement {
    sid    = "VisualEditor9"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-aoma-delivery-prod-db-team",
      "arn:aws:s3:::sme-aoma-delivery-prod-db-team/*",
    ]

    actions = [
      "s3:PutObject",
      "s3:GetObject",
      "s3:ListBucket",
      "s3:DeleteObject",
    ]
  }
}

data "aws_iam_policy_document" "RDS-admin" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  #checkov:skip=CKV_AWS_107: Ensure IAM policies does not allow credentials exposure
  #checkov:skip=CKV_AWS_110: Ensure IAM policies does not allow privilege escalation
  #checkov:skip=CKV_AWS_109: Ensure IAM policies does not allow permissions management / resource exposure without constraints
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "account:GetAccountInformation",
      "account:GetAlternateContact",
      "account:GetChallengeQuestions",
      "account:GetContactInformation",
      "apigateway:*",
      "billing:GetBillingData",
      "billing:GetBillingDetails",
      "billing:GetBillingNotifications",
      "billing:GetBillingPreferences",
      "billing:GetContractInformation",
      "billing:GetCredits",
      "billing:GetIAMAccessPreference",
      "billing:GetSellerOfRecord",
      "billing:ListBillingViews",
      "ce:DescribeNotificationSubscription",
      "ce:DescribeReport",
      "ce:GetAnomalies",
      "ce:GetAnomalyMonitors",
      "ce:GetAnomalySubscriptions",
      "ce:GetCostAndUsage",
      "ce:GetCostAndUsageWithResources",
      "ce:GetCostCategories",
      "ce:GetCostForecast",
      "ce:GetDimensionValues",
      "ce:GetPreferences",
      "ce:GetReservationCoverage",
      "ce:GetReservationPurchaseRecommendation",
      "ce:GetReservationUtilization",
      "ce:GetRightsizingRecommendation",
      "ce:GetSavingsPlansCoverage",
      "ce:GetSavingsPlansPurchaseRecommendation",
      "ce:GetSavingsPlansUtilization",
      "ce:GetSavingsPlansUtilizationDetails",
      "ce:GetTags",
      "ce:GetUsageForecast",
      "ce:ListCostAllocationTags",
      "ce:ListSavingsPlansPurchaseRecommendationGeneration",
      "cloudwatch:*",
      "consolidatedbilling:GetAccountBillingRole",
      "consolidatedbilling:ListLinkedAccounts",
      "cur:GetClassicReport",
      "cur:GetClassicReportPreferences",
      "cur:GetUsageReport",
      "cur:ValidateReportDestination",
      "ec2:*",
      "ecs:*",
      "ecs:DescribeTaskDefinition",
      "ecs:ListTaskDefinitions",
      "ecs:RegisterTaskDefinition",
      "events:*",
      "freetier:GetFreeTierAlertPreference",
      "freetier:GetFreeTierUsage",
      "iam:ListGroups",
      "iam:ListRoles",
      "iam:ListUsers",
      "iam:PassRole",
      "inspector2:BatchGetAccountStatus",
      "inspector2:BatchGetFreeTrialInfo",
      "inspector2:DescribeOrganizationConfiguration",
      "inspector2:GetDelegatedAdminAccount",
      "inspector2:GetFindingsReportStatus",
      "inspector2:GetMember",
      "inspector2:ListAccountPermissions",
      "inspector2:ListCoverage",
      "inspector2:ListCoverageStatistics",
      "inspector2:ListDelegatedAdminAccounts",
      "inspector2:ListFindingAggregations",
      "inspector2:ListFindings",
      "inspector2:ListFilters",
      "inspector2:ListMembers",
      "inspector2:ListTagsForResource",
      "inspector2:ListUsageTotals",
      "invoicing:GetInvoiceEmailDeliveryPreferences",
      "invoicing:GetInvoicePDF",
      "invoicing:ListInvoiceSummaries",
      "kms:*",
      "lambda:*",
      "payments:GetPaymentInstrument",
      "payments:GetPaymentStatus",
      "payments:ListPaymentPreferences",
      "rds:*",
      "redshift:*",
      "sqs:*",
      "ssm:CancelCommand",
      "ssm:CreateActivation",
      "ssm:DescribeAssociationExecutionTargets",
      "ssm:DescribeAssociationExecutions",
      "ssm:DescribeAutomationExecutions",
      "ssm:DescribeAutomationStepExecutions",
      "ssm:DescribeAvailablePatches",
      "ssm:DescribeInstanceInformation",
      "ssm:DescribeInstancePatchStates",
      "ssm:DescribeInstancePatchStatesForPatchGroup",
      "ssm:DescribeInstancePatches",
      "ssm:DescribeInstanceProperties",
      "ssm:DescribeInventoryDeletions",
      "ssm:DescribeOpsItems",
      "ssm:DescribeParameters",
      "ssm:DescribePatchGroupState",
      "ssm:GetAutomationExecution",
      "ssm:GetCommandInvocation",
      "ssm:GetConnectionStatus",
      "ssm:GetDeployablePatchSnapshotForInstance",
      "ssm:GetInventory",
      "ssm:GetInventorySchema",
      "ssm:GetMaintenanceWindowExecution",
      "ssm:GetMaintenanceWindowExecutionTask",
      "ssm:GetMaintenanceWindowExecutionTaskInvocation",
      "ssm:GetManifest",
      "ssm:GetOpsItem",
      "ssm:ListCommandInvocations",
      "ssm:ListCommands",
      "ssm:PutConfigurePackageResult",
      "ssm:PutInventory",
      "ssm:UpdateInstanceInformation",
      "ssm:UpdateOpsItem",
      "support:*",
      "tax:GetTaxInheritance",
      "tax:GetTaxRegistrationDocument",
      "tax:ListTaxRegistrations"
    ]
  }

  statement {
    sid    = "VisualEditor1"
    effect = "Allow"

    resources = [
      "arn:aws:ssm:*:${var.account_id}:patchbaseline/*",
      "arn:aws:ssm:*:${var.account_id}:maintenancewindow/*",
      "arn:aws:ssm:*:${var.account_id}:document/*",
      "arn:aws:ssm:*:${var.account_id}:parameter/*",
      "arn:aws:ssm:*:${var.account_id}:servicesetting/*",
      "arn:aws:ssm:*:${var.account_id}:resource-data-sync/*",
    ]

    actions = [
      "ssm:LabelParameterVersion",
      "ssm:DescribeDocument",
      "ssm:UpdateAssociation",
      "ssm:GetParameter",
      "ssm:DeletePatchBaseline",
      "ssm:GetMaintenanceWindowTask",
      "ssm:DeleteParameter",
      "ssm:RemoveTagsFromResource",
      "ssm:DeleteResourceDataSync",
      "ssm:AddTagsToResource",
      "ssm:GetDocument",
      "ssm:GetParametersByPath",
      "ssm:GetMaintenanceWindow",
      "ssm:UpdateDocument",
      "ssm:UpdatePatchBaseline",
      "ssm:DescribeAssociation",
      "ssm:GetParameterHistory",
      "ssm:GetParameters",
      "ssm:DeleteParameters",
      "ssm:UpdateServiceSetting",
      "ssm:PutParameter",
      "ssm:UpdateResourceDataSync",
      "ssm:ListTagsForResource",
      "ssm:DescribeDocumentParameters",
      "ssm:DescribeDocumentPermission",
      "ssm:GetCalendarState",
    ]
  }

  statement {
    sid    = "VisualEditor2"
    effect = "Allow"

    resources = [
      "arn:aws:ssm:*:${var.account_id}:maintenancewindow/*",
      "arn:aws:ssm:*:${var.account_id}:document/*",
      "arn:aws:ssm:*:${var.account_id}:servicesetting/*",
      "arn:aws:ssm:*:${var.account_id}:resource-data-sync/*",
    ]

    actions = [
      "ssm:GetMaintenanceWindowTask",
      "ssm:DescribeAssociation",
      "ssm:DescribeDocument",
      "ssm:ListTagsForResource",
      "ssm:DescribeDocumentParameters",
      "ssm:GetDocument",
      "ssm:GetServiceSetting",
      "ssm:GetMaintenanceWindow",
      "ssm:DescribeDocumentPermission",
      "ssm:GetOpsSummary",
      "ssm:GetCalendarState",
    ]
  }
}

data "aws_iam_policy_document" "prod-asset-requester-policy" {
  statement {
    sid    = ""
    effect = "Allow"

    resources = [
      "arn:aws:sqs:eu-central-1:${var.account_id}:AomaRequestQueue",
      "arn:aws:sqs:eu-central-1:${var.account_id}:AomaResponseQueue",
      "arn:aws:sqs:eu-central-1:${var.account_id}:AssetSourceDeleteQueue",
      "arn:aws:sqs:eu-central-1:${var.account_id}:SftpDeliveryQueue",
      "arn:aws:sqs:eu-central-1:${var.account_id}:S3DeliveryQueue",
      "arn:aws:sqs:eu-central-1:${var.account_id}:AsperaDeliveryQueue",
      "arn:aws:sqs:eu-central-1:${var.account_id}:TransporterDeliveryQueue",
      "arn:aws:sqs:eu-central-1:${var.account_id}:AsperaMsDeliveryQueue",
      "arn:aws:sqs:eu-central-1:${var.account_id}:SFTPMsDeliveryQueue",
      "arn:aws:sqs:eu-central-1:${var.account_id}:S3MsDeliveryQueue",
      "arn:aws:sqs:eu-central-1:${var.account_id}:TransporterMsDeliveryQueue",
      "arn:aws:sqs:eu-central-1:${var.account_id}:S3v2DeliveryDLQ.fifo",
      "arn:aws:sqs:eu-central-1:${var.account_id}:S3v2DeliveryQ.fifo",
    ]

    actions = ["sqs:*"]
  }

  statement {
    sid    = ""
    effect = "Allow"

    resources = [
      "arn:aws:kinesis:eu-central-1:${var.account_id}:stream/EmailStream",
      "arn:aws:kinesis:eu-central-1:${var.account_id}:stream/ArchivePackageStream",
    ]

    actions = ["kinesis:PutRecord"]
  }

  statement {
    sid    = "Stmt1486461269700"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delivery-source",
      "arn:aws:s3:::sme-delivery-target",
      "arn:aws:s3:::sme-delivery-target/*",
    ]

    actions = ["s3:*"]
  }

  statement {
    sid    = "VisualEditor1"
    effect = "Allow"
    resources = ["arn:aws:iam::613871678587:role/aomap-sa-msk-delivery-prod",
    "arn:aws:iam::635220336377:role/globaldsp-sa-msk-delivery-role"]
    actions = ["sts:AssumeRole"]
  }
}

data "aws_iam_policy_document" "delp-external-msk-policy" {
  statement {
    sid       = "VisualEditor1"
    effect    = "Allow"
    resources = ["arn:aws:iam::635220336377:role/globaldsp-sa-msk-delivery-role"]
    actions   = ["sts:AssumeRole"]
  }
}


data "aws_iam_policy_document" "lambda-create" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  #checkov:skip=CKV_AWS_110: Ensure IAM policies does not allow privilege escalation
  #checkov:skip=CKV_AWS_109: Ensure IAM policies does not allow permissions management / resource exposure without constraints
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "sns:List*",
      "sns:CheckIfPhoneNumberIsOptedOut",
      "sns:Get*",
      "sns:ConfirmSubscription",
      "sns:Create*",
      "sns:Delete*",
      "sns:OptInPhoneNumber",
      "sns:Publish",
      "sns:PutDataProtectionPolicy",
      "sns:Set*",
      "sns:Subscribe",
      "sns:Unsubscribe",
      "sns:VerifySMSSandboxPhoneNumber",
      "sns:AddPermission",
      "sns:RemovePermission",
      "sns:TagResource",
      "sns:UntagResource",
      "acm:ExportCertificate",
      "ses:List*",
      "ses:Describe*",
      "ses:Get*",
      "ses:CloneReceiptRuleSet",
      "ses:Create*",
      "ses:Delete*",
      "ses:Put*",
      "ses:ReorderReceiptRuleSet",
      "ses:Send*",
      "ses:Set*",
      "ses:TestRenderTemplate",
      "ses:Update*",
      "ses:Verify*",
      "kms:List*",
      "kms:Describe*",
      "kms:Get*",
      "kms:CancelKeyDeletion",
      "kms:ConnectCustomKeyStore",
      "kms:Create*",
      "kms:Decrypt",
      "kms:Delete*",
      "kms:DeriveSharedSecret",
      "kms:DisableKey",
      "kms:DisableKeyRotation",
      "kms:DisconnectCustomKeyStore",
      "kms:EnableKey",
      "kms:EnableKeyRotation",
      "kms:Encrypt",
      "kms:Generate*",
      "kms:ImportKeyMaterial",
      "kms:ReEncrypt*",
      "kms:ReplicateKey",
      "kms:RotateKeyOnDemand",
      "kms:ScheduleKeyDeletion",
      "kms:Sign",
      "kms:SynchronizeMultiRegionKey",
      "kms:Update*",
      "kms:Verify",
      "kms:VerifyMac",
      "kms:PutKeyPolicy",
      "kms:RetireGrant",
      "kms:RevokeGrant",
      "kms:TagResource",
      "kms:UntagResource",
      "lambda:List*",
      "lambda:Get*",
      "lambda:CheckpointDurableExecution",
      "lambda:Create*",
      "lambda:Delete*",
      "lambda:Invoke*",
      "lambda:PassCapacityProvider",
      "lambda:Publish*",
      "lambda:Put*",
      "lambda:Send*",
      "lambda:StopDurableExecution",
      "lambda:Update*",
      "lambda:Add*",
      "lambda:DisableReplication",
      "lambda:EnableReplication",
      "lambda:Remove*",
      "lambda:TagResource",
      "lambda:UntagResource",
      "events:List*",
      "events:Describe*",
      "events:TestEventPattern",
      "events:ActivateEventSource",
      "events:AllowVendedLogDeliveryForResource",
      "events:CancelReplay",
      "events:Create*",
      "events:DeactivateEventSource",
      "events:DeauthorizeConnection",
      "events:Delete*",
      "events:DisableRule",
      "events:EnableRule",
      "events:InvokeApiDestination",
      "events:Put*",
      "events:Remove*",
      "events:RetrieveConnectionCredentials",
      "events:StartReplay",
      "events:Update*",
      "events:TagResource",
      "events:UntagResource",
      "backup:List*",
      "backup:Describe*",
      "backup:ExportBackupPlanTemplate",
      "backup:Get*",
      "backup:AssociateBackupVaultMpaApprovalTeam",
      "backup:CancelLegalHold",
      "backup:Copy*",
      "backup:Create*",
      "backup:Delete*",
      "backup:Disassociate*",
      "backup:Put*",
      "backup:RevokeRestoreAccessBackupVault",
      "backup:Start*",
      "backup:StopBackupJob",
      "backup:Update*",
      "backup:SearchRecoveryPoint",
      "backup:TagResource",
      "backup:UntagResource",
      "backup-storage:CommitBackupJob",
      "backup-storage:DeleteObjects",
      "backup-storage:DescribeBackupJob",
      "backup-storage:Get*",
      "backup-storage:List*",
      "backup-storage:MountCapsule",
      "backup-storage:NotifyObjectComplete",
      "backup-storage:Put*",
      "backup-storage:StartObject",
      "backup-storage:UpdateObjectComplete",
      "iam:PassRole"
    ]
  }
}

data "aws_iam_policy_document" "AWSLambdaBasicExecutionRole-6b75a65a-dcda-450b-80e0-c17bd36472fd" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:logs:eu-central-1:${var.account_id}:*"]
    actions   = ["logs:CreateLogGroup"]
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:logs:eu-central-1:${var.account_id}:log-group:/aws/lambda/ResponseQTest:*"]

    actions = [
      "logs:CreateLogStream",
      "logs:PutLogEvents",
    ]
  }
}





data "aws_iam_policy_document" "Kosmo-Kontor-Assets" {
  statement {
    sid       = "AllowStatement1"
    effect    = "Allow"
    resources = ["arn:aws:s3:::*"]

    actions = [
      "s3:ListAllMyBuckets",
      "s3:GetBucketLocation",
    ]
  }

  statement {
    sid       = "AllowStatement2B"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-media-production"]
    actions   = ["s3:ListBucket"]

    condition {
      test     = "StringEquals"
      variable = "s3:prefix"

      values = [
        "",
        "Kosmo-Kontor-Assets",
      ]
    }

    condition {
      test     = "StringEquals"
      variable = "s3:delimiter"
      values   = ["/"]
    }
  }

  statement {
    sid       = "AllowStatement3"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-media-production"]
    actions   = ["s3:ListBucket"]

    condition {
      test     = "StringLike"
      variable = "s3:prefix"
      values   = ["Kosmo-Kontor-Assets/*"]
    }
  }

  statement {
    sid       = "AllowStatement4B"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-media-production/Kosmo-Kontor-Assets/*"]

    actions = [
      "s3:GetObject",
      "s3:PutObject",
      "s3:DeleteObject",
    ]
  }
}

data "aws_iam_policy_document" "dsrv-prod-eks-cluster-mediagate-prod-service-policy" {
  statement {
    sid       = "AllowStatement1"
    effect    = "Allow"
    resources = ["arn:aws:kms:eu-central-1:023180329437:key/7fcf7089-a08e-4de9-8177-1a3026ed3a1c"]

    actions = [
      "kms:Encrypt",
      "kms:Decrypt",
      "kms:ReEncrypt*",
      "kms:GenerateDataKey*",
      "kms:DescribeKey"
    ]
  }

  statement {
    sid    = "AllowStatement3"
    effect = "Allow"

    actions = [
      "s3:*"
    ]

    resources = [
      "arn:aws:s3:::sme-aoma-delivery-prod-rds-backups/*"
    ]
  }

  statement {
    sid    = "AllowStatement4"
    effect = "Allow"

    actions = [
      "kinesis:PutRecord"
    ]

    resources = [
      "arn:aws:kinesis:eu-central-1:023180329437:stream/EmailStream"
    ]
  }
}

data "aws_iam_policy_document" "RDSAdminPolicyForTerraform" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  #checkov:skip=CKV_AWS_109: Ensure IAM policies does not allow permissions management / resource exposure without constraints
  statement {
    sid    = "RDSActions"
    effect = "Allow"

    actions = [
      "rds:StartDBInstance",
      "rds:StopDBInstance",
      "rds:RebootDBInstance",
      "rds:CreateDBSnapshot",
      "rds:CopyDBSnapshot",
      "rds:ModifyDBSnapshotAttribute",
      "rds:DeleteDBSnapshot",
      "rds:CreateEventSubscription",
      "rds:ModifyEventSubscription",
      "rds:DeleteEventSubscription",
      "rds:ApplyPendingMaintenanceAction",
      "rds:AddTagsToResource"
    ]

    resources = ["*"]
  }

  statement {
    sid    = "RDSSnapshotExport"
    effect = "Allow"

    actions = [
      "iam:PassRole"
    ]

    resources = [
      "arn:aws:iam::023180329437:role/RDSAdmin"
    ]

    condition {
      test     = "StringEquals"
      variable = "iam:PassedToService"

      values = [
        "rds.amazonaws.com"
      ]
    }
  }

  statement {
    sid    = "RDSS3Export"
    effect = "Allow"

    actions = [
      "s3:PutObject"
    ]

    resources = [
      "arn:aws:s3:::sme-aoma-delivery-prod-rds-backups/*"
    ]
  }
}

data "aws_iam_policy_document" "DEVADMIN-POLICY" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  #checkov:skip=CKV_AWS_109: Ensure IAM policies does not allow permissions management / resource exposure without constraints
  #checkov:skip=CKV_AWS_108: Ensure IAM policies does not allow data exfiltration
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "s3:List*",
      "s3:Describe*",
      "s3:Get*",
      "s3:AbortMultipartUpload",
      "s3:Create*",
      "s3:Delete*",
      "s3:InitiateReplication",
      "s3:PauseReplication",
      "s3:Put*",
      "s3:Replicate*",
      "s3:RestoreObject",
      "s3:SubmitMultiRegionAccessPointRoutes",
      "s3:Update*",
      "s3:AssociateAccessGrantsIdentityCenter",
      "s3:BypassGovernanceRetention",
      "s3:DissociateAccessGrantsIdentityCenter",
      "s3:ObjectOwnerOverrideToBucketOwner",
      "s3:TagResource",
      "s3:UntagResource",
      "secretsmanager:BatchGetSecretValue",
      "secretsmanager:List*",
      "secretsmanager:DescribeSecret",
      "secretsmanager:Get*",
      "secretsmanager:CancelRotateSecret",
      "secretsmanager:Delete*",
      "secretsmanager:Put*",
      "secretsmanager:RemoveRegionsFromReplication",
      "secretsmanager:ReplicateSecretToRegions",
      "secretsmanager:RestoreSecret",
      "secretsmanager:RotateSecret",
      "secretsmanager:StopReplicationToReplica",
      "secretsmanager:Update*",
      "secretsmanager:ValidateResourcePolicy",
      "secretsmanager:TagResource",
      "secretsmanager:UntagResource",
      "ses:List*",
      "ses:Describe*",
      "ses:Get*",
      "ses:CloneReceiptRuleSet",
      "ses:Create*",
      "ses:Delete*",
      "ses:Put*",
      "ses:ReorderReceiptRuleSet",
      "ses:Send*",
      "ses:Set*",
      "ses:TestRenderTemplate",
      "ses:Update*",
      "ses:Verify*",
      "sns:List*",
      "sns:CheckIfPhoneNumberIsOptedOut",
      "sns:Get*",
      "sns:ConfirmSubscription",
      "sns:Create*",
      "sns:Delete*",
      "sns:OptInPhoneNumber",
      "sns:Publish",
      "sns:PutDataProtectionPolicy",
      "sns:Set*",
      "sns:Subscribe",
      "sns:Unsubscribe",
      "sns:VerifySMSSandboxPhoneNumber",
      "sns:AddPermission",
      "sns:RemovePermission",
      "sns:TagResource",
      "sns:UntagResource",
      "sqs:Get*",
      "sqs:List*",
      "sqs:ReceiveMessage",
      "sqs:CancelMessageMoveTask",
      "sqs:ChangeMessageVisibility",
      "sqs:CreateQueue",
      "sqs:Delete*",
      "sqs:PurgeQueue",
      "sqs:SendMessage",
      "sqs:SetQueueAttributes",
      "sqs:StartMessageMoveTask",
      "sqs:AddPermission",
      "sqs:RemovePermission",
      "sqs:TagQueue",
      "sqs:UntagQueue",
      "ssm:Describe*",
      "ssm:Get*",
      "ssm:List*",
      "ssm:ExecuteAPI",
      "ssm:Put*",
      "ssm:AssociateOpsItemRelatedItem",
      "ssm:Cancel*",
      "ssm:Create*",
      "ssm:Delete*",
      "ssm:Deregister*",
      "ssm:DisassociateOpsItemRelatedItem",
      "ssm:LabelParameterVersion",
      "ssm:Register*",
      "ssm:ResetServiceSetting",
      "ssm:ResumeSession",
      "ssm:Send*",
      "ssm:Start*",
      "ssm:StopAutomationExecution",
      "ssm:TerminateSession",
      "ssm:UnlabelParameterVersion",
      "ssm:Update*",
      "ssm:ModifyDocumentPermission",
      "ssm:AddTagsToResource",
      "ssm:RemoveTagsFromResource",
      "support:Describe*",
      "support:GetInteraction",
      "support:List*",
      "support:SearchForCases",
      "support:Add*",
      "support:CreateCase",
      "support:Initiate*",
      "support:PutCaseAttributes",
      "support:RateCaseCommunication",
      "support:RefreshTrustedAdvisorCheck",
      "support:Resolve*",
      "support:StartInteraction",
      "support:Update*",
      "tax:GetTaxInheritance",
      "tax:GetTaxRegistrationDocument",
      "tax:ListTaxRegistrations",
      "waf-regional:List*",
      "waf-regional:Get*",
      "waf-regional:AssociateWebACL",
      "waf-regional:Create*",
      "waf-regional:Delete*",
      "waf-regional:DisassociateWebACL",
      "waf-regional:Put*",
      "waf-regional:Update*",
      "waf-regional:TagResource",
      "waf-regional:UntagResource",
      "waf:List*",
      "waf:Get*",
      "waf:AssociateWebACL",
      "waf:Create*",
      "waf:Delete*",
      "waf:DisassociateWebACL",
      "waf:Put*",
      "waf:Update*",
      "waf:TagResource",
      "waf:UntagResource",
      "wafv2:List*",
      "wafv2:CheckCapacity",
      "wafv2:Describe*",
      "wafv2:GenerateMobileSdkReleaseUrl",
      "wafv2:Get*",
      "wafv2:AssociateWebACL",
      "wafv2:Create*",
      "wafv2:Delete*",
      "wafv2:Disassociate*",
      "wafv2:Put*",
      "wafv2:Update*",
      "wafv2:TagResource",
      "wafv2:UntagResource"
    ]
  }
}

data "aws_iam_policy_document" "DEVADMIN-POLICY-2" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  #checkov:skip=CKV_AWS_107: Ensure IAM policies does not allow credentials exposure
  #checkov:skip=CKV_AWS_109: Ensure IAM policies does not allow permissions management / resource exposure without constraints
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "ce:DescribeNotificationSubscription",
      "ce:DescribeReport",
      "ce:GetAnomalies",
      "ce:GetAnomalyMonitors",
      "ce:GetAnomalySubscriptions",
      "ce:GetCostAndUsage",
      "ce:GetCostAndUsageWithResources",
      "ce:GetCostCategories",
      "ce:GetCostForecast",
      "ce:GetDimensionValues",
      "ce:GetPreferences",
      "ce:GetReservationCoverage",
      "ce:GetReservationPurchaseRecommendation",
      "ce:GetReservationUtilization",
      "ce:GetRightsizingRecommendation",
      "ce:GetSavingsPlansCoverage",
      "ce:GetSavingsPlansPurchaseRecommendation",
      "ce:GetSavingsPlansUtilization",
      "ce:GetSavingsPlansUtilizationDetails",
      "ce:GetTags",
      "ce:GetUsageForecast",
      "ce:ListCostAllocationTags",
      "ce:ListSavingsPlansPurchaseRecommendationGeneration",
      "cloudformation:List*",
      "cloudformation:BatchDescribeTypeConfigurations",
      "cloudformation:Describe*",
      "cloudformation:Detect*",
      "cloudformation:EstimateTemplateCost",
      "cloudformation:Get*",
      "cloudformation:ValidateTemplate",
      "cloudformation:Activate*",
      "cloudformation:CancelUpdateStack",
      "cloudformation:ContinueUpdateRollback",
      "cloudformation:Create*",
      "cloudformation:Deactivate*",
      "cloudformation:Delete*",
      "cloudformation:DeregisterType",
      "cloudformation:Execute*",
      "cloudformation:ImportStacksToStackSet",
      "cloudformation:PublishType",
      "cloudformation:RecordHandlerProgress",
      "cloudformation:Register*",
      "cloudformation:RollbackStack",
      "cloudformation:Set*",
      "cloudformation:SignalResource",
      "cloudformation:StartResourceScan",
      "cloudformation:StopStackSetOperation",
      "cloudformation:TestType",
      "cloudformation:Update*",
      "cloudformation:TagResource",
      "cloudformation:UntagResource",
      "cloudwatch:List*",
      "cloudwatch:Batch*",
      "cloudwatch:Describe*",
      "cloudwatch:Generate*",
      "cloudwatch:Get*",
      "cloudwatch:CreateServiceLevelObjective",
      "cloudwatch:Delete*",
      "cloudwatch:Disable*",
      "cloudwatch:Enable*",
      "cloudwatch:Link",
      "cloudwatch:Put*",
      "cloudwatch:SetAlarmState",
      "cloudwatch:StartMetricStreams",
      "cloudwatch:StopMetricStreams",
      "cloudwatch:UpdateServiceLevelObjective",
      "cloudwatch:TagResource",
      "cloudwatch:UntagResource",
      "consolidatedbilling:GetAccountBillingRole",
      "consolidatedbilling:ListLinkedAccounts",
      "cur:GetClassicReport",
      "cur:GetClassicReportPreferences",
      "cur:GetUsageReport",
      "cur:ValidateReportDestination",
      "dynamodb:List*",
      "dynamodb:Batch*",
      "dynamodb:ConditionCheckItem",
      "dynamodb:Describe*",
      "dynamodb:Get*",
      "dynamodb:PartiQL*",
      "dynamodb:Query",
      "dynamodb:Scan",
      "dynamodb:Create*",
      "dynamodb:Delete*",
      "dynamodb:DisableKinesisStreamingDestination",
      "dynamodb:EnableKinesisStreamingDestination",
      "dynamodb:ExportTableToPointInTime",
      "dynamodb:ImportTable",
      "dynamodb:PurchaseReservedCapacityOfferings",
      "dynamodb:Put*",
      "dynamodb:Restore*",
      "dynamodb:StartAwsBackupJob",
      "dynamodb:Update*",
      "dynamodb:TagResource",
      "dynamodb:UntagResource",
      "ec2:Describe*",
      "ec2:Get*",
      "ec2:List*",
      "ec2:Search*",
      "ec2:Export*",
      "ec2:Accept*",
      "ec2:AdvertiseByoipCidr",
      "ec2:Allocate*",
      "ec2:ApplySecurityGroupsToClientVpnTargetNetwork",
      "ec2:Assign*",
      "ec2:Associate*",
      "ec2:Attach*",
      "ec2:Authorize*",
      "ec2:BundleInstance",
      "ec2:Cancel*",
      "ec2:ConfirmProductInstance",
      "ec2:Copy*",
      "ec2:Create*",
      "ec2:Delete*",
      "ec2:Deprovision*",
      "ec2:Deregister*",
      "ec2:Detach*",
      "ec2:Disable*",
      "ec2:Disassociate*",
      "ec2:Enable*",
      "ec2:Import*",
      "ec2:InjectApiError",
      "ec2:LockSnapshot",
      "ec2:Modify*",
      "ec2:MonitorInstances",
      "ec2:Move*",
      "ec2:PauseVolumeIO",
      "ec2:Provision*",
      "ec2:Purchase*",
      "ec2:RebootInstances",
      "ec2:Register*",
      "ec2:Reject*",
      "ec2:Release*",
      "ec2:Replace*",
      "ec2:ReportInstanceStatus",
      "ec2:Request*",
      "ec2:Reset*",
      "ec2:Restore*",
      "ec2:Revoke*",
      "ec2:Run*",
      "ec2:Send*",
      "ec2:Start*",
      "ec2:StopInstances",
      "ec2:Terminate*",
      "ec2:Unassign*",
      "ec2:UnlockSnapshot",
      "ec2:UnmonitorInstances",
      "ec2:Update*",
      "ec2:WithdrawByoipCidr",
      "ec2:PutResourcePolicy"
    ]
  }
}

data "aws_iam_policy_document" "DEVADMIN-POLICY-3" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  #checkov:skip=CKV_AWS_107: Ensure IAM policies does not allow credentials exposure
  #checkov:skip=CKV_AWS_109: Ensure IAM policies does not allow permissions management / resource exposure without constraints
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "account:GetAccountInformation",
      "apigateway:GET",
      "apigateway:DELETE",
      "apigateway:PATCH",
      "apigateway:POST",
      "apigateway:PUT",
      "apigateway:AddCertificateToDomain",
      "apigateway:CreateAccessAssociation",
      "apigateway:RejectAccessAssociation",
      "apigateway:RemoveCertificateFromDomain",
      "apigateway:SetWebACL",
      "apigateway:Update*",
      "athena:List*",
      "athena:Batch*",
      "athena:Get*",
      "athena:Cancel*",
      "athena:Create*",
      "athena:Delete*",
      "athena:ExportNotebook",
      "athena:ImportNotebook",
      "athena:PutCapacityAssignmentConfiguration",
      "athena:RunQuery",
      "athena:Start*",
      "athena:Stop*",
      "athena:TerminateSession",
      "athena:Update*",
      "athena:TagResource",
      "athena:UntagResource",
      "billing:GetBillingData",
      "billing:GetBillingDetails",
      "billing:GetBillingNotifications",
      "billing:GetBillingPreferences",
      "billing:GetContractInformation",
      "billing:GetCredits",
      "billing:GetIAMAccessPreference",
      "billing:GetSellerOfRecord",
      "billing:ListBillingViews",
      "ecr:Describe*",
      "ecr:List*",
      "ecr:Batch*",
      "ecr:Get*",
      "ecr:ValidatePullThroughCacheRule",
      "ecr:CompleteLayerUpload",
      "ecr:Create*",
      "ecr:Delete*",
      "ecr:DeregisterPullTimeUpdateExclusion",
      "ecr:InitiateLayerUpload",
      "ecr:Put*",
      "ecr:RegisterPullTimeUpdateExclusion",
      "ecr:ReplicateImage",
      "ecr:Start*",
      "ecr:Update*",
      "ecr:UploadLayerPart",
      "ecr:SetRepositoryPolicy",
      "ecr:TagResource",
      "ecr:UntagResource",
      "ecs:List*",
      "ecs:Describe*",
      "ecs:GetTaskProtection",
      "ecs:Create*",
      "ecs:Delete*",
      "ecs:Deregister*",
      "ecs:DiscoverPollEndpoint",
      "ecs:ExecuteCommand",
      "ecs:Poll",
      "ecs:Put*",
      "ecs:Register*",
      "ecs:RunTask",
      "ecs:Start*",
      "ecs:Stop*",
      "ecs:Submit*",
      "ecs:Update*",
      "ecs:TagResource",
      "ecs:UntagResource",
      "eks:List*",
      "eks:AccessKubernetesApi",
      "eks:Describe*",
      "eks:Associate*",
      "eks:Create*",
      "eks:Delete*",
      "eks:DeregisterCluster",
      "eks:Disassociate*",
      "eks:MutateViaKubernetesApi",
      "eks:RegisterCluster",
      "eks:StartInsightsRefresh",
      "eks:Update*",
      "eks:TagResource",
      "eks:UntagResource",
      "elasticloadbalancing:SetWebACL",
      "es:Describe*",
      "es:Get*",
      "es:List*",
      "es:ES*",
      "es:Accept*",
      "es:Add*",
      "es:Associate*",
      "es:AuthorizeVpcEndpointAccess",
      "es:Cancel*",
      "es:Create*",
      "es:Delete*",
      "es:dissociate*",
      "es:Purchase*",
      "es:Reject*",
      "es:RevokeVpcEndpointAccess",
      "es:Start*",
      "es:Update*",
      "es:Upgrade*",
      "es:AddTags",
      "es:RemoveTags",
      "events:List*",
      "events:Describe*",
      "events:TestEventPattern",
      "events:ActivateEventSource",
      "events:AllowVendedLogDeliveryForResource",
      "events:CancelReplay",
      "events:Create*",
      "events:DeactivateEventSource",
      "events:DeauthorizeConnection",
      "events:Delete*",
      "events:DisableRule",
      "events:EnableRule",
      "events:InvokeApiDestination",
      "events:Put*",
      "events:Remove*",
      "events:RetrieveConnectionCredentials",
      "events:StartReplay",
      "events:Update*",
      "events:TagResource",
      "events:UntagResource",
      "firehose:List*",
      "firehose:DescribeDeliveryStream",
      "firehose:CreateDeliveryStream",
      "firehose:DeleteDeliveryStream",
      "firehose:Put*",
      "firehose:StartDeliveryStreamEncryption",
      "firehose:StopDeliveryStreamEncryption",
      "firehose:UpdateDestination",
      "firehose:TagDeliveryStream",
      "firehose:UntagDeliveryStream",
      "freetier:GetFreeTierAlertPreference",
      "freetier:GetFreeTierUsage",
      "iam:PassRole",
      "invoicing:GetInvoiceEmailDeliveryPreferences",
      "invoicing:GetInvoicePDF",
      "invoicing:ListInvoiceSummaries",
      "sts:Get*",
      "sts:Assume*",
      "sts:DecodeAuthorizationMessage",
      "sts:Set*",
      "sts:Tag*"
    ]
  }
}

data "aws_iam_policy_document" "DEVADMIN-POLICY-4" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  #checkov:skip=CKV_AWS_107: Ensure IAM policies does not allow credentials exposure
  #checkov:skip=CKV_AWS_110: Ensure IAM policies does not allow privilege escalation
  #checkov:skip=CKV_AWS_109: Ensure IAM policies does not allow permissions management / resource exposure without constraints
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "inspector2:Get*",
      "inspector2:List*",
      "inspector2:Batch*",
      "inspector2:DescribeOrganizationConfiguration",
      "inspector2:SearchVulnerabilities",
      "inspector2:AssociateMember",
      "inspector2:Cancel*",
      "inspector2:Create*",
      "inspector2:Delete*",
      "inspector2:Disable",
      "inspector2:DisableDelegatedAdminAccount",
      "inspector2:DisassociateMember",
      "inspector2:Enable",
      "inspector2:EnableDelegatedAdminAccount",
      "inspector2:ResetEncryptionKey",
      "inspector2:Send*",
      "inspector2:Start*",
      "inspector2:StopCisSession",
      "inspector2:Update*",
      "inspector2:TagResource",
      "inspector2:UntagResource",
      "kinesis:List*",
      "kinesis:Describe*",
      "kinesis:Get*",
      "kinesis:SubscribeToShard",
      "kinesis:CreateStream",
      "kinesis:DecreaseStreamRetentionPeriod",
      "kinesis:Delete*",
      "kinesis:DeregisterStreamConsumer",
      "kinesis:DisableEnhancedMonitoring",
      "kinesis:EnableEnhancedMonitoring",
      "kinesis:IncreaseStreamRetentionPeriod",
      "kinesis:InjectApiError",
      "kinesis:MergeShards",
      "kinesis:Put*",
      "kinesis:RegisterStreamConsumer",
      "kinesis:SplitShard",
      "kinesis:StartStreamEncryption",
      "kinesis:StopStreamEncryption",
      "kinesis:Update*",
      "kinesis:AddTagsToStream",
      "kinesis:RemoveTagsFromStream",
      "kinesis:TagResource",
      "kinesis:UntagResource",
      "kms:List*",
      "kms:Describe*",
      "kms:Get*",
      "kms:CancelKeyDeletion",
      "kms:ConnectCustomKeyStore",
      "kms:Create*",
      "kms:Decrypt",
      "kms:Delete*",
      "kms:DeriveSharedSecret",
      "kms:DisableKey",
      "kms:DisableKeyRotation",
      "kms:DisconnectCustomKeyStore",
      "kms:EnableKey",
      "kms:EnableKeyRotation",
      "kms:Encrypt",
      "kms:Generate*",
      "kms:ImportKeyMaterial",
      "kms:ReEncrypt*",
      "kms:ReplicateKey",
      "kms:RotateKeyOnDemand",
      "kms:ScheduleKeyDeletion",
      "kms:Sign",
      "kms:SynchronizeMultiRegionKey",
      "kms:Update*",
      "kms:Verify",
      "kms:VerifyMac",
      "kms:PutKeyPolicy",
      "kms:RetireGrant",
      "kms:RevokeGrant",
      "kms:TagResource",
      "kms:UntagResource",
      "lambda:List*",
      "lambda:Get*",
      "lambda:CheckpointDurableExecution",
      "lambda:Create*",
      "lambda:Delete*",
      "lambda:Invoke*",
      "lambda:PassCapacityProvider",
      "lambda:Publish*",
      "lambda:Put*",
      "lambda:Send*",
      "lambda:StopDurableExecution",
      "lambda:Update*",
      "lambda:Add*",
      "lambda:DisableReplication",
      "lambda:EnableReplication",
      "lambda:Remove*",
      "lambda:TagResource",
      "lambda:UntagResource",
      "payments:GetPaymentInstrument",
      "payments:GetPaymentStatus",
      "payments:ListPaymentMethods",
      "payments:ListPaymentPreferences",
      "redshift:Describe*",
      "redshift:List*",
      "redshift:View*",
      "redshift:FetchResults",
      "redshift:Get*",
      "redshift:AcceptReservedNodeExchange",
      "redshift:AddPartner",
      "redshift:AssociateDataShareConsumer",
      "redshift:Authorize*",
      "redshift:Batch*",
      "redshift:Cancel*",
      "redshift:CopyClusterSnapshot",
      "redshift:Create*",
      "redshift:Delete*",
      "redshift:DeregisterNamespace",
      "redshift:Disable*",
      "redshift:DisassociateDataShareConsumer",
      "redshift:Enable*",
      "redshift:ExecuteQuery",
      "redshift:FailoverPrimaryCompute",
      "redshift:Modify*",
      "redshift:PauseCluster",
      "redshift:PurchaseReservedNodeOffering",
      "redshift:RebootCluster",
      "redshift:RegisterNamespace",
      "redshift:ResetClusterParameterGroup",
      "redshift:ResizeCluster",
      "redshift:Restore*",
      "redshift:ResumeCluster",
      "redshift:RotateEncryptionKey",
      "redshift:UpdatePartnerStatus",
      "redshift:DeauthorizeDataShare",
      "redshift:JoinGroup",
      "redshift:PutResourcePolicy",
      "redshift:RejectDataShare",
      "redshift:Revoke*",
      "redshift:CreateTags",
      "redshift:DeleteTags",
      "redshift-data:List*",
      "redshift-data:Describe*",
      "redshift-data:Get*",
      "redshift-data:BatchExecuteStatement",
      "redshift-data:CancelStatement",
      "redshift-data:ExecuteStatement",
      "route53:Get*",
      "route53:List*",
      "route53:TestDNSAnswer",
      "route53:ActivateKeySigningKey",
      "route53:AssociateVPCWithHostedZone",
      "route53:Change*",
      "route53:Create*",
      "route53:DeactivateKeySigningKey",
      "route53:Delete*",
      "route53:DisableHostedZoneDNSSEC",
      "route53:DisassociateVPCFromHostedZone",
      "route53:EnableHostedZoneDNSSEC",
      "route53:Update*",
    ]
  }
}

data "aws_iam_policy_document" "delp-rds-cmk" {
  statement {
    sid    = "VisualEditor3"
    effect = "Allow"
    resources = [
      "arn:aws:kms:eu-central-1:023180329437:key/7fcf7089-a08e-4de9-8177-1a3026ed3a1c",
      "arn:aws:kms:eu-central-1:023180329437:key/c43c70ed-018c-40b0-b70b-5d7fd4a5f58d"
    ]

    actions = [
      "kms:Encrypt",
      "kms:Decrypt",
      "kms:ReEncrypt*",
      "kms:GenerateDataKey*",
      "kms:DescribeKey"
    ]
  }

  statement {
    sid    = "VisualEditor9"
    effect = "Allow"

    resources = ["arn:aws:iam::504436705349:role/MSK-role"]

    actions = [
      "sts:AssumeRole"
    ]
  }
}

data "aws_iam_policy_document" "prod-ampsv-s3-policy" {
  statement {
    sid    = ""
    effect = "Allow"

    resources = [
      "arn:aws:s3:::amp-asset-repo-*-p",
      "arn:aws:s3:::amp-asset-repo-*-p/*",
    ]

    actions = [
      "s3:Get*",
      "s3:List*",
    ]
  }
}

data "aws_iam_policy_document" "KubeCostFederatedRoleIAMPolicy" {
  #checkov:skip=CKV_AWS_107: Ensure IAM policies does not allow credentials exposure
  statement {
    sid    = "VisualEditor0"
    effect = "Allow"
    actions = [
      "s3:ListBucket",
      "s3:GetBucketLocation"
    ]
    resources = ["arn:aws:s3:::sme-core-cloud-shared-kubecost"]
  }

  statement {
    sid    = "VisualEditor1"
    effect = "Allow"
    actions = [
      "s3:PutObject",
      "s3:GetObject",
      "s3:ListBucketMultipartUploads",
      "s3:AbortMultipartUpload",
      "s3:ListBucket",
      "s3:DeleteObject",
      "s3:ListMultipartUploadParts"
    ]
    resources = [
      "arn:aws:s3:::sme-core-cloud-shared-kubecost",
      "arn:aws:s3:::sme-core-cloud-shared-kubecost/*"
    ]
  }

  statement {
    sid    = "VisualEditor2"
    effect = "Allow"
    actions = [
      "ec2:Get*",
      "ec2:Describe*"
    ]
    resources = ["*"]
  }
}


data "aws_iam_policy_document" "IAM-Policy" {
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "iam:GetPolicy",
      "iam:GetPolicyVersion",
      "iam:GetRole",
      "iam:GetRolePolicy",
      "iam:ListAttachedRolePolicies",
      "iam:ListRolePolicies",
      "iam:ListRoles",
      "iam:GetContextKeysForPrincipalPolicy",
      "iam:SimulatePrincipalPolicy",
      "iam:GetContextKeysForCustomPolicy",
      "iam:SimulateCustomPolicy",
    ]
  }
}

data "aws_iam_policy_document" "github-actions-lambda-policy" {
  version = "2012-10-17"

  statement {
    sid    = "LambdaBasicOperations"
    effect = "Allow"
    actions = [
      "lambda:UpdateFunctionConfiguration",
      "lambda:UpdateFunctionCode",
      "lambda:UpdateEventSourceMapping",
      "lambda:UpdateAlias",
      "lambda:RemovePermission",
      "lambda:PublishVersion",
      "lambda:ListVersionsByFunction",
      "lambda:ListTags",
      "lambda:ListEventSourceMappings",
      "lambda:GetFunctionCodeSigningConfig",
      "lambda:GetFunction",
      "lambda:DeleteFunction",
      "lambda:DeleteEventSourceMapping",
      "lambda:DeleteAlias",
      "lambda:CreateFunction",
      "lambda:CreateEventSourceMapping",
      "lambda:CreateAlias",
      "lambda:AddPermission",
      "lambda:GetPolicy",
      "lambda:PublishLayerVersion",
      "lambda:GetLayerVersion",
      "lambda:ListLayerVersions",
      "lambda:GetLayerVersionPolicy",
      "lambda:DeleteLayerVersion"
    ]
    resources = [
      "arn:aws:lambda:eu-central-1:${var.account_id}:layer:delivery-*",
      "arn:aws:lambda:eu-central-1:${var.account_id}:function:delivery-*",
      "arn:aws:lambda:eu-central-1:${var.account_id}:event-source-mapping:*",
    ]
  }

  statement {
    sid    = "APIGatewayPermissions"
    effect = "Allow"
    actions = [
      "apigateway:GET",
      "apigateway:POST",
      "apigateway:PUT",
      "apigateway:PATCH",
      "apigateway:GetRestApi",
      "apigateway:GetRestApis",
      "apigateway:CreateResource",
      "apigateway:GetResource",
      "apigateway:UpdateResource",
      "apigateway:DeleteResource",
      "apigateway:PutMethod",
      "apigateway:GetMethod",
      "apigateway:UpdateMethod",
      "apigateway:DeleteMethod",
      "apigateway:PutIntegration",
      "apigateway:GetIntegration",
      "apigateway:UpdateIntegration",
      "apigateway:DeleteIntegration",
      "apigateway:CreateDeployment",
      "apigateway:GetDeployment",
      "apigateway:UpdateDeployment",
      "apigateway:DeleteDeployment",
      "apigateway:GetStage",
      "apigateway:UpdateStage"
    ]
    resources = [
      "arn:aws:apigateway:eu-central-1::/restapis/*",
      "arn:aws:apigateway:eu-central-1::/restapis"
    ]
  }

  statement {
    sid    = ""
    effect = "Allow"
    actions = [
      "apigateway:*"
    ]
    resources = [
      "arn:aws:apigateway:eu-central-1:023180329437:/domainnames/*"
    ]
  }

  statement {
    sid     = "LambdaIAMRoleOperations"
    effect  = "Allow"
    actions = ["iam:PassRole"]
    resources = [
      "arn:aws:iam::${var.account_id}:role/sme-pitch-user-role",
      "arn:aws:iam::${var.account_id}:role/delivery-*",
      "arn:aws:iam::${var.account_id}:role/delivery_*",
      "arn:aws:iam::${var.account_id}:role/universal-email-notifier-role",
    ]
    condition {
      test     = "StringLike"
      variable = "iam:PassedToService"
      values   = ["lambda.amazonaws.com"]
    }
  }

  statement {
    sid    = "S3BucketNotifications"
    effect = "Allow"
    actions = [
      "s3:PutBucketNotification",
      "s3:GetBucketNotification"
    ]
    resources = ["arn:aws:s3:::*"]
  }

  statement {
    sid    = "CloudWatchLogs"
    effect = "Allow"
    actions = [
      "logs:PutLogEvents",
      "logs:CreateLogStream",
      "logs:CreateLogGroup"
    ]
    resources = ["arn:aws:logs:eu-central-1:${var.account_id}:log-group:/aws/lambda/*"]
  }

  statement {
    sid       = "GetEventSourceMapping"
    effect    = "Allow"
    actions   = ["lambda:GetEventSourceMapping"]
    resources = ["*"]
  }

  statement {
    sid       = "EventBridgeListTags"
    effect    = "Allow"
    actions   = ["events:ListTagsForResource"]
    resources = ["arn:aws:events:eu-central-1:${var.account_id}:rule/*"]
  }
}

data "aws_iam_policy_document" "KarpenterControllerPolicy-dsrv-prod-eks-cluster" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  #checkov:skip=CKV_AWS_109: Ensure IAM policies does not allow permissions management / resource exposure without constraints
  statement {
    sid    = "AllowScopedEC2InstanceAccessActions"
    effect = "Allow"
    resources = [
      "arn:aws:ec2:eu-central-1::image/*",
      "arn:aws:ec2:eu-central-1::snapshot/*",
      "arn:aws:ec2:eu-central-1:*:security-group/*",
      "arn:aws:ec2:eu-central-1:*:subnet/*",
    ]
    actions = [
      "ec2:RunInstances",
      "ec2:CreateFleet",
    ]
  }

  statement {
    sid    = "AllowScopedEC2LaunchTemplateAccessActions"
    effect = "Allow"
    resources = [
      "arn:aws:ec2:eu-central-1:*:launch-template/*"
    ]
    actions = [
      "ec2:RunInstances",
      "ec2:CreateFleet",
    ]

    condition {
      test     = "StringEquals"
      variable = "aws:ResourceTag/kubernetes.io/cluster/dsrv-prod-eks-cluster"
      values   = ["owned"]
    }

    condition {
      test     = "StringLike"
      variable = "aws:ResourceTag/karpenter.sh/nodepool"
      values   = ["*"]
    }
  }

  statement {
    sid    = "AllowScopedEC2InstanceActionsWithTags"
    effect = "Allow"
    resources = [
      "arn:aws:ec2:eu-central-1:*:fleet/*",
      "arn:aws:ec2:eu-central-1:*:instance/*",
      "arn:aws:ec2:eu-central-1:*:volume/*",
      "arn:aws:ec2:eu-central-1:*:network-interface/*",
      "arn:aws:ec2:eu-central-1:*:launch-template/*",
      "arn:aws:ec2:eu-central-1:*:spot-instances-request/*",
    ]
    actions = [
      "ec2:RunInstances",
      "ec2:CreateFleet",
      "ec2:CreateLaunchTemplate",
    ]

    condition {
      test     = "StringEquals"
      variable = "aws:RequestTag/kubernetes.io/cluster/dsrv-prod-eks-cluster"
      values   = ["owned"]
    }

    condition {
      test     = "StringLike"
      variable = "aws:RequestTag/karpenter.sh/nodepool"
      values   = ["*"]
    }
  }

  statement {
    sid    = "AllowScopedResourceCreationTagging"
    effect = "Allow"
    resources = [
      "arn:aws:ec2:eu-central-1:*:fleet/*",
      "arn:aws:ec2:eu-central-1:*:instance/*",
      "arn:aws:ec2:eu-central-1:*:volume/*",
      "arn:aws:ec2:eu-central-1:*:network-interface/*",
      "arn:aws:ec2:eu-central-1:*:launch-template/*",
      "arn:aws:ec2:eu-central-1:*:spot-instances-request/*",
    ]
    actions = [
      "ec2:CreateTags"
    ]

    condition {
      test     = "StringEquals"
      variable = "aws:RequestTag/kubernetes.io/cluster/dsrv-prod-eks-cluster"
      values   = ["owned"]
    }

    condition {
      test     = "StringEquals"
      variable = "ec2:CreateAction"
      values = [
        "RunInstances",
        "CreateFleet",
        "CreateLaunchTemplate",
      ]
    }

    condition {
      test     = "StringLike"
      variable = "aws:RequestTag/karpenter.sh/nodepool"
      values   = ["*"]
    }
  }

  statement {
    sid    = "AllowScopedResourceTagging"
    effect = "Allow"
    resources = [
      "arn:aws:ec2:eu-central-1:*:instance/*"
    ]
    actions = [
      "ec2:CreateTags"
    ]

    condition {
      test     = "ForAllValues:StringEquals"
      variable = "aws:TagKeys"
      values = [
        "karpenter.sh/nodeclaim",
        "Name",
      ]
    }

    condition {
      test     = "StringEquals"
      variable = "aws:ResourceTag/kubernetes.io/cluster/dsrv-prod-eks-cluster"
      values   = ["owned"]
    }

    condition {
      test     = "StringLike"
      variable = "aws:ResourceTag/karpenter.sh/nodepool"
      values   = ["*"]
    }
  }

  statement {
    sid    = "AllowScopedDeletion"
    effect = "Allow"
    resources = [
      "arn:aws:ec2:eu-central-1:*:instance/*",
      "arn:aws:ec2:eu-central-1:*:launch-template/*",
    ]
    actions = [
      "ec2:TerminateInstances",
      "ec2:DeleteLaunchTemplate",
    ]

    condition {
      test     = "StringEquals"
      variable = "aws:ResourceTag/kubernetes.io/cluster/dsrv-prod-eks-cluster"
      values   = ["owned"]
    }

    condition {
      test     = "StringLike"
      variable = "aws:ResourceTag/karpenter.sh/nodepool"
      values   = ["*"]
    }
  }

  statement {
    sid    = "AllowRegionalReadActions"
    effect = "Allow"
    resources = [
      "*"
    ]
    actions = [
      "ec2:DescribeAvailabilityZones",
      "ec2:DescribeImages",
      "ec2:DescribeInstances",
      "ec2:DescribeInstanceTypeOfferings",
      "ec2:DescribeInstanceTypes",
      "ec2:DescribeLaunchTemplates",
      "ec2:DescribeSecurityGroups",
      "ec2:DescribeSpotPriceHistory",
      "ec2:DescribeSubnets",
    ]

    condition {
      test     = "StringEquals"
      variable = "aws:RequestedRegion"
      values   = ["eu-central-1"]
    }
  }

  statement {
    sid    = "AllowSSMReadActions"
    effect = "Allow"
    resources = [
      "arn:aws:ssm:eu-central-1::parameter/aws/service/*"
    ]
    actions = [
      "ssm:GetParameter"
    ]
  }

  statement {
    sid    = "AllowPricingReadActions"
    effect = "Allow"
    resources = [
      "*"
    ]
    actions = [
      "pricing:GetProducts"
    ]
  }

  statement {
    sid    = "AllowInterruptionQueueActions"
    effect = "Allow"
    resources = [
      "arn:aws:sqs:eu-central-1:023180329437:Karpenter-*"
    ]
    actions = [
      "sqs:DeleteMessage",
      "sqs:GetQueueUrl",
      "sqs:ReceiveMessage",
    ]
  }

  statement {
    sid    = "AllowPassingInstanceRole"
    effect = "Allow"
    resources = [
      "arn:aws:iam::023180329437:role/delp-EKS-worker-node-Role"
    ]
    actions = [
      "iam:PassRole"
    ]

    condition {
      test     = "StringEquals"
      variable = "iam:PassedToService"
      values   = ["ec2.amazonaws.com"]
    }
  }

  statement {
    sid    = "AllowScopedInstanceProfileCreationActions"
    effect = "Allow"
    resources = [
      "*"
    ]
    actions = [
      "iam:CreateInstanceProfile",
    ]

    condition {
      test     = "StringEquals"
      variable = "aws:RequestTag/kubernetes.io/cluster/dsrv-prod-eks-cluster"
      values   = ["owned"]
    }

    condition {
      test     = "StringEquals"
      variable = "aws:RequestTag/topology.kubernetes.io/region"
      values   = ["eu-central-1"]
    }

    condition {
      test     = "StringLike"
      variable = "aws:RequestTag/karpenter.k8s.aws/ec2nodeclass"
      values   = ["*"]
    }
  }

  statement {
    sid    = "AllowScopedInstanceProfileTagActions"
    effect = "Allow"
    resources = [
      "*"
    ]
    actions = [
      "iam:TagInstanceProfile",
    ]

    condition {
      test     = "StringEquals"
      variable = "aws:RequestTag/kubernetes.io/cluster/dsrv-prod-eks-cluster"
      values   = ["owned"]
    }

    condition {
      test     = "StringEquals"
      variable = "aws:RequestTag/topology.kubernetes.io/region"
      values   = ["eu-central-1"]
    }

    condition {
      test     = "StringEquals"
      variable = "aws:ResourceTag/kubernetes.io/cluster/dsrv-prod-eks-cluster"
      values   = ["owned"]
    }

    condition {
      test     = "StringEquals"
      variable = "aws:ResourceTag/topology.kubernetes.io/region"
      values   = ["eu-central-1"]
    }

    condition {
      test     = "StringLike"
      variable = "aws:RequestTag/karpenter.k8s.aws/ec2nodeclass"
      values   = ["*"]
    }

    condition {
      test     = "StringLike"
      variable = "aws:ResourceTag/karpenter.k8s.aws/ec2nodeclass"
      values   = ["*"]
    }
  }

  statement {
    sid    = "AllowScopedInstanceProfileActions"
    effect = "Allow"
    resources = [
      "*"
    ]
    actions = [
      "iam:AddRoleToInstanceProfile",
      "iam:RemoveRoleFromInstanceProfile",
      "iam:DeleteInstanceProfile",
    ]

    condition {
      test     = "StringEquals"
      variable = "aws:ResourceTag/kubernetes.io/cluster/dsrv-prod-eks-cluster"
      values   = ["owned"]
    }

    condition {
      test     = "StringEquals"
      variable = "aws:ResourceTag/topology.kubernetes.io/region"
      values   = ["eu-central-1"]
    }

    condition {
      test     = "StringLike"
      variable = "aws:ResourceTag/karpenter.k8s.aws/ec2nodeclass"
      values   = ["*"]
    }
  }

  statement {
    sid    = "AllowInstanceProfileReadActions"
    effect = "Allow"
    resources = [
      "*"
    ]
    actions = [
      "iam:GetInstanceProfile"
    ]
  }

  statement {
    sid    = "AllowAPIServerEndpointDiscovery"
    effect = "Allow"
    resources = [
      "arn:aws:eks:eu-central-1:023180329437:cluster/dsrv-prod-eks-cluster"
    ]
    actions = [
      "eks:DescribeCluster"
    ]
  }

  statement {
    sid    = ""
    effect = "Allow"
    resources = [
      "*"
    ]
    actions = [
      "kms:List*",
      "kms:Describe*",
      "kms:Get*",
      "kms:CancelKeyDeletion",
      "kms:ConnectCustomKeyStore",
      "kms:Create*",
      "kms:Decrypt",
      "kms:Delete*",
      "kms:DeriveSharedSecret",
      "kms:DisableKey",
      "kms:DisableKeyRotation",
      "kms:DisconnectCustomKeyStore",
      "kms:EnableKey",
      "kms:EnableKeyRotation",
      "kms:Encrypt",
      "kms:Generate*",
      "kms:ImportKeyMaterial",
      "kms:ReEncrypt*",
      "kms:ReplicateKey",
      "kms:RotateKeyOnDemand",
      "kms:ScheduleKeyDeletion",
      "kms:Sign",
      "kms:SynchronizeMultiRegionKey",
      "kms:Update*",
      "kms:Verify",
      "kms:VerifyMac",
      "kms:PutKeyPolicy",
      "kms:RetireGrant",
      "kms:RevokeGrant",
      "kms:TagResource",
      "kms:UntagResource"
    ]
  }

  statement {
    sid    = "AllowCreateSpotServiceLinkedRole"
    effect = "Allow"
    actions = [
      "iam:CreateServiceLinkedRole"
    ]
    resources = ["*"]

    condition {
      test     = "StringEquals"
      variable = "iam:AWSServiceName"
      values   = ["spot.amazonaws.com"]
    }
  }
}

data "aws_iam_policy_document" "SendRawEmail" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["*"]
    actions   = ["ses:SendRawEmail"]
  }
}

data "aws_iam_policy_document" "RDS-EC2" {
  #checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  #checkov:skip=CKV_AWS_110: Ensure IAM policies does not allow privilege escalation
  #checkov:skip=CKV_AWS_109: Ensure IAM policies does not allow permissions management / resource exposure without constraints
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "ec2:CreateNetworkInterface",
      "ec2:DescribeInstances",
      "ec2:DescribeNetworkInterfaces",
      "ec2:DeleteNetworkInterface",
      "sqs:*",
      "ec2:AttachNetworkInterface",
      "athena:UpdateWorkGroup",
      "athena:UpdateDataCatalog",
      "athena:StartQueryExecution",
      "athena:ListWorkGroups",
      "athena:ListQueryExecutions",
      "athena:ListNamedQueries",
      "athena:GetWorkGroup",
      "athena:GetTables",
      "athena:GetTable",
      "athena:GetQueryResultsStream",
      "athena:GetQueryResults",
      "athena:GetQueryExecutions",
      "athena:GetQueryExecution",
      "athena:GetNamespaces",
      "athena:GetNamespace",
      "athena:GetNamedQuery",
      "athena:GetExecutionEngines",
      "athena:GetExecutionEngine",
      "athena:GetDatabase",
      "athena:GetDataCatalog",
      "athena:GetCatalogs",
      "athena:CreateWorkGroup",
      "athena:CreateNamedQuery",
      "athena:CreateDataCatalog",
      "athena:BatchGetQueryExecution",
      "athena:BatchGetNamedQuery",
      "glue:*",
      "kms:Decrypt",
    ]
  }
}

data "aws_iam_policy_document" "AsperaV2DeliveryQ-sqs-policy" {
  statement {
    sid    = ""
    effect = "Allow"

    resources = [
      "arn:aws:sqs:eu-central-1:023180329437:AsperaV2DeliveryQueue",
      "arn:aws:sqs:eu-central-1:023180329437:AsperaV2DeliveryDLQ",
    ]

    actions = ["sqs:*"]
  }
}


data "aws_iam_policy_document" "delp-watermarking-role-policy" {

  statement {
    sid    = "SQSGetQueueUrl"
    effect = "Allow"

    resources = [
      "*"
    ]

    actions = [
      "sqs:GetQueueUrl"
    ]
  }

  statement {
    sid    = "SQSQueueAccess"
    effect = "Allow"

    resources = [
      "arn:aws:sqs:eu-central-1:023180329437:WatermarkDeliveryQueue",
      "arn:aws:sqs:eu-central-1:023180329437:WatermarkDeliveryQueue-DLQ"
    ]

    actions = [
      "sqs:ChangeMessageVisibility",
      "sqs:GetQueueAttributes",
      "sqs:ReceiveMessage",
      "sqs:DeleteMessage"
    ]
  }

  statement {
    sid    = "S3Access"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delp-watermarking",
      "arn:aws:s3:::sme-delp-watermarking/*",
      "arn:aws:s3:::sme-delivery-target",
      "arn:aws:s3:::sme-delivery-target/*",
      "arn:aws:s3:::sme-conversion-shelf",
      "arn:aws:s3:::sme-conversion-shelf/*"
    ]

    actions = [
      "s3:*",
    ]
  }

  statement {
    sid    = "KinesisPutRecord"
    effect = "Allow"

    resources = [
      "arn:aws:kinesis:eu-central-1:023180329437:stream/EmailStream",
      "arn:aws:kinesis:eu-central-1:023180329437:stream/StatusUpdateStream"
    ]

    actions = [
      "kinesis:PutRecord",
      "kinesis:PutRecords",
    ]
  }

  statement {
    sid    = "SMWatermarkingCredentials"
    effect = "Allow"

    resources = [
      "arn:aws:secretsmanager:eu-central-1:023180329437:secret:PROD/MsiOnDemandWatermarkingIamUserCredentials*",
      "arn:aws:secretsmanager:eu-central-1:023180329437:secret:PROD/Delivery/AMP-API*",
      "arn:aws:secretsmanager:eu-central-1:023180329437:secret:PROD/EOM*",
      "arn:aws:secretsmanager:eu-central-1:023180329437:secret:db/del/prod/delivery_watermarking_service*",
      "arn:aws:secretsmanager:eu-central-1:023180329437:secret:PROD/RabbitMQ*",
    ]

    actions = [
      "secretsmanager:GetSecretValue",
      "secretsmanager:DescribeSecret",
    ]
  }

  statement {
    sid    = "Kmsdecrypt1"
    effect = "Allow"

    resources = [
      "arn:aws:kms:eu-central-1:023180329437:key/7fcf7089-a08e-4de9-8177-1a3026ed3a1c"
    ]

    actions = [
      "kms:Decrypt",
      "kms:DescribeKey",
    ]
  }

  statement {
    sid    = "globaldsdassumerole"
    effect = "Allow"

    resources = ["arn:aws:iam::635220336377:role/globaldsp-sa-msk-delivery-role"]

    actions = [
      "sts:AssumeRole"
    ]
  }
}

data "aws_iam_policy_document" "delp-msi-ondemand-watermarking-user-policy" {

  statement {
    sid    = "SNSPublish"
    effect = "Allow"

    resources = [
      "arn:aws:sns:us-east-1:023180329437:delp-watermark-completion"
    ]

    actions = [
      "sns:Publish"
    ]
  }

  statement {
    sid    = "S3Access"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-delp-watermarking",
      "arn:aws:s3:::sme-delp-watermarking/*",
    ]

    actions = [
      "s3:ListBucket",
      "s3:GetObject",
      "s3:PutObject"
    ]
  }
}

data "aws_iam_policy_document" "sme-media-production-s3" {

  statement {
    sid    = "VisualEditor1"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-media-production/*",
      "arn:aws:s3:::sme-media-production*",
      "arn:aws:s3:::sme-amazon-lfv-dropoff",
      "arn:aws:s3:::sme-amazon-lfv-dropoff/*"

    ]

    actions = [
      "s3:PutObjectAcl",
      "s3:PutObject",
      "s3:PutBucketAcl",
      "s3:ListMultipartUploadParts",
      "s3:ListBucketMultipartUploads",
      "s3:ListBucket",
      "s3:ListAllMyBuckets",
      "s3:GetObject",
      "s3:DeleteObject",
      "s3:AbortMultipartUpload",
    ]
  }
}

data "aws_iam_policy_document" "aomadel-supplychain-s3-access-policy" {
  statement {
    sid    = "AllowListAllBuckets"
    effect = "Allow"

    resources = ["*"]

    actions = [
      "s3:ListAllMyBuckets"
    ]
  }

  statement {
    sid    = "AllowS3BucketAccess"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::dsrv-dsp-package-xml-prod",
      "arn:aws:s3:::dsrv-dsp-package-xml-prod/*"
    ]

    actions = [
      "s3:GetObject",
      "s3:GetObjectVersion",
      "s3:GetObjectAcl",
      "s3:ListBucket",
      "s3:GetBucketLocation"
    ]
  }
}

data "aws_iam_policy_document" "delivery-prod-s3-replicator" {
  statement {
    sid       = "VisualEditor0"
    effect    = "Allow"
    resources = ["*"]

    actions = [
      "s3:ListStorageLensConfigurations",
      "s3:ListAccessPointsForObjectLambda",
      "s3:GetAccessPoint",
      "s3:PutAccountPublicAccessBlock",
      "s3:GetAccountPublicAccessBlock",
      "s3:ListAllMyBuckets",
      "s3:ListAccessPoints",
      "s3:ListJobs",
      "s3:PutStorageLensConfiguration",
      "s3:CreateJob",
    ]
  }

  statement {
    sid    = "VisualEditor1"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-aoma-delivery-prod-us-east-1-logs",
      "arn:aws:s3:::sme-aoma-delivery-prod-us-east-1-logs/*",
      "arn:aws:s3:::sme-aoma-delivery-prod-eu-central-1-logs",
      "arn:aws:s3:::sme-aoma-delivery-prod-eu-central-1-logs/*",
      "arn:aws:s3:::sme-core-cloud-compliance-centralized-s3-use1-logs",
      "arn:aws:s3:::sme-core-cloud-compliance-centralized-s3-use1-logs/*",
      "arn:aws:s3:::sme-core-cloud-compliance-centralized-s3-euc1-logs",
      "arn:aws:s3:::sme-core-cloud-compliance-centralized-s3-euc1-logs/*",
    ]

    actions = [
      "s3:Get*",
      "s3:Put*",
      "s3:Delete*",
      "s3:ReplicateObject",
      "s3:ReplicateDelete",
    ]
  }
}

data "aws_iam_policy_document" "sme-media-production-full-access" {
  statement {
    sid    = "AllowListBucket"
    effect = "Allow"
    resources = [
      "arn:aws:s3:::sme-media-production",
    ]
    actions = [
      "s3:ListBucket",
    ]
  }

  statement {
    sid    = "AllowObjectAccess"
    effect = "Allow"
    resources = [
      "arn:aws:s3:::sme-media-production/*",
    ]
    actions = [
      "s3:PutObject",
      "s3:GetObject",
      "s3:DeleteObject",
      "s3:ListMultipartUploadParts",
      "s3:AbortMultipartUpload",
    ]
  }
}

data "aws_iam_policy_document" "sme-delivery-user-upload-full-access" {
  statement {
    sid    = "AllowListBucket"
    effect = "Allow"
    resources = [
      "arn:aws:s3:::sme-delivery-user-upload",
    ]
    actions = [
      "s3:ListBucket",
    ]
  }

  statement {
    sid    = "AllowObjectAccess"
    effect = "Allow"
    resources = [
      "arn:aws:s3:::sme-delivery-user-upload/*",
    ]
    actions = [
      "s3:PutObject",
      "s3:GetObject",
      "s3:DeleteObject",
      "s3:ListMultipartUploadParts",
      "s3:ListBucketMultipartUploads",
      "s3:AbortMultipartUpload",
    ]
  }
}


data "aws_iam_policy_document" "globalds-prod-assumerole" {
  statement {
    sid    = "globaldsdassumerole"
    effect = "Allow"

    resources = ["arn:aws:iam::635220336377:role/globaldsp-sa-msk-delivery-role"]

    actions = [
      "sts:AssumeRole"
    ]
  }
}

data "aws_iam_policy_document" "delp-eks-node-eip-association" {
#checkov:skip=CKV_AWS_111: Ensure IAM policies does not allow write access without constraints
  statement {
    sid       = "AssociateStaticEIP"
    effect    = "Allow"
    resources = ["*"]
    actions = [
      "ec2:AssociateAddress",
      "ec2:DisassociateAddress",
    ]
  }
}
