data "aws_iam_policy_document" "cf-templates-6uadb4178z7p-eu-central-1" {
  statement {
    sid       = "Stmt1541176402668"
    effect    = "Deny"
    resources = ["arn:aws:s3:::cf-templates-6uadb4178z7p-eu-central-1"]
    actions   = ["s3:*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "digital-systems-prod-frankfurt-elb-logs" {
  statement {
    sid       = "AWSConsoleStmt-1569470552059"
    effect    = "Allow"
    resources = ["arn:aws:s3:::digital-systems-prod-frankfurt-elb-logs/*"]
    actions   = ["s3:PutObject"]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::054676820928:root"]
    }
  }

  statement {
    sid       = "AWSLogDeliveryWrite"
    effect    = "Allow"
    resources = ["arn:aws:s3:::digital-systems-prod-frankfurt-elb-logs/*"]
    actions   = ["s3:PutObject"]

    condition {
      test     = "StringEquals"
      variable = "s3:x-amz-acl"
      values   = ["bucket-owner-full-control"]
    }

    principals {
      type        = "Service"
      identifiers = ["delivery.logs.amazonaws.com"]
    }
  }

  statement {
    sid       = "AWSLogDeliveryAclCheck"
    effect    = "Allow"
    resources = ["arn:aws:s3:::digital-systems-prod-frankfurt-elb-logs"]
    actions   = ["s3:GetBucketAcl"]

    principals {
      type        = "Service"
      identifiers = ["delivery.logs.amazonaws.com"]
    }
  }

  statement {
    sid       = ""
    effect    = "Deny"
    resources = ["arn:aws:s3:::digital-systems-prod-frankfurt-elb-logs/*"]
    actions   = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "digsys-ff-audit-vpc-flow-logs" {
  statement {
    sid       = "AWSLogDeliveryWrite"
    effect    = "Allow"
    resources = ["arn:aws:s3:::digsys-ff-audit-vpc-flow-logs/AWSLogs/799833541840/*"]
    actions   = ["s3:PutObject"]

    condition {
      test     = "StringEquals"
      variable = "s3:x-amz-acl"
      values   = ["bucket-owner-full-control"]
    }

    principals {
      type        = "Service"
      identifiers = ["delivery.logs.amazonaws.com"]
    }
  }

  statement {
    sid       = "AWSLogDeliveryAclCheck"
    effect    = "Allow"
    resources = ["arn:aws:s3:::digsys-ff-audit-vpc-flow-logs"]
    actions   = ["s3:GetBucketAcl"]

    principals {
      type        = "Service"
      identifiers = ["delivery.logs.amazonaws.com"]
    }
  }
}

data "aws_iam_policy_document" "dms-799833541840-cvjcnngozmcw" {
  statement {
    sid    = "BucketPolicy"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::dms-799833541840-cvjcnngozmcw/*",
      "arn:aws:s3:::dms-799833541840-cvjcnngozmcw",
    ]

    actions = [
      "s3:GetObject",
      "s3:PutObject",
      "s3:DeleteObject",
      "s3:GetObjectVersion",
      "s3:GetBucketPolicy",
      "s3:PutBucketPolicy",
      "s3:DeleteBucketPolicy",
      "s3:ListBucket",
      "s3:GetBucketLocation",
      "s3:DeleteBucket",
    ]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::799833541840:role/dms-access-for-tasks"]
    }
  }
}

data "aws_iam_policy_document" "eom-ff-p-vpc-flow-logs" {
  statement {
    sid       = "AWSLogDeliveryWrite"
    effect    = "Allow"
    resources = ["arn:aws:s3:::eom-ff-p-vpc-flow-logs/AWSLogs/799833541840/*"]
    actions   = ["s3:PutObject"]

    condition {
      test     = "StringEquals"
      variable = "s3:x-amz-acl"
      values   = ["bucket-owner-full-control"]
    }

    principals {
      type        = "Service"
      identifiers = ["delivery.logs.amazonaws.com"]
    }
  }

  statement {
    sid       = "AWSLogDeliveryAclCheck"
    effect    = "Allow"
    resources = ["arn:aws:s3:::eom-ff-p-vpc-flow-logs"]
    actions   = ["s3:GetBucketAcl"]

    principals {
      type        = "Service"
      identifiers = ["delivery.logs.amazonaws.com"]
    }
  }
}

data "aws_iam_policy_document" "eom-prod-rds-log-backup" {
  statement {
    sid       = "Stmt1541176343243"
    effect    = "Deny"
    resources = ["arn:aws:s3:::eom-prod-rds-log-backup"]
    actions   = ["s3:*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "sme-digital-systems-prod-aws-config" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-digital-systems-prod-aws-config/*"]
    actions   = ["s3:GetObject"]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::797906716436:root"]
    }
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-digital-systems-prod-aws-config"]
    actions   = ["s3:ListBucket"]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::797906716436:root"]
    }
  }

  statement {
    sid       = ""
    effect    = "Deny"
    resources = ["arn:aws:s3:::sme-digital-systems-prod-aws-config/*"]
    actions   = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "sme-digital-systems-prod-eu-central-1-logs" {
  statement {
    sid       = "Stmt1541176242596"
    effect    = "Deny"
    resources = ["arn:aws:s3:::sme-digital-systems-prod-eu-central-1-logs"]
    actions   = ["s3:*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
  statement {
    sid       = "S3PolicyStmt-DO-NOT-MODIFY-1749542501192"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-digital-systems-prod-eu-central-1-logs/*"]
    actions   = ["s3:PutObject"]

    condition {
      test     = "StringEquals"
      variable = "aws:SourceAccount"
      values   = ["799833541840"]
    }

    principals {
      type        = "Service"
      identifiers = ["logging.s3.amazonaws.com"]
    }
  }
  statement {
    sid    = "AllowDigsyspUtil01"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-digital-systems-prod-eu-central-1-logs",
      "arn:aws:s3:::sme-digital-systems-prod-eu-central-1-logs/*",
    ]

    actions = ["s3:*"]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::799833541840:role/digsysp-digsysp-util01"]
    }
  }
}

data "aws_iam_policy_document" "sme-digital-systems-prod-euc1-s3-inventory" {
  statement {
    sid       = "S3PolicyStmt-DO-NOT-MODIFY-1603804496875"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-digital-systems-prod-euc1-s3-inventory/*"]
    actions   = ["s3:PutObject"]

    condition {
      test     = "StringEquals"
      variable = "aws:SourceAccount"
      values   = ["799833541840"]
    }

    condition {
      test     = "StringEquals"
      variable = "s3:x-amz-acl"
      values   = ["bucket-owner-full-control"]
    }

    condition {
      test     = "ArnLike"
      variable = "aws:SourceArn"
      values   = ["arn:aws:s3:::*"]
    }

    principals {
      type        = "Service"
      identifiers = ["s3.amazonaws.com"]
    }
  }
}

data "aws_iam_policy_document" "sme-digital-systems-prod-us-east-1-logs" {
  statement {
    sid       = "Stmt1541176277712"
    effect    = "Deny"
    resources = ["arn:aws:s3:::sme-digital-systems-prod-us-east-1-logs"]
    actions   = ["s3:*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}
data "aws_iam_policy_document" "sme-digital-systems-prod-athena-out" {
  statement {
    sid       = "Stmt1541176277712"
    effect    = "Deny"
    resources = ["arn:aws:s3:::sme-digital-systems-prod-athena-out", "arn:aws:s3:::sme-digital-systems-prod-athena-out/*"]
    actions   = ["s3:*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}
data "aws_iam_policy_document" "sme-digital-systems-prod-use1-s3-inventory" {
  statement {
    sid       = "S3PolicyStmt-DO-NOT-MODIFY-1603804496875"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-digital-systems-prod-use1-s3-inventory/*"]
    actions   = ["s3:PutObject"]

    condition {
      test     = "StringEquals"
      variable = "aws:SourceAccount"
      values   = ["799833541840"]
    }

    condition {
      test     = "StringEquals"
      variable = "s3:x-amz-acl"
      values   = ["bucket-owner-full-control"]
    }

    condition {
      test     = "ArnLike"
      variable = "aws:SourceArn"
      values   = ["arn:aws:s3:::*"]
    }

    principals {
      type        = "Service"
      identifiers = ["s3.amazonaws.com"]
    }
  }
}

data "aws_iam_policy_document" "sme-digsysp-txmgr01" {
  statement {
    sid    = "Stmt1550039914267"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-digsysp-txmgr01",
      "arn:aws:s3:::sme-digsysp-txmgr01/*",
    ]

    actions = ["s3:*"]

    principals {
      type        = "AWS"
      identifiers = [
        "arn:aws:iam::799833541840:role/sme-digsysp-txmgr01",
        "arn:aws:iam::799833541840:role/digsysp-digsysp-util01",
        "arn:aws:iam::564397575384:role/carmap-app01",
        "arn:aws:iam::613871678587:user/aomap-aoma-txmgr-user",
        ]
    }
  }
}

data "aws_iam_policy_document" "sme-eom-prod-cloudtrail" {
  statement {
    sid       = "AWSCloudTrailAclCheck20150319"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-eom-prod-cloudtrail"]
    actions   = ["s3:GetBucketAcl"]

    principals {
      type        = "Service"
      identifiers = ["cloudtrail.amazonaws.com"]
    }
  }

  statement {
    sid       = "AWSCloudTrailWrite20150319"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-eom-prod-cloudtrail/AWSLogs/799833541840/*"]
    actions   = ["s3:PutObject"]

    condition {
      test     = "StringEquals"
      variable = "s3:x-amz-acl"
      values   = ["bucket-owner-full-control"]
    }

    principals {
      type        = "Service"
      identifiers = ["cloudtrail.amazonaws.com"]
    }
  }

  statement {
    sid       = ""
    effect    = "Deny"
    resources = ["arn:aws:s3:::sme-eom-prod-cloudtrail/*"]
    actions   = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "sme-max-data-prod-mi" {
  statement {
    sid       = "Access to sme-max-data-prod-mi"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-max-data-prod-mi/*"]
    actions   = ["s3:*"]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::799833541840:user/digsysp-s3-sme-mipr-rman-backups"]
    }
  }
}

data "aws_iam_policy_document" "sme-max-data-prod-oh" {
  statement {
    sid       = "Access to sme-max-data-prod-oh"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-max-data-prod-oh/*"]
    actions   = ["s3:*"]

    principals {
      type = "AWS"

      identifiers = [
        "arn:aws:iam::504436705349:user/maxp-dataload-user",
        "arn:aws:iam::799833541840:role/rds-rman-s3",
        "arn:aws:iam::799833541840:user/digsysp-s3-sme-mipr-rman-backups",
      ]
    }
  }
}

data "aws_iam_policy_document" "sme-mipr-rman-backups" {
  statement {
    sid       = "Access to sme-cloudops-splunk-uf"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-mipr-rman-backups/*"]
    actions   = ["s3:*"]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::799833541840:user/digsysp-s3-sme-mipr-rman-backups"]
    }
  }

  statement {
    sid    = "Stmt1567613957138"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-mipr-rman-backups",
      "arn:aws:s3:::sme-mipr-rman-backups/*",
    ]

    actions = ["s3:*"]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::799833541840:user/digsysp-s3-sme-mipr-rman-backups"]
    }
  }
}

data "aws_iam_policy_document" "sme-digsp-mi-dictionary-on-demand" {
  statement {
    sid       = "Access to sme-digsp-mi-dictionary-on-demand"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-digsp-mi-dictionary-on-demand/*"]
    actions   = ["s3:*"]
    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::799833541840:role/sme-digsp-mi-dictionary-role"]
    }
  }

  statement {
    sid    = "Stmt1567613957138"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-digsp-mi-dictionary-on-demand",
      "arn:aws:s3:::sme-digsp-mi-dictionary-on-demand/*",
    ]

    actions = ["s3:*"]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::799833541840:role/sme-digsp-mi-dictionary-role"]
    }
  }
}

data "aws_iam_policy_document" "sme-digsp-mi-dictionary-regular-batch" {
  statement {
    sid       = "Access to sme-digsp-mi-dictionary-regular-batch"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-digsp-mi-dictionary-regular-batch/*"]
    actions   = ["s3:*"]
    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::799833541840:role/sme-digsp-mi-dictionary-role"]
    }
  }

  statement {
    sid    = "Stmt1567613957138"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-digsp-mi-dictionary-regular-batch",
      "arn:aws:s3:::sme-digsp-mi-dictionary-regular-batch/*",
    ]

    actions = ["s3:*"]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::799833541840:role/sme-digsp-mi-dictionary-role"]
    }
  }
}

data "aws_iam_policy_document" "sme-digital-systems-prod-digsys-p3-vpc-flow-logs" {
  statement {
    sid       = "AWSLogDeliveryWrite"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-digital-systems-prod-digsys-p3-vpc-flow-logs/AWSLogs/799833541840/*"]
    actions   = ["s3:PutObject"]

    condition {
      test     = "ArnLike"
      variable = "aws:SourceArn"
      values   = ["arn:aws:logs:eu-central-1:799833541840:*"]
    }

    condition {
      test     = "StringEquals"
      variable = "aws:SourceAccount"
      values   = ["799833541840"]
    }

    condition {
      test     = "StringEquals"
      variable = "s3:x-amz-acl"
      values   = ["bucket-owner-full-control"]
    }

    principals {
      type        = "Service"
      identifiers = ["delivery.logs.amazonaws.com"]
    }
  }

  statement {
    sid       = "AWSLogDeliveryAclCheck"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-digital-systems-prod-digsys-p3-vpc-flow-logs"]
    actions   = ["s3:GetBucketAcl"]

    condition {
      test     = "ArnLike"
      variable = "aws:SourceArn"
      values   = ["arn:aws:logs:eu-central-1:799833541840:*"]
    }

    condition {
      test     = "StringEquals"
      variable = "aws:SourceAccount"
      values   = ["799833541840"]
    }

    principals {
      type        = "Service"
      identifiers = ["delivery.logs.amazonaws.com"]
    }
  }

  statement {
    sid       = "S3PolicyStmt-DO-NOT-MODIFY-1653542309917"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-digital-systems-prod-digsys-p3-vpc-flow-logs/*"]
    actions   = ["s3:PutObject"]

    principals {
      type        = "Service"
      identifiers = ["logging.s3.amazonaws.com"]
    }
  }
}

