data "aws_iam_policy_document" "aws-athena-query-results-981599956623-us-east-1" {
  statement {
    sid    = ""
    effect = "Deny"

    resources = [
      "arn:aws:s3:::aws-athena-query-results-981599956623-us-east-1/*",
      "arn:aws:s3:::aws-athena-query-results-981599956623-us-east-1",
    ]

    actions = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "aws-glue-assets-981599956623-eu-central-1" {
  statement {
    sid    = ""
    effect = "Deny"

    resources = [
      "arn:aws:s3:::aws-glue-assets-981599956623-eu-central-1/*",
      "arn:aws:s3:::aws-glue-assets-981599956623-eu-central-1",
    ]

    actions = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "aws-glue-scripts-981599956623-us-east-1" {
  statement {
    sid    = ""
    effect = "Deny"

    resources = [
      "arn:aws:s3:::aws-glue-scripts-981599956623-us-east-1/*",
      "arn:aws:s3:::aws-glue-scripts-981599956623-us-east-1",
    ]

    actions = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "aws-glue-temporary-981599956623-us-east-1" {
  statement {
    sid    = ""
    effect = "Deny"

    resources = [
      "arn:aws:s3:::aws-glue-temporary-981599956623-us-east-1/*",
      "arn:aws:s3:::aws-glue-temporary-981599956623-us-east-1",
    ]

    actions = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "aws-logs-981599956623-eu-central-1" {
  statement {
    sid    = ""
    effect = "Deny"

    resources = [
      "arn:aws:s3:::aws-logs-981599956623-eu-central-1/*",
      "arn:aws:s3:::aws-logs-981599956623-eu-central-1",
    ]

    actions = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "aws-logs-981599956623-us-east-1" {
  statement {
    sid       = "Stmt1541094687595"
    effect    = "Deny"
    resources = ["arn:aws:s3:::aws-logs-981599956623-us-east-1"]
    actions   = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "ben-emr-test" {
  statement {
    sid    = "DelegateS3Access"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::ben-emr-test/*",
      "arn:aws:s3:::ben-emr-test",
    ]

    actions = ["s3:*"]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::765134955759:root"]
    }
  }

  statement {
    sid       = ""
    effect    = "Deny"
    resources = ["arn:aws:s3:::ben-emr-test/*"]
    actions   = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "cf-templates-1gjdlx5bjzh2u-us-east-1" {
  statement {
    sid       = ""
    effect    = "Deny"
    resources = ["arn:aws:s3:::cf-templates-1gjdlx5bjzh2u-us-east-1/*"]
    actions   = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "ckoi_bucket" {
  statement {
    sid       = "Stmt1357935647218"
    effect    = "Allow"
    resources = ["arn:aws:s3:::ckoi_bucket"]
    actions   = ["s3:ListBucket"]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::379237304985:root"]
    }
  }

  statement {
    sid       = "Stmt1357935676138"
    effect    = "Allow"
    resources = ["arn:aws:s3:::ckoi_bucket/*"]
    actions   = ["s3:*"]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::379237304985:root"]
    }
  }

  statement {
    sid       = ""
    effect    = "Deny"
    resources = ["arn:aws:s3:::ckoi_bucket/*"]
    actions   = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "cm-hive-backup" {
  statement {
    sid    = ""
    effect = "Deny"

    resources = [
      "arn:aws:s3:::cm-hive-backup/*",
      "arn:aws:s3:::cm-hive-backup",
    ]

    actions = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "cm-query-results" {
  statement {
    sid    = ""
    effect = "Deny"

    resources = [
      "arn:aws:s3:::cm-query-results/*",
      "arn:aws:s3:::cm-query-results",
    ]

    actions = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "dsrv-dsp-package-xml-dev" {
  statement {
    sid    = "Access"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::dsrv-dsp-package-xml-dev/*",
      "arn:aws:s3:::dsrv-dsp-package-xml-dev",
    ]

    actions = ["s3:*"]

    principals {
      type = "AWS"

      identifiers = [
        "arn:aws:iam::058029036333:role/delivery-package-archiver-dev",
        "arn:aws:iam::981599956623:role/sme-max-dev-athena-access",
        "arn:aws:iam::058029036333:role/delivery-package-archiver-stage",
        "arn:aws:iam::981599956623:user/maxd-etl-user",
        "arn:aws:iam::981599956623:role/ReadOnlyExtern",
      ]
    }
  }

  statement {
    sid       = ""
    effect    = "Deny"
    resources = ["arn:aws:s3:::dsrv-dsp-package-xml-dev/*"]
    actions   = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "dsrv-dsp-package-xml-stg" {
  statement {
    sid    = ""
    effect = "Allow"

    resources = [
      "arn:aws:s3:::dsrv-dsp-package-xml-stg/*",
      "arn:aws:s3:::dsrv-dsp-package-xml-stg",
    ]

    actions = [
      "s3:PutObject",
      "s3:ListBucket",
      "s3:GetObject",
      "s3:DeleteObject",
    ]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::981599956623:user/maxd-s3-stg-datalake"]
    }
  }

  statement {
    sid    = ""
    effect = "Deny"

    resources = [
      "arn:aws:s3:::dsrv-dsp-package-xml-stg/*",
      "arn:aws:s3:::dsrv-dsp-package-xml-stg",
    ]

    actions = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "elasticbeanstalk-us-east-1-981599956623" {
  statement {
    sid       = "eb-ad78f54a-f239-4c90-adda-49e5f56cb51e"
    effect    = "Allow"
    resources = ["arn:aws:s3:::elasticbeanstalk-us-east-1-981599956623/resources/environments/logs/*"]
    actions   = ["s3:PutObject"]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::981599956623:role/aws-elasticbeanstalk-ec2-role"]
    }
  }

  statement {
    sid    = "eb-af163bf3-d27b-4712-b795-d1e33e331ca4"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::elasticbeanstalk-us-east-1-981599956623/resources/environments/*",
      "arn:aws:s3:::elasticbeanstalk-us-east-1-981599956623",
    ]

    actions = [
      "s3:ListBucketVersions",
      "s3:ListBucket",
      "s3:GetObjectVersion",
      "s3:GetObject",
    ]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::981599956623:role/aws-elasticbeanstalk-ec2-role"]
    }
  }

  statement {
    sid       = "eb-58950a8c-feb6-11e2-89e0-0800277d041b"
    effect    = "Deny"
    resources = ["arn:aws:s3:::elasticbeanstalk-us-east-1-981599956623"]
    actions   = ["s3:DeleteBucket"]

    principals {
      type        = "AWS"
      identifiers = ["*"]
    }
  }

  statement {
    sid       = ""
    effect    = "Deny"
    resources = ["arn:aws:s3:::elasticbeanstalk-us-east-1-981599956623/*"]
    actions   = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "max-d-virginia-alb-logs" {
  statement {
    sid       = "AWSConsoleStmt-1524479950090"
    effect    = "Allow"
    resources = ["arn:aws:s3:::max-d-virginia-alb-logs/*"]
    actions   = ["s3:PutObject"]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::127311923021:root"]
    }
  }

  statement {
    sid       = "Stmt1541094687595"
    effect    = "Deny"
    resources = ["arn:aws:s3:::max-d-virginia-alb-logs"]
    actions   = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "maxd-cm-athena-query-results" {
  statement {
    sid    = "Stmt1583849478374"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::maxd-cm-athena-query-results/*",
      "arn:aws:s3:::maxd-cm-athena-query-results",
    ]

    actions = ["s3:*"]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::981599956623:role/sme-max-dev-athena-access"]
    }
  }

  statement {
    sid    = ""
    effect = "Deny"

    resources = [
      "arn:aws:s3:::maxd-cm-athena-query-results/*",
      "arn:aws:s3:::maxd-cm-athena-query-results",
    ]

    actions = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "maxffs-vpc-flow-logs" {
  statement {
    sid       = "AWSLogDeliveryWrite"
    effect    = "Allow"
    resources = ["arn:aws:s3:::maxffs-vpc-flow-logs/AWSLogs/981599956623/*"]
    actions   = ["s3:PutObject"]

    condition {
      test     = "StringEquals"
      variable = "s3:x-amz-acl"
      values   = ["bucket-owner-full-control"]
    }

    principals {
      type        = "Service"
      identifiers = ["delivery.logs.amazonaws.com"]
    }
  }

  statement {
    sid       = "AWSLogDeliveryAclCheck"
    effect    = "Allow"
    resources = ["arn:aws:s3:::maxffs-vpc-flow-logs"]
    actions   = ["s3:GetBucketAcl"]

    principals {
      type        = "Service"
      identifiers = ["delivery.logs.amazonaws.com"]
    }
  }

  statement {
    sid    = "SecureDataTransportPolicy"
    effect = "Deny"

    resources = [
      "arn:aws:s3:::maxffs-vpc-flow-logs/*",
      "arn:aws:s3:::maxffs-vpc-flow-logs",
    ]

    actions = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "maxohs-vpc-flow-logs" {
  statement {
    sid       = "AWSLogDeliveryWrite"
    effect    = "Allow"
    resources = ["arn:aws:s3:::maxohs-vpc-flow-logs/AWSLogs/981599956623/*"]
    actions   = ["s3:PutObject"]

    condition {
      test     = "StringEquals"
      variable = "s3:x-amz-acl"
      values   = ["bucket-owner-full-control"]
    }

    principals {
      type        = "Service"
      identifiers = ["delivery.logs.amazonaws.com"]
    }
  }

  statement {
    sid       = "AWSLogDeliveryAclCheck"
    effect    = "Allow"
    resources = ["arn:aws:s3:::maxohs-vpc-flow-logs"]
    actions   = ["s3:GetBucketAcl"]

    principals {
      type        = "Service"
      identifiers = ["delivery.logs.amazonaws.com"]
    }
  }

  statement {
    sid    = "SecureDataTransportPolicy"
    effect = "Deny"

    resources = [
      "arn:aws:s3:::maxohs-vpc-flow-logs/*",
      "arn:aws:s3:::maxohs-vpc-flow-logs",
    ]

    actions = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "mps-EMR-Test" {
  statement {
    sid       = ""
    effect    = "Deny"
    resources = ["arn:aws:s3:::mps-EMR-Test/*"]
    actions   = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "mps-db-dump" {
  statement {
    sid       = ""
    effect    = "Deny"
    resources = ["arn:aws:s3:::mps-db-dump/*"]
    actions   = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "mps_dev" {
  statement {
    sid    = "DelegateS3Access"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::mps_dev/*",
      "arn:aws:s3:::mps_dev",
    ]

    actions = ["s3:*"]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::765134955759:root"]
    }
  }

  statement {
    sid       = ""
    effect    = "Deny"
    resources = ["arn:aws:s3:::mps_dev/*"]
    actions   = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "mps_prod" {
  statement {
    sid    = "DelegateS3Access"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::mps_prod/*",
      "arn:aws:s3:::mps_prod",
    ]

    actions = ["s3:*"]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::765134955759:root"]
    }
  }

  statement {
    sid       = ""
    effect    = "Deny"
    resources = ["arn:aws:s3:::mps_prod/*"]
    actions   = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "mps_stage" {
  statement {
    sid       = "Stmt1335892150622"
    effect    = "Allow"
    resources = ["arn:aws:s3:::mps_stage"]

    actions = [
      "s3:GetBucketPolicy",
      "s3:GetBucketAcl",
    ]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::386209384616:root"]
    }
  }

  statement {
    sid       = "Stmt1335892526596"
    effect    = "Allow"
    resources = ["arn:aws:s3:::mps_stage/*"]
    actions   = ["s3:PutObject"]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::386209384616:root"]
    }
  }

  statement {
    sid    = "DelegateS3Access"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::mps_stage/*",
      "arn:aws:s3:::mps_stage",
    ]

    actions = ["s3:*"]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::765134955759:root"]
    }
  }

  statement {
    sid       = ""
    effect    = "Deny"
    resources = ["arn:aws:s3:::mps_stage/*"]
    actions   = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "oracle-data-cloudmps-1" {
  statement {
    sid       = ""
    effect    = "Deny"
    resources = ["arn:aws:s3:::oracle-data-cloudmps-1/*"]
    actions   = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "sam-deploy-max-partner-asset-id" {
  statement {
    sid    = "Stmt1583849478374"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sam-deploy-max-partner-asset-id/*",
      "arn:aws:s3:::sam-deploy-max-partner-asset-id",
    ]

    actions = ["s3:*"]

    principals {
      type = "AWS"

      identifiers = [
        "arn:aws:iam::981599956623:user/sam-deploy-user",
        "arn:aws:iam::981599956623:role/sam-deploy-max-role",
        "arn:aws:iam::981599956623:role/aws-reserved/sso.amazonaws.com/AWSReservedSSO_SupplyChain-Dev-Maxd-Admin02_0cd13c5906246bd8",
      ]
    }
  }

  statement {
    sid    = ""
    effect = "Deny"

    resources = [
      "arn:aws:s3:::sam-deploy-max-partner-asset-id/*",
      "arn:aws:s3:::sam-deploy-max-partner-asset-id",
    ]

    actions = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "sme-dev-replay-datalake-test" {
  statement {
    sid    = ""
    effect = "Deny"

    resources = [
      "arn:aws:s3:::sme-dev-replay-datalake-test/*",
      "arn:aws:s3:::sme-dev-replay-datalake-test",
    ]

    actions = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "sme-dev-replay-datalake-test-copy" {
  statement {
    sid    = ""
    effect = "Deny"

    resources = [
      "arn:aws:s3:::sme-dev-replay-datalake-test-copy/*",
      "arn:aws:s3:::sme-dev-replay-datalake-test-copy",
    ]

    actions = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "sme-max-dev-applogs" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-max-dev-applogs"]
    actions   = ["s3:GetBucketAcl"]

    principals {
      type        = "Service"
      identifiers = ["logs.eu-central-1.amazonaws.com"]
    }
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-max-dev-applogs/*"]
    actions   = ["s3:PutObject"]

    condition {
      test     = "StringEquals"
      variable = "s3:x-amz-acl"
      values   = ["bucket-owner-full-control"]
    }

    principals {
      type        = "Service"
      identifiers = ["logs.eu-central-1.amazonaws.com"]
    }
  }
}

data "aws_iam_policy_document" "sme-max-dev-dataload" {
  statement {
    sid       = "Allow-OAI-Access-To-Bucket"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-max-dev-dataload/*"]
    actions   = ["s3:GetObject"]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::cloudfront:user/CloudFront Origin Access Identity E388J4W3MDO54L"]
    }
  }

  statement {
    sid       = "3"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-max-dev-dataload/*"]
    actions   = ["s3:GetObject"]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::cloudfront:user/CloudFront Origin Access Identity E388J4W3MDO54L"]
    }
  }

  statement {
    sid    = "Access to sme.max.dev.dataload"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-max-dev-dataload/*",
      "arn:aws:s3:::sme-max-dev-dataload",
    ]

    actions = ["s3:*"]

    principals {
      type = "AWS"

      identifiers = [
        "arn:aws:iam::981599956623:user/maxd-etl-user",
        "arn:aws:iam::981599956623:role/lamda-s3",
        "arn:aws:iam::981599956623:role/maxRDSLoadFromS3",
      ]
    }
  }

  statement {
    sid    = "SecureDataTransportPolicy"
    effect = "Deny"

    resources = [
      "arn:aws:s3:::sme-max-dev-dataload/*",
      "arn:aws:s3:::sme-max-dev-dataload",
    ]

    actions = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "sme-max-dev-eai-applogs" {
  statement {
    sid    = "Stmt1648708373861"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-max-dev-eai-applogs/*",
      "arn:aws:s3:::sme-max-dev-eai-applogs",
    ]

    actions = [
      "s3:PutObject",
      "s3:ListBucket",
      "s3:GetObject",
      "s3:GetBucketAcl",
      "s3:DeleteObject",
    ]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::981599956623:role/max2-logs-s3-lamda-role"]
    }
  }

  statement {
    sid    = "Stmt2"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-max-dev-eai-applogs/*",
      "arn:aws:s3:::sme-max-dev-eai-applogs",
    ]

    actions = [
      "s3:PutObject",
      "s3:ListBucket",
      "s3:GetObject",
      "s3:GetBucketAcl",
      "s3:DeleteObject",
    ]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::981599956623:role/max2-logs-s3-lamda-role"]
    }
  }

  statement {
    sid    = "AllowLogs"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-max-dev-eai-applogs/*",
      "arn:aws:s3:::sme-max-dev-eai-applogs",
    ]

    actions = [
      "s3:PutObject",
      "s3:GetObjectAcl",
      "s3:GetBucketAcl",
    ]

    condition {
      test     = "ArnLike"
      variable = "aws:SourceArn"
      values   = ["arn:aws:logs:*:*:*:*:*"]
    }

    principals {
      type        = "Service"
      identifiers = ["logs.eu-central-1.amazonaws.com"]
    }
  }

  statement {
    sid       = ""
    effect    = "Deny"
    resources = ["arn:aws:s3:::sme-max-dev-eai-applogs/*"]
    actions   = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "sme-max-dev-noro002" {
  statement {
    sid    = "Access for digimax_oh_data"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-max-dev-noro002/*",
      "arn:aws:s3:::sme-max-dev-noro002",
    ]

    actions = ["s3:*"]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::981599956623:role/Maxd-Admin02"]
    }
  }

  statement {
    sid       = ""
    effect    = "Deny"
    resources = ["arn:aws:s3:::sme-max-dev-noro002/*"]
    actions   = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "sme-max-dev-perm-group-store" {
  statement {
    sid    = "Access for digimax_oh_data"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-max-dev-perm-group-store/*",
      "arn:aws:s3:::sme-max-dev-perm-group-store",
    ]

    actions = ["s3:*"]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::981599956623:user/maxd-etl-user"]
    }
  }

  statement {
    sid       = ""
    effect    = "Deny"
    resources = ["arn:aws:s3:::sme-max-dev-perm-group-store/*"]
    actions   = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-max-dev-perm-group-store"]
    actions   = ["s3:*"]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::981599956623:role/maxRDSLoadFromS3"]
    }
  }
}

data "aws_iam_policy_document" "sme-max-dev-reports" {
  statement {
    sid       = "Allow-OAI-Access-To-Bucket"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-max-dev-reports/*"]
    actions   = ["s3:GetObject"]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::cloudfront:user/CloudFront Origin Access Identity E388J4W3MDO54L"]
    }
  }

  statement {
    sid       = "3"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-max-dev-reports/*"]
    actions   = ["s3:GetObject"]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::cloudfront:user/CloudFront Origin Access Identity E388J4W3MDO54L"]
    }
  }

  statement {
    sid    = "Access to sme.max.dev.dataload"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-max-dev-reports/*",
      "arn:aws:s3:::sme-max-dev-reports",
    ]

    actions = ["s3:*"]

    principals {
      type = "AWS"

      identifiers = [
        "arn:aws:iam::981599956623:user/maxd-etl-user",
        "arn:aws:iam::981599956623:role/maxRDSLoadFromS3",
        "arn:aws:iam::981599956623:role/lamda-s3",
      ]
    }
  }

  statement {
    sid    = "SecureDataTransportPolicy"
    effect = "Deny"

    resources = [
      "arn:aws:s3:::sme-max-dev-reports/*",
      "arn:aws:s3:::sme-max-dev-reports",
    ]

    actions = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "sme-max-dev-web-reports" {
  statement {
    sid    = ""
    effect = "Deny"

    resources = [
      "arn:aws:s3:::sme-max-dev-web-reports/*",
      "arn:aws:s3:::sme-max-dev-web-reports",
    ]

    actions = ["s3:*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "AWS"
      identifiers = ["*"]
    }
  }

  statement {
    sid    = ""
    effect = "Deny"

    resources = [
      "arn:aws:s3:::sme-max-dev-web-reports/*",
      "arn:aws:s3:::sme-max-dev-web-reports",
    ]

    actions = ["s3:*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "AWS"
      identifiers = ["*"]
    }
  }

  statement {
    sid       = "Allow-OAI-Access-To-Bucket"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-max-dev-web-reports/*"]
    actions   = ["s3:GetObject"]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::cloudfront:user/CloudFront Origin Access Identity E388J4W3MDO54L"]
    }
  }

  statement {
    sid       = "3"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-max-dev-web-reports/*"]
    actions   = ["s3:GetObject"]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::cloudfront:user/CloudFront Origin Access Identity E388J4W3MDO54L"]
    }
  }

  statement {
    sid    = "Access to sme.max.dev.dataload"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-max-dev-web-reports/*",
      "arn:aws:s3:::sme-max-dev-web-reports",
    ]

    actions = ["s3:*"]

    principals {
      type = "AWS"

      identifiers = [
        "arn:aws:iam::981599956623:role/maxRDSLoadFromS3",
        "arn:aws:iam::981599956623:user/maxd-etl-user",
        "arn:aws:iam::981599956623:role/lamda-s3",
      ]
    }
  }

  statement {
    sid    = "SecureDataTransportPolicy"
    effect = "Deny"

    resources = [
      "arn:aws:s3:::sme-max-dev-web-reports/*",
      "arn:aws:s3:::sme-max-dev-web-reports",
    ]

    actions = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "AWS"
      identifiers = ["*"]
    }
  }

  statement {
    sid    = "AllowCloudFrontServicePrincipal"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-max-dev-web-reports/*",
      "arn:aws:s3:::sme-max-dev-web-reports",
    ]

    actions = [
      "s3:ListBucket",
      "s3:GetObject",
    ]

    condition {
      test     = "StringEquals"
      variable = "AWS:SourceArn"
      values   = ["arn:aws:cloudfront::981599956623:distribution/E7I1ZZQMDJ8DR"]
    }

    principals {
      type        = "Service"
      identifiers = ["cloudfront.amazonaws.com"]
    }
  }
}

data "aws_iam_policy_document" "sme-max-ff-alb-logs-euc" {
  statement {
    sid       = "AWSConsoleStmt-1600402229514"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-max-ff-alb-logs-euc/*"]
    actions   = ["s3:PutObject"]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::054676820928:root"]
    }
  }

  statement {
    sid       = "AWSLogDeliveryWrite"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-max-ff-alb-logs-euc/*"]
    actions   = ["s3:PutObject"]

    condition {
      test     = "StringEquals"
      variable = "s3:x-amz-acl"
      values   = ["bucket-owner-full-control"]
    }

    principals {
      type        = "Service"
      identifiers = ["delivery.logs.amazonaws.com"]
    }
  }

  statement {
    sid       = "AWSLogDeliveryAclCheck"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-max-ff-alb-logs-euc"]
    actions   = ["s3:GetBucketAcl"]

    principals {
      type        = "Service"
      identifiers = ["delivery.logs.amazonaws.com"]
    }
  }

  statement {
    sid       = ""
    effect    = "Deny"
    resources = ["arn:aws:s3:::sme-max-ff-alb-logs-euc/*"]
    actions   = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "sme-max-prod-reports-stage" {
  statement {
    sid    = "Stmt1575561694443"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-max-prod-reports-stage/*",
      "arn:aws:s3:::sme-max-prod-reports-stage",
    ]

    actions = ["s3:*"]

    principals {
      type = "AWS"

      identifiers = [
        "arn:aws:iam::981599956623:role/Maxd-Admin02",
        "arn:aws:iam::981599956623:user/maxd-s3-stg-datalake",
        "arn:aws:iam::981599956623:user/maxd-etl-user",
      ]
    }
  }

  statement {
    sid    = ""
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-max-prod-reports-stage/*",
      "arn:aws:s3:::sme-max-prod-reports-stage",
    ]

    actions = [
      "s3:Put*",
      "s3:List*",
      "s3:Get*",
    ]

    principals {
      type = "AWS"

      identifiers = [
        "arn:aws:iam::718729873097:user/digsysd-vall002",
        "arn:aws:iam::981599956623:user/maxd-s3-user",
        "arn:aws:iam::718729873097:role/digsysd-digsysd-tools01",
      ]
    }
  }

  statement {
    sid    = "SecureDataTransportPolicy"
    effect = "Deny"

    resources = [
      "arn:aws:s3:::sme-max-prod-reports-stage/*",
      "arn:aws:s3:::sme-max-prod-reports-stage",
    ]

    actions = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "sme-max-stage-applogs" {
  statement {
    sid    = "Stmt1648708373861"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-max-stage-applogs/*",
      "arn:aws:s3:::sme-max-stage-applogs",
    ]

    actions = [
      "s3:PutObject",
      "s3:ListBucket",
      "s3:GetObject",
      "s3:GetBucketAcl",
      "s3:DeleteObject",
    ]

    principals {
      type = "AWS"

      identifiers = [
        "arn:aws:iam::981599956623:role/max2-logs-s3-lamda-role",
        "arn:aws:iam::981599956623:user/maxd-s3-stg-datalake",
      ]
    }
  }

  statement {
    sid    = "Stmt2"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-max-stage-applogs/*",
      "arn:aws:s3:::sme-max-stage-applogs",
    ]

    actions = [
      "s3:PutObject",
      "s3:ListBucket",
      "s3:GetObject",
      "s3:GetBucketAcl",
      "s3:DeleteObject",
    ]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::981599956623:role/max2-logs-s3-lamda-role"]
    }
  }

  statement {
    sid    = "AllowLogs"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-max-stage-applogs/*",
      "arn:aws:s3:::sme-max-stage-applogs",
    ]

    actions = [
      "s3:PutObject",
      "s3:GetObjectAcl",
      "s3:GetBucketAcl",
    ]

    condition {
      test     = "ArnLike"
      variable = "aws:SourceArn"
      values   = ["arn:aws:logs:*:*:*:*:*"]
    }

    principals {
      type        = "Service"
      identifiers = ["logs.eu-central-1.amazonaws.com"]
    }
  }

  statement {
    sid       = ""
    effect    = "Deny"
    resources = ["arn:aws:s3:::sme-max-stage-applogs/*"]
    actions   = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "sme-max-stage-dsrv-process-applogs" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-max-stage-dsrv-process-applogs"]
    actions   = ["s3:GetBucketAcl"]

    condition {
      test     = "StringEquals"
      variable = "aws:SourceAccount"
      values   = ["981599956623"]
    }

    condition {
      test     = "ArnLike"
      variable = "aws:SourceArn"
      values   = ["arn:aws:logs:eu-central-1:981599956623:log-group:maxs-dsrv-process-ecs:*"]
    }

    principals {
      type        = "Service"
      identifiers = ["logs.eu-central-1.amazonaws.com"]
    }
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-max-stage-dsrv-process-applogs/*"]
    actions   = ["s3:PutObject"]

    condition {
      test     = "StringEquals"
      variable = "aws:SourceAccount"
      values   = ["981599956623"]
    }

    condition {
      test     = "StringEquals"
      variable = "s3:x-amz-acl"
      values   = ["bucket-owner-full-control"]
    }

    condition {
      test     = "ArnLike"
      variable = "aws:SourceArn"
      values   = ["arn:aws:logs:eu-central-1:981599956623:log-group:maxs-dsrv-process-ecs:*"]
    }

    principals {
      type        = "Service"
      identifiers = ["logs.eu-central-1.amazonaws.com"]
    }
  }
}

data "aws_iam_policy_document" "sme-max-stage-eai-listener-applogs" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-max-stage-eai-listener-applogs"]
    actions   = ["s3:GetBucketAcl"]

    condition {
      test     = "StringEquals"
      variable = "aws:SourceAccount"
      values   = ["981599956623"]
    }

    condition {
      test     = "ArnLike"
      variable = "aws:SourceArn"
      values   = ["arn:aws:logs:eu-central-1:981599956623:log-group:maxs-eai-listener-ecs:*"]
    }

    principals {
      type        = "Service"
      identifiers = ["logs.eu-central-1.amazonaws.com"]
    }
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-max-stage-eai-listener-applogs/*"]
    actions   = ["s3:PutObject"]

    condition {
      test     = "StringEquals"
      variable = "aws:SourceAccount"
      values   = ["981599956623"]
    }

    condition {
      test     = "StringEquals"
      variable = "s3:x-amz-acl"
      values   = ["bucket-owner-full-control"]
    }

    condition {
      test     = "ArnLike"
      variable = "aws:SourceArn"
      values   = ["arn:aws:logs:eu-central-1:981599956623:log-group:maxs-eai-listener-ecs:*"]
    }

    principals {
      type        = "Service"
      identifiers = ["logs.eu-central-1.amazonaws.com"]
    }
  }
}

data "aws_iam_policy_document" "sme-max-stg-backfill-datalake" {
  statement {
    sid    = ""
    effect = "Deny"

    resources = [
      "arn:aws:s3:::sme-max-stg-backfill-datalake/*",
      "arn:aws:s3:::sme-max-stg-backfill-datalake",
    ]

    actions = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "sme-max-stg-datalake" {
  statement {
    sid    = "Stmt1575561694443"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-max-stg-datalake/*",
      "arn:aws:s3:::sme-max-stg-datalake",
    ]

    actions = ["s3:*"]

    principals {
      type = "AWS"

      identifiers = [
        "arn:aws:iam::981599956623:user/maxd-s3-stg-datalake",
        "arn:aws:iam::981599956623:role/Maxd-Admin02",
        "arn:aws:iam::981599956623:user/maxd-etl-user",
        "arn:aws:iam::981599956623:role/service-role/AWSAthenaSparkExecutionRole-v4clj5fk",
      ]
    }
  }

  statement {
    sid    = ""
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-max-stg-datalake/*",
      "arn:aws:s3:::sme-max-stg-datalake",
    ]

    actions = [
      "s3:Put*",
      "s3:List*",
      "s3:Get*",
    ]

    principals {
      type = "AWS"

      identifiers = [
        "arn:aws:iam::981599956623:user/maxd-s3-user",
        "arn:aws:iam::718729873097:user/digsysd-vall002",
        "arn:aws:iam::718729873097:role/digsysd-digsysd-tools01",
      ]
    }
  }

  statement {
    sid    = "SecureDataTransportPolicy"
    effect = "Deny"

    resources = [
      "arn:aws:s3:::sme-max-stg-datalake/*",
      "arn:aws:s3:::sme-max-stg-datalake",
    ]

    actions = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "sme-max-stg-perm-group-store" {
  statement {
    sid    = "Stmt1575561694443"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-max-stg-perm-group-store/*",
      "arn:aws:s3:::sme-max-stg-perm-group-store",
    ]

    actions = ["s3:*"]

    principals {
      type = "AWS"

      identifiers = [
        "arn:aws:iam::981599956623:role/maxRDSLoadFromS3",
        "arn:aws:iam::981599956623:user/maxd-etl-user",
        "arn:aws:iam::981599956623:user/maxd-s3-stg-datalake",
      ]
    }
  }

  statement {
    sid    = "SecureDataTransportPolicy"
    effect = "Deny"

    resources = [
      "arn:aws:s3:::sme-max-stg-perm-group-store/*",
      "arn:aws:s3:::sme-max-stg-perm-group-store",
    ]

    actions = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "sme-max-stg-perm-group-store-backfill" {
  statement {
    sid    = "Access for digimax_oh_data"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-max-stg-perm-group-store-backfill/*",
      "arn:aws:s3:::sme-max-stg-perm-group-store-backfill",
    ]

    actions = ["s3:*"]

    principals {
      type = "AWS"

      identifiers = [
        "arn:aws:iam::981599956623:user/maxd-etl-user",
        "arn:aws:iam::981599956623:user/maxd-s3-stg-datalake",
      ]
    }
  }

  statement {
    sid       = ""
    effect    = "Deny"
    resources = ["arn:aws:s3:::sme-max-stg-perm-group-store-backfill/*"]
    actions   = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-max-stg-perm-group-store-backfill"]
    actions   = ["s3:*"]

    principals {
      type = "AWS"

      identifiers = [
        "arn:aws:iam::981599956623:role/maxRDSLoadFromS3",
        "arn:aws:iam::981599956623:user/maxd-s3-stg-datalake",
      ]
    }
  }
}

data "aws_iam_policy_document" "sme-supply-chain-dev-awsconfig" {
  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-supply-chain-dev-awsconfig/*"]
    actions   = ["s3:GetObject"]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::797906716436:root"]
    }
  }

  statement {
    sid       = ""
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-supply-chain-dev-awsconfig"]
    actions   = ["s3:ListBucket"]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::797906716436:root"]
    }
  }

  statement {
    sid       = "Stmt1541094687595"
    effect    = "Deny"
    resources = ["arn:aws:s3:::sme-supply-chain-dev-awsconfig"]
    actions   = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "sme-supply-chain-dev-us-east-1-logs" {
  statement {
    sid       = ""
    effect    = "Deny"
    resources = ["arn:aws:s3:::sme-supply-chain-dev-us-east-1-logs/*"]
    actions   = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }

  statement {
    sid       = "Stmt1554228043940"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-supply-chain-dev-us-east-1-logs/*"]
    actions   = ["s3:PutObject"]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::127311923021:root"]
    }
  }

  statement {
    sid       = "S3PolicyStmt-DO-NOT-MODIFY-1645146356170"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-supply-chain-dev-us-east-1-logs/*"]
    actions   = ["s3:PutObject"]

    principals {
      type        = "Service"
      identifiers = ["logging.s3.amazonaws.com"]
    }
  }
}

data "aws_iam_policy_document" "sme-supply-chain-max-dev-athena-out" {
  statement {
    sid    = ""
    effect = "Deny"

    resources = [
      "arn:aws:s3:::sme-supply-chain-max-dev-athena-out/*",
      "arn:aws:s3:::sme-supply-chain-max-dev-athena-out",
    ]

    actions = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "sme-supply-chain-max-dev-eailistener-processor-s3" {
  statement {
    sid    = ""
    effect = "Deny"

    resources = [
      "arn:aws:s3:::sme-supply-chain-max-dev-eailistener-processor-s3/*",
      "arn:aws:s3:::sme-supply-chain-max-dev-eailistener-processor-s3",
    ]

    actions = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "sme-supply-chain-max-dev-euc1-s3-inventory" {
  statement {
    sid       = "S3PolicyStmt-DO-NOT-MODIFY-1603804496875"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-supply-chain-max-dev-euc1-s3-inventory/*"]
    actions   = ["s3:PutObject"]

    condition {
      test     = "StringEquals"
      variable = "s3:x-amz-acl"
      values   = ["bucket-owner-full-control"]
    }

    condition {
      test     = "StringEquals"
      variable = "aws:SourceAccount"
      values   = ["981599956623"]
    }

    condition {
      test     = "ArnLike"
      variable = "aws:SourceArn"
      values   = ["arn:aws:s3:::*"]
    }

    principals {
      type        = "Service"
      identifiers = ["s3.amazonaws.com"]
    }
  }

  statement {
    sid    = "SecureDataTransportPolicy"
    effect = "Deny"

    resources = [
      "arn:aws:s3:::sme-supply-chain-max-dev-euc1-s3-inventory/*",
      "arn:aws:s3:::sme-supply-chain-max-dev-euc1-s3-inventory",
    ]

    actions = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "sme-supply-chain-max-dev-max-d2-vpc-flow-logs" {
  statement {
    sid       = "AWSLogDeliveryWrite"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-supply-chain-max-dev-max-d2-vpc-flow-logs/AWSLogs/981599956623/*"]
    actions   = ["s3:PutObject"]

    condition {
      test     = "StringEquals"
      variable = "s3:x-amz-acl"
      values   = ["bucket-owner-full-control"]
    }

    principals {
      type        = "Service"
      identifiers = ["delivery.logs.amazonaws.com"]
    }
  }

  statement {
    sid       = "AWSLogDeliveryAclCheck"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-supply-chain-max-dev-max-d2-vpc-flow-logs"]
    actions   = ["s3:GetBucketAcl"]

    principals {
      type        = "Service"
      identifiers = ["delivery.logs.amazonaws.com"]
    }
  }

  statement {
    sid    = "SecureDataTransportPolicy"
    effect = "Deny"

    resources = [
      "arn:aws:s3:::sme-supply-chain-max-dev-max-d2-vpc-flow-logs/*",
      "arn:aws:s3:::sme-supply-chain-max-dev-max-d2-vpc-flow-logs",
    ]

    actions = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "sme-supply-chain-max-dev-ohstream-processor-s3" {
  statement {
    sid    = "Stmt1645136583711"
    effect = "Allow"

    resources = [
      "arn:aws:s3:::sme-supply-chain-max-dev-ohstream-processor-s3/*",
      "arn:aws:s3:::sme-supply-chain-max-dev-ohstream-processor-s3",
    ]

    actions = ["s3:*"]

    principals {
      type = "AWS"

      identifiers = [
        "arn:aws:iam::981599956623:user/maxd-s3-stg-datalake",
        "arn:aws:iam::981599956623:user/maxd-etl-user",
        "arn:aws:iam::504436705349:user/maxp-s3-prod-datalake",
      ]
    }
  }
}

data "aws_iam_policy_document" "sme-supply-chain-max-dev-s3-ff-logs" {
  statement {
    sid    = ""
    effect = "Deny"

    resources = [
      "arn:aws:s3:::sme-supply-chain-max-dev-s3-ff-logs/*",
      "arn:aws:s3:::sme-supply-chain-max-dev-s3-ff-logs",
    ]

    actions = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }

  statement {
    sid       = "S3PolicyStmt-DO-NOT-MODIFY-1643259874113"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-supply-chain-max-dev-s3-ff-logs/*"]

    actions = [
      "s3:PutObjectAcl",
      "s3:PutObject",
    ]

    principals {
      type        = "Service"
      identifiers = ["logging.s3.amazonaws.com"]
    }
  }
}

data "aws_iam_policy_document" "sme-supply-chain-max-dev-ssm-out" {
  statement {
    sid    = ""
    effect = "Deny"

    resources = [
      "arn:aws:s3:::sme-supply-chain-max-dev-ssm-out/*",
      "arn:aws:s3:::sme-supply-chain-max-dev-ssm-out",
    ]

    actions = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "sme-supply-chain-max-dev-use1-s3-inventory" {
  statement {
    sid       = "S3PolicyStmt-DO-NOT-MODIFY-1603804496875"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-supply-chain-max-dev-use1-s3-inventory/*"]
    actions   = ["s3:PutObject"]

    condition {
      test     = "StringEquals"
      variable = "aws:SourceAccount"
      values   = ["981599956623"]
    }

    condition {
      test     = "StringEquals"
      variable = "s3:x-amz-acl"
      values   = ["bucket-owner-full-control"]
    }

    condition {
      test     = "ArnLike"
      variable = "aws:SourceArn"
      values   = ["arn:aws:s3:::*"]
    }

    principals {
      type        = "Service"
      identifiers = ["s3.amazonaws.com"]
    }
  }

  statement {
    sid    = "SecureDataTransportPolicy"
    effect = "Deny"

    resources = [
      "arn:aws:s3:::sme-supply-chain-max-dev-use1-s3-inventory/*",
      "arn:aws:s3:::sme-supply-chain-max-dev-use1-s3-inventory",
    ]

    actions = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "sme-supply-chain-max-prod" {
  statement {
    sid    = ""
    effect = "Deny"

    resources = [
      "arn:aws:s3:::sme-supply-chain-max-prod/*",
      "arn:aws:s3:::sme-supply-chain-max-prod",
    ]

    actions = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "supply-chain-dev-rds-log-backup" {
  statement {
    sid       = ""
    effect    = "Deny"
    resources = ["arn:aws:s3:::supply-chain-dev-rds-log-backup/*"]
    actions   = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "supplychain-dev-rman-backups" {
  statement {
    sid       = ""
    effect    = "Deny"
    resources = ["arn:aws:s3:::supplychain-dev-rman-backups/*"]
    actions   = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "vpc-max-dev-vpc-flow-logs" {
  statement {
    sid       = "AWSLogDeliveryWrite"
    effect    = "Allow"
    resources = ["arn:aws:s3:::vpc-max-dev-vpc-flow-logs/AWSLogs/981599956623/*"]
    actions   = ["s3:PutObject"]

    condition {
      test     = "StringEquals"
      variable = "s3:x-amz-acl"
      values   = ["bucket-owner-full-control"]
    }

    principals {
      type        = "Service"
      identifiers = ["delivery.logs.amazonaws.com"]
    }
  }

  statement {
    sid       = "AWSLogDeliveryAclCheck"
    effect    = "Allow"
    resources = ["arn:aws:s3:::vpc-max-dev-vpc-flow-logs"]
    actions   = ["s3:GetBucketAcl"]

    principals {
      type        = "Service"
      identifiers = ["delivery.logs.amazonaws.com"]
    }
  }

  statement {
    sid    = "SecureDataTransportPolicy"
    effect = "Deny"

    resources = [
      "arn:aws:s3:::vpc-max-dev-vpc-flow-logs/*",
      "arn:aws:s3:::vpc-max-dev-vpc-flow-logs",
    ]

    actions = ["*"]

    condition {
      test     = "Bool"
      variable = "aws:SecureTransport"
      values   = ["false"]
    }

    principals {
      type        = "*"
      identifiers = ["*"]
    }
  }
}

data "aws_iam_policy_document" "sme-gluetest" {
}

data "aws_iam_policy_document" "sme-dr-dev-dataload" {
}

data "aws_iam_policy_document" "sme-for-mike-gupta" {
  statement {
    sid    = "Listbucket"
    effect = "Allow"
    actions = [
      "s3:GetBucketLocation",
      "s3:ListBucket"
    ]
    resources = [
      "arn:aws:s3:::sme.for.mike.gupta"
    ]
    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::197559811661:root"]
    }
  }

  statement {
    sid     = "GetObjects"
    effect  = "Allow"
    actions = ["s3:GetObject"]
    resources = [
      "arn:aws:s3:::sme.for.mike.gupta/*"
    ]
    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::197559811661:root"]
    }
  }
}

data "aws_iam_policy_document" "sme-max-dev-datalake" {
  version = "2012-10-17"

  statement {
    sid    = "Access for digimax oh data"
    effect = "Allow"
    principals {
      type = "AWS"
      identifiers = [
        "arn:aws:iam::981599956623:user/maxd-etl-user",
        "arn:aws:iam::981599956623:role/Maxd-Admin02"
      ]
    }
    actions = ["s3:*"]
    resources = [
      "arn:aws:s3:::sme.max.dev.datalake/*",
      "arn:aws:s3:::sme.max.dev.datalake"
    ]
  }

  statement {
    effect = "Allow"
    principals {
      type = "AWS"
      identifiers = [
        "arn:aws:iam::718729873097:role/digsysd-digsysd-tools01",
        "arn:aws:iam::981599956623:user/maxd-s3-user",
        "arn:aws:iam::718729873097:user/digsysd-vall002"
      ]
    }
    actions = [
      "s3:List*",
      "s3:Get*",
      "s3:Put*"
    ]
    resources = [
      "arn:aws:s3:::sme.max.dev.datalake",
      "arn:aws:s3:::sme.max.dev.datalake/*"
    ]
  }

  statement {
    effect = "Allow"
    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::981599956623:role/maxRDSLoadFromS3"]
    }
    actions   = ["s3:*"]
    resources = ["arn:aws:s3:::sme.max.dev.datalake"]
  }
}

data "aws_iam_policy_document" "sme_supply_chain_max_dev_max_u3_vpc_flow_logs" {
  statement {
    sid       = "AWSLogDeliveryWrite"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-supply-chain-max-dev-max-u3-vpc-flow-logs/AWSLogs/981599956623/*"]
    actions   = ["s3:PutObject"]

    condition {
      test     = "StringEquals"
      variable = "s3:x-amz-acl"
      values   = ["bucket-owner-full-control"]
    }

    principals {
      type        = "Service"
      identifiers = ["delivery.logs.amazonaws.com"]
    }
  }

  statement {
    sid       = "AWSLogDeliveryAclCheck"
    effect    = "Allow"
    resources = ["arn:aws:s3:::sme-supply-chain-max-dev-max-u3-vpc-flow-logs"]
    actions   = ["s3:GetBucketAcl"]

    principals {
      type        = "Service"
      identifiers = ["delivery.logs.amazonaws.com"]
    }
  }
}
