» Resource: aws_iam_policy_attachment

Attaches a Managed IAM Policy to user(s), role(s), and/or group(s)

» Example Usage

resource "aws_iam_user" "user" {
  name = "test-user"

resource "aws_iam_role" "role" {
  name = "test-role"
  assume_role_policy = <<EOF
  "Version": "2012-10-17",
  "Statement": [
      "Action": "sts:AssumeRole",
      "Principal": {
        "Service": "ec2.amazonaws.com"
      "Effect": "Allow",
      "Sid": ""

resource "aws_iam_group" "group" {
  name = "test-group"

resource "aws_iam_policy" "policy" {
  name        = "test-policy"
  description = "A test policy"
  policy = <<EOF
  "Version": "2012-10-17",
  "Statement": [
      "Action": [
      "Effect": "Allow",
      "Resource": "*"

resource "aws_iam_policy_attachment" "test-attach" {
  name       = "test-attachment"
  users      = ["${aws_iam_user.user.name}"]
  roles      = ["${aws_iam_role.role.name}"]
  groups     = ["${aws_iam_group.group.name}"]
  policy_arn = "${aws_iam_policy.policy.arn}"

» Argument Reference

The following arguments are supported:

  • name (Required) - The name of the attachment. This cannot be an empty string.
  • users (Optional) - The user(s) the policy should be applied to
  • roles (Optional) - The role(s) the policy should be applied to
  • groups (Optional) - The group(s) the policy should be applied to
  • policy_arn (Required) - The ARN of the policy you want to apply

» Attributes Reference

In addition to all arguments above, the following attributes are exported:

  • id - The policy's ID.
  • name - The name of the attachment.