forked from GSA/grace-inventory
-
Notifications
You must be signed in to change notification settings - Fork 0
/
lambda.tf
36 lines (33 loc) · 1.33 KB
/
lambda.tf
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
#tfsec:ignore:aws-lambda-enable-tracing
resource "aws_lambda_function" "lambda_function" {
filename = var.source_file
function_name = local.app_name
description = "Creates report of AWS Services in Organization accounts and saves to Excel spreadsheet in S3 bucket"
role = aws_iam_role.iam_role.arn
handler = "grace-inventory-lambda"
memory_size = var.lambda_memory
source_code_hash = filebase64sha256(var.source_file)
kms_key_arn = aws_kms_key.kms_key.arn
runtime = "go1.x"
timeout = 900
environment {
variables = {
accounts_info = var.accounts_info
kms_key_id = aws_kms_key.kms_key.key_id
master_role_name = var.master_role_name
master_account_id = var.master_account_id
// organizational_units = "${organizational_units}"
regions = var.regions
s3_bucket = aws_s3_bucket.bucket.bucket
tenant_role_name = var.tenant_role_name
sheets = var.sheets
}
}
}
resource "aws_lambda_permission" "lambda_permission" {
statement_id = "AllowExecutionFromCloudWatch"
action = "lambda:InvokeFunction"
function_name = aws_lambda_function.lambda_function.function_name
principal = "events.amazonaws.com"
source_arn = aws_cloudwatch_event_rule.cwe_rule.arn
}