diff --git a/modules/iam-assumable-role-with-oidc/main.tf b/modules/iam-assumable-role-with-oidc/main.tf index 216b299f..bf49dd74 100644 --- a/modules/iam-assumable-role-with-oidc/main.tf +++ b/modules/iam-assumable-role-with-oidc/main.tf @@ -71,6 +71,12 @@ data "aws_iam_policy_document" "assume_role_with_oidc" { } } + condition { + test = "ForAllValues:StringEquals" + variable = "${statement.value}:iss" + values = ["https://${statement.value}"] + } + dynamic "condition" { for_each = length(var.oidc_fully_qualified_audiences) > 0 ? local.urls : []