diff --git a/modules/services/workload-scanning/main.tf b/modules/services/workload-scanning/main.tf index 983c165..f4780b3 100644 --- a/modules/services/workload-scanning/main.tf +++ b/modules/services/workload-scanning/main.tf @@ -41,7 +41,7 @@ data "aws_iam_policy_document" "scanning" { } } -resource "aws_iam_policy" "scanning" { +resource "aws_iam_policy" "ecr_scanning" { count = (var.deploy_global_resources || var.is_organizational) ? 1 : 0 name = var.name @@ -88,5 +88,5 @@ resource "aws_iam_policy_attachment" "scanning" { name = var.name roles = [aws_iam_role.scanning[0].name] - policy_arn = aws_iam_policy.scanning[0].arn + policy_arn = aws_iam_policy.ecr_scanning[0].arn } diff --git a/modules/services/workload-scanning/organizational.tf b/modules/services/workload-scanning/organizational.tf index f3ee675..01efd34 100644 --- a/modules/services/workload-scanning/organizational.tf +++ b/modules/services/workload-scanning/organizational.tf @@ -41,7 +41,7 @@ resource "aws_cloudformation_stack_set" "scanning_role_stackset" { template_body = <