diff --git a/infrastructure/terraform/modules/eventsub/iam_role_sns.tf b/infrastructure/terraform/modules/eventsub/iam_role_sns.tf index 97bdc99..294e392 100644 --- a/infrastructure/terraform/modules/eventsub/iam_role_sns.tf +++ b/infrastructure/terraform/modules/eventsub/iam_role_sns.tf @@ -48,4 +48,17 @@ data "aws_iam_policy_document" "firehose_delivery" { "${aws_kinesis_firehose_delivery_stream.main[0].arn}", ] } + statement { + sid = "AllowKmsAccessForFirehoseDelivery" + effect = "Allow" + + actions = [ + "kms:GenerateDataKey", + "kms:Decrypt", + ] + + resources = [ + var.kms_key_arn, + ] + } }