diff --git a/role/main.tf b/role/main.tf index 97a05bd..17994c7 100644 --- a/role/main.tf +++ b/role/main.tf @@ -1,10 +1,5 @@ data "aws_caller_identity" "current" {} -variable "namespace" { - type = string - default = "${var.NameSpace != null ? var.NameSpace : var.GroupName}" -} - # ROLES resource "aws_iam_role" "api-service-role" { name = "${var.GroupName}-api-service-role" @@ -27,7 +22,7 @@ resource "aws_iam_role" "api-service-role" { "Condition": { "StringEquals": { "oidc.eks.us-east-1.amazonaws.com/id/${var.OIDCProviderID}:aud": "sts.amazonaws.com", - "oidc.eks.us-east-1.amazonaws.com/id/${var.OIDCProviderID}:sub": "system:serviceaccount:${var.namespace}:${var.GroupName}-api-service-account" + "oidc.eks.us-east-1.amazonaws.com/id/${var.OIDCProviderID}:sub": "system:serviceaccount:${var.NameSpace != null ? var.NameSpace : var.GroupName}:${var.GroupName}-api-service-account" } } }] @@ -56,7 +51,7 @@ resource "aws_iam_role" "job-scheduler-service-role" { "Condition": { "StringEquals": { "oidc.eks.us-east-1.amazonaws.com/id/${var.OIDCProviderID}:aud": "sts.amazonaws.com", - "oidc.eks.us-east-1.amazonaws.com/id/${var.OIDCProviderID}:sub": "system:serviceaccount:${var.namespace}:${var.GroupName}-job-scheduler-service-account" + "oidc.eks.us-east-1.amazonaws.com/id/${var.OIDCProviderID}:sub": "system:serviceaccount:${var.NameSpace != null ? var.NameSpace : var.GroupName}:${var.GroupName}-job-scheduler-service-account" } } }]