= "terraform-automation" assume_role_policy = jsonencode({ Version = "2012-10-17" Statement = [ { Action = "sts:AssumeRoleWithWebIdentity", Effect = "Allow" Sid = "TerraformCloudAccess", Principal = { Federated = "arn:aws:iam::xxxxxx:oidc-provider/app.terraform.io" } Condition = { StringLike = { "app.terraform.io:aud" = ["aws.workload.identity"] } } }, ] }) }