resource "alks_iamrole" "role" { tags = {"coxauto:ci-id" = var.ciid} name = "${var.short_name}" type = "Amazon EC2 Container Service Task Role" include_default_policies = true } resource "aws_iam_role_policy" "ecr_allow_policy" { name = "${var.short_name}_ecr_allow_policy" role = "${alks_iamrole.role.name}" policy = <