resource "aws_config_config_rule" "sg_attached" { name = "ec2-security-group-attached-to-eni" source { owner = "AWS" source_identifier = "EC2_SECURITY_GROUP_ATTACHED_TO_ENI" } } resource "aws_iam_role" "aws_config_sg_attached_remediation_role" { name = "aws_config_sg_attached_remediation_role" assume_role_policy = <