resource "aws_iam_role" "cloudtrail_log_group_role" { name = aws_s3_bucket.cloudtrail_bucket.id tags = var.tags assume_role_policy = <