resource "aws_iam_role" "app_role" { name = "app_role" path = "/" assume_role_policy = <