# # iam roles # resource "aws_iam_role" "demo-codebuild" { name = "demo-codebuild" assume_role_policy = <