resource "aws_iam_role" "demo-codepipeline" { name = "demo-codepipeline" assume_role_policy = <