OpenTofu used the selected providers to generate the following execution
plan. Resource actions are indicated with the following symbols:
  + create
  ~ update in-place
  - destroy
  -/+ destroy and then create replacement

OpenTofu will perform the following actions:

  # aws_s3_bucket.audit_logs will be created
  + resource "aws_s3_bucket" "audit_logs" {
      + bucket = "audit-logs-prod"
    }

  # module.app_role.aws_iam_role.this will be updated in-place
  ~ resource "aws_iam_role" "this" {
        name = "app-role"
      ~ assume_role_policy = jsonencode(
            ~ {
              ...
            }
        )
    }

  # aws_security_group.legacy will be destroyed
  - resource "aws_security_group" "legacy" {
      - id = "sg-123" -> null
    }

  # aws_iam_user.svc must be replaced
-/+ resource "aws_iam_user" "svc" {
      ~ name = "old" -> "new" # forces replacement
    }

Plan: 2 to add, 1 to change, 1 to destroy.
