fn allow_s3_policy(queue_arn: &str, bucket: &str, self_account: &str) -> String