I am trying to create an IAM policy for a lambda role which will give permissions to delete an object. If I do not specify the resource this policy works, but I would like t