ecr.tf: restore Vault account access to ecr_pushpull_role

At some point it seems like the sts:AssumeRole permission was
dropped for the Vault ARN and limited to only ec2 instances.

This adds the Vault ARN back in as a principal which should
restore their access.

Change-Id: I993bd05b8bd8f441444f50890e514ea74ccbf911
1 file changed