# iam-role — IAM role > **Module kind:** primitive | **Version:** 1.0.0 A single IAM role with an assume-role policy and optional managed policy attachments. Used as the ECS task execution role. ## Resources | Resource | Type | Purpose | |----------|------|---------| | role | `aws_iam_role` | The IAM role with assume-role policy | ## Inputs | Name | Type | Required | Default | Description | |------|------|----------|---------|-------------| | `role_name` | string | yes | — | The IAM role name | | `assume_role_policy` | string | yes | — | Assume-role policy document (JSON string) | | `managed_policies` | string | no | — | Comma-separated list of managed policy ARNs to attach | | `region` | string | yes | — | AWS region the role is created in | ## Outputs | Name | Type | Description | |------|------|-------------| | `role_arn` | arn | The IAM role ARN | | `role_id` | string | The IAM role id | ## Usage ```json { "id": "roles", "type": "aws:iam:role", "module": "iam-role@1.0.0", "inputs": { "role_name": "acdl-microservice-exec", "assume_role_policy": "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Effect\":\"Allow\",\"Principal\":{\"Service\":\"ecs-tasks.amazonaws.com\"},\"Action\":\"sts:AssumeRole\"}]}", "managed_policies": "arn:aws:iam::aws:policy/service-role/AmazonECSTaskExecutionRolePolicy", "region": "us-east-1" } } ``` The `assume_role_policy` is a JSON string — the adapter jsonencodes it into the Terraform `assume_role_policy` argument. The `managed_policies` input is a comma-separated list of ARNs, emitted as `managed_policy_arns = [...]`. ## Compliance extension points - **Permissions boundary** — add `permissions_boundary` to enforce least-privilege guardrails (SOC2 CC6.1, SOX ITGC, DORA ICT access control). - **Inline policy** — add `aws_iam_role_policy` for fine-grained least-privilege instead of broad managed policies (SOC2 CC6.1, HIPAA §164.308(a)(4)). - **MFA conditions** — add `condition` blocks requiring MFA for assume-role (SOC2 CC6.1, HIPAA §164.312(d)). - **Source IP / region conditions** — add `aws:SourceIp` / `aws:RequestedRegion` conditions for data residency enforcement (GDPR Art.44-49, DORA ICT third-party risk). - **Access Analyzer** — add `aws_accessanalyzer_analyzer` to verify least-privilege (SOC2 CC6.1, GDPR Art.32). - **Role separation** — add a separate task role vs. execution role (SOC2 CC6.3 segregation of duties). ## Examples Validated example contracts are in [`examples/`](examples/). The platform-test pipeline validates them against `schemas/contract.schema.json`. ### Simple A minimal deployment: [`examples/simple.yaml`](examples/simple.yaml) ```yaml uses: acdl/pipelines/deploy.yaml@v1.6 module: iam-role environment: dev inputs: name: my-task-role region: us-east-1 ``` ### Complex A production deployment with optional inputs: [`examples/complex.yaml`](examples/complex.yaml) ```yaml # Complex IAM role with managed policies uses: acdl/pipelines/deploy.yaml@v1.6 module: iam-role environment: dev inputs: name: my-production-task-role region: us-east-1 ``` ## Versioning `1.0.0` — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps require a new registry entry (immutable publication); old entries enter a 12-month deprecation window.