Files
acdl/modules/l1/iam-role
Jon Chery 2682719f24
acdl-ci / Lint (push) Successful in 7s
acdl-ci / Test (push) Successful in 26s
acdl-ci / Platform check-only (offline) (push) Successful in 8s
docs(P47): presentation slide updates + HIPAA removal from all docs
Presentation changes (both Marp decks + source markdown):
1. Title slide: deck title as H1 (slightly bigger), 'Agentic Cloud Delivery
   Platform' as H3 subtitle — cleaner title hierarchy
2. DX deck: removed Local Reproducibility slide (not beneficial for DX)
3. DX deck: Safe Promotion Path slide redesigned with side-by-side layout
   for Approaches A and B (HTML table, two columns)
4. DX deck: 'an agent' → 'an AI agent' (slide 2 + Citizen Developer slide)
5. DX deck: What a Developer Does — diagram floated to the right side
6. Header simplified to just the deck name (subtitle now on title slide)

HIPAA removal (25 files):
- Completely removed all HIPAA references from all markdown documentation,
  presentation source files, module READMEs, and rendered HTML
- Removed HIPAA from compliance milestone lists (GDPR, SOX, SOC2, DORA remain)
- Removed HIPAA section references (§164.xxx) from compliance annotations
- Cleaned up empty parentheses and broken commas left by removal
- Re-rendered both HTML decks from updated Marp source

---ci---
phase: 47
milestone: v1.9
status: complete
requirements:
  covered: []
  partial: []
---/ci---
2026-07-23 14:08:40 +00:00
..

iam-role — IAM role

Module kind: primitive | Version: 1.0.0

A single IAM role with an assume-role policy and optional managed policy attachments. Used as the ECS task execution role.

Resources

Resource Type Purpose
role aws_iam_role The IAM role with assume-role policy

Inputs

Name Type Required Default Description
role_name string yes The IAM role name
assume_role_policy string yes Assume-role policy document (JSON string)
managed_policies string no Comma-separated list of managed policy ARNs to attach
region string yes AWS region the role is created in

Outputs

Name Type Description
role_arn arn The IAM role ARN
role_id string The IAM role id

Usage

{
  "id": "roles",
  "type": "aws:iam:role",
  "module": "iam-role@1.0.0",
  "inputs": {
    "role_name": "acdl-microservice-exec",
    "assume_role_policy": "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Effect\":\"Allow\",\"Principal\":{\"Service\":\"ecs-tasks.amazonaws.com\"},\"Action\":\"sts:AssumeRole\"}]}",
    "managed_policies": "arn:aws:iam::aws:policy/service-role/AmazonECSTaskExecutionRolePolicy",
    "region": "us-east-1"
  }
}

The assume_role_policy is a JSON string — the adapter jsonencodes it into the Terraform assume_role_policy argument. The managed_policies input is a comma-separated list of ARNs, emitted as managed_policy_arns = [...].

Compliance extension points

  • Permissions boundary — add permissions_boundary to enforce least-privilege guardrails (SOC2 CC6.1, SOX ITGC, DORA ICT access control).
  • Inline policy — add aws_iam_role_policy for fine-grained least-privilege instead of broad managed policies (SOC2 CC6.1.
  • MFA conditions — add condition blocks requiring MFA for assume-role (SOC2 CC6.1.
  • Source IP / region conditions — add aws:SourceIp / aws:RequestedRegion conditions for data residency enforcement (GDPR Art.44-49, DORA ICT third-party risk).
  • Access Analyzer — add aws_accessanalyzer_analyzer to verify least-privilege (SOC2 CC6.1, GDPR Art.32).
  • Role separation — add a separate task role vs. execution role (SOC2 CC6.3 segregation of duties).

Examples

Validated example contracts are in examples/. The platform-test pipeline validates them against schemas/contract.schema.json.

Simple

A minimal deployment:

examples/simple.yaml

uses: acdl/pipelines/deploy.yaml@v1.6
module: iam-role
environment: dev
inputs:
  name: my-task-role
  region: us-east-1

Complex

A production deployment with optional inputs:

examples/complex.yaml

# Complex IAM role with managed policies
uses: acdl/pipelines/deploy.yaml@v1.6
module: iam-role
environment: dev
inputs:
  name: my-production-task-role
  region: us-east-1

Versioning

1.0.0 — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps require a new registry entry (immutable publication); old entries enter a 12-month deprecation window.