Files
acdl/modules-ir/l1/l1-iam-role
Jon Chery 4ed2542ecf docs(P13): plan-as-execute + verify (v1.2.3)
---ci---
project: acdl
phase: 13
milestone: v1.2
status: verify
verdict: VERIFIED
requirements:
  covered: [REQ-31]
---/ci---

Phase 13 plan-as-execute + verify. scripts/verify_phase13.sh green.
6 ECS L1s authored + registered (l1-vpc, l1-ecs-cluster, l1-ecs-service,
l1-iam-role, l1-alb, l1-ecr). Adapter generalized to table-driven
TYPE_MAP (12 IR types) + INPUT_MAP + OUTPUT_MAP. S3 regression: the v1.1
spike l1-s3 produces byte-identical main.tf. Ready to ship v1.2.3.
2026-07-21 21:05:48 +00:00
..

l1-iam-role — IAM role primitive

An L1 module for an IAM role (used as the ECS task execution role). Single-purpose, substrate-agnostic (the IR type is aws:iam:role, not a Terraform resource type).

Interface (the IR-typed contract)

See interface.json: inputs role_name (string), assume_role_policy (JSON string), managed_policies (optional comma-separated ARNs), region (string); outputs role_arn (arn) + role_id (string), no NFRs.

IR → Terraform mapping (performed by the adapter)

The Terraform adapter (adapters/terraform/adapter.py) translates this L1's IR shape to Terraform:

IR Terraform
resource.type = aws:iam:role resource "aws_iam_role" "<id>" { ... }
resource.inputs.role_name name = <value> arg
resource.inputs.assume_role_policy assume_role_policy = <value> arg (JSON string)
resource.inputs.managed_policies managed_policy_arns = [<arns>] arg (comma-split)
resource.inputs.region provider "aws" { region = <value> }
resource.outputs.role_arn output "role_arn" { value = aws_iam_role.<id>.arn }
resource.outputs.role_id output "role_id" { value = aws_iam_role.<id>.id }

The adapter is a thin layer (ARCHITECTURE.md §12.2); it does not own L1 content — it only translates.

Versioning (W3.D)

1.0.0 — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps require a new registry entry (immutable publication); old entries enter a 12-month deprecation window.