Files
acdl/modules-ir/l1/l1-iam-role/README.md
T
Jon Chery 4ed2542ecf docs(P13): plan-as-execute + verify (v1.2.3)
---ci---
project: acdl
phase: 13
milestone: v1.2
status: verify
verdict: VERIFIED
requirements:
  covered: [REQ-31]
---/ci---

Phase 13 plan-as-execute + verify. scripts/verify_phase13.sh green.
6 ECS L1s authored + registered (l1-vpc, l1-ecs-cluster, l1-ecs-service,
l1-iam-role, l1-alb, l1-ecr). Adapter generalized to table-driven
TYPE_MAP (12 IR types) + INPUT_MAP + OUTPUT_MAP. S3 regression: the v1.1
spike l1-s3 produces byte-identical main.tf. Ready to ship v1.2.3.
2026-07-21 21:05:48 +00:00

36 lines
1.5 KiB
Markdown

# l1-iam-role — IAM role primitive
An L1 module for an IAM role (used as the ECS task execution role).
Single-purpose, substrate-agnostic (the IR type is `aws:iam:role`, not a
Terraform resource type).
## Interface (the IR-typed contract)
See `interface.json`: inputs `role_name` (string), `assume_role_policy`
(JSON string), `managed_policies` (optional comma-separated ARNs),
`region` (string); outputs `role_arn` (arn) + `role_id` (string), no
NFRs.
## IR → Terraform mapping (performed by the adapter)
The Terraform adapter (`adapters/terraform/adapter.py`) translates this
L1's IR shape to Terraform:
| IR | Terraform |
|----|-----------|
| `resource.type = aws:iam:role` | `resource "aws_iam_role" "<id>" { ... }` |
| `resource.inputs.role_name` | `name = <value>` arg |
| `resource.inputs.assume_role_policy` | `assume_role_policy = <value>` arg (JSON string) |
| `resource.inputs.managed_policies` | `managed_policy_arns = [<arns>]` arg (comma-split) |
| `resource.inputs.region` | `provider "aws" { region = <value> }` |
| `resource.outputs.role_arn` | `output "role_arn" { value = aws_iam_role.<id>.arn }` |
| `resource.outputs.role_id` | `output "role_id" { value = aws_iam_role.<id>.id }` |
The adapter is a thin layer (ARCHITECTURE.md §12.2); it does not own L1
content — it only translates.
## Versioning (W3.D)
`1.0.0` — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps
require a new registry entry (immutable publication); old entries enter
a 12-month deprecation window.