Files
acdl/modules/l1/iam-role
Jon Chery 7585c828f0
acdl-ci / Lint (push) Successful in 7s
acdl-ci / Test (push) Successful in 23s
acdl-ci / Platform check-only (offline) (push) Successful in 8s
docs(P48): vision gaps + badge system + substrate→engine + CR format + agentic tags
9 requirements implemented across presentation decks and project docs:

1. DX closing slide: added 'Infrastructure as a utility, not a craft' bullet
   to convey the full vision (infrastructure consumed, not maintained;
   platform compounds value over time).
2. PW Problem slide: 'moving a merged change' → 'promoting a change'.
3. PW Problem slide: added 'Red tape' and 'Scalability without increasing
   headcount' bullets (4 frictions, not 2).
4. PW Roadmap slide: redesigned with side-by-side HTML table layout
   (Testing | Planned), 16px font, no overflow.
5. PW deck: added new slide 'What This Platform Is — and Isn't' after North
   Star (sovereign boundary, infrastructure as utility, 4 anti-goals).
   PW deck now 16 slides (was 15).
6. Maturity nomenclature: 'Available today'/'shipped' → 'Testing' across
   both decks + source markdown. New .testing badge (blue/teal #DBEAFE).
   Roadmap title: 'Testing vs. Planned'. The platform has 0 consumer
   adoption — 'shipped' was inaccurate.
7. Global: 'substrate' → 'engine' across entire project (88 matches, 30+
   files including .ciagent/, docs/, modules/, adapters/, schemas/, code).
8. Presentation files only: 'forge' → 'VCS' / 'version control system'
   (6 occurrences in 4 files). 'forge' retained in all technical docs and
   code as the industry-standard term.
9. New .agentic badge (purple/violet #EDE9FE) appended to agentic features
   in both decks: confidence signal, autonomous dev, pattern recognition,
   dynamic module creation, citizen developer surface, auto-promotion.

Also: Change Request ID format changed from 'CR-2026-001' to 'CHG0678912'
across presentation files, consumer guide, and test fixtures.

HTML re-rendered. PPTX rendered for release upload.

---ci---
phase: 48
milestone: v1.9
status: complete
requirements:
  covered: []
  partial: []
---/ci---
2026-07-23 14:58:29 +00:00
..

iam-role — IAM role

Module kind: primitive | Version: 1.0.0

A single IAM role with an assume-role policy and optional managed policy attachments. Used as the ECS task execution role.

Resources

Resource Type Purpose
role aws_iam_role The IAM role with assume-role policy

Inputs

Name Type Required Default Description
role_name string yes The IAM role name
assume_role_policy string yes Assume-role policy document (JSON string)
managed_policies string no Comma-separated list of managed policy ARNs to attach
region string yes AWS region the role is created in

Outputs

Name Type Description
role_arn arn The IAM role ARN
role_id string The IAM role id

Usage

{
  "id": "roles",
  "type": "aws:iam:role",
  "module": "iam-role@1.0.0",
  "inputs": {
    "role_name": "acdl-microservice-exec",
    "assume_role_policy": "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Effect\":\"Allow\",\"Principal\":{\"Service\":\"ecs-tasks.amazonaws.com\"},\"Action\":\"sts:AssumeRole\"}]}",
    "managed_policies": "arn:aws:iam::aws:policy/service-role/AmazonECSTaskExecutionRolePolicy",
    "region": "us-east-1"
  }
}

The assume_role_policy is a JSON string — the adapter jsonencodes it into the Terraform assume_role_policy argument. The managed_policies input is a comma-separated list of ARNs, emitted as managed_policy_arns = [...].

Compliance extension points

  • Permissions boundary — add permissions_boundary to enforce least-privilege guardrails (SOC2 CC6.1, SOX ITGC, DORA ICT access control).
  • Inline policy — add aws_iam_role_policy for fine-grained least-privilege instead of broad managed policies (SOC2 CC6.1.
  • MFA conditions — add condition blocks requiring MFA for assume-role (SOC2 CC6.1.
  • Source IP / region conditions — add aws:SourceIp / aws:RequestedRegion conditions for data residency enforcement (GDPR Art.44-49, DORA ICT third-party risk).
  • Access Analyzer — add aws_accessanalyzer_analyzer to verify least-privilege (SOC2 CC6.1, GDPR Art.32).
  • Role separation — add a separate task role vs. execution role (SOC2 CC6.3 segregation of duties).

Examples

Validated example contracts are in examples/. The platform-test pipeline validates them against schemas/contract.schema.json.

Simple

A minimal deployment:

examples/simple.yaml

uses: acdl/pipelines/deploy.yaml@v1.6
module: iam-role
environment: dev
inputs:
  name: my-task-role
  region: us-east-1

Complex

A production deployment with optional inputs:

examples/complex.yaml

# Complex IAM role with managed policies
uses: acdl/pipelines/deploy.yaml@v1.6
module: iam-role
environment: dev
inputs:
  name: my-production-task-role
  region: us-east-1

Versioning

1.0.0 — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps require a new registry entry (immutable publication); old entries enter a 12-month deprecation window.