Files
acdl/modules/l1/iam-role
Jon Chery c80060878a feat(P56b): author 11 L1 module terraform subdirs + fix adapter output format
EXECUTE stage. Authors the remaining 11 L1 module terraform subdirs with
the full versions/variables/locals/main/outputs split. Defaults previously
hardcoded in the adapter move into locals.tf.

Simple single-resource modules (7):
- kms-key: aws_kms_key + alias (enable_key_rotation, deletion_window defaults)
- ecr: aws_ecr_repository (encryption_configuration from kms_key_arn, image_scanning)
- ecs-cluster: aws_ecs_cluster (name default)
- iam-role: aws_iam_role + inline_policy (assume_role_policy fallback, ECR/logs policy in locals.tf)
- rds: aws_db_instance (storage_encrypted, multi_az, kms_key_arn defaults)
- waf: aws_wafv2_web_acl (default_action, visibility_config, dynamic rules)
- uptime: aws_ecs_task_definition + aws_ecs_service (Fargate compat, container_definitions in locals.tf)

Multi-resource modules with intra-refs (4):
- vpc: aws_vpc + aws_subnet + aws_internet_gateway + aws_route_table (CIDR derivation in locals.tf)
- ecs-service: aws_ecs_task_definition + aws_ecs_service (Fargate compat, container_definitions, network_config in locals.tf)
- alb: aws_lb + aws_lb_target_group + aws_lb_listener (subnet/security_group list derivation in locals.tf)
- cloudfront: aws_cloudfront_distribution + aws_cloudfront_origin_access_control (OAC defaults in locals.tf)

Registry: terraform_dir added to all 11 remaining entries.

Adapter fix: stack output format uses separate 'from' + 'output' fields
(not 'from': 'rid.output'). Fixed _emit_root_output to read both fields.

6 previously-skipped tests unblocked (run_platform.sh --check-only now
resolves static-assets.yml through the new module-assembled adapter).
Removed skip markers. Fixed test assertion (aws_s3_bucket → module).

Regression: 461 passed, 0 skipped, 5 deselected (slow). All 12 modules
pass run_primitive_plan.sh --check-only. All 12 terraform/ subdirs pass
terraform init + validate standalone.

---ci---
project: acdl
phase: P56b
milestone: v1.11
status: execute
---/ci---
2026-07-28 16:07:57 +00:00
..

iam-role — IAM role

Module kind: primitive | Version: 1.0.0

A single IAM role with an assume-role policy and optional managed policy attachments. Used as the ECS task execution role.

Resources

Resource Type Purpose
role aws_iam_role The IAM role with assume-role policy

Inputs

Name Type Required Default Description
role_name string yes The IAM role name
assume_role_policy string yes Assume-role policy document (JSON string)
managed_policies string no Comma-separated list of managed policy ARNs to attach
region string yes AWS region the role is created in

Outputs

Name Type Description
role_arn arn The IAM role ARN
role_id string The IAM role id

Usage

{
  "id": "roles",
  "type": "aws:iam:role",
  "module": "iam-role@1.0.0",
  "inputs": {
    "role_name": "acdl-microservice-exec",
    "assume_role_policy": "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Effect\":\"Allow\",\"Principal\":{\"Service\":\"ecs-tasks.amazonaws.com\"},\"Action\":\"sts:AssumeRole\"}]}",
    "managed_policies": "arn:aws:iam::aws:policy/service-role/AmazonECSTaskExecutionRolePolicy",
    "region": "us-east-1"
  }
}

The assume_role_policy is a JSON string — the adapter jsonencodes it into the Terraform assume_role_policy argument. The managed_policies input is a comma-separated list of ARNs, emitted as managed_policy_arns = [...].

Compliance extension points

  • Permissions boundary — add permissions_boundary to enforce least-privilege guardrails (SOC2 CC6.1, SOX ITGC, DORA ICT access control).
  • Inline policy — add aws_iam_role_policy for fine-grained least-privilege instead of broad managed policies (SOC2 CC6.1.
  • MFA conditions — add condition blocks requiring MFA for assume-role (SOC2 CC6.1.
  • Source IP / region conditions — add aws:SourceIp / aws:RequestedRegion conditions for data residency enforcement (GDPR Art.44-49, DORA ICT third-party risk).
  • Access Analyzer — add aws_accessanalyzer_analyzer to verify least-privilege (SOC2 CC6.1, GDPR Art.32).
  • Role separation — add a separate task role vs. execution role (SOC2 CC6.3 segregation of duties).

Examples

Validated example contracts are in examples/. The platform-test pipeline validates them against schemas/contract.schema.json.

Simple

A minimal deployment:

examples/simple.yml

environment: dev
id: role
infrastructure:
  iam-role:
    inputs:
      name: my-task-role
      region: us-east-1
    version: 1.0.0
name: iam-role

Complex

A production deployment with optional inputs:

examples/complex.yml

environment: dev
id: role
infrastructure:
  iam-role:
    inputs:
      name: my-production-task-role
      region: us-east-1
    version: 1.0.0
name: iam-role

Versioning

1.0.0 — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps require a new registry entry (immutable publication); old entries enter a 12-month deprecation window.