Files
acdl/modules-ir/l1/l1-iam-role
Jon Chery 3508671377 refactor(modules): remove thin-composition layer; rewrite all module READMEs
The L2 thin-composition layer (composition.json + contract_resolver.py +
contract schema + sample contracts) has been removed completely. The
implementation was unsatisfactory and is deferred for a later redesign.

- Delete: composition.json x2, contract_resolver.py, contracts/ x2,
  contract.schema.json
- Patch: run_platform.sh now loads a pre-existing IR instance instead of
  resolving a contract (the downstream adapter/checkov/confidence/outbox
  pipeline is unchanged)
- Prune: L2 entries removed from registry.json (L1 entries unchanged)
- Rewrite: all 7 L1 module READMEs in plain language (no jargon), each
  with Resources/Inputs/Outputs/Usage/Compliance-extension-points/Versioning
  sections derived from interface.json
- Add: 2 L2 placeholder READMEs noting the composition is under redesign
- Add: modules-ir/README.md catalog index + README-TEMPLATE.md

---ci---
project: acdl
phase: 17
milestone: v1.3
status: execute
---/ci---
2026-07-22 13:54:40 +00:00
..

l1-iam-role — IAM role

Module kind: L1 primitive | Version: 1.0.0

A single IAM role with an assume-role policy and optional managed policy attachments. Used as the ECS task execution role.

Resources

Resource Type Purpose
role aws_iam_role The IAM role with assume-role policy

Inputs

Name Type Required Default Description
role_name string yes The IAM role name
assume_role_policy string yes Assume-role policy document (JSON string)
managed_policies string no Comma-separated list of managed policy ARNs to attach
region string yes AWS region the role is created in

Outputs

Name Type Description
role_arn arn The IAM role ARN
role_id string The IAM role id

Usage

{
  "id": "roles",
  "type": "aws:iam:role",
  "module": "l1-iam-role@1.0.0",
  "inputs": {
    "role_name": "acdl-microservice-exec",
    "assume_role_policy": "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Effect\":\"Allow\",\"Principal\":{\"Service\":\"ecs-tasks.amazonaws.com\"},\"Action\":\"sts:AssumeRole\"}]}",
    "managed_policies": "arn:aws:iam::aws:policy/service-role/AmazonECSTaskExecutionRolePolicy",
    "region": "us-east-1"
  }
}

The assume_role_policy is a JSON string — the adapter jsonencodes it into the Terraform assume_role_policy argument. The managed_policies input is a comma-separated list of ARNs, emitted as managed_policy_arns = [...].

Compliance extension points

  • Permissions boundary — add permissions_boundary to enforce least-privilege guardrails (SOC2 CC6.1, SOX ITGC, DORA ICT access control).
  • Inline policy — add aws_iam_role_policy for fine-grained least-privilege instead of broad managed policies (SOC2 CC6.1, HIPAA §164.308(a)(4)).
  • MFA conditions — add condition blocks requiring MFA for assume-role (SOC2 CC6.1, HIPAA §164.312(d)).
  • Source IP / region conditions — add aws:SourceIp / aws:RequestedRegion conditions for data residency enforcement (GDPR Art.44-49, DORA ICT third-party risk).
  • Access Analyzer — add aws_accessanalyzer_analyzer to verify least-privilege (SOC2 CC6.1, GDPR Art.32).
  • Role separation — add a separate task role vs. execution role (SOC2 CC6.3 segregation of duties).

Versioning

1.0.0 — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps require a new registry entry (immutable publication); old entries enter a 12-month deprecation window.