MDAA TS Docs
    Preparing search index...

    A role for which Role ID, Arn, or Name can be resolved using a custom resource. If one of these properties is requested of the object and is not already populated, then a custom Cfn resource will be created to facilitate the lookup.

    Cross-account roles (where the ARN account differs from the deployment account) are detected automatically. These roles cannot have their ID resolved via the local IAM API, so they are surfaced as ARN-based principals for use in resource policies.

    Index

    Constructors

    • Parameters

      • scope: Construct

        The scope in which custom resources for role resolution will be created (if required)

      • roleRef: MdaaResolvableRoleRef

        The role reference which will be used to resolve a role. The role ref must contain at least one 'anchor' property (one of id, arn, or name) on which the remaining properties can be resolved.

      • OptionalroleHelper: MdaaRoleHelper

        The MDAA role helper which will be used as a custom resource Provider. Required unless the ref already carries every anchor, as it does when built by fromRole, since without a helper an unpopulated property cannot be looked up. Trails roleRef because jsii rejects an optional parameter ahead of a required one.

      Returns MdaaResolvableRole

    Methods

    • Returns string

      Either directly the role ref arn (if already populated) or a CR attribute token which will contain the arn at deployment time.

    • Returns an ArnPrincipal for this role, suitable for use in resource policies when the role is cross-account and cannot be resolved to a role ID.

      Returns ArnPrincipal

      An ArnPrincipal constructed from the role's ARN.

    • Returns string

      Either directly the role ref id (if already populated) or a CR attribute token which will contain the id at deployment time.

    • Returns boolean

      The immutability flag of the ref (defaults false)

      A cross-account role is always immutable: a managed policy or inline policy can only be attached to a role from the role's own account, and IAM resolves an attachment by role name within the deploying account. Attempting it fails the deployment with 'The role with name cannot be found', or silently attaches to an unrelated local role of the same name.

    • Determines whether this role reference points to a role in a different AWS account than the deployment account. Cross-account detection requires a non-tokenized ARN with an account segment that differs from Stack.of(scope).account.

      Returns boolean

      true if the role ARN belongs to a different account, false otherwise. Returns false if cross-account status cannot be determined (e.g., tokenized values).

    • Returns string

      Either directly the role ref name (if already populated) or a CR attribute token which will contain the name at deployment time.

    • Creates an MdaaResolvableRole wrapping a concrete CDK Role. Use this for infrastructure roles created within the same stack that already have their role ID available (e.g., MdaaRole, MdaaLambdaRole).

      Every anchor is populated from the role, so no lookup custom resource is ever needed and no role helper is required. The ARN of a role created in the stack is a CloudFormation token, so such a role is never treated as cross-account.

      Parameters

      • scope: Construct

        The construct scope

      • refId: string

        A unique reference identifier for this role

      • role: Role

        The concrete CDK Role instance

      Returns MdaaResolvableRole