The scope in which custom resources for role resolution will be created (if required)
The role reference which will be used to resolve a role. The role ref must contain at least one 'anchor' property (one of id, arn, or name) on which the remaining properties can be resolved.
OptionalroleHelper: MdaaRoleHelperThe MDAA role helper which will be used as a custom resource Provider. Required unless the ref already carries every anchor, as it does when built by fromRole, since without a helper an unpopulated property cannot be looked up. Trails roleRef because jsii rejects an optional parameter ahead of a required one.
Either directly the role ref arn (if already populated) or a CR attribute token which will contain the arn at deployment time.
Returns an ArnPrincipal for this role, suitable for use in resource policies when the role is cross-account and cannot be resolved to a role ID.
An ArnPrincipal constructed from the role's ARN.
Either directly the role ref id (if already populated) or a CR attribute token which will contain the id at deployment time.
The immutability flag of the ref (defaults false)
A cross-account role is always immutable: a managed policy or inline policy can only be
attached to a role from the role's own account, and IAM resolves an attachment by role name
within the deploying account. Attempting it fails the deployment with 'The role with name
Determines whether this role reference points to a role in a different AWS account than the deployment account. Cross-account detection requires a non-tokenized ARN with an account segment that differs from Stack.of(scope).account.
true if the role ARN belongs to a different account, false otherwise. Returns false if cross-account status cannot be determined (e.g., tokenized values).
Either directly the role ref name (if already populated) or a CR attribute token which will contain the name at deployment time.
The unique reference id for the role ref
The sso flag of the ref( defaults false )
StaticfromCreates an MdaaResolvableRole wrapping a concrete CDK Role. Use this for infrastructure roles created within the same stack that already have their role ID available (e.g., MdaaRole, MdaaLambdaRole).
Every anchor is populated from the role, so no lookup custom resource is ever needed and no role helper is required. The ARN of a role created in the stack is a CloudFormation token, so such a role is never treated as cross-account.
The construct scope
A unique reference identifier for this role
The concrete CDK Role instance
A role for which Role ID, Arn, or Name can be resolved using a custom resource. If one of these properties is requested of the object and is not already populated, then a custom Cfn resource will be created to facilitate the lookup.
Cross-account roles (where the ARN account differs from the deployment account) are detected automatically. These roles cannot have their ID resolved via the local IAM API, so they are surfaced as ARN-based principals for use in resource policies.