ReadonlybucketsS3 bucket(s) for HealthLake read/write access
Optional ReadonlycreateFlag controlling CloudFormation output and stack export creation for construct resources
Optional ReadonlycreateFlag controlling SSM parameter creation for construct resource references enabling
ReadonlydatastoreARN of the datastore this role serves. Used to scope the assume-role trust policy to a single datastore (aws:SourceArn), so that in a multi-datastore account one datastore cannot be used as a confused deputy to assume another datastore's role and reach its bucket/CMK.
ReadonlykmsKMS key for encrypt/decrypt operations
ReadonlynamingMDAA naming implementation for consistent resource naming across all MDAA constructs
Optional ReadonlyroleRole name suffix (combined with MDAA naming prefix). Use a per-datastore value when deploying multiple datastores in the same stack to avoid IAM role name collisions.
Properties for the MdaaHealthLakeDataAccessRole construct.