OptionalresourceArns: string[]list of ARNs to allow access to
scoped id of the resource
scope in which this resource is defined
the SQS queue to grant access to
the EventBridge rule that sends events to the queue
OptionalservicePrincipals: ServicePrincipal[]optional list of service principals, defaults to events.amazonaws.com
scoped id of the resource
scope in which this resource is defined
the inline policy document to attach to the role
OptionalservicePrincipal: ServicePrincipaloptional service principal, defaults to appconfig.amazonaws.com
scoped id of the resource
scope in which this resource is defined
scoped id of the resource
scope in which this resource is defined
the CloudWatch log group for CloudTrail to deliver logs to
scoped id of the resource
scope in which this resource is defined
the ARN of the DynamoDB stream (source)
the ARN of the Lambda function (target)
scoped id of the resource
scope in which this resource is defined
the ECS cluster the task runs in
the ECS task definition to allow running
scoped id of the resource
scope in which this resource is defined
the inline policy document to attach to the role
scoped id of the resource
scope in which this resource is defined
the inline policy document to attach to the role
OptionalservicePrincipal: ServicePrincipaloptional service principal, defaults to lambda.amazonaws.com
scoped id of the resource
scope in which this resource is defined
the ARN of the SQS queue (source)
the ARN of the Lambda function (target)
scoped id of the resource
scope in which this resource is defined
the ARN of the SQS queue (source)
the ARN of the Step Function (target)
scoped id of the resource
scope in which this resource is defined
the inline policy document to attach to the role
OptionalservicePrincipal: ServicePrincipaloptional service principal, defaults to states.amazonaws.com
OptionalresourceArns: string[]list of ARNs to allow access to
scope in which this resource is defined
the list of service principals allowed to assume the role
OptionalresourceArns: string[]list of ARNs to allow access to
OptionalresourceArns: string[]list of ARNs to allow access to
scope in which this resource is defined
the CloudWatch log group to allow creating log streams in
OptionalresourceArns: string[]list of ARNs to allow access to
scope in which this resource is defined
the S3 bucket to grant delete access to
OptionalresourceArns: string[]optional list of ARNs to allow access to, defaults to all objects in the bucket
OptionalresourceArns: string[]list of ARNs to allow access to
OptionalresourceArns: string[]list of ARNs to allow access to
scope in which this resource is defined
the S3 bucket to grant read access to
OptionalresourceArns: string[]optional list of ARNs to allow access to, defaults to all objects in the bucket
OptionalresourceArns: string[]list of ARNs to allow access to
OptionalresourceArns: string[]list of ARNs to allow access to
scope in which this resource is defined
the S3 bucket to grant list access to
OptionalresourceArns: string[]list of ARNs to allow access to
OptionalresourceArns: string[]list of ARNs to allow access to
OptionalresourceArns: string[]list of ARNs to allow access to
scope in which this resource is defined
the S3 bucket to grant write access to
OptionalresourceArns: string[]optional list of ARNs to allow access to, defaults to all objects in the bucket
OptionalresourceArns: string[]list of ARNs to allow access to
scope in which this resource is defined
the CloudWatch log group to allow writing log events to
OptionalresourceArns: string[]list of ARNs to allow access to
OptionalresourceArns: string[]list of ARNs to allow access to
scope in which this resource is defined
OptionalresourceArns: string[]list of ARNs to allow access to
OptionalresourceArns: string[]list of ARNs to allow access to
scope in which this resource is defined
the ECS cluster the task runs in
the ECS task definition to allow running
OptionalresourceArns: string[]list of ARNs to allow access to
OptionalresourceArns: string[]list of ARNs to allow access to
OptionalresourceArns: string[]list of ARNs to allow access to
Provides operations on AWS Identity and Access Management (IAM).
Example
See
[CDK IAM Module]https://docs.aws.amazon.com/cdk/api/v2/docs/aws-cdk-lib.aws_iam-readme.html