{"_id":"@aws-mdaa/roles","_rev":"8-c00e06ce468ed172d05e9e63049b571d","name":"@aws-mdaa/roles","dist-tags":{"latest":"1.8.1"},"versions":{"1.2.0":{"name":"@aws-mdaa/roles","version":"1.2.0","author":{"url":"https://aws.amazon.com/solutions","name":"Amazon Web Services"},"license":"Apache-2.0","_id":"@aws-mdaa/roles@1.2.0","maintainers":[{"name":"mdaa-dev-team","email":"mdaa-dev-team@amazon.com"}],"homepage":"https://github.com/aws/modern-data-architecture-accelerator#readme","bugs":{"url":"https://github.com/aws/modern-data-architecture-accelerator/issues"},"bin":{"roles-cdk":"bin/roles.js"},"dist":{"shasum":"492dd662c64a9f3bcd0870b3bacb97e806d30b1b","tarball":"https://registry.npmjs.org/@aws-mdaa/roles/-/roles-1.2.0.tgz","fileCount":12,"integrity":"sha512-ePcRkDAbPSF1l9YqvQLRcaW9MpnaisQf/hswJ0uqwBDCYHE//ftVAOVDk8Y6b/G0CRWd0PQeybd0AJ1+YhUjAA==","signatures":[{"sig":"MEYCIQCjYxwf2eBnJDbptl2Es2N0sjRaM0oPrHhrmLR9Dk0mJwIhALGD5MxaZa30js+iBlh4hCvHiHesq5HEnK+HKVARMJXP","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":150090},"main":"lib/index.js","types":"lib/index.d.ts","gitHead":"8b49a2b371014baec046605ffdbfe38951099c31","scripts":{"cdk":"cdk","lint":"eslint --max-warnings 0 -c ../../../../.eslintrc.json '**/*.{ts,tsx}' --ignore-pattern 'dist/*' --ignore-pattern 'node_modules/*' --ignore-pattern \"*.d.ts\" ","test":"jest --passWithNoTests --coverage","build":"tsc && typescript-json-schema --required --noExtraProps tsconfig.json RolesConfigContents --include 'lib/*.ts' --include '../../../../node_modules/@types/**/*.ts' --include 'lib/config-schema.json' > lib/config-schema.json  && cp lib/config-schema.json ../../../../schemas/${npm_package_name}.json","watch":"tsc -w"},"_npmUser":{"name":"mdaa-dev-team","email":"mdaa-dev-team@amazon.com"},"overrides":{"aws-cdk-lib":"2.201.0","@types/babel__traverse":"7.18.2"},"repository":{"url":"git+https://github.com/aws/modern-data-architecture-accelerator.git","type":"git"},"_npmVersion":"10.9.3","description":"MDAA roles module","directories":{},"_nodeVersion":"22.20.0","dependencies":{"ajv":"8.17.1","yaml":"1.10.2","cdk-nag":"2.37.1","constructs":"10.0.96","aws-cdk-lib":"2.201.0","@aws-mdaa/app":"1.2.0","@aws-mdaa/config":"1.2.0","source-map-support":"0.5.21","@aws-mdaa/l3-construct":"1.2.0","@aws-mdaa/roles-l3-construct":"1.2.0"},"_hasShrinkwrap":false,"devDependencies":{"jest":"29.5.0","ts-jest":"29.1.0","ts-node":"10.9.1","typescript":"4.6.3","@types/jest":"29.5.0","@types/node":"17.0.23","@types/prettier":"2.6.0","@aws-mdaa/testing":"1.2.0","typescript-json-schema":"0.63.0"},"_npmOperationalInternal":{"tmp":"tmp/roles_1.2.0_1760996723746_0.40811711383232585","host":"s3://npm-registry-packages-npm-production"}},"1.3.0":{"name":"@aws-mdaa/roles","version":"1.3.0","author":{"url":"https://aws.amazon.com/solutions","name":"Amazon Web Services"},"license":"Apache-2.0","_id":"@aws-mdaa/roles@1.3.0","maintainers":[{"name":"mdaa-dev-team","email":"mdaa-dev-team@amazon.com"}],"homepage":"https://github.com/aws/modern-data-architecture-accelerator#readme","bugs":{"url":"https://github.com/aws/modern-data-architecture-accelerator/issues"},"bin":{"roles-cdk":"bin/roles.js"},"dist":{"shasum":"f1dc139607f40a4266913943b10bc07b67744761","tarball":"https://registry.npmjs.org/@aws-mdaa/roles/-/roles-1.3.0.tgz","fileCount":12,"integrity":"sha512-YiEW0CCHCUYbi20G2A/Sl+npZUvqBEnfTalfrhqzededUYecfbKOnLWS8T2aKG0NT8CAVOKwJ852ZUrLiILSqQ==","signatures":[{"sig":"MEUCICi6hR7umdvP29X2bxhLZ+VicYFEZ2kXa84oXM/3xCPTAiEAi+1WsQ//KDPW2Yz2oP83QfiRoP/Zqeqaf4HDsJSYXQg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":150087},"main":"lib/index.js","_from":"file:/Users/guoneng/projects/mdaa/publications/us-east-1/1.3.0/mdaa-1.3.0/target/package-build/aws-mdaa-roles-1.3.0.tgz","types":"lib/index.d.ts","gitHead":"8b49a2b371014baec046605ffdbfe38951099c31","scripts":{"cdk":"cdk","lint":"eslint --max-warnings 0 -c ../../../../.eslintrc.json '**/*.{ts,tsx}' --ignore-pattern 'dist/*' --ignore-pattern 'node_modules/*' --ignore-pattern \"*.d.ts\" ","test":"jest --passWithNoTests --coverage","build":"tsc && typescript-json-schema --required --noExtraProps tsconfig.json RolesConfigContents --include 'lib/*.ts' --include '../../../../node_modules/@types/**/*.ts' --include 'lib/config-schema.json' > lib/config-schema.json  && cp lib/config-schema.json ../../../../schemas/${npm_package_name}.json","watch":"tsc -w"},"_npmUser":{"name":"mdaa-dev-team","email":"mdaa-dev-team@amazon.com"},"_resolved":"/Users/guoneng/projects/mdaa/publications/us-east-1/1.3.0/mdaa-1.3.0/target/package-build/aws-mdaa-roles-1.3.0.tgz","overrides":{"aws-cdk-lib":"2.220.0","@types/babel__traverse":"7.18.2"},"_integrity":"sha512-YiEW0CCHCUYbi20G2A/Sl+npZUvqBEnfTalfrhqzededUYecfbKOnLWS8T2aKG0NT8CAVOKwJ852ZUrLiILSqQ==","repository":{"url":"git+https://github.com/aws/modern-data-architecture-accelerator.git","type":"git"},"_npmVersion":"11.6.0","description":"MDAA roles module","directories":{},"_nodeVersion":"24.10.0","dependencies":{"ajv":"8.17.1","yaml":"1.10.2","cdk-nag":"2.37.55","constructs":"10.0.96","aws-cdk-lib":"2.220.0","@aws-mdaa/app":"1.3.0","@aws-mdaa/config":"1.3.0","source-map-support":"0.5.21","@aws-mdaa/l3-construct":"1.3.0","@aws-mdaa/roles-l3-construct":"1.3.0"},"_hasShrinkwrap":false,"devDependencies":{"jest":"29.5.0","ts-jest":"29.1.0","ts-node":"10.9.1","typescript":"4.6.3","@types/jest":"29.5.0","@types/node":"17.0.23","@types/prettier":"2.6.0","@aws-mdaa/testing":"1.3.0","typescript-json-schema":"0.63.0"},"_npmOperationalInternal":{"tmp":"tmp/roles_1.3.0_1764173695864_0.7095241230411027","host":"s3://npm-registry-packages-npm-production"}},"1.4.0":{"name":"@aws-mdaa/roles","version":"1.4.0","author":{"url":"https://aws.amazon.com/solutions","name":"Amazon Web Services"},"license":"Apache-2.0","_id":"@aws-mdaa/roles@1.4.0","maintainers":[{"name":"mdaa-dev-team","email":"mdaa-dev-team@amazon.com"}],"homepage":"https://github.com/aws/modern-data-architecture-accelerator#readme","bugs":{"url":"https://github.com/aws/modern-data-architecture-accelerator/issues"},"bin":{"roles-cdk":"bin/roles.js"},"dist":{"shasum":"821690b9674917bef4770d54da31d9d4b3d227fe","tarball":"https://registry.npmjs.org/@aws-mdaa/roles/-/roles-1.4.0.tgz","fileCount":12,"integrity":"sha512-7X591k3a6nPzJ9FJtSx5v3t2kPrkLKFSw1hVOxifatLQPbyxKs9pG5h24iXzoy0PoGgxKkGquHtLL4LlmYs82w==","signatures":[{"sig":"MEUCIQDUjmGWuCpT5oDyK3ujsVf5a/7cvMl2E3H+94rDwZThSgIgMVw6mZ+bX3cH1OD3KV81hTr09OUjcQ1Wzy8WYpp8Dkg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":149996},"main":"lib/index.js","_from":"file:/Users/guoneng/projects/mdaa/npm-publish/1.4.0/mdaa-1.4.0/target/package-build/aws-mdaa-roles-1.4.0.tgz","types":"lib/index.d.ts","gitHead":"8b49a2b371014baec046605ffdbfe38951099c31","scripts":{"cdk":"cdk","lint":"eslint --max-warnings 0 -c ../../../../.eslintrc.json '**/*.{ts,tsx}' --ignore-pattern 'dist/*' --ignore-pattern 'node_modules/*' --ignore-pattern \"*.d.ts\" ","test":"jest --passWithNoTests --coverage","build":"tsc && typescript-json-schema --required --noExtraProps tsconfig.json RolesConfigContents --include 'lib/*.ts' --include '../../../../node_modules/@types/**/*.ts' --include 'lib/config-schema.json' > lib/config-schema.json  && cp lib/config-schema.json ../../../../schemas/${npm_package_name}.json","watch":"tsc -w"},"_npmUser":{"name":"mdaa-dev-team","email":"mdaa-dev-team@amazon.com"},"_resolved":"/Users/guoneng/projects/mdaa/npm-publish/1.4.0/mdaa-1.4.0/target/package-build/aws-mdaa-roles-1.4.0.tgz","_integrity":"sha512-7X591k3a6nPzJ9FJtSx5v3t2kPrkLKFSw1hVOxifatLQPbyxKs9pG5h24iXzoy0PoGgxKkGquHtLL4LlmYs82w==","repository":{"url":"git+https://github.com/aws/modern-data-architecture-accelerator.git","type":"git"},"_npmVersion":"10.9.4","description":"MDAA roles module","directories":{},"_nodeVersion":"24.12.0","dependencies":{"ajv":"8.17.1","yaml":"1.10.2","cdk-nag":"2.37.55","constructs":"10.0.96","aws-cdk-lib":"2.220.0","@aws-mdaa/app":"1.4.0","@aws-mdaa/config":"1.4.0","source-map-support":"0.5.21","@aws-mdaa/l3-construct":"1.4.0","@aws-mdaa/roles-l3-construct":"1.4.0"},"_hasShrinkwrap":false,"devDependencies":{"jest":"29.7.0","ts-jest":"29.4.6","ts-node":"10.9.2","typescript":"5.9.3","@types/jest":"29.5.14","@types/node":"22.9.0","@types/prettier":"2.6.0","@aws-mdaa/testing":"1.4.0","typescript-json-schema":"0.67.1"},"_npmOperationalInternal":{"tmp":"tmp/roles_1.4.0_1770193366351_0.5879422164575252","host":"s3://npm-registry-packages-npm-production"}},"1.5.0":{"name":"@aws-mdaa/roles","version":"1.5.0","author":{"url":"https://aws.amazon.com/solutions","name":"Amazon Web Services"},"license":"Apache-2.0","_id":"@aws-mdaa/roles@1.5.0","maintainers":[{"name":"mdaa-dev-team","email":"mdaa-dev-team@amazon.com"}],"homepage":"https://github.com/aws/modern-data-architecture-accelerator#readme","bugs":{"url":"https://github.com/aws/modern-data-architecture-accelerator/issues"},"bin":{"roles-cdk":"bin/roles.js"},"dist":{"shasum":"cff57993083c50952642416cd891a3f293f8510b","tarball":"https://registry.npmjs.org/@aws-mdaa/roles/-/roles-1.5.0.tgz","fileCount":12,"integrity":"sha512-eNdrPrzjdoPnFOzKCHg5a5nBqUHmuwWnOykmZSMOtV0MqH4fkDGUlZ/bsfiJQ+kZswAFnO4/oVUGQRVoCM4zkQ==","signatures":[{"sig":"MEQCIG7LpOpKLliWcA6H4vbKaG/aClLMDTKp61ZzpKqLMtFuAiAu7sFuXvrPqYtnzAqMNuuMGlI3wG29YTx51GwlllAtgw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1168338},"main":"lib/index.js","_from":"file:/Users/suddash/Documents/MDAA/caef-delivery/1.5.0/mdaa-1.5.0/target/package-build/aws-mdaa-roles-1.5.0.tgz","types":"lib/index.d.ts","gitHead":"8b49a2b371014baec046605ffdbfe38951099c31","scripts":{"cdk":"cdk","lint":"eslint --max-warnings 0 -c ../../../../eslint.config.mjs","test":"jest --passWithNoTests --testPathIgnorePatterns='.*\\.snapshot\\.test\\.ts'","build":"tsc && typescript-json-schema --required --noExtraProps tsconfig.json RolesConfigContents --include 'lib/*.ts' --include '../../../../node_modules/@types/**/*.ts' --include 'lib/config-schema.json' > lib/config-schema.json  && cp lib/config-schema.json ../../../../schemas/${npm_package_name}.json","watch":"tsc -w","test:coverage":"jest --passWithNoTests --coverage --testPathIgnorePatterns='.*\\.snapshot\\.test\\.ts'","test:snapshots":"jest --passWithNoTests --testPathPattern='.*\\.snapshot\\.test\\.ts'","test:snapshots:update":"jest --passWithNoTests --testPathPattern='.*\\.snapshot\\.test\\.ts' --updateSnapshot"},"_npmUser":{"name":"mdaa-dev-team","email":"mdaa-dev-team@amazon.com"},"_resolved":"/Users/suddash/Documents/MDAA/caef-delivery/1.5.0/mdaa-1.5.0/target/package-build/aws-mdaa-roles-1.5.0.tgz","_integrity":"sha512-eNdrPrzjdoPnFOzKCHg5a5nBqUHmuwWnOykmZSMOtV0MqH4fkDGUlZ/bsfiJQ+kZswAFnO4/oVUGQRVoCM4zkQ==","repository":{"url":"git+https://github.com/aws/modern-data-architecture-accelerator.git","type":"git"},"_npmVersion":"10.9.2","description":"MDAA roles module","directories":{},"_nodeVersion":"23.9.0","dependencies":{"ajv":"8.17.1","yaml":"1.10.2","cdk-nag":"2.37.55","constructs":"10.0.96","aws-cdk-lib":"2.220.0","@aws-mdaa/app":"1.5.0","@aws-mdaa/config":"1.5.0","source-map-support":"0.5.21","@aws-mdaa/l3-construct":"1.5.0","@aws-mdaa/roles-l3-construct":"1.5.0"},"_hasShrinkwrap":false,"devDependencies":{"jest":"29.7.0","ts-jest":"29.4.6","ts-node":"10.9.2","typescript":"5.9.3","@types/jest":"29.5.14","@types/node":"22.9.0","@types/prettier":"2.6.0","@aws-mdaa/testing":"1.5.0","typescript-json-schema":"0.67.1"},"_npmOperationalInternal":{"tmp":"tmp/roles_1.5.0_1774537259008_0.06052220203766767","host":"s3://npm-registry-packages-npm-production"}},"1.6.0":{"name":"@aws-mdaa/roles","version":"1.6.0","author":{"url":"https://aws.amazon.com/solutions","name":"Amazon Web Services"},"license":"Apache-2.0","_id":"@aws-mdaa/roles@1.6.0","maintainers":[{"name":"mdaa-dev-team","email":"mdaa-dev-team@amazon.com"}],"homepage":"https://github.com/aws/modern-data-architecture-accelerator#readme","bugs":{"url":"https://github.com/aws/modern-data-architecture-accelerator/issues"},"bin":{"roles-cdk":"bin/roles.js"},"dist":{"shasum":"4fd02d0e3cbae79388258a3ade0f3bd5b4e3dff5","tarball":"https://registry.npmjs.org/@aws-mdaa/roles/-/roles-1.6.0.tgz","fileCount":14,"integrity":"sha512-vrGwqs5xhpYJ2JSQQDdPDG9wkPHtO8u22Nbp3UAGYbgKDh9gt+kZRxM2ydUI9sMdRjirGmonamJH9iJoecd5IA==","signatures":[{"sig":"MEQCIAhVXYbEQeuAFzr7muddRYOn3kYZacB4ZNVXCM91bHToAiBXgSNM46ULEW+X/xBWYdDOVsqnVqKpEp0ARGqkLIEcUg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1118508},"main":"lib/index.js","mdaa":{"deployStage":"1"},"_from":"file:/Users/guoneng/projects/mdaa/mdaa-pipeline/npmjs-build/mdaa/target/package-build/aws-mdaa-roles-1.6.0.tgz","types":"lib/index.d.ts","gitHead":"8b49a2b371014baec046605ffdbfe38951099c31","scripts":{"cdk":"cdk","lint":"eslint --max-warnings 0 -c ../../../../eslint.config.mjs","test":"jest --passWithNoTests --coverage","build":"../../../../scripts/build/build_package.sh RolesConfigContents","watch":"tsc -w","test:package-docs":"../../../../scripts/generate_docs/test_package_docs.sh","test:update-baselines":"UPDATE_BASELINES=true jest --passWithNoTests --testPathPattern='.*\\.diff\\.test\\.ts'"},"_npmUser":{"name":"mdaa-dev-team","email":"mdaa-dev-team@amazon.com"},"_resolved":"/Users/guoneng/projects/mdaa/mdaa-pipeline/npmjs-build/mdaa/target/package-build/aws-mdaa-roles-1.6.0.tgz","_integrity":"sha512-vrGwqs5xhpYJ2JSQQDdPDG9wkPHtO8u22Nbp3UAGYbgKDh9gt+kZRxM2ydUI9sMdRjirGmonamJH9iJoecd5IA==","repository":{"url":"git+https://github.com/aws/modern-data-architecture-accelerator.git","type":"git"},"_npmVersion":"10.9.4","description":"MDAA roles module","directories":{},"_nodeVersion":"24.12.0","dependencies":{"ajv":"8.18.0","yaml":"1.10.2","cdk-nag":"2.37.55","constructs":"10.0.96","aws-cdk-lib":"2.220.0","@aws-mdaa/app":"1.6.0","@aws-mdaa/config":"1.6.0","source-map-support":"0.5.21","@aws-mdaa/l3-construct":"1.6.0","@aws-mdaa/roles-l3-construct":"1.6.0"},"_hasShrinkwrap":false,"devDependencies":{"jest":"29.7.0","ts-jest":"29.4.9","ts-node":"10.9.2","typescript":"5.9.3","@types/jest":"29.5.14","@types/node":"22.9.0","@types/prettier":"2.6.0","@aws-mdaa/testing":"1.6.0","typescript-json-schema":"0.67.4"},"_npmOperationalInternal":{"tmp":"tmp/roles_1.6.0_1779447930592_0.2810187036968961","host":"s3://npm-registry-packages-npm-production"}},"1.7.0":{"name":"@aws-mdaa/roles","version":"1.7.0","author":{"url":"https://aws.amazon.com/solutions","name":"Amazon Web Services"},"license":"Apache-2.0","_id":"@aws-mdaa/roles@1.7.0","maintainers":[{"name":"mdaa-dev-team","email":"mdaa-dev-team@amazon.com"}],"homepage":"https://github.com/aws/modern-data-architecture-accelerator#readme","bugs":{"url":"https://github.com/aws/modern-data-architecture-accelerator/issues"},"bin":{"roles-cdk":"bin/roles.js"},"dist":{"shasum":"cb95db269031c20336efbe19e93014370909bb40","tarball":"https://registry.npmjs.org/@aws-mdaa/roles/-/roles-1.7.0.tgz","fileCount":14,"integrity":"sha512-2p3REhJLfkjo1/XnVKn5SgGPQzfUvpr+hP7nC30uyS+wqeToF9WjK15YHHduQ7dVIUGwOsZCfPoHOi04vAHrDw==","signatures":[{"sig":"MEQCICGKhqtjLP8iBX8FWp27BMgmvwwXMFMfc3FfiZ2wF23kAiBx0mTWrhJlVk74Wz43xb0NLBjXPRhf5VK3NdVFKDcmvA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1163640},"main":"lib/index.js","mdaa":{"deployStage":"1"},"_from":"file:/Users/guoneng/projects/mdaa/mdaa-pipeline/npmjs-build/mdaa/target/package-build/aws-mdaa-roles-1.7.0.tgz","types":"lib/index.d.ts","gitHead":"8b49a2b371014baec046605ffdbfe38951099c31","scripts":{"cdk":"cdk","lint":"eslint --max-warnings 0 -c ../../../../eslint.config.mjs","test":"jest --passWithNoTests --coverage","build":"../../../../scripts/build/build_package.sh RolesConfigContents","watch":"tsc -w","test:package-docs":"../../../../scripts/generate_docs/test_package_docs.sh","test:update-baselines":"UPDATE_BASELINES=true jest --passWithNoTests --testPathPattern='.*\\.diff\\.test\\.ts'"},"_npmUser":{"name":"mdaa-dev-team","email":"mdaa-dev-team@amazon.com"},"_resolved":"/Users/guoneng/projects/mdaa/mdaa-pipeline/npmjs-build/mdaa/target/package-build/aws-mdaa-roles-1.7.0.tgz","_integrity":"sha512-2p3REhJLfkjo1/XnVKn5SgGPQzfUvpr+hP7nC30uyS+wqeToF9WjK15YHHduQ7dVIUGwOsZCfPoHOi04vAHrDw==","repository":{"url":"git+https://github.com/aws/modern-data-architecture-accelerator.git","type":"git"},"_npmVersion":"10.9.4","description":"MDAA roles module","directories":{},"_nodeVersion":"24.12.0","dependencies":{"ajv":"8.18.0","yaml":"1.10.3","cdk-nag":"2.37.55","constructs":"10.6.0","aws-cdk-lib":"2.258.0","@aws-mdaa/app":"1.7.0","@aws-mdaa/config":"1.7.0","source-map-support":"0.5.21","@aws-mdaa/l3-construct":"1.7.0","@aws-mdaa/roles-l3-construct":"1.7.0"},"_hasShrinkwrap":false,"devDependencies":{"jest":"29.7.0","ts-jest":"29.4.9","ts-node":"10.9.2","typescript":"5.9.3","@types/jest":"29.5.14","@types/node":"22.9.0","@types/prettier":"2.6.0","@aws-mdaa/testing":"1.7.0","typescript-json-schema":"0.67.4"},"_npmOperationalInternal":{"tmp":"tmp/roles_1.7.0_1784277905513_0.04694300231180115","host":"s3://npm-registry-packages-npm-production"}},"1.8.0":{"name":"@aws-mdaa/roles","version":"1.8.0","author":{"url":"https://aws.amazon.com/solutions","name":"Amazon Web Services"},"license":"Apache-2.0","_id":"@aws-mdaa/roles@1.8.0","maintainers":[{"name":"mdaa-dev-team","email":"mdaa-dev-team@amazon.com"}],"homepage":"https://github.com/aws/modern-data-architecture-accelerator#readme","bugs":{"url":"https://github.com/aws/modern-data-architecture-accelerator/issues"},"bin":{"roles-cdk":"bin/roles.js"},"dist":{"shasum":"91e010690ccef1e3f3ebefe61778aa13124beaaf","tarball":"https://registry.npmjs.org/@aws-mdaa/roles/-/roles-1.8.0.tgz","fileCount":14,"integrity":"sha512-TQwBKjKpO7rRsGGARXbLGxTEDzhZri+itIcYYRBYT6/X6qhwOLtMT30GATEUODlUhq7kWNGYWcOORyrHrizixg==","signatures":[{"sig":"MEQCIAJwp+pSUtr+8e74Msp6sYwbBJSSm6z91GLxnn9O4r94AiBtcy3oOEVY8G6bMEVfrs10KXwkO1zRS5SojM2+vRtvgg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1178002},"main":"lib/index.js","mdaa":{"deployStage":"1"},"_from":"file:/Users/guoneng/.cache/mdaa-publish/mdaa/target/package-build/aws-mdaa-roles-1.8.0.tgz","types":"lib/index.d.ts","gitHead":"8b49a2b371014baec046605ffdbfe38951099c31","scripts":{"cdk":"cdk","lint":"eslint --max-warnings 0 -c ../../../../eslint.config.mjs","test":"jest --passWithNoTests --coverage","build":"../../../../scripts/build/build_package.sh RolesConfigContents","watch":"tsc -w","test:package-docs":"../../../../scripts/generate_docs/test_package_docs.sh","test:update-baselines":"UPDATE_BASELINES=true jest --passWithNoTests --testPathPattern='.*\\.diff\\.test\\.ts'"},"_npmUser":{"name":"mdaa-dev-team","email":"mdaa-dev-team@amazon.com"},"_resolved":"/Users/guoneng/.cache/mdaa-publish/mdaa/target/package-build/aws-mdaa-roles-1.8.0.tgz","_integrity":"sha512-TQwBKjKpO7rRsGGARXbLGxTEDzhZri+itIcYYRBYT6/X6qhwOLtMT30GATEUODlUhq7kWNGYWcOORyrHrizixg==","repository":{"url":"git+https://github.com/aws/modern-data-architecture-accelerator.git","type":"git"},"_npmVersion":"10.9.8","description":"MDAA roles module","directories":{},"_nodeVersion":"22.23.1","dependencies":{"ajv":"8.18.0","yaml":"1.10.3","cdk-nag":"2.37.55","constructs":"10.6.0","aws-cdk-lib":"2.261.0","@aws-mdaa/app":"1.8.0","@aws-mdaa/config":"1.8.0","source-map-support":"0.5.21","@aws-mdaa/l3-construct":"1.8.0","@aws-mdaa/roles-l3-construct":"1.8.0"},"_hasShrinkwrap":false,"devDependencies":{"jest":"29.7.0","ts-jest":"29.4.9","ts-node":"10.9.2","typescript":"5.9.3","@types/jest":"29.5.14","@types/node":"22.9.0","@types/prettier":"2.6.0","@aws-mdaa/testing":"1.8.0","typescript-json-schema":"0.67.4"},"_npmOperationalInternal":{"tmp":"tmp/roles_1.8.0_1788288106980_0.5541766715347571","host":"s3://npm-registry-packages-npm-production"}},"1.8.1":{"_id":"@aws-mdaa/roles@1.8.1","bin":{"roles-cdk":"bin/roles.js"},"bugs":{"url":"https://github.com/aws/modern-data-architecture-accelerator/issues"},"dist":{"shasum":"88823c0f72d63f93c9bbd914a7db1fc405d6fe93","tarball":"https://registry.npmjs.org/@aws-mdaa/roles/-/roles-1.8.1.tgz","fileCount":14,"integrity":"sha512-IZgy+MbS4opUHiT/PecOozY29/TryaQwRU6suNcLIXlRqCSS8JblrKJyLlg2t07WYZg8MhSxrpqnE8diN3k1HA==","signatures":[{"sig":"MEYCIQCP8OL4YmV4iR3gIAKJQTyKcuhPu7nAJmoAxmJ9QRNUSQIhAJvdVVvOTs2Yud6Owq45aho3KG/SdWKc+zQph6jKdG1E","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDph5lhatmbxplCnMj066sItqfJpjSkelEYKcxmAdGdhAIhALjr6lb+FQkXekfDiFc6xLwQK+vgwmTRrc+KwQcjBpwW"}],"unpackedSize":1181902},"main":"lib/index.js","mdaa":{"deployStage":"1"},"name":"@aws-mdaa/roles","_from":"file:/Users/guoneng/.cache/mdaa-publish/mdaa/target/package-build/aws-mdaa-roles-1.8.1.tgz","types":"lib/index.d.ts","author":{"url":"https://aws.amazon.com/solutions","name":"Amazon Web Services"},"gitHead":"8b49a2b371014baec046605ffdbfe38951099c31","license":"Apache-2.0","scripts":{"cdk":"cdk","lint":"eslint --max-warnings 0 -c ../../../../eslint.config.mjs","test":"jest --passWithNoTests --coverage","build":"../../../../scripts/build/build_package.sh RolesConfigContents","watch":"tsc -w","test:package-docs":"../../../../scripts/generate_docs/test_package_docs.sh","test:update-baselines":"UPDATE_BASELINES=true jest --passWithNoTests --testPathPattern='.*\\.diff\\.test\\.ts'"},"version":"1.8.1","_npmUser":{"name":"mdaa-dev-team","email":"mdaa-dev-team@amazon.com"},"homepage":"https://github.com/aws/modern-data-architecture-accelerator#readme","_resolved":"/Users/guoneng/.cache/mdaa-publish/mdaa/target/package-build/aws-mdaa-roles-1.8.1.tgz","_integrity":"sha512-IZgy+MbS4opUHiT/PecOozY29/TryaQwRU6suNcLIXlRqCSS8JblrKJyLlg2t07WYZg8MhSxrpqnE8diN3k1HA==","repository":{"url":"git+https://github.com/aws/modern-data-architecture-accelerator.git","type":"git"},"_npmVersion":"10.9.8","description":"MDAA roles module","directories":{},"maintainers":[{"name":"mdaa-dev-team","email":"mdaa-dev-team@amazon.com"}],"_nodeVersion":"22.23.1","dependencies":{"ajv":"8.18.0","yaml":"1.10.3","cdk-nag":"2.37.55","constructs":"10.6.0","aws-cdk-lib":"2.261.0","@aws-mdaa/app":"1.8.1","@aws-mdaa/config":"1.8.1","source-map-support":"0.5.21","@aws-mdaa/l3-construct":"1.8.1","@aws-mdaa/roles-l3-construct":"1.8.1"},"_hasShrinkwrap":false,"devDependencies":{"jest":"29.7.0","ts-jest":"29.4.9","ts-node":"10.9.2","typescript":"5.9.3","@types/jest":"29.5.14","@types/node":"22.9.0","@types/prettier":"2.6.0","@aws-mdaa/testing":"1.8.1","typescript-json-schema":"0.68.0"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/roles_1.8.1_1789417201690_0.49513939937060636"}}},"time":{"created":"2025-10-20T21:45:23.641Z","modified":"2026-09-14T20:20:02.017Z","1.2.0":"2025-10-20T21:45:23.959Z","1.3.0":"2025-11-26T16:14:56.029Z","1.4.0":"2026-02-04T08:22:46.503Z","1.5.0":"2026-03-26T15:00:59.162Z","1.6.0":"2026-05-22T11:05:30.746Z","1.7.0":"2026-07-17T08:45:05.644Z","1.8.0":"2026-09-01T18:41:47.106Z","1.8.1":"2026-09-14T20:20:01.808Z"},"bugs":{"url":"https://github.com/aws/modern-data-architecture-accelerator/issues"},"author":{"url":"https://aws.amazon.com/solutions","name":"Amazon Web Services"},"license":"Apache-2.0","homepage":"https://github.com/aws/modern-data-architecture-accelerator#readme","repository":{"url":"git+https://github.com/aws/modern-data-architecture-accelerator.git","type":"git"},"description":"MDAA roles module","maintainers":[{"name":"mdaa-dev-team","email":"mdaa-dev-team@amazon.com"}],"readme":"# IAM Roles and Policies\n\n> **Note:** This documentation is also available in a rendered format [here](https://aws.github.io/modern-data-architecture-accelerator/packages/apps/governance/roles-app/index.html).\n\nDeploys IAM roles, customer-managed policies, and SAML federation providers for a governed data environment. Supports persona-based policy assignment (data-admin, data-engineer, data-scientist, data-steward), multiple trust principal types including OIDC web identity federation, and CDK Nag suppression management. Use this module when you need to create IAM roles for your data teams that can be referenced across other MDAA modules for consistent, persona-based access control.\n\n---\n\n## Deployed Resources\n\nThis module deploys and integrates the following resources:\n\n**IAM Managed Policies** - Customer-managed policies created from config-defined policy documents. MDAA persona-based managed policies optionally created for attachment to roles. Policies violating CDK Nag rules require explicit suppressions.\n\n**IAM Roles** - Roles with configurable trust policies supporting account root, service principals, SAML federation, OIDC web identity federation, cross-account role ARNs, and assume role conditions. Roles can specify a base persona for automatic policy attachment.\n\nA `webidentity:<oidc-provider-arn>` trusted principal produces an `sts:AssumeRoleWithWebIdentity` trust policy with a `Federated` principal for the given OIDC provider (e.g. GitLab CI/CD, GitHub Actions). Because OIDC providers are not account-bound, an unscoped web identity trust would permit any identity issued by the provider to assume the role; the module therefore requires `assumeRoleTrustConditions` that scope the trust on the provider's **own** identity claims whenever a `webidentity:` principal is used, and does not support `webidentity:` as an `additionalTrustedPrincipals` entry (which cannot carry conditions). Specifically, at least one condition key must be prefixed with the OIDC issuer host derived from the provider ARN (e.g. a `StringLike` on `gitlab.com:sub`). This rejects an empty `{}`, an empty operator such as `{ StringLike: {} }`, conditions that only constrain unrelated keys (e.g. `aws:RequestTag/*`), a provider claim matched against a bare `*` (e.g. `{ StringLike: { \"gitlab.com:sub\": \"*\" } }`), and provider claims behind operators that do not positively pin the identity — negation (`StringNotEquals`/`StringNotLike`), set operators satisfied when the claim is absent (`ForAllValues:*`), `*IfExists` variants, and `Null`. All of these would leave the OIDC principal effectively unscoped. Use a positive matching operator such as `StringEquals`/`StringLike` (or their `ForAnyValue:` variants). (The module does not attempt to judge how narrow a non-`*` value is; partial wildcards are the operator's responsibility.) For provider-federated CI/CD (e.g. GitLab CI/CD, GitHub Actions), scope on the `:sub` claim: the `:aud` claim is a constant shared by every tenant of the provider and does not isolate a specific project/branch. (Providers such as `cognito-identity.amazonaws.com`, where `:aud` is the identity-pool ID, are the exception — there `:aud` is itself the tenant boundary, so scoping on `<provider>:aud` is accepted.)\n\n**IAM Identity (Federation) Providers** - SAML identity providers for establishing federated assume-role trust into generated roles. New providers created from SAML metadata XML documents.\n\n**SSM Parameters** - Role ARN and Role ID stored in Parameter Store for each generated role, enabling cross-module reference via `generated-role-id:` shorthand. A role can optionally share these with other accounts - see [Sharing a Role with Another Account](#sharing-a-role-with-another-account).\n\n![Roles](../../../constructs/L3/governance/roles-l3-construct/docs/Roles.png)\n\n---\n\n## Related Modules\n\n- [Data Lake](../../datalake/datalake-app/README.md) — Roles created here can be referenced as data admin, read, write, or super roles on data lake buckets\n- [Athena Workgroup](../../datalake/athena-workgroup-app/README.md) — Roles can be referenced as data admin or user roles for workgroup access\n- [DataOps Project](../../dataops/dataops-project-app/README.md) — Roles can be referenced as data engineer, execution, or data admin roles for project resources\n- [Data Warehouse](../../analytics/datawarehouse-app/README.md) — Roles can be used as execution roles or federation roles for Redshift access\n- [Data Science Team](../../ai/data-science-team-app/README.md) — Roles can be referenced as team user or data admin roles for SageMaker and Athena access\n- [Lake Formation Access Control](../lakeformation-access-control-app/README.md) — Roles can be used as principals for Lake Formation fine-grained access grants\n- [SageMaker Studio](../../ai/sm-studio-domain-app/README.md) — Roles can be referenced as data admin roles or custom execution roles for Studio domains\n- [QuickSight Namespace](../../analytics/quicksight-namespace-app/README.md) — Roles can be used for SAML federation into QuickSight namespaces\n\n---\n\n## Security/Compliance Details\n\nThis module is designed in alignment with MDAA security/compliance principles and CDK nag rulesets. Additional review is recommended prior to production deployment, ensuring organization-specific compliance requirements are met.\n\n- **Least Privilege**:\n  - Roles follow least-privilege principles with explicit trust policies\n  - Persona-based managed policies provide standardized permission sets\n  - CDK Nag integration validates security best practices with required suppressions for exceptions\n- **Separation of Duties**:\n  - Permission boundaries and CDK Nag rules help guide roles toward organizational security standards\n  - SAML federation enables SSO integration with existing identity providers\n- **Cross-Account Parameter Sharing**:\n  - Opt-in and default-off; a role's parameters are shared only with the accounts its config names\n  - What is shared is the role's ARN and id, not any permission to assume it\n\n---\n\n## Sharing a Role with Another Account\n\nA deployment in another account sometimes has to name one of these roles - in a bucket policy, a KMS key policy, or as an S3 replication role - and it cannot build the ARN itself, because MDAA truncates a role name at 64 characters with a hash of the untruncated name. `shareParametersWithAccounts` lets the named accounts read the role's ARN and id parameters instead:\n\n```yaml\ngenerateRoles:\n  s3-replication:\n    trustedPrincipal: service:s3.amazonaws.com\n    shareParametersWithAccounts:\n      - '222222222222'\n```\n\nThe consumer then references the parameter by its full ARN, and CloudFormation resolves it at deploy time:\n\n```yaml\n# in the consuming data lake's module config, not in this module's\nbuckets:\n  curated:\n    accessPolicies: [Root]\n    replication:\n      inbound:\n        sourceReplicationRoleArn: 'ssm:arn:{{partition}}:ssm:{{region}}:{{context:roles_account}}:parameter/{{org}}/<domain>/generated-role/s3-replication/arn'\n        sourceAccount: '{{context:roles_account}}'\n```\n\nThese parameter paths assume the default SSM layout. With the `@mdaaIncludeEnvInSsmPath` flag enabled, `env` is inserted after the domain - `parameter/{{org}}/<domain>/<env>/<module>/...`.\n\nWorth knowing before turning it on:\n\n- **Only the `generated-role/<name>/{arn,id}` parameters are shared.** The same role's conventional `<module>/role/<name>/{arn,id,name}` parameters stay Standard-tier and unshared, so a consumer following that path gets AccessDenied with no indication why.\n- **Only the accounts named here can read the parameters.** A RAM share always names its principals, and this module has no way to know which deployments consume the roles it creates, so it cannot be inferred.\n- **Sharing is confined to your AWS Organization.** The share sets `allowExternalPrincipals: false`, so only accounts in the same organization as the account this module deploys into can be named, and the deployment fails if one is not. Within the organization the share is accepted automatically, provided RAM sharing is enabled for it (`aws ram enable-sharing-with-aws-organization`). This keeps the share usable by a consumer deployed in the same `mdaa deploy` run, which is what it exists for; to hand a role ARN to an account in another organization, state it as a literal in that account's config.\n- **The role's parameters move to the Advanced tier**, which RAM requires in order to share them and which AWS bills. Roles without this field are unaffected and stay Standard-tier. Turning it on is a one-way change for the parameters it covers: AWS does not allow an Advanced-tier parameter to be moved back to Standard, so removing this field later leaves them Advanced and still billed until they are deleted and recreated out of band.\n- **The reading account must be in the same region.** A parameter reference is resolved by CloudFormation in the region of the stack reading it, and a parameter exists only in the region that published it.\n- **Sharing a parameter grants no access to the role.** It exposes the ARN and id, nothing else; who may assume the role is still governed entirely by its trust policy.\n- **The consuming account needs its own permission too.** The CloudFormation execution role there still needs `ssm:GetParameter*` on the shared parameter.\n\n---\n\n## Configuration\n\n### MDAA Config\n\nAdd the following snippet to your mdaa.yaml under the `modules:` section of a domain/env in order to use this module:\n\n```yaml\nroles: # Module Name can be customized\n  module_path: '@aws-mdaa/roles' # Must match module NPM package name\n  module_configs:\n    - ./roles.yaml # Filename/path can be customized\n```\n\n### Module Config Samples and Variants\n\nCopy the contents of the relevant sample config below into the `./roles.yaml` file referenced in the MDAA config snippet above.\n\n#### Minimal Configuration\n\nCreates a single IAM role with account-level trust. All properties are optional, but at least one role is recommended for a useful deployment. Start here for a basic role that other MDAA modules can reference.\n\n[sample-config-minimal.yaml](sample_configs/sample-config-minimal.yaml)\n\n```yaml\n# Contents available via above link\n--8<-- \"target/docs/packages/apps/governance/roles-app/sample_configs/sample-config-minimal.yaml\"\n```\n\n#### Comprehensive Configuration\n\nGenerates IAM roles, customer-managed policies, and SAML federation providers with persona-based policy assignment (data-admin, data-engineer, data-scientist), multiple trust principal types, and CDK Nag suppression management. Start here when evaluating all available options for personas, trust policies, SAML federation, and custom managed policies.\n\n[sample-config-comprehensive.yaml](sample_configs/sample-config-comprehensive.yaml)\n\n```yaml\n# Contents available via above link\n--8<-- \"target/docs/packages/apps/governance/roles-app/sample_configs/sample-config-comprehensive.yaml\"\n```\n\n---\n\n[Config Schema Docs](SCHEMA.md)\n","readmeFilename":"README.md"}