enclave_certificate_iam_role_associations
Creates, updates, deletes or gets an enclave_certificate_iam_role_association
resource or lists enclave_certificate_iam_role_associations
in a region
Overview
Name | enclave_certificate_iam_role_associations |
Type | Resource |
Description | Associates an AWS Identity and Access Management (IAM) role with an AWS Certificate Manager (ACM) certificate. This association is based on Amazon Resource Names and it enables the certificate to be used by the ACM for Nitro Enclaves application inside an enclave. |
Id | aws.ec2.enclave_certificate_iam_role_associations |
Fields
Name | Datatype | Description |
---|---|---|
certificate_arn | string | The Amazon Resource Name (ARN) of the ACM certificate with which to associate the IAM role. |
role_arn | string | The Amazon Resource Name (ARN) of the IAM role to associate with the ACM certificate. You can associate up to 16 IAM roles with an ACM certificate. |
certificate_s3_bucket_name | string | The name of the Amazon S3 bucket to which the certificate was uploaded. |
certificate_s3_object_key | string | The Amazon S3 object key where the certificate, certificate chain, and encrypted private key bundle are stored. |
encryption_kms_key_id | string | The ID of the AWS KMS CMK used to encrypt the private key of the certificate. |
region | string | AWS region. |
Methods
Name | Accessible by | Required Params |
---|---|---|
create_resource | INSERT | CertificateArn, RoleArn, region |
delete_resource | DELETE | data__Identifier, region |
list_resources | SELECT | region |
get_resource | SELECT | data__Identifier, region |
SELECT
examples
Gets all enclave_certificate_iam_role_associations
in a region.
SELECT
region,
certificate_arn,
role_arn,
certificate_s3_bucket_name,
certificate_s3_object_key,
encryption_kms_key_id
FROM aws.ec2.enclave_certificate_iam_role_associations
WHERE region = 'us-east-1';
Gets all properties from an individual enclave_certificate_iam_role_association
.
SELECT
region,
certificate_arn,
role_arn,
certificate_s3_bucket_name,
certificate_s3_object_key,
encryption_kms_key_id
FROM aws.ec2.enclave_certificate_iam_role_associations
WHERE region = 'us-east-1' AND data__Identifier = '<CertificateArn>|<RoleArn>';
INSERT
example
Use the following StackQL query and manifest file to create a new enclave_certificate_iam_role_association
resource, using stack-deploy
.
- Required Properties
- All Properties
- Manifest
/*+ create */
INSERT INTO aws.ec2.enclave_certificate_iam_role_associations (
CertificateArn,
RoleArn,
region
)
SELECT
'{{ CertificateArn }}',
'{{ RoleArn }}',
'{{ region }}';
/*+ create */
INSERT INTO aws.ec2.enclave_certificate_iam_role_associations (
CertificateArn,
RoleArn,
region
)
SELECT
'{{ CertificateArn }}',
'{{ RoleArn }}',
'{{ region }}';
version: 1
name: stack name
description: stack description
providers:
- aws
globals:
- name: region
value: '{{ vars.AWS_REGION }}'
resources:
- name: enclave_certificate_iam_role_association
props:
- name: CertificateArn
value: '{{ CertificateArn }}'
- name: RoleArn
value: '{{ RoleArn }}'
DELETE
example
/*+ delete */
DELETE FROM aws.ec2.enclave_certificate_iam_role_associations
WHERE data__Identifier = '<CertificateArn|RoleArn>'
AND region = 'us-east-1';
Permissions
To operate on the enclave_certificate_iam_role_associations
resource, the following permissions are required:
Create
ec2:AssociateEnclaveCertificateIamRole
Read
ec2:GetAssociatedEnclaveCertificateIamRoles
Delete
ec2:DisassociateEnclaveCertificateIamRole
List
ec2:GetAssociatedEnclaveCertificateIamRoles