role_aliases
Creates, updates, deletes or gets a role_alias
resource or lists role_aliases
in a region
Overview
Name | role_aliases |
Type | Resource |
Description | Use the AWS::IoT::RoleAlias resource to declare an AWS IoT RoleAlias. |
Id | aws.iot.role_aliases |
Fields
Name | Datatype | Description |
---|---|---|
role_alias | string | |
role_alias_arn | string | |
role_arn | string | |
credential_duration_seconds | integer | |
tags | array | |
region | string | AWS region. |
Methods
Name | Accessible by | Required Params |
---|---|---|
create_resource | INSERT | RoleArn, region |
delete_resource | DELETE | data__Identifier, region |
update_resource | UPDATE | data__Identifier, data__PatchDocument, region |
list_resources | SELECT | region |
get_resource | SELECT | data__Identifier, region |
SELECT
examples
Gets all role_aliases
in a region.
SELECT
region,
role_alias,
role_alias_arn,
role_arn,
credential_duration_seconds,
tags
FROM aws.iot.role_aliases
WHERE region = 'us-east-1';
Gets all properties from an individual role_alias
.
SELECT
region,
role_alias,
role_alias_arn,
role_arn,
credential_duration_seconds,
tags
FROM aws.iot.role_aliases
WHERE region = 'us-east-1' AND data__Identifier = '<RoleAlias>';
INSERT
example
Use the following StackQL query and manifest file to create a new role_alias
resource, using stack-deploy
.
- Required Properties
- All Properties
- Manifest
/*+ create */
INSERT INTO aws.iot.role_aliases (
RoleArn,
region
)
SELECT
'{{ RoleArn }}',
'{{ region }}';
/*+ create */
INSERT INTO aws.iot.role_aliases (
RoleAlias,
RoleArn,
CredentialDurationSeconds,
Tags,
region
)
SELECT
'{{ RoleAlias }}',
'{{ RoleArn }}',
'{{ CredentialDurationSeconds }}',
'{{ Tags }}',
'{{ region }}';
version: 1
name: stack name
description: stack description
providers:
- aws
globals:
- name: region
value: '{{ vars.AWS_REGION }}'
resources:
- name: role_alias
props:
- name: RoleAlias
value: '{{ RoleAlias }}'
- name: RoleArn
value: '{{ RoleArn }}'
- name: CredentialDurationSeconds
value: '{{ CredentialDurationSeconds }}'
- name: Tags
value:
- Key: '{{ Key }}'
Value: '{{ Value }}'
DELETE
example
/*+ delete */
DELETE FROM aws.iot.role_aliases
WHERE data__Identifier = '<RoleAlias>'
AND region = 'us-east-1';
Permissions
To operate on the role_aliases
resource, the following permissions are required:
Create
iam:GetRole,
iam:PassRole,
iot:CreateRoleAlias,
iot:DescribeRoleAlias,
iot:TagResource,
iot:ListTagsForResource
Read
iam:GetRole,
iam:PassRole,
iot:DescribeRoleAlias,
iot:ListTagsForResource
Update
iam:GetRole,
iam:PassRole,
iot:UpdateRoleAlias,
iot:DescribeRoleAlias,
iot:TagResource,
iot:UntagResource,
iot:ListTagsForResource
Delete
iot:DeleteRoleAlias,
iot:DescribeRoleAlias
List
iot:ListRoleAliases