Skip to content
Proud to collaborate with Microsoft for Startups

aws.iam.create_role ​

Call AWS IAM CreateRole using a CloudConnection UUID.

Overview ​

PropertyValue
Workflow typeAtomic
LibraryBase-aws
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
organization_uuiduuidYes—Authenticated organization UUID used for field resolution and connection scoping.
connection_uuiduuidYes—AWS CloudConnection UUID for the target IAM account, scoped to the caller organization.
workflow_run_idstringNo—Engine DAG run ID stamped onto child steps.
regionstringNo—AWS API endpoint region override; omit to use the connection or SDK default.
pathstringNo—The path to the role. For more information about paths, see IAM Identifiers in the IAM User Guide. This parameter is optional. If it is not included, it defaults to a slash (/). This parameter allo...
role_namestringYes—The name of the role to create. IAM user, group, role, and policy names must be unique within the account. Names are not distinguished by case. For example, you cannot create resources named both "...
assume_role_policy_documentstringYes—The trust relationship policy document that grants an entity permission to assume the role. In IAM, you must provide a JSON policy that has been converted to a string. However, for CloudFormation t...
descriptionstringNo—A description of the role.
max_session_durationintegerNo—The maximum session duration (in seconds) that you want to set for the specified role. If you do not specify a value for this setting, the default value of one hour is applied. This setting can hav...
permissions_boundarystringNo—The ARN of the managed policy that is used to set the permissions boundary for the role. A permissions boundary policy defines the maximum permissions that identity-based policies can grant to an e...
tagslistNo—A list of tags that you want to attach to the new role. Each tag consists of a key name and an associated value. For more information about tagging, see Tagging IAM resources in the IAM User Guide....
provider_native_requestjsonNo—Optional provider-native request overrides for AWS parameters not yet promoted to first-class fields.

Output Schema ​

FieldTypeRequiredDefaultDescription
organization_uuiduuidNo—Organization UUID echoed from input.
connection_uuiduuidNo—AWS CloudConnection UUID echoed from input.
regionstringNo—AWS API endpoint region used.
servicestringNo—AWS boto3 service/client name.
operationstringNo—AWS API operation invoked.
request_idstringNo—AWS request ID when available.
responsejsonNo—Sanitized provider response object.
itemslistNo—Primary response item list when the API returns a collection.
result_countintegerNo—Count of primary response items.
next_page_tokenstringNo—Pagination token for the next page.
failure_reasonstringNo—Human-readable failure reason.
failed_stepstringNo—Failed logical step.
failed_layerjsonNo—Failed DAG layer if engine supplies one.
failed_at_statestringNo—State where failure occurred.
errorstringNo—Error message.
error_typestringNo—Error class.
failed_atstringNo—ISO failure timestamp.

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—execute—
completedNoYesYes——
failedNoYesNo——

State Diagram ​

Transitions ​

FromActionToDescription
pendingexecutecompleted—
* (any state)failfailed—

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "aws.iam.create_role",
  "initial_data": {
    "organization_uuid": "value",
    "connection_uuid": "value",
    "role_name": "value",
    "assume_role_policy_document": "value"
  }
}