Class CfnRolePolicy
Adds or updates an inline policy document that is embedded in the specified IAM role.
Implements
Inherited Members
Namespace: Amazon.CDK.AWS.IAM
Assembly: Amazon.CDK.Lib.dll
Syntax (csharp)
public class CfnRolePolicy : CfnResource, IInspectable
Syntax (vb)
Public Class CfnRolePolicy
Inherits CfnResource
Implements IInspectable
Remarks
When you embed an inline policy in a role, the inline policy is used as part of the role's access (permissions) policy. The role's trust policy is created at the same time as the role, using CreateRole
. You can update a role's trust policy using UpdateAssumeRolePolicy
. For information about roles, see IAM roles in the IAM User Guide .
A role can also have a managed policy attached to it. To attach a managed policy to a role, use AWS::IAM::Role
. To create a new managed policy, use AWS::IAM::ManagedPolicy
. For information about policies, see Managed policies and inline policies in the IAM User Guide .
For information about the maximum number of inline policies that you can embed with a role, see IAM and AWS STS quotas in the IAM User Guide .
See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-iam-rolepolicy.html
CloudformationResource: AWS::IAM::RolePolicy
ExampleMetadata: fixture=_generated
Examples
// The code below shows an example of how to instantiate this type.
// The values are placeholders you should change.
using Amazon.CDK.AWS.IAM;
var policyDocument;
var cfnRolePolicy = new CfnRolePolicy(this, "MyCfnRolePolicy", new CfnRolePolicyProps {
PolicyName = "policyName",
RoleName = "roleName",
// the properties below are optional
PolicyDocument = policyDocument
});
Synopsis
Constructors
CfnRolePolicy(ByRefValue) | Used by jsii to construct an instance of this class from a Javascript-owned object reference |
CfnRolePolicy(DeputyBase.DeputyProps) | Used by jsii to construct an instance of this class from DeputyProps |
CfnRolePolicy(Construct, String, ICfnRolePolicyProps) |
Properties
CFN_RESOURCE_TYPE_NAME | The CloudFormation resource type name for this resource class. |
CfnProperties | |
PolicyDocument | The policy document. |
PolicyName | The name of the policy document. |
RoleName | The name of the role to associate the policy with. |
Methods
Inspect(TreeInspector) | Examines the CloudFormation resource and discloses attributes. |
RenderProperties(IDictionary<String, Object>) |
Constructors
CfnRolePolicy(ByRefValue)
Used by jsii to construct an instance of this class from a Javascript-owned object reference
protected CfnRolePolicy(ByRefValue reference)
Parameters
- reference Amazon.JSII.Runtime.Deputy.ByRefValue
The Javascript-owned object reference
CfnRolePolicy(DeputyBase.DeputyProps)
Used by jsii to construct an instance of this class from DeputyProps
protected CfnRolePolicy(DeputyBase.DeputyProps props)
Parameters
- props Amazon.JSII.Runtime.Deputy.DeputyBase.DeputyProps
The deputy props
CfnRolePolicy(Construct, String, ICfnRolePolicyProps)
public CfnRolePolicy(Construct scope, string id, ICfnRolePolicyProps props)
Parameters
- scope Constructs.Construct
Scope in which this resource is defined.
- id System.String
Construct identifier for this resource (unique in its scope).
- props ICfnRolePolicyProps
Resource properties.
Properties
CFN_RESOURCE_TYPE_NAME
The CloudFormation resource type name for this resource class.
public static string CFN_RESOURCE_TYPE_NAME { get; }
Property Value
System.String
CfnProperties
protected override IDictionary<string, object> CfnProperties { get; }
Property Value
System.Collections.Generic.IDictionary<System.String, System.Object>
Overrides
PolicyDocument
The policy document.
public virtual object PolicyDocument { get; set; }
Property Value
System.Object
PolicyName
The name of the policy document.
public virtual string PolicyName { get; set; }
Property Value
System.String
RoleName
The name of the role to associate the policy with.
public virtual string RoleName { get; set; }
Property Value
System.String
Methods
Inspect(TreeInspector)
Examines the CloudFormation resource and discloses attributes.
public virtual void Inspect(TreeInspector inspector)
Parameters
- inspector TreeInspector
tree inspector to collect and process attributes.
RenderProperties(IDictionary<String, Object>)
protected override IDictionary<string, object> RenderProperties(IDictionary<string, object> props)
Parameters
- props System.Collections.Generic.IDictionary<System.String, System.Object>
Returns
System.Collections.Generic.IDictionary<System.String, System.Object>