Role
- Implements: IRole, IPrincipal
This class encapsulates and extends the ROS resource type ALIYUN::RAM::Role.
Initializers
import com.aliyun.ros.cdk.ram.Role;
Role.Builder.create(Construct scope, java.lang.String id, java.lang.Boolean enableResourcePropertyConstraint)
.assumeRolePolicyDocument(IResolvable)
.assumeRolePolicyDocument(AssumeRolePolicyDocumentProperty)
.roleName(java.lang.String)
.roleName(IResolvable)
// .deletionForce(java.lang.Boolean)
// .deletionForce(IResolvable)
// .description(java.lang.String)
// .description(IResolvable)
// .ignoreExisting(java.lang.Boolean)
// .ignoreExisting(IResolvable)
// .maxSessionDuration(java.lang.Number)
// .maxSessionDuration(IResolvable)
// .policies(IResolvable)
// .policies(java.util.List<IResolvable)
// .policies(PoliciesProperty>)
// .policyAttachments(IResolvable)
// .policyAttachments(PolicyAttachmentsProperty)
// .tags(java.util.List<TagsProperty>)
.build();
| Name | Type | Description |
|---|---|---|
scope | com.aliyun.ros.cdk.core.Construct | No description. |
id | java.lang.String | No description. |
enableResourcePropertyConstraint | java.lang.Boolean | No description. |
assumeRolePolicyDocument | com.aliyun.ros.cdk.core.IResolvable OR AssumeRolePolicyDocumentProperty | Property assumeRolePolicyDocument: The trust policy that specifies one or more trusted entities allowed to assume the RAM role. |
roleName | java.lang.String OR com.aliyun.ros.cdk.core.IResolvable | Property roleName: Specifies the role name, containing up to 64 characters. |
deletionForce | java.lang.Boolean OR com.aliyun.ros.cdk.core.IResolvable | Property deletionForce: Whether force detach the policies attached to the role. |
description | java.lang.String OR com.aliyun.ros.cdk.core.IResolvable | Property description: Remark information, up to 1024 characters or Chinese characters. |
ignoreExisting | java.lang.Boolean OR com.aliyun.ros.cdk.core.IResolvable | Property ignoreExisting: Whether to ignore existing role False: ROS will perform a uniqueness check.If a role with the same name exists, an error will be reported when creating it. True: ROS will not check the uniqueness.If there is a role with the same name, the role creation process will be ignored. If the role is not created by ROS, it will be ignored during update and delete stage. |
maxSessionDuration | java.lang.Number OR com.aliyun.ros.cdk.core.IResolvable | Property maxSessionDuration: The maximum session duration of the RAM role. |
policies | com.aliyun.ros.cdk.core.IResolvable OR java.util.List | Property policies: Describes what actions are allowed on what resources. |
policyAttachments | com.aliyun.ros.cdk.core.IResolvable OR PolicyAttachmentsProperty | Property policyAttachments: System and custom policy names to attach. |
tags | java.util.List<TagsProperty> | Property tags: Tags to attach to role. |
scopeRequired
- Type: com.aliyun.ros.cdk.core.Construct
idRequired
- Type: java.lang.String
enableResourcePropertyConstraintOptional
- Type: java.lang.Boolean
assumeRolePolicyDocumentRequired
- Type: com.aliyun.ros.cdk.core.IResolvable OR AssumeRolePolicyDocumentProperty
Property assumeRolePolicyDocument: The trust policy that specifies one or more trusted entities allowed to assume the RAM role.
Trusted entities can be cloud accounts, cloud services, or identity providers (IdPs).
RAM users cannot assume RAM roles whose trusted entity is a cloud service.
roleNameRequired
- Type: java.lang.String OR com.aliyun.ros.cdk.core.IResolvable
Property roleName: Specifies the role name, containing up to 64 characters.
deletionForceOptional
- Type: java.lang.Boolean OR com.aliyun.ros.cdk.core.IResolvable
Property deletionForce: Whether force detach the policies attached to the role.
Default value is false.
descriptionOptional
- Type: java.lang.String OR com.aliyun.ros.cdk.core.IResolvable
Property description: Remark information, up to 1024 characters or Chinese characters.
ignoreExistingOptional
- Type: java.lang.Boolean OR com.aliyun.ros.cdk.core.IResolvable
Property ignoreExisting: Whether to ignore existing role False: ROS will perform a uniqueness check.If a role with the same name exists, an error will be reported when creating it. True: ROS will not check the uniqueness.If there is a role with the same name, the role creation process will be ignored. If the role is not created by ROS, it will be ignored during update and delete stage.
maxSessionDurationOptional
- Type: java.lang.Number OR com.aliyun.ros.cdk.core.IResolvable
Property maxSessionDuration: The maximum session duration of the RAM role.
Valid values: 3600 to 43200. Unit: seconds. Default value: 3600. The default value is used if the parameter is not specified.
policiesOptional
- Type: com.aliyun.ros.cdk.core.IResolvable OR java.util.List
PoliciesProperty>
Property policies: Describes what actions are allowed on what resources.
policyAttachmentsOptional
- Type: com.aliyun.ros.cdk.core.IResolvable OR PolicyAttachmentsProperty
Property policyAttachments: System and custom policy names to attach.
tagsOptional
- Type: java.util.List<TagsProperty>
Property tags: Tags to attach to role.
Max support 20 tags to add during create role. Each tag with two properties Key and Value, and Key is required.
Methods
| Name | Description |
|---|---|
toString | Returns a string representation of this construct. |
synthesize | Allows this construct to emit artifacts into the cloud assembly during synthesis. |
addCondition | No description. |
addCount | No description. |
addDependency | No description. |
addResourceDesc | No description. |
applyRemovalPolicy | No description. |
fetchCondition | No description. |
fetchDependency | No description. |
fetchResourceDesc | No description. |
getAtt | No description. |
setMetadata | No description. |
addToPolicy | Add to the policy of this principal. |
toString
public java.lang.String toString()
Returns a string representation of this construct.
synthesize
public void synthesize(ISynthesisSession session)
Allows this construct to emit artifacts into the cloud assembly during synthesis.
This method is usually implemented by framework-level constructs such as Stack and Asset as they participate in synthesizing the cloud assembly.
- Type: com.aliyun.ros.cdk.core.ISynthesisSession
The synthesis session.
addCondition
public void addCondition(RosCondition condition)
- Type: com.aliyun.ros.cdk.core.RosCondition
addCount
public void addCount(java.lang.Number OR IResolvable count)
- Type: java.lang.Number OR com.aliyun.ros.cdk.core.IResolvable
addDependency
public void addDependency(Resource resource)
- Type: com.aliyun.ros.cdk.core.Resource
addResourceDesc
public void addResourceDesc(java.lang.String desc)
- Type: java.lang.String
applyRemovalPolicy
public void applyRemovalPolicy(RemovalPolicy policy)
- Type: com.aliyun.ros.cdk.core.RemovalPolicy
fetchCondition
public RosCondition fetchCondition()
fetchDependency
public java.util.List<java.lang.String> fetchDependency()
fetchResourceDesc
public java.lang.String fetchResourceDesc()
getAtt
public IResolvable getAtt(java.lang.String name)
- Type: java.lang.String
setMetadata
public void setMetadata(java.lang.String key, java.lang.Object value)
- Type: java.lang.String
- Type: java.lang.Object
addToPolicy
public ManagedPolicy addToPolicy(PolicyDocumentProperty policyDocument)
Add to the policy of this principal.
- Type: PolicyDocumentProperty
Static Functions
| Name | Description |
|---|---|
isConstruct | Return whether the given object is a Construct. |
isConstruct
import com.aliyun.ros.cdk.ram.Role;
Role.isConstruct(java.lang.Object x)
Return whether the given object is a Construct.
- Type: java.lang.Object
Properties
| Name | Type | Description |
|---|---|---|
node | com.aliyun.ros.cdk.core.ConstructNode | The construct tree node associated with this construct. |
env | com.aliyun.ros.cdk.core.IResourceEnvironment | The environment this resource belongs to. |
ref | java.lang.String | No description. |
stack | com.aliyun.ros.cdk.core.Stack | The stack in which this resource is defined. |
resource | com.aliyun.ros.cdk.core.RosResource | No description. |
attrArn | java.lang.String OR com.aliyun.ros.cdk.core.IResolvable | Attribute Arn: Name of alicloud resource. |
attrRoleId | java.lang.String OR com.aliyun.ros.cdk.core.IResolvable | Attribute RoleId: Id of ram role. |
attrRoleName | java.lang.String OR com.aliyun.ros.cdk.core.IResolvable | Attribute RoleName: Name of ram role. |
grantPrincipal | IPrincipal | The principal to grant permissions to. |
principalName | java.lang.String OR com.aliyun.ros.cdk.core.IResolvable | The principal to grant permissions to. |
principalType | java.lang.String | The principal type, such as 'Group', 'Role', 'User'. |
props | RoleProps | No description. |
nodeRequired
public ConstructNode getNode();
- Type: com.aliyun.ros.cdk.core.ConstructNode
The construct tree node associated with this construct.
envRequired
public IResourceEnvironment getEnv();
- Type: com.aliyun.ros.cdk.core.IResourceEnvironment
The environment this resource belongs to.
For resources that are created and managed by the CDK (generally, those created by creating new class instances like Role, Bucket, etc.), this is always the same as the environment of the stack they belong to; however, for imported resources (those obtained from static methods like fromRoleArn, fromBucketName, etc.), that might be different than the stack they were imported into.
refRequired
public java.lang.String getRef();
- Type: java.lang.String
stackRequired
public Stack getStack();
- Type: com.aliyun.ros.cdk.core.Stack
The stack in which this resource is defined.
resourceOptional
public RosResource getResource();
- Type: com.aliyun.ros.cdk.core.RosResource
attrArnRequired
public java.lang.Object getAttrArn();
- Type: java.lang.String OR com.aliyun.ros.cdk.core.IResolvable
Attribute Arn: Name of alicloud resource.
attrRoleIdRequired
public java.lang.Object getAttrRoleId();
- Type: java.lang.String OR com.aliyun.ros.cdk.core.IResolvable
Attribute RoleId: Id of ram role.
attrRoleNameRequired
public java.lang.Object getAttrRoleName();
- Type: java.lang.String OR com.aliyun.ros.cdk.core.IResolvable
Attribute RoleName: Name of ram role.
grantPrincipalRequired
public IPrincipal getGrantPrincipal();
- Type: IPrincipal
The principal to grant permissions to.
principalNameRequired
public java.lang.Object getPrincipalName();
- Type: java.lang.String OR com.aliyun.ros.cdk.core.IResolvable
The principal to grant permissions to.
principalTypeRequired
public java.lang.String getPrincipalType();
- Type: java.lang.String
The principal type, such as 'Group', 'Role', 'User'.
propsRequired
public RoleProps getProps();
- Type: RoleProps