npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@aws-mdaa/roles

v1.7.0

Published

MDAA roles module

Readme

IAM Roles and Policies

Note: This documentation is also available in a rendered format here.

Deploys IAM roles, customer-managed policies, and SAML federation providers for a governed data environment. Supports persona-based policy assignment (data-admin, data-engineer, data-scientist, data-steward), multiple trust principal types, and CDK Nag suppression management. Use this module when you need to create IAM roles for your data teams that can be referenced across other MDAA modules for consistent, persona-based access control.


Deployed Resources

This module deploys and integrates the following resources:

IAM Managed Policies - Customer-managed policies created from config-defined policy documents. MDAA persona-based managed policies optionally created for attachment to roles. Policies violating CDK Nag rules require explicit suppressions.

IAM Roles - Roles with configurable trust policies supporting account root, service principals, SAML federation, cross-account role ARNs, and assume role conditions. Roles can specify a base persona for automatic policy attachment.

IAM Identity (Federation) Providers - SAML identity providers for establishing federated assume-role trust into generated roles. New providers created from SAML metadata XML documents.

SSM Parameters - Role ARN and Role ID stored in Parameter Store for each generated role, enabling cross-module reference via generated-role-id: shorthand.

Roles


Related Modules

  • Data Lake — Roles created here can be referenced as data admin, read, write, or super roles on data lake buckets
  • Athena Workgroup — Roles can be referenced as data admin or user roles for workgroup access
  • DataOps Project — Roles can be referenced as data engineer, execution, or data admin roles for project resources
  • Data Warehouse — Roles can be used as execution roles or federation roles for Redshift access
  • Data Science Team — Roles can be referenced as team user or data admin roles for SageMaker and Athena access
  • Lake Formation Access Control — Roles can be used as principals for Lake Formation fine-grained access grants
  • SageMaker Studio — Roles can be referenced as data admin roles or custom execution roles for Studio domains
  • QuickSight Namespace — Roles can be used for SAML federation into QuickSight namespaces

Security/Compliance Details

This module is designed in alignment with MDAA security/compliance principles and CDK nag rulesets. Additional review is recommended prior to production deployment, ensuring organization-specific compliance requirements are met.

  • Least Privilege:
    • Roles follow least-privilege principles with explicit trust policies
    • Persona-based managed policies provide standardized permission sets
    • CDK Nag integration validates security best practices with required suppressions for exceptions
  • Separation of Duties:
    • Permission boundaries and CDK Nag rules help guide roles toward organizational security standards
    • SAML federation enables SSO integration with existing identity providers

Configuration

MDAA Config

Add the following snippet to your mdaa.yaml under the modules: section of a domain/env in order to use this module:

roles: # Module Name can be customized
  module_path: '@aws-mdaa/roles' # Must match module NPM package name
  module_configs:
    - ./roles.yaml # Filename/path can be customized

Module Config Samples and Variants

Copy the contents of the relevant sample config below into the ./roles.yaml file referenced in the MDAA config snippet above.

Minimal Configuration

Creates a single IAM role with account-level trust. All properties are optional, but at least one role is recommended for a useful deployment. Start here for a basic role that other MDAA modules can reference.

sample-config-minimal.yaml

# Contents available via above link
--8<-- "target/docs/packages/apps/governance/roles-app/sample_configs/sample-config-minimal.yaml"

Comprehensive Configuration

Generates IAM roles, customer-managed policies, and SAML federation providers with persona-based policy assignment (data-admin, data-engineer, data-scientist), multiple trust principal types, and CDK Nag suppression management. Start here when evaluating all available options for personas, trust policies, SAML federation, and custom managed policies.

sample-config-comprehensive.yaml

# Contents available via above link
--8<-- "target/docs/packages/apps/governance/roles-app/sample_configs/sample-config-comprehensive.yaml"

Config Schema Docs