AWSRoleARN
The optional Amazon Resource Name of the role to use when authenticating.
Data Type
string
Default Value
""
Remarks
It is common to use a role for authentication instead of your direct AWS account credentials. Entering the AWSRoleARN causes the provider to call AWS STS AssumeRole for that role and use the resulting temporary credentials to authenticate, instead of signing with base credentials directly.
When AuthScheme is set to AWSMSKIAM, the provider determines the base credentials used for the AssumeRole call as follows:
- If AWSAccessKey and AWSSecretKey are set, those static keys are used as the base credentials for the AssumeRole call. In this case, the keys must be those of an IAM user; you cannot use the credentials of an AWS root user when setting AWSRoleARN.
- If AWSAccessKey and AWSSecretKey are not set, and the host machine has an attached EC2 instance IAM role, the provider automatically obtains base credentials from the instance profile (via the instance metadata service). Setting only AWSRoleARN is sufficient in this case, and it is not necessary to specify AWSAccessKey and AWSSecretKey.