(Optional) A dedicated deployment account can be used to further enhance security. This configuration creates a second role within the newly created account. This role trusts the given deployment account, allowing users in the given deployment account to assume the role.
To declare this entity in your AWS CloudFormation template, use the following syntax:
{ "AccountId" : String, "RoleName" : String, "AWSManagedPolicyArns" : [ String, ... ] }
AccountId: String RoleName: String AWSManagedPolicyArns: - String
Deployment Account Id
Required: Yes
Type: String
Minimum: 12
Maximum: 12
Update requires: No interruption
Deployment Role Name.
Required: No
Type: String
Minimum: 1
Maximum: 256
Update requires: No interruption
A List of AWS managed policy arn's to attach to the deployment account role
Required: Yes
Type: List of String
Update requires: No interruption