To support a clean separation of concerns and robust cdk destroy cycles, the IAM roles for the Fargate Task and Task Execution are managed out-of-band. They must be created in your AWS account before deploying the main CDK infrastructure.
These roles are long-lived and will remain intact even when the transient application stack is created, updated, or destroyed.
The Task Execution Role is used by the ECS container agent to authenticate with ECR (to pull the MapServer Docker image) and with CloudWatch (to stream logs).
Create the role and allow the ECS Task service principal to assume it:
aws iam create-role \
--role-name MapserverFargateExecutionRole \
--assume-role-policy-document file://task-role-trust-policy.json
Attach the custom task execution policy to the role:
aws iam put-role-policy \
--role-name MapserverFargateExecutionRole \
--policy-name MapserverFargateExecutionPolicy \
--policy-document file://task-execution-role-policy.json
The Task Role is the identity assumed by the MapServer proxy and scanner running inside the container. It enables reading and writing S3 collections metadata, and signing S3 range requests for serving COGs.
aws iam create-role \
--role-name MapserverFargateTaskRole \
--assume-role-policy-document file://task-role-trust-policy.json
Attach the S3 config and imagery access permissions policy:
aws iam put-role-policy \
--role-name MapserverFargateTaskRole \
--policy-name MapserverFargateTaskPolicy \
--policy-document file://task-role-policy.json
Verify that both roles were created successfully and grab their ARNs:
aws iam get-role --role-name MapserverFargateTaskRole --query "Role.Arn" --output text
aws iam get-role --role-name MapserverFargateExecutionRole --query "Role.Arn" --output text
You will pass these ARNs to your cdk deploy command:
npx cdk deploy \
-c task_role_arn=arn:aws:iam::123456789012:role/MapserverFargateTaskRole \
-c execution_role_arn=arn:aws:iam::123456789012:role/MapserverFargateExecutionRole