This is a JSON file that is attached to an AWS IAM role using the assume-role-policy-document flag
"Version": "2012-10-17",
"Statement": [
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::$(TrustedAccountID):root"
"Action": "sts:AssumeRole",
"Condition": {}
