AWSTemplateFormatVersion: '2010-09-09'
Description: 'Automated Cost Auditor: Read-Only IAM Role for multi-region EC2 waste scanning.'

Parameters:
  ExternalId:
    Type: String
    Description: 'The secure External ID provided on your Automated Cost Auditor dashboard.'
    MinLength: '8'

Resources:
  CostAuditorScannerRole:
    Type: 'AWS::IAM::Role'
    Properties:
      RoleName: 'CostAuditorScannerRole'
      AssumeRolePolicyDocument:
        Version: '2012-10-17'
        Statement:
          - Effect: Allow
            Principal:
              AWS: 'arn:aws:iam::YOUR_12_DIGIT_ID:root'
            Action: 'sts:AssumeRole'
            Condition:
              StringEquals:
                'sts:ExternalId': !Ref ExternalId
      Policies:
        - PolicyName: 'EC2StrictReadOnlyPolicy'
          PolicyDocument:
            Version: '2012-10-17'
            Statement:
              - Effect: Allow
                Action:
                  - 'ec2:DescribeVolumes'
                  - 'ec2:DescribeAddresses'
                  - 'ec2:DescribeSnapshots'
                  - 'ec2:DescribeNetworkInterfaces'
                  - 'ec2:DescribeNatGateways'
                  - 'ec2:DescribeInstances'
                Resource: '*'

Outputs:
  RoleARN:
    Description: 'Copy this Role ARN and paste it into the Automated Cost Auditor website to begin your scan.'
    Value: !GetAtt CostAuditorScannerRole.Arn
