Rotate a root AWS credential to a scoped IAM operator
connections_mint_org_operatorMint a real IAM user (+ a standing connections-vault-operator role trusting it) in the SAME AWS account as an already-connected ROOT-tagged instance, carrying an explicit org+iam+sts:AssumeRole policy (narrower than AdministratorAccess), and store the minted key over that instance - all in-lambda, using the currently vaulted root key server-side. The new key stays in the vault; the reply carries {connection, userArn, roleArn}. Fixes the AWS-inherent limitation where a root credential can reach Organizations/STS but every IAM API call fails (GetSessionToken creds are IAM-blocked for root) - the org-management credential's own IAM ops start working immediately after this call, both through connections_execute (server-signed) and through shell/script_run (the new vault-operator role's AssumeRole fast path).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| userName | No | IAM user name to create/reuse. Defaults to 'connections-org-operator'. | |
| instanceName | No | Instance name to write the minted operator credential to. Defaults to fromRootInstance (self-rotate in place). | |
| fromRootInstance | Yes | The already-connected ROOT-tagged AWS instance name to source authority from (e.g. 'Root/Connections'). |