Figuring out EC2 Support 'IAM Role Per Service'

We have a setup around creating one IAM role per application. Both within and outside of VPC, can this be managed via the Ansible EC2 modules or is there some additional scripting necessary on my end?