Skip to content

Actions

[!caution]

This service is not deployed. There is no iam.shelfcs.com or sts.shelfcs.com in the published endpoint list, and no call on this page will answer. This page is the specification, not a description of something running.

For the identity system that does exist — the identity service users, one project, one role, and EC2 access keys — read Identity, as deployed.

ActionPurpose
CreateUserCreate a user in this account
GetUserRetrieve a user
ListUsersList users, paginated
UpdateUserChange a user’s name or path
DeleteUserDelete a user; fails if credentials or attachments remain
ActionPurpose
CreateGroupCreate a group
GetGroupRetrieve a group and its members
ListGroupsList groups, paginated
DeleteGroupDelete a group
AddUserToGroupAdd a member
RemoveUserFromGroupRemove a member
ListGroupsForUserGroups a user belongs to
ActionPurpose
CreateAccessKeyIssue a key pair; the secret is returned once
ListAccessKeysList key ids for a user; never returns secrets
UpdateAccessKeyActivate or deactivate a key
DeleteAccessKeyDelete a key permanently
GetAccessKeyLastUsedWhen and against which service a key was last used

GetAccessKeyLastUsed exists so that a customer can rotate keys safely: it is the only way to know whether a key is still in use before deleting it.

ActionPurpose
CreateRoleCreate a role with a trust policy
GetRoleRetrieve a role
ListRolesList roles, paginated
UpdateAssumeRolePolicyReplace the trust policy
DeleteRoleDelete a role

OPEN (Michael): whether roles and temporary credentials ship in v1 at all. If they do, AssumeRole and the credential-vending endpoint are part of v1 and need their own decisions on session duration and token format. If they do not, these actions are removed rather than stubbed.

ActionPurpose
CreatePolicyCreate a managed policy
GetPolicyRetrieve a managed policy and its metadata
GetPolicyVersionRetrieve a specific version’s document
ListPoliciesList managed policies, paginated
CreatePolicyVersionAdd a version, optionally setting it default
DeletePolicyDelete a managed policy
AttachUserPolicyAttach a managed policy to a user
DetachUserPolicyDetach it
AttachGroupPolicyAttach to a group
DetachGroupPolicyDetach it
AttachRolePolicyAttach to a role
DetachRolePolicyDetach it
ListAttachedUserPoliciesWhat is attached to a user
PutUserPolicyWrite an inline policy on a user
GetUserPolicyRead an inline policy
DeleteUserPolicyRemove an inline policy

PROPOSED: managed policies and inline policies both exist, because customer tooling assumes both. Managed policies are versioned; inline policies are not.

ActionPurpose
GetCallerIdentityWho am I, which account, which ARN

GetCallerIdentity is the first call anyone makes. It must work with any valid credential, require no permission, and never fail for authorisation reasons — it is how a customer proves their credentials are configured correctly.

PROPOSED: GetCallerIdentity lives at the STS endpoint in AWS, not IAM. Whether we mirror that split, or answer it from IAM, is a compatibility decision: clients call sts.<domain> for it. Mirroring AWS means shipping an STS endpoint in v1 even if nothing else in STS exists.

Federation, identity providers, SAML, OIDC, MFA devices, service-linked roles, account aliases, credential reports, permission boundaries, and organisations. They are named here so that their absence is deliberate rather than an oversight, and so that nothing in v1 makes them harder to add.

  • Shelf Cloud API conventions
  • Shelf Cloud API Reference