Actions
[!caution]
This service is not deployed. There is no
iam.shelfcs.comorsts.shelfcs.comin the published endpoint list, and no call on this page will answer. This page is the specification, not a description of something running.For the identity system that does exist — the identity service users, one project, one role, and EC2 access keys — read Identity, as deployed.
Objective
Section titled “Objective”| Action | Purpose |
|---|---|
CreateUser | Create a user in this account |
GetUser | Retrieve a user |
ListUsers | List users, paginated |
UpdateUser | Change a user’s name or path |
DeleteUser | Delete a user; fails if credentials or attachments remain |
Groups
Section titled “Groups”| Action | Purpose |
|---|---|
CreateGroup | Create a group |
GetGroup | Retrieve a group and its members |
ListGroups | List groups, paginated |
DeleteGroup | Delete a group |
AddUserToGroup | Add a member |
RemoveUserFromGroup | Remove a member |
ListGroupsForUser | Groups a user belongs to |
Access keys
Section titled “Access keys”| Action | Purpose |
|---|---|
CreateAccessKey | Issue a key pair; the secret is returned once |
ListAccessKeys | List key ids for a user; never returns secrets |
UpdateAccessKey | Activate or deactivate a key |
DeleteAccessKey | Delete a key permanently |
GetAccessKeyLastUsed | When and against which service a key was last used |
GetAccessKeyLastUsed exists so that a customer can rotate keys safely: it is
the only way to know whether a key is still in use before deleting it.
| Action | Purpose |
|---|---|
CreateRole | Create a role with a trust policy |
GetRole | Retrieve a role |
ListRoles | List roles, paginated |
UpdateAssumeRolePolicy | Replace the trust policy |
DeleteRole | Delete a role |
OPEN (Michael): whether roles and temporary credentials ship in v1 at all.
If they do, AssumeRole and the credential-vending endpoint are part of v1 and
need their own decisions on session duration and token format. If they do not,
these actions are removed rather than stubbed.
Policies
Section titled “Policies”| Action | Purpose |
|---|---|
CreatePolicy | Create a managed policy |
GetPolicy | Retrieve a managed policy and its metadata |
GetPolicyVersion | Retrieve a specific version’s document |
ListPolicies | List managed policies, paginated |
CreatePolicyVersion | Add a version, optionally setting it default |
DeletePolicy | Delete a managed policy |
AttachUserPolicy | Attach a managed policy to a user |
DetachUserPolicy | Detach it |
AttachGroupPolicy | Attach to a group |
DetachGroupPolicy | Detach it |
AttachRolePolicy | Attach to a role |
DetachRolePolicy | Detach it |
ListAttachedUserPolicies | What is attached to a user |
PutUserPolicy | Write an inline policy on a user |
GetUserPolicy | Read an inline policy |
DeleteUserPolicy | Remove an inline policy |
PROPOSED: managed policies and inline policies both exist, because customer tooling assumes both. Managed policies are versioned; inline policies are not.
Account-level
Section titled “Account-level”| Action | Purpose |
|---|---|
GetCallerIdentity | Who am I, which account, which ARN |
GetCallerIdentity is the first call anyone makes. It must work with any valid
credential, require no permission, and never fail for authorisation reasons —
it is how a customer proves their credentials are configured correctly.
PROPOSED: GetCallerIdentity lives at the STS endpoint in AWS, not IAM.
Whether we mirror that split, or answer it from IAM, is a compatibility
decision: clients call sts.<domain> for it. Mirroring AWS means shipping an
STS endpoint in v1 even if nothing else in STS exists.
Not in v1
Section titled “Not in v1”Federation, identity providers, SAML, OIDC, MFA devices, service-linked roles, account aliases, credential reports, permission boundaries, and organisations. They are named here so that their absence is deliberate rather than an oversight, and so that nothing in v1 makes them harder to add.
Go further
Section titled “Go further”- Shelf Cloud API conventions
- Shelf Cloud API Reference