Data types
[!caution]
This service is not deployed. There is no
iam.shelfcs.comorsts.shelfcs.comin the published endpoint list, and no call on this page will answer. This page is the specification, not a description of something running.For the identity system that does exist — the identity service users, one project, one role, and EC2 access keys — read Identity, as deployed.
Objective
Section titled “Objective”| Field | Type | Notes |
|---|---|---|
UserName | string | Required. Mutable. Unique within the account. |
UserId | string | Immutable. Opaque. |
Arn | string | Immutable. arn:aws-shelf:iam::<account>:user/<name> |
Path | string | Optional. Mutable. Defaults to /. |
CreateDate | timestamp | Immutable. |
PROPOSED: UserName constraints — 1 to 64 characters, alphanumeric plus
+=,.@_-. This matches what existing tooling validates before it calls us,
so a narrower rule would reject names that clients believe are valid.
Note that the ARN embeds the user name, which is mutable. Renaming a user therefore changes its ARN, and any policy referencing the old ARN stops matching. This is inherited AWS behaviour, it is a genuine hazard, and it is documented rather than silently fixed, because fixing it would break compatibility.
| Field | Type | Notes |
|---|---|---|
GroupName | string | Required. Mutable. Unique within the account. |
GroupId | string | Immutable. |
Arn | string | Immutable form; embeds the name. |
Path | string | Optional. Mutable. |
CreateDate | timestamp | Immutable. |
AccessKey
Section titled “AccessKey”| Field | Type | Notes |
|---|---|---|
AccessKeyId | string | Immutable. |
SecretAccessKey | string | Returned only by CreateAccessKey, once. |
Status | string | Active or Inactive. Mutable. |
UserName | string | Immutable. The owning user. |
CreateDate | timestamp | Immutable. |
A secret is never stored in a form we can return. ListAccessKeys returns ids
and status only.
AccessKeyLastUsed
Section titled “AccessKeyLastUsed”| Field | Type | Notes |
|---|---|---|
LastUsedDate | timestamp | Absent if never used. |
ServiceName | string | The service last called. |
Region | string | The region of that call. |
PROPOSED: last-used is updated asynchronously and may lag. The lag is documented with a bound, because a customer deleting a key relies on it.
| Field | Type | Notes |
|---|---|---|
RoleName | string | Required. Mutable. |
RoleId | string | Immutable. |
Arn | string | Immutable form; embeds the name. |
AssumeRolePolicyDocument | string | Required. Mutable. |
MaxSessionDuration | integer | Seconds. OPEN: bounds. |
CreateDate | timestamp | Immutable. |
Policy
Section titled “Policy”| Field | Type | Notes |
|---|---|---|
PolicyName | string | Required. Immutable after creation. |
PolicyId | string | Immutable. |
Arn | string | Immutable. |
DefaultVersionId | string | Mutable. |
AttachmentCount | integer | Derived. |
CreateDate, UpdateDate | timestamp |
PROPOSED: a managed policy keeps up to five versions, matching AWS, so that tooling which rotates versions does not fail on the sixth.
Go further
Section titled “Go further”- Shelf Cloud API conventions
- Shelf Cloud API Reference