Skip to content

Data types

[!caution]

This service is not deployed. There is no iam.shelfcs.com or sts.shelfcs.com in the published endpoint list, and no call on this page will answer. This page is the specification, not a description of something running.

For the identity system that does exist — the identity service users, one project, one role, and EC2 access keys — read Identity, as deployed.

FieldTypeNotes
UserNamestringRequired. Mutable. Unique within the account.
UserIdstringImmutable. Opaque.
ArnstringImmutable. arn:aws-shelf:iam::<account>:user/<name>
PathstringOptional. Mutable. Defaults to /.
CreateDatetimestampImmutable.

PROPOSED: UserName constraints — 1 to 64 characters, alphanumeric plus +=,.@_-. This matches what existing tooling validates before it calls us, so a narrower rule would reject names that clients believe are valid.

Note that the ARN embeds the user name, which is mutable. Renaming a user therefore changes its ARN, and any policy referencing the old ARN stops matching. This is inherited AWS behaviour, it is a genuine hazard, and it is documented rather than silently fixed, because fixing it would break compatibility.

FieldTypeNotes
GroupNamestringRequired. Mutable. Unique within the account.
GroupIdstringImmutable.
ArnstringImmutable form; embeds the name.
PathstringOptional. Mutable.
CreateDatetimestampImmutable.
FieldTypeNotes
AccessKeyIdstringImmutable.
SecretAccessKeystringReturned only by CreateAccessKey, once.
StatusstringActive or Inactive. Mutable.
UserNamestringImmutable. The owning user.
CreateDatetimestampImmutable.

A secret is never stored in a form we can return. ListAccessKeys returns ids and status only.

FieldTypeNotes
LastUsedDatetimestampAbsent if never used.
ServiceNamestringThe service last called.
RegionstringThe region of that call.

PROPOSED: last-used is updated asynchronously and may lag. The lag is documented with a bound, because a customer deleting a key relies on it.

FieldTypeNotes
RoleNamestringRequired. Mutable.
RoleIdstringImmutable.
ArnstringImmutable form; embeds the name.
AssumeRolePolicyDocumentstringRequired. Mutable.
MaxSessionDurationintegerSeconds. OPEN: bounds.
CreateDatetimestampImmutable.
FieldTypeNotes
PolicyNamestringRequired. Immutable after creation.
PolicyIdstringImmutable.
ArnstringImmutable.
DefaultVersionIdstringMutable.
AttachmentCountintegerDerived.
CreateDate, UpdateDatetimestamp

PROPOSED: a managed policy keeps up to five versions, matching AWS, so that tooling which rotates versions does not fail on the sixth.

  • Shelf Cloud API conventions
  • Shelf Cloud API Reference