Skip to content

Policy actions

[!caution]

This service is not deployed. There is no iam.shelfcs.com or sts.shelfcs.com in the published endpoint list, and no call on this page will answer. This page is the specification, not a description of something running.

For the identity system that does exist — the identity service users, one project, one role, and EC2 access keys — read Identity, as deployed.

Policies decide what an identity may do. These actions create them, version them, attach them and read them back.

ActionResource scope
iam:CreatePolicy, iam:DeletePolicypolicy/<name>
iam:GetPolicy, iam:GetPolicyVersion, iam:ListPoliciespolicy/*
iam:CreatePolicyVersion, iam:SetDefaultPolicyVersionpolicy/<name>
iam:AttachUserPolicy, iam:DetachUserPolicyBoth user/<name> and policy/<name>
iam:PutUserPolicy, iam:DeleteUserPolicyuser/<name>

The attach and detach actions evaluate against both the identity and the policy.

[!warning]

An identity holding iam:AttachUserPolicy and iam:CreatePolicy can grant itself any permission in the account. There is no permission boundary in v1 to constrain that. Treat those two actions as equivalent to full administrative access, and grant them accordingly.

Managed policies are standalone documents with their own ARN, attachable to many identities, and versioned. Use them for anything reused.

Inline policies are embedded in one identity, have no ARN of their own, are not versioned, and are deleted with the identity. Use them for permissions that belong to exactly one identity and should not outlive it.

ParameterTypeRequiredNotes
PolicyNamestringYesImmutable after creation
PolicyDocumentstringYesURL-encoded JSON
PathstringNo
DescriptionstringNoImmutable after creation

PROPOSED: a policy document is at most 6144 characters, counted with whitespace removed.

The document is validated at creation. A document that does not parse, names a malformed ARN, or uses a construct we do not implement is rejected with MalformedPolicyDocument — never accepted and then evaluated differently from what it says.

That rule matters most for any construct in the policy language we do not support: silently ignoring an unsupported Condition would turn a restrictive policy into a permissive one, which is the worst possible failure mode for this service.

Response: the Policy — PolicyName, PolicyId, Arn, DefaultVersionId, AttachmentCount, CreateDate, UpdateDate.

A managed policy is not edited in place. CreatePolicyVersion adds a version, optionally making it the default:

ParameterTypeRequiredNotes
PolicyArnstringYes
PolicyDocumentstringYes
SetAsDefaultbooleanNoDefault false

PROPOSED: five versions per policy, matching what tooling expects. The sixth returns LimitExceeded; delete an old version first.

Only the default version is evaluated. A new version created without SetAsDefault changes nothing until SetDefaultPolicyVersion is called — which is what makes a policy change reviewable before it takes effect, and instantly reversible afterwards by setting the previous version back.

ActionAttaches to
AttachUserPolicy / DetachUserPolicyA user
AttachGroupPolicy / DetachGroupPolicyA group
AttachRolePolicy / DetachRolePolicyA role
ListAttachedUserPoliciesLists what is attached to a user

Attaching an already-attached policy succeeds and changes nothing.

A policy cannot be deleted while attached to anything: DeletePolicy returns DeleteConflict until every attachment is removed.

ActionPurpose
PutUserPolicyWrite an inline policy; overwrites by name
GetUserPolicyRead one
ListUserPoliciesNames of inline policies on a user
DeleteUserPolicyRemove one

PutUserPolicy overwrites without warning. There is no version history and no undo — the previous document is gone. This is the practical reason to prefer managed policies for anything that matters.

GetPolicy returns metadata only, not the document. GetPolicyVersion returns the document, URL-encoded.

To answer “what can this user do”, a caller must gather: inline policies on the user, managed policies attached to the user, and both again for every group the user belongs to. There is no single call that returns an effective permission set, and no policy simulator in v1.

OPEN (Michael): whether a policy simulator exists in v1. Without one, the only way to test a policy is to hold the credential and try the call — which is what DryRun on the EC2 actions is for.