Welcome
[!caution]
This service is not deployed. There is no
iam.shelfcs.comorsts.shelfcs.comin the published endpoint list, and no call on this page will answer. This page is the specification, not a description of something running.For the identity system that does exist — the identity service users, one project, one role, and EC2 access keys — read Identity, as deployed.
Objective
Section titled “Objective”Endpoint
Section titled “Endpoint”PROPOSED: IAM is a global service. One endpoint, and a fixed signing region.
iam.<domain>The signing region for IAM is hel1 regardless of where the caller is, because
a global service still requires a region in the credential scope.
OPEN (Michael): whether a global IAM is correct, or whether identities are regional. A global IAM means one identity store, which is what customers expect; it also means the identity store is a single failure domain for every region.
API version
Section titled “API version”PROPOSED: 2010-05-08, the AWS IAM API version, so that existing clients
send a version we recognise.
What IAM does
Section titled “What IAM does”- Holds users: identities within an account
- Issues access keys: the credentials that sign API requests
- Holds roles: identities that can be assumed, with temporary credentials
- Holds policies: the documents that decide whether a request is allowed
- Answers authorisation: for every request to every service
What IAM does not do
Section titled “What IAM does not do”- It is not an identity provider for a customer’s own application’s end users.
- It does not federate with an external identity provider in v1.
- It does not support cross-account access in v1.
- It does not manage sign-in to the console. Console sign-in is an Account concern; API credentials are an IAM concern, and the two are separate.
Authorisation model in one paragraph
Section titled “Authorisation model in one paragraph”A request arrives signed by an access key. The key identifies a user or a role session in exactly one account. Every policy attached to that identity is gathered, and the request’s action and resource are evaluated against them. An explicit deny wins over any allow. In the absence of an allow, the request is denied. Nothing is permitted by default, including for the account owner’s own resources.
Go further
Section titled “Go further”- Shelf Cloud API conventions
- Shelf Cloud API Reference