Skip to content

Welcome

[!caution]

This service is not deployed. There is no iam.shelfcs.com or sts.shelfcs.com in the published endpoint list, and no call on this page will answer. This page is the specification, not a description of something running.

For the identity system that does exist — the identity service users, one project, one role, and EC2 access keys — read Identity, as deployed.

PROPOSED: IAM is a global service. One endpoint, and a fixed signing region.

iam.<domain>

The signing region for IAM is hel1 regardless of where the caller is, because a global service still requires a region in the credential scope.

OPEN (Michael): whether a global IAM is correct, or whether identities are regional. A global IAM means one identity store, which is what customers expect; it also means the identity store is a single failure domain for every region.

PROPOSED: 2010-05-08, the AWS IAM API version, so that existing clients send a version we recognise.

  • Holds users: identities within an account
  • Issues access keys: the credentials that sign API requests
  • Holds roles: identities that can be assumed, with temporary credentials
  • Holds policies: the documents that decide whether a request is allowed
  • Answers authorisation: for every request to every service
  • It is not an identity provider for a customer’s own application’s end users.
  • It does not federate with an external identity provider in v1.
  • It does not support cross-account access in v1.
  • It does not manage sign-in to the console. Console sign-in is an Account concern; API credentials are an IAM concern, and the two are separate.

A request arrives signed by an access key. The key identifies a user or a role session in exactly one account. Every policy attached to that identity is gathered, and the request’s action and resource are evaluated against them. An explicit deny wins over any allow. In the absence of an allow, the request is denied. Nothing is permitted by default, including for the account owner’s own resources.

  • Shelf Cloud API conventions
  • Shelf Cloud API Reference