Identity
Identity here is deliberately small: one user, one project, one role. Most of what an AWS-shaped identity service would offer is absent, and this section says so plainly rather than leaving you to discover it.
Identity resources
Section titled “Identity resources”Identity, as deployed What actually authenticates you — the two identity systems, the objects your account is made of, and every IAM concept mapped onto them, most of it to “does not exist”.
Access keys The credential the compute API signs with: how to mint, rotate and withdraw one, what it can do, and the one way it does not behave like AWS.
Authentication The signing contract every service shares.
Specification only — not deployed
Section titled “Specification only — not deployed”The pages below describe an AWS-shaped identity service that is not running. There is no IAM or STS endpoint in the published endpoint list, and no call in them will answer. They are a design document.
IAM API reference — users, groups, policies, access keys.
STS API reference — short-lived credentials.
What this means for your security model
Section titled “What this means for your security model”There are no groups, no roles, no policies, no permission boundaries, no condition keys, no temporary credentials, no instance profiles and no MFA. A policy written for AWS restricts nothing here.
The only boundary is the account itself. Two things that must not touch each other need two accounts.
Related
Section titled “Related”Account — what signing up creates.
Quotas and limits — what your one role permits you to consume.