IAM Policies
What is an IAM Policy?
IAM policies allow which actions a user can make regarding account management. For example, an admin can allow a user to create and delete their own access keys.
Supported Policies
You can view the full list of actions that are supported in IAM policies here: Feature Support
Examples
Adding help after aws iam and any other subcommand will open the manual page.
On the bottom of the manual pages they provide cli examples as well.
Custom Policies
This policy allows a user to list all the users of their account, and manage their own credentials
{
"Version":"2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"iam:ListUsers"
],
"Resource": "*"
},
{
"Effect": "Allow",
"Action": [
"iam:*AccessKey*",
"iam:GetUser",
],
"Resource": ["arn:aws:iam::<account-id>:user/<user-name>"]
}
]
}
The resource data can be obtained via the Switch Cloud Portal UI or via the AWS CLI:
$ aws --profile myproject-admin iam list-users
{
"Users": [
{
"Path": "/",
"UserName": "01a08fdc-85d2-71cc-855b-6e1b1f86e653",
"UserId": "01a08fdc-85d2-71cc-855b-6e1b1f86e653",
"Arn": "arn:aws:iam::RGW07642419864320583:user/01a08fdc-85d2-71cc-855b-6e1b1f86e653",
"CreateDate": "2025-02-03T22:37:04.044215+00:00"
},
{
"Path": "/",
"UserName": "credentials-admin",
"UserId": "01a08fe0-19f2-7096-aa08-a61b907cc9ab",
"Arn": "arn:aws:iam::RGW07642419864320583:user/credentials-admin",
"CreateDate": "2025-02-03T23:40:00.080133+00:00"
}
]
}
The first user which has the same name as their ID, is the main user of the account. We created the second one to apply the above policy.
You can copy/paste the Arn part to the Resource segment on the above policy to apply it
to the credentials-admin user.
We then save the json in a file called CredentialManagementPolicy.json and we run the
following to apply the policy to the user.
% aws --profile myproject-admin iam put-user-policy \
--user-name credentials-admin \
--policy-name CredentialManagementPolicy \
--policy-document file://CredentialManagementPolicy.json
Managed policies
We can also create policy templates called managed policies and directly attach them to a user, group, or role. The backend currently supports the following predefined managed policies for IAM:
arn:aws:iam::aws:policy/IAMFullAccessarn:aws:iam::aws:policy/IAMReadOnlyAccessarn:aws:iam::aws:policy/AmazonSNSFullAccessarn:aws:iam::aws:policy/AmazonSNSReadOnlyAccessarn:aws:iam::aws:policy/AmazonS3FullAccessarn:aws:iam::aws:policy/AmazonS3ReadOnlyAccess
These policies can be applied like this:
% aws --profile myproject-admin iam create-group --group-name readonly-users
{
"Group": {
"Path": "/",
"GroupName": "readonly-users",
"GroupId": "2e9fa915-1ebf-4e68-8005-bff5cb095292",
"Arn": "arn:aws:iam::RGW07642419864320583:group/readonly-users"
}
}
% aws --profile myproject-admin iam attach-group-policy \
--group-name readonly-users \
--policy-arn arn:aws:iam::aws:policy/AmazonS3ReadOnlyAccess
% aws --profile myproject-admin iam list-attached-group-policies --group-name readonly-users
{
"AttachedPolicies": [
{
"PolicyName": "AmazonS3ReadOnlyAccess",
"PolicyArn": "arn:aws:iam::aws:policy/AmazonS3ReadOnlyAccess"
}
]
}
Best Practices for IAM Policies
-
Follow the Principle of Least Privilege: Grant only the permissions necessary for a specific task. If a user is allowed to manage policies without proper measures, they can edit their own policies and become an admin.
-
Test Policies Before Deployment: Validate JSON syntax using a JSON linter. Apply policies to a test bucket to confirm they behave as intended before using them in production.
-
Regularly Review and Update Policies: Periodically audit bucket policies to ensure they comply with organizational security standards and remove obsolete rules.
-
Only Use Policies When Needed: It is often better to use multiple buckets than grant access to different users based on prefix through policies.