Amazon AWS IAM
AWS Identity and Access Management(IAM) Connector
This connector allows Turbine to connect with AWS Identity and Access Management(IAM).
Prerequisites
This integration authenticates with AWS IAM using the following input values:
Requirements
- AWS Access Key ID: A long-term AWS access key ID with access to IAM.
- AWS Secret Key ID: A long-term secret access key associated with the above AccessKey ID.
- Role ARN: An ARN of an AWS IAM Role to assume.
Capabilities
This connector provides the following capabilities:
- Create Access Key
- Disable Access Key
- Update Policy
Notes
For more information on AWS Identity and Access Management(IAM):
Configurations
AWS IAM Asset
Authenticates using AWS credentials.
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
access_key | A specific long-term AWS access key ID. | string | Required |
secret_key | A specific long-term AWS secret access key. | string | Required |
region_name | The AWS Region where you want to create new connections. | string | Optional |
role_arn | Role ARN | string | Required |
session_token | Use if a session token is provided when switching roles. | string | Optional |
Actions
Create Access Key
Creates a new AWS secret access key and corresponding AWS access key ID for the specified user. The default status for new keys is Active.
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
iam_user_name | string | Required | The name of the IAM user that the new key will belong to. |
Input Example
{"iam_user_name":"axyzusername"}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
AccessKey | object | Output field: AccessKey |
AccessKey.AccessKeyId | string | Unique identifier |
AccessKey.CreateDate | string | Date value |
AccessKey.SecretAccessKey | string | Output field: AccessKey.SecretAccessKey |
AccessKey.Status | string | Status value |
AccessKey.UserName | string | Name of the resource |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"AccessKey":{"AccessKeyId":"AKIAIOSFODNN7EXAMPLE","CreateDate":"datetime(2015, 3, 9, 18, 39, 23, 0, 68, 0)","SecretAccessKey":"wJalrXUtnFEMI/K7MDENG/bPxRfiCYzEXAMPLEKEY","Status":"Active","UserName":"Bob"}}}
Disable Access Key
Disable a specific AWS IAM user's Access Key.
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
iam_user_name | string | Required | The name of the user whose key should be updated. |
access_key_id | string | Required | The access key ID of the secret access key that needs to be updated. |
Input Example
{"iam_user_name":"Bob","access_key_id":"AKIDPMS9RO4H3FEXAMPLE"}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{}}
Update Policy
Add New Version of AWS IAM Policy. (Policies can have a maximum of 5 versions).
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
policy_arn | string | Required | The Amazon Resource Name (ARN) of the IAM policy to which you want to add a new version. |
policy_document | string | Required | The JSON policy document that you want to use as the content for this new version of the policy. |
set_as_default | boolean | Optional | Specifies whether to set this version as the policy's default version. When this parameter is true, the new policy version becomes the operative version. That is, it becomes the version that is in effect for the IAM users, groups, and roles that the policy is attached to. |
Input Example
{"policy_arn":"abcxyz","policy_document":"{'Version':'2012-10-17','Statement':[{'Effect':'Allow','Principal':{'Service':['ec2.amazonaws.com']},'Action':['sts:AssumeRole']}]}","set_as_default":true}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
PolicyVersion | object | Output field: PolicyVersion |
PolicyVersion.Document | string | Output field: PolicyVersion.Document |
PolicyVersion.VersionId | string | Unique identifier |
PolicyVersion.IsDefaultVersion | boolean | Output field: PolicyVersion.IsDefaultVersion |
PolicyVersion.CreateDate | string | Date value |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"PolicyVersion":{"Document":"xyz","VersionId":"version","IsDefaultVersion":true,"CreateDate":"datetime(2015, 1, 1)"}}}
Response Headers
Header | Description | Example |
|---|---|---|
Content-Type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Thu, 01 Jan 2024 00:00:00 GMT |