diff --git a/AWS-IAM-CLI.md b/AWS-IAM-CLI.md index b3db080..f118245 100644 --- a/AWS-IAM-CLI.md +++ b/AWS-IAM-CLI.md @@ -260,6 +260,32 @@ aws --endpoint $AWS_ENDPOINT iam delete-user-policy \ --policy-name ReadOnlyPolicy ``` +### Managed Policies + +Managed policies are standalone policies that are stored in the configuration and can be attached to multiple users. + +#### Attach a Managed Policy + +```bash +aws --endpoint $AWS_ENDPOINT iam attach-user-policy \ + --user-name bob \ + --policy-arn arn:aws:iam::seaweedfs:policy/ReadOnlyPolicy +``` + +#### List Attached Managed Policies + +```bash +aws --endpoint $AWS_ENDPOINT iam list-attached-user-policies --user-name bob +``` + +#### Detach a Managed Policy + +```bash +aws --endpoint $AWS_ENDPOINT iam detach-user-policy \ + --user-name bob \ + --policy-arn arn:aws:iam::seaweedfs:policy/ReadOnlyPolicy +``` + --- ## Verify Configuration @@ -331,13 +357,18 @@ cat > alice-policy.json << 'EOF' } EOF -# 5. Attach policy to user +# 5. Attach inline policy to user aws --endpoint $AWS_ENDPOINT iam put-user-policy \ --user-name alice \ --policy-name SharedBucketReadOnly \ --policy-document file://alice-policy.json -# 6. Verify +# 6. Attach a managed policy (e.g., ReadOnlyPolicy is built-in or previously created) +aws --endpoint $AWS_ENDPOINT iam attach-user-policy \ + --user-name alice \ + --policy-arn arn:aws:iam::seaweedfs:policy/ReadOnlyPolicy + +# 7. Verify echo 's3.configure' | weed shell ``` diff --git a/Amazon-IAM-API.md b/Amazon-IAM-API.md index e88b70d..9656f5e 100644 --- a/Amazon-IAM-API.md +++ b/Amazon-IAM-API.md @@ -60,10 +60,13 @@ weed iam -filer=localhost:8888 -port=8111 | `DeleteAccessKey` | Delete access key | Yes (own keys) | | `UpdateAccessKey` | Change access key status (Active/Inactive) | Yes (own keys) | | `ListAccessKeys` | List access keys for user | Yes (own keys) | -| `CreatePolicy` | Validate a policy document | Admin only | +| `CreatePolicy` | Validate and store a managed policy | Admin only | | `PutUserPolicy` | Attach inline policy to user | Admin only | | `GetUserPolicy` | Get user's inline policy | Admin only | | `DeleteUserPolicy` | Remove user's inline policy | Admin only | +| `AttachUserPolicy` | Attach managed policy to user | Admin only | +| `DetachUserPolicy` | Remove managed policy from user | Admin only | +| `ListAttachedUserPolicies` | List managed policies for user | Admin only | ### Self-Service Operations @@ -143,6 +146,25 @@ aws --endpoint $AWS_ENDPOINT iam list-users aws --endpoint $AWS_ENDPOINT iam list-access-keys --user-name alice ``` +### Managed Policies + +Managed policies are standalone policies that can be attached to multiple users. + +```bash +# Attach a managed policy to user +aws --endpoint $AWS_ENDPOINT iam attach-user-policy \ + --user-name alice \ + --policy-arn arn:aws:iam::seaweedfs:policy/ReadOnlyPolicy + +# List attached managed policies +aws --endpoint $AWS_ENDPOINT iam list-attached-user-policies --user-name alice + +# Detach a managed policy +aws --endpoint $AWS_ENDPOINT iam detach-user-policy \ + --user-name alice \ + --policy-arn arn:aws:iam::seaweedfs:policy/ReadOnlyPolicy +``` + ### Self-Service: User Managing Their Own Keys A non-admin user can manage their own access keys: