Skip to content

Write a policy

A policy says what an identity may do, and on which resources. Nothing is granted by default, so a policy is how an identity stops being able to do nothing.

Do not start from a blank file. The CLI generates a sample with the current grammar in it:

Terminal window
deployport iam identity-policy example

Edit it down rather than building it up. The question to answer is what this identity must do, not everything it may do.

Terminal window
deployport iam identity-policy create --file ./build-runner.json

To a user:

Terminal window
deployport iam users policies attach --username build-runner --policy build-runner

To a role, which is how a program gets temporary credentials instead of a long-lived key:

Terminal window
deployport iam roles policies attach --role build-runner --policy build-runner

Before you hand it over, see everything it is attached to:

Terminal window
deployport iam identity-policy attachment list <policy-name>

A policy attached to more identities than you expected is the ordinary way a scope becomes wider than it reads.

Identity Policy JSON Reference has every field, the effect values, and how resource matching works.

A policy names actions. A policy that names an action which no longer exists refuses everything it used to allow, because nothing matches. That is silent at the identity and loud at the call site, so check a policy after any platform change that renames an action.