Write a policy
A policy says what an identity may do, and on which resources. Nothing is granted by default, so a policy is how an identity stops being able to do nothing.
Start from the example
Section titled “Start from the example”Do not start from a blank file. The CLI generates a sample with the current grammar in it:
deployport iam identity-policy exampleEdit it down rather than building it up. The question to answer is what this identity must do, not everything it may do.
Create it
Section titled “Create it”deployport iam identity-policy create --file ./build-runner.jsonAttach it
Section titled “Attach it”To a user:
deployport iam users policies attach --username build-runner --policy build-runnerTo a role, which is how a program gets temporary credentials instead of a long-lived key:
deployport iam roles policies attach --role build-runner --policy build-runnerCheck what a policy reaches
Section titled “Check what a policy reaches”Before you hand it over, see everything it is attached to:
deployport iam identity-policy attachment list <policy-name>A policy attached to more identities than you expected is the ordinary way a scope becomes wider than it reads.
The grammar
Section titled “The grammar”Identity Policy JSON Reference has every field, the effect values, and how resource matching works.
When an action name changes
Section titled “When an action name changes”A policy names actions. A policy that names an action which no longer exists refuses everything it used to allow, because nothing matches. That is silent at the identity and loud at the call site, so check a policy after any platform change that renames an action.