Skip to main content

role_policy

Gets an individual role_policy resource

Overview

Namerole_policy
TypeResource
Descriptionrole_policy
Idawscc.iam.role_policy

Fields

NameDatatypeDescription
policy_documentobjectThe policy document.<br/> You must provide policies in JSON format in IAM. However, for CFN templates formatted in YAML, you can provide the policy in JSON or YAML format. CFN always converts a YAML policy to JSON format before submitting it to IAM.<br/> The [regex pattern](https://docs.aws.amazon.com/http://wikipedia.org/wiki/regex) used to validate this parameter is a string of characters consisting of the following:<br/> + Any printable ASCII character ranging from the space character (``\u0020``) through the end of the ASCII character range<br/> + The printable characters in the Basic Latin and Latin-1 Supplement character set (through ``\u00FF``)<br/> + The special characters tab (``\u0009``), line feed (``\u000A``), and carriage return (``\u000D``)
policy_namestringThe name of the policy document.<br/> This parameter allows (through its [regex pattern](https://docs.aws.amazon.com/http://wikipedia.org/wiki/regex)) a string of characters consisting of upper and lowercase alphanumeric characters with no spaces. You can also include any of the following characters: _+=,.@-
role_namestringThe name of the role to associate the policy with.<br/> This parameter allows (through its [regex pattern](https://docs.aws.amazon.com/http://wikipedia.org/wiki/regex)) a string of characters consisting of upper and lowercase alphanumeric characters with no spaces. You can also include any of the following characters: _+=,.@-
regionstringAWS region.

Methods

Currently only SELECT is supported for this resource resource.

Example

SELECT
region,
policy_document,
policy_name,
role_name
FROM awscc.iam.role_policy
WHERE data__Identifier = '<PolicyName>|<RoleName>';

Permissions

To operate on the role_policy resource, the following permissions are required:

Read

iam:GetRolePolicy

Update

iam:PutRolePolicy,
iam:GetRolePolicy

Delete

iam:DeleteRolePolicy,
iam:GetRolePolicy