open-vault/builtin/logical/aws
Theron Voran e1a432a167
AWS: Add iam_groups parameter to role create/update (#8811)
Allows vault roles to be associated with IAM groups in the AWS
secrets engine, since IAM groups are a recommended way to manage
IAM user policies. IAM users generated against a vault role will
be added to the IAM Groups. For a credential type of
`assumed_role` or `federation_token`, the policies sent to the
corresponding AWS call (sts:AssumeRole or sts:GetFederation) will
be the policies from each group in `iam_groups` combined with the
`policy_document` and `policy_arns` parameters.

Co-authored-by: Jim Kalafut <jkalafut@hashicorp.com>
2020-06-09 16:56:12 -07:00
..
cmd/aws Update to api 1.0.1 and sdk 0.1.8 2019-04-15 14:10:07 -04:00
backend.go Switch to go modules (#6585) 2019-04-13 03:44:06 -04:00
backend_test.go AWS: Add iam_groups parameter to role create/update (#8811) 2020-06-09 16:56:12 -07:00
client.go Migrate built in auto seal to go-kms-wrapping (#8118) 2020-01-10 20:39:52 -05:00
iam_policies.go AWS: Add iam_groups parameter to role create/update (#8811) 2020-06-09 16:56:12 -07:00
iam_policies_test.go AWS: Add iam_groups parameter to role create/update (#8811) 2020-06-09 16:56:12 -07:00
path_config_lease.go Switch to go modules (#6585) 2019-04-13 03:44:06 -04:00
path_config_root.go Add reading AWS root/config endpoint (#7245) 2019-09-13 10:07:04 -07:00
path_config_root_test.go Add reading AWS root/config endpoint (#7245) 2019-09-13 10:07:04 -07:00
path_config_rotate_root.go Switch to go modules (#6585) 2019-04-13 03:44:06 -04:00
path_roles.go AWS: Add iam_groups parameter to role create/update (#8811) 2020-06-09 16:56:12 -07:00
path_roles_test.go secret/aws: Support permissions boundaries on iam_user creds (#6786) 2019-09-19 16:35:12 -07:00
path_user.go AWS: Add iam_groups parameter to role create/update (#8811) 2020-06-09 16:56:12 -07:00
rollback.go Switch to go modules (#6585) 2019-04-13 03:44:06 -04:00
secret_access_keys.go AWS: Add iam_groups parameter to role create/update (#8811) 2020-06-09 16:56:12 -07:00
secret_access_keys_test.go Allow use of pre-existing policies for AWS users 2015-12-30 18:05:54 +00:00