{"repo":"cloud-copilot/iam-simulate","free":true,"listed":false,"github":"https://github.com/cloud-copilot/iam-simulate","clone":"git clone https://github.com/cloud-copilot/iam-simulate.git","description":"An IAM Simulator that outputs detailed explains of how a request was evaluated.","language":"TypeScript","stars":103,"topics":["aws","iam"],"license":"AGPL-3.0","category":"deployment-docker-iac","readme_excerpt":"IAM Simulate An AWS IAM Simulator and Policy Tester built as a Node/Typescript library. The simulator currently supports these features of AWS IAM IAM Feature Support - Identity Policies - Resource Policies - Service Control Policies - Resource Control Policies - Permission Boundaries - All AWS Condition Operators - Same Account and Cross Account Requests - Custom trust behavior for IAM Trust Policies and KMS Key Policies Request Validation iam-simulate will automatically validate inputs including - IAM policies using iam-policy - IAM Actions using iam-data - The resource ARN against allowed resource types for the action - The context keys allowed for the action/resource and their types. Currently all global condition keys are allowed for all requests which is not strictly true. More validation will be added in the future. Explanation iam-simulate will detail which statements were decisive in the final decision to allow or deny a request. It will also return \"explains\" for each statement that was evaluated, detailing why that statement applied to the request or not. Features Coming Soon - Session Policies - Validation of Global Condition Keys for each action - Automatically populating context keys from the request such as aws:PrincipalServiceName Anonymous Requests Use anonymousPrincipal to simulate unsigned requests, such as public S3 object access granted by a bucket policy. Anonymous requests do not have identity policies, session policies, permission boundaries, or SCPs; ","default_branch":null,"files":null,"tree":[],"storefront":"/r/cloud-copilot","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/cloud-copilot/iam-simulate/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}