aws-iam
Provides verified corrections for IAM behaviors that AI agents frequently get wrong — policy evaluation edge cases, trust policy gotchas, STS session limits, Organizations quirks, and SAML/MFA specifics. Also provides structured workflows for IAM role management and baseline policy generation from application source code or a Terraform plan JSON. Covers condition operator safety (ForAnyValue/ForAllValues with Null checks), bucket policy deny patterns (VPC endpoint restrictions, org paths), confused deputy protection, and service role creation for AWS services (Glue, CloudTrail, Lambda, ECS, etc.) with aws:SourceAccount/aws:SourceArn trust conditions. Applies when creating IAM roles, writing IAM or bucket policies, generating policies from application source code or a Terraform plan JSON, working with STS, Organizations, or condition operators, or any task needing a service or execution role. Does not cover non-IAM authorization like Cognito user-pool policies or app-level RBAC.
- Version
- 2
Pinned to revision 2c8eac6005ad, so it is the text this page describes rather than whatever the author pushed since.
Files
- skills/aws-iam/SKILL.md
- skills/aws-iam/references/aws-iam-policy-generation.md
- skills/aws-iam/references/aws-iam-role-management.md
- skills/aws-iam/references/common-pitfalls.md
- skills/aws-iam/references/service-authorization.md
Every link opens the file at its source, pinned to the revision this page describes.