> ## Documentation Index
> Fetch the complete documentation index at: https://klef.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# AWS

<div className="page-title-row">
  <img src="https://mintcdn.com/klef/xJ0kXbcegZOD2G3h/images/connectors/aws.svg?fit=max&auto=format&n=xJ0kXbcegZOD2G3h&q=85&s=0d7cfab6e38a19984288c22772d996e6" alt="" noZoom width="189" height="126" data-path="images/connectors/aws.svg" />

  <h1>AWS</h1>
</div>

## Connection

### Setup

<Steps>
  <Step title="Create an IAM user">
    [Create an IAM user](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_users_create.html) for Klef
    and give it an access key.
  </Step>

  <Step title="Allow the actions">
    Attach a policy allowing the actions under [Permissions](#permissions).
  </Step>

  <Step title="Reach the organization">
    Only needed for accounts the key was not issued in. Let the user assume a role in each account, and
    name that role on the connection.
  </Step>
</Steps>

### Settings

| Setting                | Required | Description                                                                                    |
| ---------------------- | -------- | ---------------------------------------------------------------------------------------------- |
| Access key ID          | Yes      | Access key ID of the IAM user Klef signs in as.                                                |
| Secret access key      | Yes      | Secret of that access key. Stored encrypted.                                                   |
| Region                 |          | AWS region. Defaults to us-east-1.                                                             |
| Role ARN               |          | Role to assume, for an account the key was not issued in.                                      |
| External ID            |          | External ID the role's trust policy requires. Stored encrypted.                                |
| Organization role name |          | Role Klef assumes in the organization's other accounts, such as OrganizationAccountAccessRole. |

### Permissions

Minimum permissions the connection requires.

| Capability                            | Required | Granted by (any one)                                                                                                                                                                                                                                                                        |
| ------------------------------------- | -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Read the IAM roster                   | Yes      | `iam:GetAccountAuthorizationDetails`, `iam:ListUsers`, `iam:GetUser`                                                                                                                                                                                                                        |
| Create and update IAM users           | Yes      | `iam:CreateUser`, `iam:UpdateUser`                                                                                                                                                                                                                                                          |
| Tag IAM users                         | Yes      | `iam:TagUser`, `iam:UntagUser`                                                                                                                                                                                                                                                              |
| Open and close console sign-in        | Yes      | `iam:GetLoginProfile`, `iam:CreateLoginProfile`, `iam:DeleteLoginProfile`, `iam:GetAccountPasswordPolicy`                                                                                                                                                                                   |
| Reset console passwords               | Yes      | `iam:UpdateLoginProfile`                                                                                                                                                                                                                                                                    |
| Revoke sign-in credentials            | Yes      | `iam:ListAccessKeys`, `iam:UpdateAccessKey`, `iam:ListMFADevices`, `iam:DeactivateMFADevice`, `iam:ListSSHPublicKeys`, `iam:UpdateSSHPublicKey`, `iam:ListServiceSpecificCredentials`, `iam:UpdateServiceSpecificCredential`, `iam:ListSigningCertificates`, `iam:UpdateSigningCertificate` |
| Write inline policies                 | Yes      | `iam:ListUserPolicies`, `iam:GetUserPolicy`, `iam:PutUserPolicy`, `iam:DeleteUserPolicy`                                                                                                                                                                                                    |
| Manage group membership               | Yes      | `iam:ListGroups`, `iam:ListGroupsForUser`, `iam:AddUserToGroup`, `iam:RemoveUserFromGroup`                                                                                                                                                                                                  |
| Attach and detach managed policies    | Yes      | `iam:ListPolicies`, `iam:ListAttachedUserPolicies`, `iam:AttachUserPolicy`, `iam:DetachUserPolicy`                                                                                                                                                                                          |
| Set a permissions boundary            |          | `iam:PutUserPermissionsBoundary`, `iam:DeleteUserPermissionsBoundary`                                                                                                                                                                                                                       |
| Enumerate the organization's accounts |          | `organizations:ListAccounts`                                                                                                                                                                                                                                                                |
| Assume the role in each account       |          | `sts:AssumeRole`                                                                                                                                                                                                                                                                            |

## aws.iam\_user

### Fields

| Field                                | Type               | Required | Description                                                                                              |
| ------------------------------------ | ------------------ | -------- | -------------------------------------------------------------------------------------------------------- |
| `userName`                           | string, up to 64   | Yes      | IAM user name. Unique within the account.                                                                |
| `accountId`                          | string, up to 12   |          | Account the user is created in. Defaults to the connection's own account.                                |
| `path`                               | string, up to 512  |          | IAM path, such as /engineering/.                                                                         |
| `permissionsBoundary`                | string, up to 2048 |          | ARN of the managed policy that caps the user's permissions.                                              |
| `email`                              | string, up to 256  |          | Email address, kept as a tag.                                                                            |
| `fullName`                           | string, up to 256  |          | Full name, kept as a tag.                                                                                |
| `jobTitle`                           | string, up to 256  |          | Job title, kept as a tag.                                                                                |
| `department`                         | string, up to 256  |          | Department, kept as a tag.                                                                               |
| `employeeId`                         | string, up to 256  |          | Employee number, kept as a tag.                                                                          |
| `expiresAt` (Access expires)         | date               |          | When access should end, kept as a tag. AWS does not act on it unless a policy condition reads the tag.   |
| `consoleAccess` (Console sign-in)    | bool               |          | Whether the user can sign in to the AWS console.                                                         |
| `tags`                               | map                |          | Other tags on the user.                                                                                  |
| `tags.<key>`                         | string, up to 256  |          | Tag value.                                                                                               |
| `inlinePolicies`                     | map                |          | Policies embedded in the user, by name.                                                                  |
| `inlinePolicies.<name>`              | string             |          | Policy document, as JSON.                                                                                |
| `groups`                             | grant              |          | IAM groups the user is in and managed policies attached to the user. One row grants one group or policy. |
| `groups[]` (Group or managed policy) | string             |          | ARN of a group or managed policy.                                                                        |

### Default Account Matching Rules

When Klef [adopts](/docs/adoption) an account that already exists in AWS, it works out whose it is by trying these in order. A connection can override them.

| Account field | Worker field            |
| ------------- | ----------------------- |
| `email`       | `worker.business_email` |
| `employeeId`  | `worker.employee_id`    |

## Examples

### Contractor access

Unlicensed Microsoft, Slack and AWS access for contractors that expires on their end date, with a warning to their manager first.

```hcl theme={null}
stage active {
  # The group's ARN is an example; the editor lists the groups and policies in your account.
  target aws.iam_user {
    userName      = worker.business_email
    email         = worker.business_email
    fullName      = worker.display_name
    consoleAccess = true
    expiresAt     = worker.end_date
    groups        = ["arn:aws:iam::111122223333:group/contractors"]
  }
}
```
