CLOUD / A CONCEPT NOTE

IAM

who can do what on which resource

~80 sec read

Overview · mechanism
pitfall · examples

01 / THE SHORT VERSION

The idea in a few sentences.

IAM (Identity and Access Management) is the policy engine for cloud platforms. A principal (user, role, or service account) attempts an action (like s3:GetObject) on a resource (like arn:aws:s3:::my-bucket/*). A policy document — JSON with Effect: Allow/Deny — either permits or denies the request.

02 / FOLLOW THE MECHANISM

How an IAM decision is made

  1. Principal

    makes an API call with their credentials (access key, OIDC token, or session).

  2. Cloud IAM engine

    collects all applicable policies: identity-based, resource-based, and organization SCPs.

  3. Engine

    evaluates policy statements in order: explicit Deny → explicit Allow → default Deny.

  4. Engine

    caches the decision for the duration of the credentials' TTL to avoid re-evaluating every call.

04 / COMMAND NOTES

Read the command, then the result.

Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.

EXAMPLE 01 · REFERENCE

test what actions a policy allows

aws iam simulate-principal-policy --policy-source-arn arn:aws:iam::123456789012:user/admin --action-names s3:ListBucket

EXAMPLE 02 · REFERENCE

list all custom IAM roles

gcloud iam roles list --project MY_PROJECT

Explore command anatomy in the CLI lab