AWS SDK 또는 CLI로 ListAttachedRolePolicies 사용하기
AWS SDK 또는 CLI로 ListAttachedRolePolicies 사용하기
다음 코드 예시는 ListAttachedRolePolicies을(를) 사용하는 방법을 보여줘요.
출처: 문서
본문
SDK for .NET
참고: GitHub에 더 많은 내용이 있어요. AWS Code Examples Repository에서 전체 예시를 찾아 실행·설정 방법을 배울 수 있어요.
/// <summary>
/// List the IAM role policies that are attached to an IAM role.
/// </summary>
/// <param name="roleName">The IAM role to list IAM policies for.</param>
/// <returns>A list of the IAM policies attached to the IAM role.</returns>
public async Task<List<AttachedPolicyType>> ListAttachedRolePoliciesAsync(string roleName)
{
var attachedPolicies = new List<AttachedPolicyType>();
var attachedRolePoliciesPaginator = _IAMService.Paginators.ListAttachedRolePolicies(new ListAttachedRolePoliciesRequest
{
RoleName = roleName });
await foreach (var response in attachedRolePoliciesPaginator.Responses)
{
attachedPolicies.AddRange(response.AttachedPolicies);
}
return attachedPolicies;
}
API 상세 내용은 AWS SDK for .NET API Reference의 ListAttachedRolePolicies 문서를 참고하세요.
AWS CLI
지정 역할에 연결된 모든 관리형 정책을 나열하려면
이 명령은 AWS 계정의 SecurityAuditRole IAM 역할에 연결된 관리형 정책의 이름과 ARN을 반환해요.
aws iam list-attached-role-policies \
--role-name
SecurityAuditRole
출력:
{
"AttachedPolicies": [
{
"PolicyName": "SecurityAudit",
"PolicyArn": "arn:aws:iam::aws:policy/SecurityAudit"
}
],
"IsTruncated": false
}
더 자세한 내용은 AWS IAM 사용자 가이드의 'IAM의 정책과 권한' 문서를 참고하세요.
API 상세 내용은 AWS CLI Command Reference의 ListAttachedRolePolicies 문서를 참고하세요.
SDK for Go V2
참고: GitHub에 더 많은 내용이 있어요. AWS Code Examples Repository에서 전체 예시를 찾아 실행·설정 방법을 배울 수 있어요.
import (
"context"
"encoding/json"
"log"
"github.com/aws/aws-sdk-go-v2/aws"
"github.com/aws/aws-sdk-go-v2/service/iam"
"github.com/aws/aws-sdk-go-v2/service/iam/types"
)
// RoleWrapper encapsulates AWS Identity and Access Management (IAM) role actions
// used in the examples.
// It contains an IAM service client that is used to perform role actions.
type RoleWrapper struct
{
IamClient *iam.Client
}
// ListAttachedRolePolicies lists the policies that are attached to the specified role.
func (wrapper RoleWrapper) ListAttachedRolePolicies(ctx context.Context, roleName string) ([]types.AttachedPolicy, error)
{
var policies []types.AttachedPolicy
result, err := wrapper.IamClient.ListAttachedRolePolicies(ctx, &iam.ListAttachedRolePoliciesInput
{
RoleName: aws.String(roleName),
})
if err != nil
{
log.Printf("Couldn't list attached policies for role %v. Here's why: %v\n", roleName, err)
} else
{
policies = result.AttachedPolicies
}
return policies, err
}
API 상세 내용은 AWS SDK for Go API Reference의 ListAttachedRolePolicies 문서를 참고하세요.
SDK for JavaScript (v3)
참고: GitHub에 더 많은 내용이 있어요. AWS Code Examples Repository에서 전체 예시를 찾아 실행·설정 방법을 배울 수 있어요.
역할에 연결된 정책을 나열해요.
import
{
ListAttachedRolePoliciesCommand,
IAMClient,
} from "@aws-sdk/client-iam";
const client = new IAMClient(
{
});
/**
* A generator function that handles paginated results.
* The AWS SDK for JavaScript (v3) provides
{
@link https://docs.aws.amazon.com/AWSJavaScriptSDK/v3/latest/index.html#paginators | paginator} functions to simplify this.
* @param
{
string} roleName
*/
export async function* listAttachedRolePolicies(roleName)
{
const command = new ListAttachedRolePoliciesCommand(
{
RoleName: roleName,
});
let response = await client.send(command);
while (response.AttachedPolicies?.length)
{
for (const policy of response.AttachedPolicies)
{
yield policy;
}
if (response.IsTruncated)
{
response = await client.send(
new ListAttachedRolePoliciesCommand(
{
RoleName: roleName,
Marker: response.Marker,
}),
);
} else
{
break;
}
}
}
API 상세 내용은 AWS SDK for JavaScript API Reference의 ListAttachedRolePolicies 문서를 참고하세요.
SDK for PHP
참고: GitHub에 더 많은 내용이 있어요. AWS Code Examples Repository에서 전체 예시를 찾아 실행·설정 방법을 배울 수 있어요.
$uuid = uniqid();
$service = new IAMService();
public function listAttachedRolePolicies($roleName, $pathPrefix = "", $marker = "", $maxItems = 0)
{
$listAttachRolePoliciesArguments = ['RoleName' => $roleName];
if ($pathPrefix)
{
$listAttachRolePoliciesArguments['PathPrefix'] = $pathPrefix;
}
if ($marker)
{
$listAttachRolePoliciesArguments['Marker'] = $marker;
}
if ($maxItems)
{
$listAttachRolePoliciesArguments['MaxItems'] = $maxItems;
}
return $this->iamClient->listAttachedRolePolicies($listAttachRolePoliciesArguments);
}
API 상세 내용은 AWS SDK for PHP API Reference의 ListAttachedRolePolicies 문서를 참고하세요.
Tools for PowerShell V4
예시 1: 이 명령은 AWS 계정의 SecurityAuditRole IAM 역할에 연결된 관리형 정책의 이름과 ARN을 반환해요. 역할에 포함된 인라인 정책 목록을 보려면 Get-IAMRolePolicyList 명령을 사용하면 돼요.
Get-IAMAttachedRolePolicyList -RoleName "SecurityAuditRole"
출력:
PolicyArn PolicyName
--------- ----------
arn:aws:iam::aws:policy/SecurityAudit SecurityAudit
API 상세 내용은 AWS Tools for PowerShell Cmdlet Reference (V4)의 ListAttachedRolePolicies 문서를 참고하세요.
Tools for PowerShell V5
예시 1: 이 명령은 AWS 계정의 SecurityAuditRole IAM 역할에 연결된 관리형 정책의 이름과 ARN을 반환해요. 역할에 포함된 인라인 정책 목록을 보려면 Get-IAMRolePolicyList 명령을 사용하면 돼요.
Get-IAMAttachedRolePolicyList -RoleName "SecurityAuditRole"
출력:
PolicyArn PolicyName
--------- ----------
arn:aws:iam::aws:policy/SecurityAudit SecurityAudit
API 상세 내용은 AWS Tools for PowerShell Cmdlet Reference (V5)의 ListAttachedRolePolicies 문서를 참고하세요.
SDK for Python (Boto3)
참고: GitHub에 더 많은 내용이 있어요. AWS Code Examples Repository에서 전체 예시를 찾아 실행·설정 방법을 배울 수 있어요.
def list_attached_policies(role_name):
"""
Lists policies attached to a role.
:param role_name: The name of the role to query.
"""
try:
role = iam.Role(role_name)
for policy in role.attached_policies.all():
logger.info("Got policy %s.", policy.arn)
except ClientError:
logger.exception("Couldn't list attached policies for %s.", role_name)
raise
API 상세 내용은 AWS SDK for Python (Boto3) API Reference의 ListAttachedRolePolicies 문서를 참고하세요.
SDK for Ruby
참고: GitHub에 더 많은 내용이 있어요. AWS Code Examples Repository에서 전체 예시를 찾아 실행·설정 방법을 배울 수 있어요.
이 예시 모듈은 역할 정책을 나열·생성·연결·분리해요.
# Manages policies in AWS Identity and Access Management (IAM)
class RolePolicyManager
# Initialize with an AWS IAM client
#
# @param iam_client [Aws::IAM::Client] An initialized IAM client
def initialize(iam_client, logger: Logger.new($stdout))
@iam_client = iam_client
@logger = logger
@logger.progname = 'PolicyManager'
end
# Creates a policy
#
# @param policy_name [String] The name of the policy
# @param policy_document [Hash] The policy document
# @return [String] The policy ARN if successful, otherwise nil
def create_policy(policy_name, policy_document)
response = @iam_client.create_policy(
policy_name: policy_name,
policy_document: policy_document.to_json
)
response.policy.arn
rescue Aws::IAM::Errors::ServiceError => e
@logger.error("Error creating policy: #
{
e.message}")
nil
end
# Fetches an IAM policy by its ARN
# @param policy_arn [String] the ARN of the IAM policy to retrieve
# @return [Aws::IAM::Types::GetPolicyResponse] the policy object if found
def get_policy(policy_arn)
response = @iam_client.get_policy(policy_arn: policy_arn)
policy = response.policy
@logger.info("Got policy '#
{
policy.policy_name}'. Its ID is: #
{
policy.policy_id}.")
policy
rescue Aws::IAM::Errors::NoSuchEntity
@logger.error("Couldn't get policy '#
{
policy_arn}'. The policy does not exist.")
raise
rescue Aws::IAM::Errors::ServiceError => e
@logger.error("Couldn't get policy '#
{
policy_arn}'. Here's why: #
{
e.code}: #
{
e.message}")
raise
end
# Attaches a policy to a role
#
# @param role_name [String] The name of the role
# @param policy_arn [String] The policy ARN
# @return [Boolean] true if successful, false otherwise
def attach_policy_to_role(role_name, policy_arn)
@iam_client.attach_role_policy(
role_name: role_name,
policy_arn: policy_arn
)
true
rescue Aws::IAM::Errors::ServiceError => e
@logger.error("Error attaching policy to role: #
{
e.message}")
false
end
# Lists policy ARNs attached to a role
#
# @param role_name [String] The name of the role
# @return [Array<String>] List of policy ARNs
def list_attached_policy_arns(role_name)
response = @iam_client.list_attached_role_policies(role_name: role_name)
response.attached_policies.map(&:policy_arn)
rescue Aws::IAM::Errors::ServiceError => e
@logger.error("Error listing policies attached to role: #
{
e.message}")
[]
end
# Detaches a policy from a role
#
# @param role_name [String] The name of the role
# @param policy_arn [String] The policy ARN
# @return [Boolean] true if successful, false otherwise
def detach_policy_from_role(role_name, policy_arn)
@iam_client.detach_role_policy(
role_name: role_name,
policy_arn: policy_arn
)
true
rescue Aws::IAM::Errors::ServiceError => e
@logger.error("Error detaching policy from role: #
{
e.message}")
false
end
end
API 상세 내용은 AWS SDK for Ruby API Reference의 ListAttachedRolePolicies 문서를 참고하세요.
SDK for Rust
참고: GitHub에 더 많은 내용이 있어요. AWS Code Examples Repository에서 전체 예시를 찾아 실행·설정 방법을 배울 수 있어요.
pub async fn list_attached_role_policies(
client: &iamClient,
role_name: String,
path_prefix: Option<String>,
marker: Option<String>,
max_items: Option<i32>,
) -> Result<ListAttachedRolePoliciesOutput, SdkError<ListAttachedRolePoliciesError>>
{
let response = client
.list_attached_role_policies()
.role_name(role_name)
.set_path_prefix(path_prefix)
.set_marker(marker)
.set_max_items(max_items)
.send()
.await?;
Ok(response)
}
API 상세 내용은 AWS SDK for Rust API reference의 ListAttachedRolePolicies 문서를 참고하세요.
SDK for SAP ABAP
참고: GitHub에 더 많은 내용이 있어요. AWS Code Examples Repository에서 전체 예시를 찾아 실행·설정 방법을 배울 수 있어요.
TRY.
oo_result = lo_iam->listattachedrolepolicies(
iv_rolename = iv_role_name ).
MESSAGE 'Retrieved attached policy list for role.' TYPE 'I'.
CATCH /aws1/cx_iamnosuchentityex.
MESSAGE 'Role does not exist.' TYPE 'E'.
ENDTRY.
API 상세 내용은 AWS SDK for SAP ABAP API reference의 ListAttachedRolePolicies 문서를 참고하세요.
SDK for Swift
참고: GitHub에 더 많은 내용이 있어요. AWS Code Examples Repository에서 전체 예시를 찾아 실행·설정 방법을 배울 수 있어요.
import AWSIAM
import AWSS3
/// Returns a list of AWS Identity and Access Management (IAM) policies
/// that are attached to the role.
///
/// - Parameter role: The IAM role to return the policy list for.
///
/// - Returns: An array of `IAMClientTypes.AttachedPolicy` objects
/// describing each managed policy that's attached to the role.
public func listAttachedRolePolicies(role: String) async throws -> [IAMClientTypes.AttachedPolicy]
{
var policyList: [IAMClientTypes.AttachedPolicy] = []
// Use "Paginated" to get all the attached role polices.
// This lets the SDK handle the 'isTruncated' in "ListAttachedRolePoliciesOutput".
let input = ListAttachedRolePoliciesInput(
roleName: role
)
let output = client.listAttachedRolePoliciesPaginated(input: input)
do
{
for try await page in output
{
guard let attachedPolicies = page.attachedPolicies else
{
print("Error: no attached policies returned.")
continue
}
for attachedPolicy in attachedPolicies
{
policyList.append(attachedPolicy)
}
}
} catch
{
print("ERROR: listAttachedRolePolicies:", dump(error))
throw error
}
return policyList
}
API 상세 내용은 AWS SDK for Swift API reference의 ListAttachedRolePolicies 문서를 참고하세요.