Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Dell ObjectScale 1.3 Administration Guide

Policies

IAM policies are documents in JSON format that define permissions for an operation regardless of the method that you use to perform the operation.

The table below describes the policy types that are designed for use in ObjectScale.

Table 1. IAM Policies
Identity-based policies Identity-based policies grant permissions to an IAM entity to control what actions an entity (users, groups of users, and roles) can perform, on which resources, and under what conditions.

In ObjectScale, resource-based policies are further categorized as:

ObjectScale managed policies Created and managed by ObjectScale. These policies cannot be modified or deleted.
Customer-managed policies Managed policies that users create and manage in account.
Inline policies Policies that are added to a single user, group, or role.
Resource-based policies Attached inline policies to resources. Resource-based policies grant permissions to the principal that is specified in the policy. Principals can be in the same account as the resource or in other accounts.

In ObjectScale, resource-based policies are further categorized as:

  • S3 bucket policies
  • IAM role trust policies
Permissions boundaries Sets the maximum permissions that an identity-based policy can grant to an IAM entity (user or role). When you set a permissions boundary for an entity, the entity can perform only the actions that are allowed by both its identity-based policies and its permissions boundaries. Resource-based policies that specify the user or role as the principal are not limited by the permissions boundary. An explicit deny in any of these policies overrides the allow.
Session policies Session policies are advanced policies that you enter a parameter when you programmatically create a temporary session for a role. The permissions for a session are the intersection of the identity-based policies for the IAM entity (user or role) used to create the session and the session policies. Permissions can also come from a resource-based policy. An explicit deny in any of these policies overrides the allow.

Use the following tasks to manage ObjectScale IAM policies.

NOTE:Only customer-managed policy documents can be edited or deleted.

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\