Update an IAM policy | Tigris Object Storage Documentation

Update an IAM policy

PUT https://mgmt.storage.dev/v1/providers/:provider_id/orgs/:org_id/policies/:policy_name

Updates the document and/or description of an existing IAM policy. Changes take effect immediately for all access keys the policy is attached to.

The policy document follows the AWS IAM policy syntax. For supported actions, see the full list of supported actions.

Request

Path Parameters

provider_id stringrequired
Provider ID

org_id stringrequired
Organization ID

policy_name stringrequired
Name of the IAM policy

Body required

document objectrequired
AWS IAM-compatible policy document. See IAM Policies documentation for details.

Version stringrequired
Policy language version.

Possible values: [2012-10-17]

Statement object[]required
Array [

Sid string
Optional identifier for the statement

Effect stringrequired
Whether this statement allows or denies the specified actions

Possible values: [Allow, Deny]

Action string[]required
S3 actions to allow or deny. Common actions: s3:GetObject, s3:PutObject, s3:DeleteObject, s3:ListBucket, s3:*. See supported actions.

Resource string[]required
S3 resource ARNs. Use arn:aws:s3:::bucket for bucket-level and arn:aws:s3:::bucket/prefix/* for prefix-scoped access.

Condition object
Optional conditions (IP, time-based). See condition examples.

]

description string
A description for the policy

Possible values:<= 1000 characters

{
  "document": {
    "Version": "2012-10-17",
    "Statement": [
      {
        "Sid": "string",
        "Effect": "Allow",
        "Action": [
          "string"
        ],
        "Resource": [
          "string"
        ],
        "Condition": {}
      }
    ]
  },
  "description": "string"
}

Responses

Schema

name stringrequired
Name of the policy

description string

Version stringrequired
Policy language version.

Possible values: [2012-10-17]

Statement object[]required
Array [

Sid string
Optional identifier for the statement

Effect stringrequired
Whether this statement allows or denies the specified actions

Possible values: [Allow, Deny]

Resource string[]required
S3 resource ARNs. Use arn:aws:s3:::bucket for bucket-level and arn:aws:s3:::bucket/prefix/* for prefix-scoped access.

Condition object
Optional conditions (IP, time-based). See condition examples.

]

attachment_count integer
Number of access keys this policy is attached to

created_at date-time

updated_at date-time

{
  "name": "string",
  "description": "string",
  "document": {
    "Version": "2012-10-17",
    "Statement": [
      {
        "Sid": "string",
        "Effect": "Allow",
        "Action": [
          "string"
        ],
        "Resource": [
          "string"
        ],
        "Condition": {}
      }
    ]
  },
  "attachment_count": 0,
  "created_at": "2024-07-29T15:51:28.071Z",
  "updated_at": "2024-07-29T15:51:28.071Z"
}

Unexpected error

Schema

message string

{
  "message": "string"
}

Authorization: X-Tigris-Signature

name: X-Tigris-Signature  
type: apiKey  
in: header  
description: HMAC-SHA256 of the canonical request signed using the signing key. To create the signature, concatenate the HTTP method, URL, timestamp, and nonce with a newline character in between. Then, calculate the HMAC-SHA256 of the concatenated string using the signing key. Example:

Create the `canonical_request` as:

POST https://mgmt.storage.dev/provider/your-provider-id/orgs/user-org-id/provision 1731703213870 f8d133cb-5a42-47b1-9ef2-874bb55bab72

Then, calculate HMAC-SHA256 of the canonical request using the signing key as:

Signature = hex(sha256sign(canonical_request, "signing_key"))


name: X-Tigris-Noncetype: apiKeyin: headerdescription: Random unique string to identify the request and prevent replay attacks. Example: "f8d133cb-5a42-47b1-9ef2-874bb55bab72"
name: X-Tigris-Timetype: apiKeyin: headerdescription: Unix timestamp in milliseconds of the request. Example: 1731703213870
var client = new HttpClient();
var request = new HttpRequestMessage(HttpMethod.Put, "https://mgmt.storage.dev/v1/providers/:provider_id/orgs/:org_id/policies/:policy_name");
request.Headers.Add("Accept", "application/json");
request.Headers.Add("X-Tigris-Signature", "<X-Tigris-Signature>");
request.Headers.Add("X-Tigris-Nonce", "<X-Tigris-Nonce>");
request.Headers.Add("X-Tigris-Time", "<X-Tigris-Time>");
var content = new StringContent("{\n  \"document\": {\n    \"Version\": \"2012-10-17\",\n    \"Statement\": [\n      {\n        \"Sid\": \"string\",\n        \"Effect\": \"Allow\",\n        \"Action\": [\n          \"string\"\n        ],\n        \"Resource\": [\n          \"string\"\n        ],\n        \"Condition\": {}\n      }\n    ]\n  },\n  \"description\": \"string\"\n}", null, "application/json");
request.Content = content;
var response = await client.SendAsync(request);
response.EnsureSuccessStatusCode();
Console.WriteLine(await response.Content.ReadAsStringAsync());

Request

Base URL
https://mgmt.storage.dev

Auth
Signature
Nonce
Timestamp

Parameters
provider_id — pathrequired
org_id — pathrequired
policy_name — pathrequired

Body required

Send API Request
ResponseClear
Click the Send API Request button above and see the response here!