I'm having a hard time finding the correct API call to answer this question: given an IAM User, what is the effective IAM Policy document governing that user?
It looks like I can accomplish the above using a combination of several API calls and concatenating the policies in the client:
aws iam list-groups-for-user --user-name my-user- for each returned group:
aws iam list-attached-group-policies --group-name my-group aws iam list-attached-user-policies --user-name my-user- Concatenate policies returned from steps 2. and 3.
- for each policy:
aws iam get-policy --policy-arn my-policy-arn - and again for each policy:
aws iam get-policy-version --policy-arn my-policy-arn -version-id my-version
This is at fewest 5 API calls and at most an unbounded number of calls. I'm hesitant to even write this logic because it is common for a user to belong to several groups and for those groups to contain tens or hundreds of policies.
Surely there is a single API endpoint somewhere that I am missing?
Something like this: aws iam get-effective-user-policy --user-name my-user