Creating a Custom Identity Policy
Function
This API is used to create a custom identity policy whose default version is v1.
Authorization Information
Each account root user has all the permissions required to call all APIs, but IAM users must be assigned the following required identity policy-based permissions. For details about the required permissions, see Permissions Policies and Supported Actions.
| Action | Access Level | Resource Type (*: required) | Condition Key | Alias | Dependencies |
|---|---|---|---|---|---|
| iam:policies:createV5 | Permission_management | policy * | - | - | - |
URI
POST /v5/policies
Request Parameters
| Parameter | Mandatory | Type | Description |
|---|---|---|---|
| policy_name | Yes | String | Definition: Name of an identity policy. Constraints: The value contains 1 to 128 characters, including only letters, digits, underscores (_), plus signs (+), equal signs (=), periods (.), at signs (@), and hyphens (-). Range: N/A Default Value: N/A |
| path | No | String | Definition: Resource path. Constraints: The value consists of several character strings. Each character string contains one or more letters, digits, periods (.), commas (,), plus signs (+), at signs (@), equal signs (=), underscores (_), or hyphens (-), and ends with a slash (/), for example, foo/bar/. The value contains 0 to 512 characters. Range: N/A Default Value: The value is an empty string by default. |
| policy_document | Yes | String | Definition: JSON format of the policy document of a custom or a preset identity policy. Constraints: Characters =, <, >, (, ), and | are special characters in the grammar and are not included in policies. The question mark (?) indicates an element is optional. For example, sid_block?. The vertical bar (|) indicates options, and the parenthesis define the range of options. For example, ("Allow" | "Deny"). When an element allows multiple values, use duplicate values, (,), and (...). For example, [ <policy_statement>, <policy_statement>, ... ]. The following recursive grammar describes the syntax of identity policies: policy = {
<version_block>,
<statement_block>
}
<version_block> = "Version" : ("5.0")
<statement_block> = "Statement" : [ <policy_statement>, <policy_statement>, ... ]
<policy_statement> = {
<sid_block?>,
<effect_block>,
<action_block>,
<resource_block?>,
<condition_block?>
}
<sid_block> = "Sid" : <sid_string>
<effect_block> = "Effect" : ("Allow" | "Deny")
<action_block> = ("Action" | "NotAction") : [ <action_string>, <action_string>, ... ]
<resource_block> = ("Resource" | "NotResource") : [ <resource_string>, <resource_string>, ... ]
<condition_block> = "Condition" : { <condition_map> }
<condition_map> = {
<condition_type_string> : { <condition_key_string> : <condition_value_list> },
<condition_type_string> : { <condition_key_string> : <condition_value_list> },
...
}
<condition_value_list> = ( <condition_value> | [ <condition_value>, <condition_value>, ... ] )
<condition_value> = "string" Range: N/A Default Value: N/A |
| description | No | String | Definition: Identity policy description. Constraints: The value contains 0 to 1,000 characters. Range: N/A Default Value: N/A |
Response Parameters
Status code: 201
| Parameter | Type | Description |
|---|---|---|
| policy | policy object | Definition: Identity policy. Range: N/A |
| Parameter | Type | Description |
|---|---|---|
| policy_type | String | Definition: Identity policy type. Range: custom or system. |
| policy_name | String | Definition: Name of an identity policy. Range: N/A |
| policy_id | String | Definition: Identity policy ID. Range: N/A |
| urn | String | Definition : Uniform Resource Name (URN). For details, see Reference. Range: N/A. |
| path | String | Definition: Resource path. Range: N/A |
| default_version_id | String | Definition: Default version number, which indicates the version number of the policy that is currently in effect. Range: N/A |
| attachment_count | Integer | Definition: Number of entities to which an identity policy is attached. Range: N/A |
| description | String | Definition: Identity policy description. Range: N/A |
| created_at | String | Definition: Time when an identity policy is created. Range: N/A |
| updated_at | String | Definition: Time when the identity policy was last updated. Range: N/A |
Status code: 400
| Parameter | Type | Description |
|---|---|---|
| error_code | String | Definition : Error code. For details, see Error Code. Range: The format is PAP5.XXXX, for example, PAP5.0012. |
| error_msg | String | Definition : Error message. For details, see Error Message. Range: N/A. |
| request_id | String | Definition: Unique identifier of an API request, which is used to locate API calling exceptions. Range: N/A |
Status code: 403
| Parameter | Type | Description |
|---|---|---|
| error_code | String | Definition : Error code. For details, see Error Code. Range: The format is PAP5.XXXX, for example, PAP5.0012. |
| error_msg | String | Definition : Error message. For details, see Error Message. Range: N/A. |
| request_id | String | Definition: Unique identifier of an API request, which is used to locate API calling exceptions. Range: N/A |
| encoded_authorization_message | String | Definition : Encrypted details returned when the authentication fails, which are used to locate authentication problems. The STS5 decryption API can be used for decryption. For details, see API link. Range: N/A. |
Status code: 409
| Parameter | Type | Description |
|---|---|---|
| error_code | String | Definition : Error code. For details, see Error Code. Range: The format is PAP5.XXXX, for example, PAP5.0012. |
| error_msg | String | Definition : Error message. For details, see Error Message. Range: N/A. |
| request_id | String | Definition: Unique identifier of an API request, which is used to locate API calling exceptions. Range: N/A |
Example Requests
Creating a custom identity policy name
POST https://{endpoint}/v5/policies
{
"policy_name" : "name",
"path" : "",
"policy_document" : "{\"Version\":\"5.0\",\"Statement\":[{\"Effect\":\"Allow\",\"Action\":[\"*\"]}]}",
"description" : "description"
} Example Responses
Status code: 201
Successful
{
"policy" : {
"policy_type" : "custom",
"policy_name" : "name",
"policy_id" : "string",
"urn" : "iam::accountid:policy:name",
"path" : "",
"default_version_id" : "v1",
"attachment_count" : 0,
"description" : "description",
"created_at" : "2023-09-25T07:49:11.582Z",
"updated_at" : "2023-09-25T07:49:11.582Z"
}
} Status Codes
| Status Code | Description |
|---|---|
| 201 | Successful |
| 400 | Bad request |
| 403 | Forbidden |
| 409 | Conflict |
Error Codes
See Error Codes.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot