curl --request PUT \
--url https://iam.basaltic.sh/v1/roles/{role_id}/inline-policies/{policy_name} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"document": {
"version": "2024-01-01",
"statements": [
{
"effect": "allow",
"actions": [
"s3:GetObject",
"s3:ListBucket"
],
"resources": [
"my-bucket/*",
"my-bucket"
],
"sid": "AllowS3Read",
"not_actions": [
"iam:*"
],
"not_resources": [
"crn:iam::production:role/*"
],
"conditions": [
{
"operator": "equals",
"key": "s3:prefix",
"values": [
"home/",
"shared/"
]
}
]
}
]
}
}
'import requests
url = "https://iam.basaltic.sh/v1/roles/{role_id}/inline-policies/{policy_name}"
payload = { "document": {
"version": "2024-01-01",
"statements": [
{
"effect": "allow",
"actions": ["s3:GetObject", "s3:ListBucket"],
"resources": ["my-bucket/*", "my-bucket"],
"sid": "AllowS3Read",
"not_actions": ["iam:*"],
"not_resources": ["crn:iam::production:role/*"],
"conditions": [
{
"operator": "equals",
"key": "s3:prefix",
"values": ["home/", "shared/"]
}
]
}
]
} }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
document: {
version: '2024-01-01',
statements: [
{
effect: 'allow',
actions: ['s3:GetObject', 's3:ListBucket'],
resources: ['my-bucket/*', 'my-bucket'],
sid: 'AllowS3Read',
not_actions: ['iam:*'],
not_resources: ['crn:iam::production:role/*'],
conditions: [{operator: 'equals', key: 's3:prefix', values: ['home/', 'shared/']}]
}
]
}
})
};
fetch('https://iam.basaltic.sh/v1/roles/{role_id}/inline-policies/{policy_name}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://iam.basaltic.sh/v1/roles/{role_id}/inline-policies/{policy_name}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'document' => [
'version' => '2024-01-01',
'statements' => [
[
'effect' => 'allow',
'actions' => [
's3:GetObject',
's3:ListBucket'
],
'resources' => [
'my-bucket/*',
'my-bucket'
],
'sid' => 'AllowS3Read',
'not_actions' => [
'iam:*'
],
'not_resources' => [
'crn:iam::production:role/*'
],
'conditions' => [
[
'operator' => 'equals',
'key' => 's3:prefix',
'values' => [
'home/',
'shared/'
]
]
]
]
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://iam.basaltic.sh/v1/roles/{role_id}/inline-policies/{policy_name}"
payload := strings.NewReader("{\n \"document\": {\n \"version\": \"2024-01-01\",\n \"statements\": [\n {\n \"effect\": \"allow\",\n \"actions\": [\n \"s3:GetObject\",\n \"s3:ListBucket\"\n ],\n \"resources\": [\n \"my-bucket/*\",\n \"my-bucket\"\n ],\n \"sid\": \"AllowS3Read\",\n \"not_actions\": [\n \"iam:*\"\n ],\n \"not_resources\": [\n \"crn:iam::production:role/*\"\n ],\n \"conditions\": [\n {\n \"operator\": \"equals\",\n \"key\": \"s3:prefix\",\n \"values\": [\n \"home/\",\n \"shared/\"\n ]\n }\n ]\n }\n ]\n }\n}")
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.put("https://iam.basaltic.sh/v1/roles/{role_id}/inline-policies/{policy_name}")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"document\": {\n \"version\": \"2024-01-01\",\n \"statements\": [\n {\n \"effect\": \"allow\",\n \"actions\": [\n \"s3:GetObject\",\n \"s3:ListBucket\"\n ],\n \"resources\": [\n \"my-bucket/*\",\n \"my-bucket\"\n ],\n \"sid\": \"AllowS3Read\",\n \"not_actions\": [\n \"iam:*\"\n ],\n \"not_resources\": [\n \"crn:iam::production:role/*\"\n ],\n \"conditions\": [\n {\n \"operator\": \"equals\",\n \"key\": \"s3:prefix\",\n \"values\": [\n \"home/\",\n \"shared/\"\n ]\n }\n ]\n }\n ]\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://iam.basaltic.sh/v1/roles/{role_id}/inline-policies/{policy_name}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Put.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"document\": {\n \"version\": \"2024-01-01\",\n \"statements\": [\n {\n \"effect\": \"allow\",\n \"actions\": [\n \"s3:GetObject\",\n \"s3:ListBucket\"\n ],\n \"resources\": [\n \"my-bucket/*\",\n \"my-bucket\"\n ],\n \"sid\": \"AllowS3Read\",\n \"not_actions\": [\n \"iam:*\"\n ],\n \"not_resources\": [\n \"crn:iam::production:role/*\"\n ],\n \"conditions\": [\n {\n \"operator\": \"equals\",\n \"key\": \"s3:prefix\",\n \"values\": [\n \"home/\",\n \"shared/\"\n ]\n }\n ]\n }\n ]\n }\n}"
response = http.request(request)
puts response.read_body{
"inline_policy": {
"crn": "crn:iam::production:role/deployer/inline-policy/read-storage",
"id": "d4e5f6a7-b8c9-0123-4567-890abcdef123",
"principal_id": "550e8400-e29b-41d4-a716-446655440000",
"principal_type": "role",
"name": "S3BucketAccess",
"document": {
"version": "2024-01-01",
"statements": [
{
"effect": "allow",
"actions": [
"s3:GetObject",
"s3:ListBucket"
],
"resources": [
"my-bucket/*",
"my-bucket"
],
"sid": "AllowS3Read",
"not_actions": [
"iam:*"
],
"not_resources": [
"crn:iam::production:role/*"
],
"conditions": [
{
"operator": "equals",
"key": "s3:prefix",
"values": [
"home/",
"shared/"
]
}
]
}
]
},
"created_at": "2026-01-15T09:30:00Z",
"updated_at": "2026-01-16T14:20:00Z"
}
}{
"error": {
"code": "INVALID_INPUT",
"message": "Invalid request parameters",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}{
"error": {
"code": "UNAUTHORIZED",
"message": "Authentication required",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}{
"error": {
"code": "ACCESS_DENIED",
"message": "You don't have permission to perform this action",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}{
"error": {
"code": "NOT_FOUND",
"message": "Resource not found",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}{
"error": {
"code": "INTERNAL_ERROR",
"message": "An internal error occurred",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}Criar ou substituir uma política inline de função
curl --request PUT \
--url https://iam.basaltic.sh/v1/roles/{role_id}/inline-policies/{policy_name} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"document": {
"version": "2024-01-01",
"statements": [
{
"effect": "allow",
"actions": [
"s3:GetObject",
"s3:ListBucket"
],
"resources": [
"my-bucket/*",
"my-bucket"
],
"sid": "AllowS3Read",
"not_actions": [
"iam:*"
],
"not_resources": [
"crn:iam::production:role/*"
],
"conditions": [
{
"operator": "equals",
"key": "s3:prefix",
"values": [
"home/",
"shared/"
]
}
]
}
]
}
}
'import requests
url = "https://iam.basaltic.sh/v1/roles/{role_id}/inline-policies/{policy_name}"
payload = { "document": {
"version": "2024-01-01",
"statements": [
{
"effect": "allow",
"actions": ["s3:GetObject", "s3:ListBucket"],
"resources": ["my-bucket/*", "my-bucket"],
"sid": "AllowS3Read",
"not_actions": ["iam:*"],
"not_resources": ["crn:iam::production:role/*"],
"conditions": [
{
"operator": "equals",
"key": "s3:prefix",
"values": ["home/", "shared/"]
}
]
}
]
} }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PUT',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
document: {
version: '2024-01-01',
statements: [
{
effect: 'allow',
actions: ['s3:GetObject', 's3:ListBucket'],
resources: ['my-bucket/*', 'my-bucket'],
sid: 'AllowS3Read',
not_actions: ['iam:*'],
not_resources: ['crn:iam::production:role/*'],
conditions: [{operator: 'equals', key: 's3:prefix', values: ['home/', 'shared/']}]
}
]
}
})
};
fetch('https://iam.basaltic.sh/v1/roles/{role_id}/inline-policies/{policy_name}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://iam.basaltic.sh/v1/roles/{role_id}/inline-policies/{policy_name}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'document' => [
'version' => '2024-01-01',
'statements' => [
[
'effect' => 'allow',
'actions' => [
's3:GetObject',
's3:ListBucket'
],
'resources' => [
'my-bucket/*',
'my-bucket'
],
'sid' => 'AllowS3Read',
'not_actions' => [
'iam:*'
],
'not_resources' => [
'crn:iam::production:role/*'
],
'conditions' => [
[
'operator' => 'equals',
'key' => 's3:prefix',
'values' => [
'home/',
'shared/'
]
]
]
]
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://iam.basaltic.sh/v1/roles/{role_id}/inline-policies/{policy_name}"
payload := strings.NewReader("{\n \"document\": {\n \"version\": \"2024-01-01\",\n \"statements\": [\n {\n \"effect\": \"allow\",\n \"actions\": [\n \"s3:GetObject\",\n \"s3:ListBucket\"\n ],\n \"resources\": [\n \"my-bucket/*\",\n \"my-bucket\"\n ],\n \"sid\": \"AllowS3Read\",\n \"not_actions\": [\n \"iam:*\"\n ],\n \"not_resources\": [\n \"crn:iam::production:role/*\"\n ],\n \"conditions\": [\n {\n \"operator\": \"equals\",\n \"key\": \"s3:prefix\",\n \"values\": [\n \"home/\",\n \"shared/\"\n ]\n }\n ]\n }\n ]\n }\n}")
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.put("https://iam.basaltic.sh/v1/roles/{role_id}/inline-policies/{policy_name}")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"document\": {\n \"version\": \"2024-01-01\",\n \"statements\": [\n {\n \"effect\": \"allow\",\n \"actions\": [\n \"s3:GetObject\",\n \"s3:ListBucket\"\n ],\n \"resources\": [\n \"my-bucket/*\",\n \"my-bucket\"\n ],\n \"sid\": \"AllowS3Read\",\n \"not_actions\": [\n \"iam:*\"\n ],\n \"not_resources\": [\n \"crn:iam::production:role/*\"\n ],\n \"conditions\": [\n {\n \"operator\": \"equals\",\n \"key\": \"s3:prefix\",\n \"values\": [\n \"home/\",\n \"shared/\"\n ]\n }\n ]\n }\n ]\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://iam.basaltic.sh/v1/roles/{role_id}/inline-policies/{policy_name}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Put.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"document\": {\n \"version\": \"2024-01-01\",\n \"statements\": [\n {\n \"effect\": \"allow\",\n \"actions\": [\n \"s3:GetObject\",\n \"s3:ListBucket\"\n ],\n \"resources\": [\n \"my-bucket/*\",\n \"my-bucket\"\n ],\n \"sid\": \"AllowS3Read\",\n \"not_actions\": [\n \"iam:*\"\n ],\n \"not_resources\": [\n \"crn:iam::production:role/*\"\n ],\n \"conditions\": [\n {\n \"operator\": \"equals\",\n \"key\": \"s3:prefix\",\n \"values\": [\n \"home/\",\n \"shared/\"\n ]\n }\n ]\n }\n ]\n }\n}"
response = http.request(request)
puts response.read_body{
"inline_policy": {
"crn": "crn:iam::production:role/deployer/inline-policy/read-storage",
"id": "d4e5f6a7-b8c9-0123-4567-890abcdef123",
"principal_id": "550e8400-e29b-41d4-a716-446655440000",
"principal_type": "role",
"name": "S3BucketAccess",
"document": {
"version": "2024-01-01",
"statements": [
{
"effect": "allow",
"actions": [
"s3:GetObject",
"s3:ListBucket"
],
"resources": [
"my-bucket/*",
"my-bucket"
],
"sid": "AllowS3Read",
"not_actions": [
"iam:*"
],
"not_resources": [
"crn:iam::production:role/*"
],
"conditions": [
{
"operator": "equals",
"key": "s3:prefix",
"values": [
"home/",
"shared/"
]
}
]
}
]
},
"created_at": "2026-01-15T09:30:00Z",
"updated_at": "2026-01-16T14:20:00Z"
}
}{
"error": {
"code": "INVALID_INPUT",
"message": "Invalid request parameters",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}{
"error": {
"code": "UNAUTHORIZED",
"message": "Authentication required",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}{
"error": {
"code": "ACCESS_DENIED",
"message": "You don't have permission to perform this action",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}{
"error": {
"code": "NOT_FOUND",
"message": "Resource not found",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}{
"error": {
"code": "INTERNAL_ERROR",
"message": "An internal error occurred",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}iam:PutInlinePolicy. Consulte permissões de IAM para obter a lista completa, o que cada uma abrange e um exemplo de política.Autorizações
Um token bearer OAuth 2.0, enviado como Authorization: Bearer <token>. Esta é a forma recomendada de autenticação.
Obtenha o token trocando o par de chaves de acesso de uma conta de serviço em POST /v1/oauth/token com grant_type=client_credentials. Esse é o fluxo padrão de credenciais de cliente; bibliotecas compatíveis com OAuth podem obter e renovar o token para você.
curl -s -u "$KEY_ID:$SECRET" -d grant_type=client_credentials \
https://iam.basaltic.sh/v1/oauth/token
Os tokens duram uma hora por padrão. O mesmo par de chaves de acesso também serve como credencial AWS SigV4 para o endpoint de objetos compatível com S3, que aceita somente esse método de autenticação.
Parâmetros de caminho
"b2c3d4e5-f6a7-8901-2345-67890abcdef1"
Nome da política em linha. As ortografias UUID e o prefixo literal crn: são reservados e não podem ser usados ao criar uma política.
"S3BucketAccess"
Corpo
Documento de política estilo IAM
Show child attributes
Show child attributes
Resposta
Política em linha armazenada
Show child attributes
Show child attributes

