aws.iam.list_roles
Example SQL Queries
SELECT * FROMaws.iam.list_roles;Description
Lists the IAM roles that have the specified path prefix. If there are none, the operation returns an empty list. For more information about roles, see IAM roles in the IAM User Guide.
IAM resource-listing operations return a subset of the available attributes for the resource. This operation does not return the following attributes, even though they are an attribute of the returned object:
PermissionsBoundary
RoleLastUsed
Tags
To view all of the information for a role, see GetRole.
You can paginate the results using the MaxItems and Marker parameters.
Table Definition
| Column Name | Column Data Type |
|---|---|
| path_prefix Input Column The path prefix for filtering the results. For example, the prefix /application_abc/component_xyz/ gets all roles whose path starts with /application_abc/component_xyz/. This parameter is optional. If it is not included, it defaults to a slash (/), listing all roles. This parameter allows (through its regex pattern) a string of characters consisting of either a forward slash (/) by itself or a string that must begin and end with forward slashes. In addition, it can contain any ASCII character from the ! (\u0021) through the DEL character (\u007F), including most punctuation characters, digits, and upper and lowercased letters. | VARCHAR |
| _aws_profile Input Column The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role. | STRUCT( |
Show child fields
| |
| arn The Amazon Resource Name (ARN) specifying the role. For more information about ARNs and how to use them in policies, see IAM identifiers in the IAM User Guide guide. | VARCHAR |
| assume_role_policy_document The policy that grants an entity permission to assume the role. | VARCHAR |
| create_date The date and time, in ISO 8601 date-time format, when the role was created. | TIMESTAMP_S |
| description A description of the role that you provide. | VARCHAR |
| max_session_duration The maximum session duration (in seconds) for the specified role. Anyone who uses the CLI, or API to assume the role can specify the duration using the optional DurationSeconds API parameter or duration-seconds CLI parameter. | BIGINT |
| path The path to the role. For more information about paths, see IAM identifiers in the IAM User Guide. | VARCHAR |
| permissions_boundary The ARN of the policy used to set the permissions boundary for the role. For more information about permissions boundaries, see Permissions boundaries for IAM identities in the IAM User Guide. | STRUCT( |
Show child fields
| |
| role_id The stable and unique string identifying the role. For more information about IDs, see IAM identifiers in the IAM User Guide. | VARCHAR |
| role_last_used Contains information about the last time that an IAM role was used. This includes the date and time and the Region in which the role was last used. Activity is only reported for the trailing 400 days. This period can be shorter if your Region began supporting these features within the last year. The role might have been used more than 400 days ago. For more information, see Regions where data is tracked in the IAM user Guide. | STRUCT( |
Show child fields
| |
| role_name The friendly name that identifies the role. | VARCHAR |
| tags A list of tags that are attached to the role. For more information about tagging, see Tagging IAM resources in the IAM User Guide. | STRUCT( |
Show child fields
| |