Example SQL Queries
aws . kms .list_key_policies
Description
Gets the names of the key policies that are attached to a KMS key. This operation is designed to get policy names that you can use in a GetKeyPolicy operation. However, the only valid policy name is default .
Cross-account use : No. You cannot perform this operation on a KMS key in a different Amazon Web Services account.
Required permissions : kms:ListKeyPolicies (key policy)
Related operations:
Eventual consistency : The KMS API follows an eventual consistency model. For more information, see KMS eventual consistency .
Table Definition
Column Name Column Data Type
key_id Required Input Column Gets the names of key policies for the specified KMS key.
Specify the key ID or key ARN of the KMS key.
For example:
To get the key ID and key ARN for a KMS key, use ListKeys or DescribeKey .
VARCHAR
_aws_profile Input Column The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.
STRUCT( "type" VARCHAR, "name" VARCHAR, "account_id" VARCHAR, "via_profile_name" VARCHAR, "assumed_role_arn" VARCHAR, "organization" STRUCT( "account_name" VARCHAR, "id" VARCHAR, "tags" STRUCT( "key" VARCHAR, "value" VARCHAR )[], "master_account" STRUCT( "id" VARCHAR, "email" VARCHAR ), "parents" STRUCT( "type" VARCHAR, "id" VARCHAR, "name" VARCHAR, "tags" STRUCT( "key" VARCHAR, "value" VARCHAR )[] )[] ) )
Show child fields _aws_profile.account_id The AWS account id
_aws_profile.assumed_role_arn The ARN of the assumed role
_aws_profile.name The unique name of the profile.
_aws_profile.organization Information about this profile's membership in the AWS organization.
Show child fields _aws_profile.organization.account_name The name of account speciifed by the organization
_aws_profile.organization.id The organization id
_aws_profile.organization.master_account Show child fields _aws_profile.organization.master_account.email The organization master account email address
_aws_profile.organization.master_account.id The organization master account id
_aws_profile.organization.parents[] Show child fields _aws_profile.organization.parents[].id The id of the parent
_aws_profile.organization.parents[].name The name of the parent
_aws_profile.organization.parents[].tags[] Show child fields _aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type The type of parent can be an organization unit or a root
_aws_profile.organization.tags[] Show child fields _aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type The type of profile, either 'credentials' or 'assumed_role'
_aws_profile.via_profile_name This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.
_aws_region Input Column The AWS region to use.
VARCHAR
policy_names VARCHAR