Skip to content

aws.rolesanywhere.list_trust_anchors

Example SQL Queries

SELECT * FROM
aws.rolesanywhere.list_trust_anchors;

Description

Lists the trust anchors in the authenticated account and Amazon Web Services Region.

Required permissions: rolesanywhere:ListTrustAnchors.

Table Definition

Column NameColumn Data Type
page_size Input Column

The number of resources in the paginated list.

BIGINT
_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

_aws_region Input Column

The AWS region to use.

VARCHAR
created_at

The ISO-8601 timestamp when the trust anchor was created.

TIMESTAMP_S
enabled

Indicates whether the trust anchor is enabled.

BOOLEAN
name

The name of the trust anchor.

VARCHAR
notification_settings

A list of notification settings to be associated to the trust anchor.

STRUCT(
"channel" VARCHAR,
"configured_by" VARCHAR,
"enabled" BOOLEAN,
"event" VARCHAR,
"threshold" BIGINT
)[]
Show child fields
notification_settings[]
Show child fields
notification_settings[].channel

The specified channel of notification. IAM Roles Anywhere uses CloudWatch metrics, EventBridge, and Health Dashboard to notify for an event.

In the absence of a specific channel, IAM Roles Anywhere applies this setting to 'ALL' channels.

notification_settings[].configured_by

The principal that configured the notification setting. For default settings configured by IAM Roles Anywhere, the value is rolesanywhere.amazonaws.com, and for customized notifications settings, it is the respective account ID.

notification_settings[].enabled

Indicates whether the notification setting is enabled.

notification_settings[].event

The event to which this notification setting is applied.

notification_settings[].threshold

The number of days before a notification event.

source

The trust anchor type and its related certificate data.

STRUCT(
"source_data" STRUCT(
"acm_pca_arn" VARCHAR,
"x509_certificate_data" VARCHAR
),
"source_type" VARCHAR
)
Show child fields
source.source_data

The data field of the trust anchor depending on its type.

Show child fields
source.source_data.acm_pca_arn

The root certificate of the Private Certificate Authority specified by this ARN is used in trust validation for temporary credential requests. Included for trust anchors of type AWS_ACM_PCA.

source.source_data.x509_certificate_data

The PEM-encoded data for the certificate anchor. Included for trust anchors of type CERTIFICATE_BUNDLE.

source.source_type

The type of the trust anchor.

trust_anchor_arn

The ARN of the trust anchor.

VARCHAR
trust_anchor_id

The unique identifier of the trust anchor.

VARCHAR
updated_at

The ISO-8601 timestamp when the trust anchor was last updated.

TIMESTAMP_S