Skip to content
Get Started for Free

IAM Policy Grammar

This page lists the IAM policy grammar that the LocalStack policy engine can evaluate: the condition operators and condition keys it understands when checking a request. The same engine backs both IAM Policy Enforcement and the IAM Policy Simulator, so the support described here applies to both.

Grammar support is expanding over time; operators and keys not listed here may not yet be evaluated. For which service actions are covered, see the IAM coverage documentation, which tracks action coverage rather than grammar.

The Condition element of a policy statement uses condition operators to compare a condition key against a value. The tables below list the operators the engine supports, grouped by category.

Operator Supported
StringEquals Yes
StringNotEquals Yes
StringEqualsIgnoreCase Yes
StringNotEqualsIgnoreCase Yes
StringLike Yes
StringNotLike Yes
Operator Supported
NumericEquals Yes
NumericNotEquals Yes
NumericLessThan Yes
NumericLessThanEquals Yes
NumericGreaterThan Yes
NumericGreaterThanEquals Yes
Operator Supported
ArnEquals Yes
ArnLike Yes
ArnNotEquals Yes
ArnNotLike Yes
Operator Supported
Bool Yes
Null Yes
ForAllValues (set qualifier, e.g. ForAllValues:StringEquals) Yes
ForAnyValue (set qualifier, e.g. ForAnyValue:StringEquals) Yes
DateEquals, DateNotEquals, DateLessThan, DateLessThanEquals, DateGreaterThan, DateGreaterThanEquals No
BinaryEquals No
IpAddress, NotIpAddress No
...IfExists variants (e.g. StringEqualsIfExists) No

In addition to the global (aws:*) condition keys, the engine evaluates the following service-specific keys.

Condition key Purpose
iam:PolicyArn Restrict policy attach/detach operations to specific policies.
s3:max-keys Numeric key for the maximum number of keys returned by a listing.

Additional service-specific condition keys are supported and will be added to this table incrementally. See Known limitations.

The expanded grammar makes it possible to express organization- and account-level guardrails locally. The following statement is illustrative; confirm the exact condition-key names against your LocalStack version.

Limit the page size of an S3 listing by denying requests that ask for more than 100 keys, using a numeric operator with the s3:max-keys key:

{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Deny",
"Action": "s3:ListBucket",
"Resource": "*",
"Condition": {
"NumericGreaterThan": { "s3:max-keys": "100" }
}
}
]
}

Grammar support is rolled out incrementally, so operators and keys not listed above may not yet be evaluated. S3 ABAC tag condition keys and the EC2 IMDSv2 metadata condition key are documented separately and are not covered on this page.

Unlike AWS’s own IAM Policy Simulator, which ignores Service Control Policy (SCP) conditions, the IAM Policy Simulator in LocalStack evaluates them.

Was this page helpful?