IAM Policy Grammar
Introduction
Section titled “Introduction”This page lists the IAM policy grammar that the LocalStack policy engine can evaluate: the condition operators and condition keys it understands when checking a request. The same engine backs both IAM Policy Enforcement and the IAM Policy Simulator, so the support described here applies to both.
Grammar support is expanding over time; operators and keys not listed here may not yet be evaluated. For which service actions are covered, see the IAM coverage documentation, which tracks action coverage rather than grammar.
Condition operators
Section titled “Condition operators”The Condition element of a policy statement uses condition operators to compare a condition key against a value.
The tables below list the operators the engine supports, grouped by category.
String
Section titled “String”| Operator | Supported |
|---|---|
StringEquals |
Yes |
StringNotEquals |
Yes |
StringEqualsIgnoreCase |
Yes |
StringNotEqualsIgnoreCase |
Yes |
StringLike |
Yes |
StringNotLike |
Yes |
Numeric
Section titled “Numeric”| Operator | Supported |
|---|---|
NumericEquals |
Yes |
NumericNotEquals |
Yes |
NumericLessThan |
Yes |
NumericLessThanEquals |
Yes |
NumericGreaterThan |
Yes |
NumericGreaterThanEquals |
Yes |
| Operator | Supported |
|---|---|
ArnEquals |
Yes |
ArnLike |
Yes |
ArnNotEquals |
Yes |
ArnNotLike |
Yes |
Other categories
Section titled “Other categories”| Operator | Supported |
|---|---|
Bool |
Yes |
Null |
Yes |
ForAllValues (set qualifier, e.g. ForAllValues:StringEquals) |
Yes |
ForAnyValue (set qualifier, e.g. ForAnyValue:StringEquals) |
Yes |
DateEquals, DateNotEquals, DateLessThan, DateLessThanEquals, DateGreaterThan, DateGreaterThanEquals |
No |
BinaryEquals |
No |
IpAddress, NotIpAddress |
No |
...IfExists variants (e.g. StringEqualsIfExists) |
No |
Condition keys
Section titled “Condition keys”In addition to the global (aws:*) condition keys, the engine evaluates the following service-specific keys.
| Condition key | Purpose |
|---|---|
iam:PolicyArn |
Restrict policy attach/detach operations to specific policies. |
s3:max-keys |
Numeric key for the maximum number of keys returned by a listing. |
Additional service-specific condition keys are supported and will be added to this table incrementally. See Known limitations.
Examples
Section titled “Examples”The expanded grammar makes it possible to express organization- and account-level guardrails locally. The following statement is illustrative; confirm the exact condition-key names against your LocalStack version.
Limit the page size of an S3 listing by denying requests that ask for more than 100 keys, using a numeric operator with the s3:max-keys key:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Deny", "Action": "s3:ListBucket", "Resource": "*", "Condition": { "NumericGreaterThan": { "s3:max-keys": "100" } } } ]}Known limitations
Section titled “Known limitations”Grammar support is rolled out incrementally, so operators and keys not listed above may not yet be evaluated. S3 ABAC tag condition keys and the EC2 IMDSv2 metadata condition key are documented separately and are not covered on this page.
Unlike AWS’s own IAM Policy Simulator, which ignores Service Control Policy (SCP) conditions, the IAM Policy Simulator in LocalStack evaluates them.