Skip to content
Get Started for Free

Resource Access Manager (RAM)

Resource Access Manager (RAM) helps resources to be shared across AWS accounts, within or across organizations. On AWS, RAM is an abstraction on top of AWS Identity and Access Management (IAM) which can manage resource-based policies to supported resource types. The API operations supported by LocalStack can be found on the API Coverage section, which provides information on the extent of RAM’s integration with LocalStack.

Start the LocalStack container using your preferred method. This section will illustrate how to create permissions and resource shares using the AWS CLI.

Terminal window
lstk aws ram create-permission \
--name example \
--resource-type appsync:apis \
--policy-template '{"Effect": "Allow", "Action": "appsync:SourceGraphQL"}'
Terminal window
lstk aws ram create-resource-share \
--name example-resource-share \
--principals arn:aws:organizations::000000000000:organization/o-truopwybwi \
--resource-arn arn:aws:appsync:eu-central-1:000000000000:apis/wcgmjril5wuyvhmpildatuaat3

LocalStack RAM supports emulated sharing for EC2 Subnets only. Only specified account principals are granted access to the shared subnets, and associated VPC and route tables. Furthermore, only the sharing aspect is implemented at this time. No IAM policies are created or attached, and no permission enforcement takes place.

For all other resource types, the functionality is limited to mocking.

When IAM Policy Enforcement is enabled, LocalStack supports the following RAM-specific condition key, matching the behavior described in the AWS condition keys reference:

  • ram:RequestedAllowsExternalPrincipals — the allowExternalPrincipals value of a CreateResourceShare or UpdateResourceShare request, useful for restricting resource shares to principals within your organization.

For example, the following policy statement only allows creating or updating a resource share when it does not allow external principals:

{
"Effect": "Allow",
"Action": ["ram:CreateResourceShare", "ram:UpdateResourceShare"],
"Resource": "*",
"Condition": {
"Bool": { "ram:RequestedAllowsExternalPrincipals": "false" }
}
}

20 of 35 operations implemented

Available from the Ultimate plan. Licensing details

Find an API

Search the full operation list, then sort the table to compare current support.

Loading operations…

Verified on Kubernetes
Loading operations…
Complete static API list All 35 operations and their current support status
OperationStatus
AcceptResourceShareInvitationImplemented
AssociateResourceShareImplemented
AssociateResourceSharePermissionNot implemented
CreatePermissionImplemented
CreatePermissionVersionNot implemented
CreateResourceShareImplemented
DeletePermissionImplemented
DeletePermissionVersionNot implemented
DeleteResourceShareImplemented
DisassociateResourceShareImplemented
DisassociateResourceSharePermissionNot implemented
EnableSharingWithAwsOrganizationImplemented
GetPermissionImplemented
GetResourcePoliciesNot implemented
GetResourceShareAssociationsImplemented
GetResourceShareInvitationsImplemented
GetResourceSharesImplemented
ListPendingInvitationResourcesNot implemented
ListPermissionAssociationsNot implemented
ListPermissionVersionsNot implemented
ListPermissionsImplemented
ListPrincipalsNot implemented
ListReplacePermissionAssociationsWorkNot implemented
ListResourceSharePermissionsImplemented
ListResourceTypesImplemented
ListResourcesImplemented
ListSourceAssociationsNot implemented
PromotePermissionCreatedFromPolicyNot implemented
PromoteResourceShareCreatedFromPolicyNot implemented
RejectResourceShareInvitationImplemented
ReplacePermissionAssociationsNot implemented
SetDefaultPermissionVersionNot implemented
TagResourceImplemented
UntagResourceImplemented
UpdateResourceShareImplemented
Was this page helpful?