# Resource Access Manager (RAM)

Source: /aws/services/ram/

## Introduction

Resource Access Manager (RAM) helps resources to be shared across AWS accounts, within or across organizations.
On AWS, RAM is an abstraction on top of AWS Identity and Access Management (IAM) which can manage resource-based policies to supported resource types.
The API operations supported by LocalStack can be found on the [API Coverage section](#api-coverage), which provides information on the extent of RAM's integration with LocalStack.

## Getting started

Start the LocalStack container using your preferred method.
This section will illustrate how to create permissions and resource shares using the AWS CLI.

### Create a permission

```bash
lstk aws ram create-permission \
    --name example \
    --resource-type appsync:apis \
    --policy-template '{"Effect": "Allow", "Action": "appsync:SourceGraphQL"}'
```

### Create a resource share

```bash
lstk aws ram create-resource-share \
    --name example-resource-share \
    --principals arn:aws:organizations::000000000000:organization/o-truopwybwi \
    --resource-arn arn:aws:appsync:eu-central-1:000000000000:apis/wcgmjril5wuyvhmpildatuaat3
```

## Current Limitations

LocalStack RAM supports emulated sharing for EC2 Subnets only.
Only specified account principals are granted access to the shared subnets, and associated VPC and route tables.
Furthermore, only the sharing aspect is implemented at this time.
No IAM policies are created or attached, and no permission enforcement takes place.

For all other resource types, the functionality is limited to mocking.

## IAM Condition Keys

When [IAM Policy Enforcement](/aws/developer-tools/security-testing/iam-policy-enforcement/) is enabled, LocalStack supports the following RAM-specific condition key, matching the behavior described in the [AWS condition keys reference](https://docs.aws.amazon.com/service-authorization/latest/reference/list_awsresourceaccessmanager.html#awsresourceaccessmanager-policy-keys):

- `ram:RequestedAllowsExternalPrincipals` &mdash; the `allowExternalPrincipals` value of a `CreateResourceShare` or `UpdateResourceShare` request, useful for restricting resource shares to principals within your organization.

For example, the following policy statement only allows creating or updating a resource share when it does not allow external principals:

```json
{
    "Effect": "Allow",
    "Action": ["ram:CreateResourceShare", "ram:UpdateResourceShare"],
    "Resource": "*",
    "Condition": {
        "Bool": { "ram:RequestedAllowsExternalPrincipals": "false" }
    }
}
```

## API Coverage


### Resource Access Manager API coverage

Source service: `ram`. 20 of 35 tracked operations are implemented.

Service documentation: /aws/services/ram/
License availability: available starting with the Ultimate plan. See /aws/licensing/ for current plan details.

| Operation | Status |
| --- | --- |
| AcceptResourceShareInvitation | Implemented |
| AssociateResourceShare | Implemented |
| AssociateResourceSharePermission | Not implemented |
| CreatePermission | Implemented |
| CreatePermissionVersion | Not implemented |
| CreateResourceShare | Implemented |
| DeletePermission | Implemented |
| DeletePermissionVersion | Not implemented |
| DeleteResourceShare | Implemented |
| DisassociateResourceShare | Implemented |
| DisassociateResourceSharePermission | Not implemented |
| EnableSharingWithAwsOrganization | Implemented |
| GetPermission | Implemented |
| GetResourcePolicies | Not implemented |
| GetResourceShareAssociations | Implemented |
| GetResourceShareInvitations | Implemented |
| GetResourceShares | Implemented |
| ListPendingInvitationResources | Not implemented |
| ListPermissionAssociations | Not implemented |
| ListPermissionVersions | Not implemented |
| ListPermissions | Implemented |
| ListPrincipals | Not implemented |
| ListReplacePermissionAssociationsWork | Not implemented |
| ListResourceSharePermissions | Implemented |
| ListResourceTypes | Implemented |
| ListResources | Implemented |
| ListSourceAssociations | Not implemented |
| PromotePermissionCreatedFromPolicy | Not implemented |
| PromoteResourceShareCreatedFromPolicy | Not implemented |
| RejectResourceShareInvitation | Implemented |
| ReplacePermissionAssociations | Not implemented |
| SetDefaultPermissionVersion | Not implemented |
| TagResource | Implemented |
| UntagResource | Implemented |
| UpdateResourceShare | Implemented |
