IAM Identity Center Identity Store
AWS IAM Identity Center Identity Store (identitystore) on fakecloud: identity stores, users, groups, group memberships, revisions, attribute lookups, and IsMemberInGroups. awsJson1.1.
fakecloud implements the AWS IAM Identity Center Identity Store (identitystore) as an awsJson1.1 control plane. The complete 22-operation surface ships: the identity stores themselves, plus the users, groups, and memberships that make up each directory, backed by account-partitioned state that persists across restarts in persistent mode.
An Identity Store is a per-account directory keyed by IdentityStoreId (d-xxxxxxxxxx). Real AWS provisions the store when an IAM Identity Center instance is enabled, and fakecloud reads the store ids from the SSO Admin instances (including the default instance seeded for the configured account). fakecloud also creates a directory lazily on the first write to any store id, so the directory API is usable immediately. Every IdentityStoreId input accepts either the bare id or the store ARN (arn:aws:identitystore::<account>:identitystore/d-xxxxxxxxxx). Nested SCIM attribute bags (Name, Emails, Addresses, PhoneNumbers, Photos, Roles, ...) are stored as submitted and round-trip verbatim on describe. The model's @length and @range constraints (IdentityStoreId 1-93, ResourceId 1-47, UserName 1-128, free-form profile attributes 1-1024, MaxResults 1-100, NextToken 1-65535) are enforced with ValidationException.
Supported now (all 22 operations)
- Identity stores:
ListIdentityStores,DescribeIdentityStore,UpdateIdentityStore. Lists every store the account owns (its Identity Center instances' stores plus any directory created by a write) with itsIdentityStoreArn.UpdateIdentityStorereplaces the store'sNetworkConfiguration(VpceAccessRequired,ApiRestrictSourceVpcs,ApiAllowSourceIps,ScimAllowSourceIps, validated against the model's VPC id and CIDR patterns) andDescribeIdentityStorereturns it. The configuration is stored and reported but not enforced: fakecloud has no VPC endpoint or source-IP context to filter requests on. An unknown store returnsResourceNotFoundExceptionwithResourceType: IDENTITY_STORE. - Resource ids and ARNs: users, groups, and memberships created in a store with a canonical
d-<10 hex>id get AWS's<10 hex>-<UUID>ids, and every response carries the resource ARN (UserArn,GroupArn,MembershipArn, in the global formarn:aws:identitystore:::user/<id>). - Revisions: users and groups carry a
Revisionthat starts at1and increments on everyUpdateUser/UpdateGroup(whose responses now return the id, store id, ARN, and new revision). PassingRevisiontoUpdateUser/UpdateGroup/DeleteUser/DeleteGroupmakes the call conditional: a stale value returnsConflictExceptionwithReason: CONCURRENT_MODIFICATION(uniqueness conflicts carryReason: UNIQUENESS_CONSTRAINT_VIOLATION). - Users —
CreateUser,DescribeUser,UpdateUser,DeleteUser,ListUsers,GetUserId.UserNameis unique per store (duplicate ->ConflictException).UpdateUserapplies SCIMAttributeOperations(add/replace/remove) over dotted attribute paths.ListUserssupports the legacy equalityFiltersshape andMaxResults/NextTokenpagination. - Groups —
CreateGroup,DescribeGroup,UpdateGroup,DeleteGroup,ListGroups,GetGroupId.DisplayNameis unique per store. Deleting a group also removes its memberships. - Group memberships —
CreateGroupMembership,DescribeGroupMembership,DeleteGroupMembership,GetGroupMembershipId,ListGroupMemberships,ListGroupMembershipsForMember. A membership links aMemberId({UserId}) into a group; the referenced user and group must exist, and a duplicate pair returnsConflictException. - Attribute lookups —
GetUserId/GetGroupIdresolve anAlternateIdentifier'sUniqueAttribute(e.g.UserName/DisplayName) to the resource id; unknown identifiers returnResourceNotFoundException. - Membership test —
IsMemberInGroupsreturns, for each queried group id, whether the member belongs to it.
Not implemented
ExternalId-basedAlternateIdentifierlookups (no external identity provider is modeled), and the SCIM external-id/attribute provisioning that a real Sync engine would drive. The paired SSO Admin control plane (instances, permission sets, account assignments, applications) is a separate service.