diff --git a/backend/src/services/identity-access-token/identity-access-token-types.ts b/backend/src/services/identity-access-token/identity-access-token-types.ts index 7d393266b..e7b73a8c1 100644 --- a/backend/src/services/identity-access-token/identity-access-token-types.ts +++ b/backend/src/services/identity-access-token/identity-access-token-types.ts @@ -22,7 +22,7 @@ export type TIdentityAccessTokenJwtPayload = { // Derived from ARN partition: string; // "aws", "aws-gov", "aws-cn" - service: string; // "iam" + service: string; // "iam", "sts" resourceType: string; // "user" or "role" resourceName: string; }; diff --git a/docs/documentation/platform/access-controls/abac/managing-machine-identity-attributes.mdx b/docs/documentation/platform/access-controls/abac/managing-machine-identity-attributes.mdx index 20da1a989..17ad9d4b2 100644 --- a/docs/documentation/platform/access-controls/abac/managing-machine-identity-attributes.mdx +++ b/docs/documentation/platform/access-controls/abac/managing-machine-identity-attributes.mdx @@ -64,7 +64,7 @@ For methods like OIDC, these come as claims in the token and can be made availab - For identities authenticated using Kubernetes, the service account's namespace and name are available in their policy and can be accessed as follows: + For identities authenticated using Kubernetes, the service account's namespace and name are available in their policy and can be accessed as follows: ``` {{ identity.auth.kubernetes.namespace }} @@ -72,10 +72,9 @@ For methods like OIDC, these come as claims in the token and can be made availab ``` - - For identities authenticated using AWS Auth, several attributes can be accessed: + For identities authenticated using AWS Auth, several attributes can be accessed: ``` {{ identity.auth.aws.accountId }} @@ -90,6 +89,6 @@ For methods like OIDC, these come as claims in the token and can be made availab - At the moment we only support OIDC claims. Payloads on other authentication methods are not yet accessible. + At the moment we only support OIDC claims, Kubernetes attributes, and AWS attributes. Payloads on other authentication methods are not yet accessible.