Thursday, September 2, 2010

How to manage Amazon Identity and Access Management Service (IAM) with CloudBerry S3 Explorer

Note: this post applies to CloudBerry Explorer 2.4 PRO and later.

As always we are trying to stay on top of the new functionality offered by Amazon S3 to offer the most compelling Amazon S3 and CloudFront client on Windows platform.
Identity and Access Management Service is a new addition to AWS Family that allows you to:
• Identity management – Enables you to manage your private identity space under your AWS account. It will allow you to create, update and delete both identities and groups in your own space.
• Capability management – Allows you to control what permissions individual identities will have in your AWS environment
• Least privilege – Enables you to lock down your AWS environment and only provide identities with the least privilege required when accessing AWS resources under your control
• Per user usage tracking – Enables to track usage of your AWS resources on a per identity basis
In the newer release of CloudBerry Explorer we are introducing support for IAM service. Although we are trying to expand our S3 support, you can use CloudBerry Explorer to manage IAM service when it comes to other AWS such as EC2, SimpleDB, SQS, etc.
You can access IAM Manager using Access Manager program menu
IAM4-main
Here is a list of then features we offer:
1. Create/Edit/Delete user
2. Create/Edit/Delete group
3. List policies for user/group
4. Add Policy to User/Group
5. Add/Remove user from group
6. Generate Access/Secrete key for user
7. Create Policy with Policy designer

This screen demonstrates how you can generate an Access/Secrete key pair for a user, so that he can access Amazon Web services just like any other regular user.
IAM2
And here is a Policy Designer screen. Those who are familiar with our Amazon S3 Policy Designer can hit the found running as it works exactly the same way.
IAM3-Policy-Designer
There are quite a few things left to be implemented when it comes to full support for Identity and Authentication Service. We are committed to improving this tool and you will see more features implemented in the near future.
Note: Access Manager is only available in CloudBerry Explorer PRO.
Note: since IAM is not limited to Amazon S3 and covers most of the other Amazon Web Services it is likely we will implement IAM as a separate tool in the future with its own pricing.
As always we would be happy to hear your feedback and you are welcome to post a comment.
CloudBerry S3 Explorer is a Windows freeware product that helps managing Amazon S3 storage and CloudFront . You can download it at http://cloudberrylab.com/
CloudBerry S3 Explorer PRO is a Windows program that helps managing Amazon S3 storage and CloudFront . You can download it at http://pro.cloudberrylab.com/ It is priced at $39.99
Like our products? Please help us spread the word about them. Learn here how to do it.

7 comments:

B P said...

This looks like what I need. I'm downloading the trial.

Hope it works!

Anonymous said...

Do the users that you manage have to already be amazon S3 users with accounts, or can they be anybody? That is, if I want to invite someone to access data in a bucket, can I do that?

andy said...

The users we mention in this post are "Amazon" users created within your Amazon account. They can't be anybody but you can create accounts for them. Check out our other post for an instruction.

Anonymous said...

Can the IAM tool be used to create user accounts and give access to resources outside of S3 and Cloudfront. Specifically I want to create a user that only has access to Route 53 commands.

andy said...

Route 53 service is integrated with IAM. He can read here how to use IAM with route 53

Neelam said...

DNS30 Professional Edition, UI to Amazon Route 53 services. We also have online interface for this application
http://www.dns30.com/

Anonymous said...

Route 53 is designed to automatically scale to handle very large query volumes without any intervention from user.We have developed a UI tool for this interface - DNS30 Professional Edition.We also have online interface for this application.
http://www.dns30.com/