Zum Hauptinhalt springen

AWS IAM syncer

The AWS IAM syncer imports users and groups from an AWS account into Casdoor using the AWS IAM API.

Konfiguration​

Casdoor fieldAWS IAM value
HostAWS region (e.g. us-east-1)
UserAWS-Zugriffsschlüssel-ID
PasswordAWS-Geheimer Zugriffsschlüssel

The IAM credentials must have at least the following permissions:

  • iam:ListUsers
  • iam:ListUserTags
  • iam:ListGroups

Field mappings​

AWS IAM fieldCasdoor fieldNotizen
UserIdIdStable unique identifier
UserNameName, DisplayName
CreateDateErstellungszeit
Tag Email / emailE-Mail
Tag Phone / phoneTelefon
Tag DisplayName / displayNameAnzeigenameOverrides UserName if set
Tag FirstName / firstNameVorname
Tag LastName / lastNameNachname
Tag Title / titleTitel
Tag Department / departmentZugehörigkeit
Other tagsEigenschaftenStored as-is

Additional user attributes are read from IAM user tags. Any tag not listed above is stored in the user's Properties map.

Status mapping​

IAM users are active by default. To mark a user as forbidden in Casdoor, add one of these tags on the IAM user:

  • Status = Inactive or Disabled
  • Active = false, False, or 0

Group sync​

The syncer fetches all IAM groups and creates corresponding Casdoor groups. Group membership sync is a known limitation: the AWS IAM API identifies groups by user name, while Casdoor's syncer interface works with user IDs. As a result, users are imported correctly but are not automatically placed in their IAM groups.

Notizen​

  • The syncer is read-only. It only pulls data from AWS; it does not create or modify IAM users.
  • All API calls use a 60-second timeout for list operations and a 10-second timeout for per-user tag lookups.
  • Pagination is handled automatically via IAM's marker-based paging, so there is no limit on the number of users.