[ aws . iam ]

get-role-template-version

Description

Retrieves information about a version of the specified role template. Role templates define a reusable configuration—including role name and path patterns, trust policy, inline and managed policies, permissions boundary, tags, and maximum session duration—that you use to create IAM roles with AcquireRole .

If you do not specify a minor version, the service returns the template’s default minor version.

See also: AWS API Documentation

Synopsis

  get-role-template-version
--template-arn <value>
[--minor-version <value>]
[--cli-input-json | --cli-input-yaml]
[--generate-cli-skeleton <value>]
[--debug]
[--endpoint-url <value>]
[--no-verify-ssl]
[--no-paginate]
[--output <value>]
[--query <value>]
[--profile <value>]
[--region <value>]
[--version <value>]
[--color <value>]
[--no-sign-request]
[--ca-bundle <value>]
[--cli-read-timeout <value>]
[--cli-connect-timeout <value>]
[--cli-binary-format <value>]
[--no-cli-pager]
[--cli-auto-prompt]
[--no-cli-auto-prompt]
[--cli-error-format <value>]

Options

--template-arn (string) [required]

The Amazon Resource Name (ARN) of the role template whose version you want to retrieve.

For more information about ARNs, see Amazon Resource Names (ARNs) in the Amazon Web Services General Reference .

Constraints:

  • min: 20
  • max: 2048

--minor-version (integer)

The minor version of the role template to retrieve. If you do not specify a minor version, the service returns the template’s default minor version.

--cli-input-json | --cli-input-yaml (string) Reads arguments from the JSON string provided. The JSON string follows the format provided by --generate-cli-skeleton. If other arguments are provided on the command line, those values will override the JSON-provided values. It is not possible to pass arbitrary binary values using a JSON-provided value as the string will be taken literally. This may not be specified along with --cli-input-yaml.

--generate-cli-skeleton (string) Prints a JSON skeleton to standard output without sending an API request. If provided with no value or the value input, prints a sample input JSON that can be used as an argument for --cli-input-json. Similarly, if provided yaml-input it will print a sample input YAML that can be used with --cli-input-yaml. If provided with the value output, it validates the command inputs and returns a sample output JSON for that command. The generated JSON skeleton is not stable between versions of the AWS CLI and there are no backwards compatibility guarantees in the JSON skeleton generated.

Global Options

--debug (boolean)

Turn on debug logging.

--endpoint-url (string)

Override command’s default URL with the given URL.

--no-verify-ssl (boolean)

By default, the AWS CLI uses SSL when communicating with AWS services. For each SSL connection, the AWS CLI will verify SSL certificates. This option overrides the default behavior of verifying SSL certificates.

--no-paginate (boolean)

Disable automatic pagination. If automatic pagination is disabled, the AWS CLI will only make one call, for the first page of results.

--output (string)

The formatting style for command output.

  • json
  • text
  • table
  • yaml
  • yaml-stream
  • off

--query (string)

A JMESPath query to use in filtering the response data.

--profile (string)

Use a specific profile from your credential file.

--region (string)

The region to use. Overrides config/env settings.

--version (string)

Display the version of this tool.

--color (string)

Turn on/off color output.

  • on
  • off
  • auto

--no-sign-request (boolean)

Do not sign requests. Credentials will not be loaded if this argument is provided.

--ca-bundle (string)

The CA certificate bundle to use when verifying SSL certificates. Overrides config/env settings.

--cli-read-timeout (int)

The maximum socket read time in seconds. If the value is set to 0, the socket read will be blocking and not timeout. The default value is 60 seconds.

--cli-connect-timeout (int)

The maximum socket connect time in seconds. If the value is set to 0, the socket connect will be blocking and not timeout. The default value is 60 seconds.

--cli-binary-format (string)

The formatting style to be used for binary blobs. The default format is base64. The base64 format expects binary blobs to be provided as a base64 encoded string. The raw-in-base64-out format preserves compatibility with AWS CLI V1 behavior and binary values must be passed literally. When providing contents from a file that map to a binary blob fileb:// will always be treated as binary and use the file contents directly regardless of the cli-binary-format setting. When using file:// the file contents will need to properly formatted for the configured cli-binary-format.

  • base64
  • raw-in-base64-out

--no-cli-pager (boolean)

Disable cli pager for output.

--cli-auto-prompt (boolean)

Automatically prompt for CLI input parameters.

--no-cli-auto-prompt (boolean)

Disable automatically prompt for CLI input parameters.

--cli-error-format (string)

The formatting style for error output. By default, errors are displayed in enhanced format.

  • legacy
  • json
  • yaml
  • text
  • table
  • enhanced

Output

RoleTemplateVersion -> (structure)

A structure that contains details about the requested role template version.

TemplateArn -> (string)

The Amazon Resource Name (ARN) that identifies the role template.

For more information about ARNs, see Amazon Resource Names (ARNs) in the Amazon Web Services General Reference .

Constraints:

  • min: 20
  • max: 2048

TemplateName -> (string)

The friendly name that identifies the role template.

Constraints:

  • min: 1
  • max: 128
  • pattern: [\w+=,.\-]+

TemplateVersionId -> (string)

The identifier of the role template version.

Constraints:

  • min: 16
  • max: 128
  • pattern: [\w]+

Description -> (string)

The description of the role template.

Constraints:

  • max: 512
  • pattern: [\u0009\u000A\u000D\u0020-\u007E\u00A1-\u00FF]*

MajorVersion -> (integer)

The major version number of the role template.

DefaultMinorVersion -> (integer)

The minor version that the service uses by default when you create a role from this template without specifying a minor version.

ManagedByType -> (string)

Indicates that the role template is managed by an Amazon Web Services service.

Possible values:

  • Service

ManagedByValue -> (string)

The identifier of the Amazon Web Services service that manages the role template.

Constraints:

  • min: 1
  • max: 128

Enabled -> (boolean)

Specifies whether the role template is enabled. When a template is disabled, you cannot create roles from it.

MinorVersion -> (integer)

The minor version number of this role template version.

RoleNamePattern -> (string)

The pattern that is used to generate the name of a role that is created from this template. The pattern can include @{parameter} placeholders that are replaced with the values you supply in the ReplacementValues parameter of AcquireRole .

Constraints:

  • min: 1
  • max: 256

RolePathPattern -> (string)

The pattern that is used to generate the path of a role that is created from this template.

Constraints:

  • min: 1
  • max: 256
  • pattern: /[\u0009\u000A\u000D\u0020-\u007E\u00A1-\u00FF]*/

RoleDescriptionPattern -> (string)

The pattern that is used to generate the description of a role that is created from this template.

Constraints:

  • min: 1
  • max: 512

AssumeRolePolicyDocumentTemplate -> (string)

The trust policy template that grants an entity permission to assume roles that you create from this template.

Constraints:

  • min: 1
  • max: 131072
  • pattern: [\u0009\u000A\u000D\u0020-\u00FF]+

InlinePolicyTemplates -> (list)

A list of inline policy templates that the service embeds in roles that you create from this template.

(structure)

Contains an inline policy template that the service embeds in roles that you create from a role template.

PolicyName -> (string) [required]

The name of the inline policy.

Constraints:

  • min: 1
  • max: 128
  • pattern: [\w+=,.@-]+

PolicyDocument -> (string) [required]

The inline policy document.

Constraints:

  • min: 1
  • max: 131072
  • pattern: [\u0009\u000A\u000D\u0020-\u00FF]+

ManagedPolicyArns -> (list)

A list of the ARNs of the managed policies that the service attaches to roles that you create from this template.

(string)

The Amazon Resource Name (ARN). ARNs are unique identifiers for Amazon Web Services resources.

For more information about ARNs, go to Amazon Resource Names (ARNs) in the Amazon Web Services General Reference .

Constraints:

  • min: 20
  • max: 2048

PermissionBoundaryArn -> (string)

The ARN of the policy that sets the permissions boundary for roles that you create from this template.

For more information about ARNs, see Amazon Resource Names (ARNs) in the Amazon Web Services General Reference .

Constraints:

  • min: 20
  • max: 2048

ParametersDefinition -> (list)

A list of the parameters that are defined for this role template version. You supply values for these parameters when you create a role with AcquireRole .

(structure)

Defines a parameter that a role template accepts. You supply values for these parameters when you create a role with AcquireRole .

Name -> (string) [required]

The name of the parameter.

Constraints:

  • min: 1
  • max: 128

Type -> (string) [required]

The data type of the parameter. Valid values are String , StringList , Number , NumberList , Arn , and ArnList .

Possible values:

  • String
  • StringList
  • Number
  • NumberList
  • Arn
  • ArnList

SubType -> (string)

An optional subtype that further constrains the values that are allowed for the parameter.

Constraints:

  • max: 256

Description -> (string)

A description of the parameter.

Constraints:

  • max: 1000

IsRequired -> (boolean)

Specifies whether you must supply a value for the parameter when you create a role from the template.

DefaultValue -> (string)

The value that the service uses for the parameter when you do not supply one.

Constraints:

  • max: 1024

Immutable -> (boolean)

Specifies whether you can change the parameter value after you create the role.

RoleTagsTemplate -> (list)

A list of tag templates that are applied to roles that are created from this template.

Constraints:

  • max: 50

(structure)

Represents a tag that is applied to roles that are created from a role template. The key and value can include @{parameter} placeholders that are replaced with template parameter values when the role is created.

Key -> (string) [required]

The key name of the tag.

Constraints:

  • min: 1
  • max: 128
  • pattern: [\p{L}\p{Z}\p{N}_.:/=+\-@{}]+

Value -> (string) [required]

The value associated with the tag key.

Constraints:

  • min: 0
  • max: 256
  • pattern: [\p{L}\p{Z}\p{N}_.:/=+\-@{}]*

MaxSessionDuration -> (integer)

The maximum session duration (in seconds) for roles that are created from this template.

Constraints:

  • min: 3600
  • max: 43200

VersionEnabled -> (boolean)

Specifies whether this specific minor version of the role template is enabled.

CreateTimestamp -> (timestamp)

The date and time, in ISO 8601 date-time format , when the role template version was created.

UpdateTimestamp -> (timestamp)

The date and time, in ISO 8601 date-time format , when the role template version was last updated.