> ## Documentation Index
> Fetch the complete documentation index at: https://docs.kubox.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# kubox admin aws policy

Print the IAM policy for one Kubox identity

### Synopsis

Renders an embedded policy document for a named identity.

Makes no AWS calls and needs no credentials, so the document can be read
before it is granted, and diffed against what is actually attached.

Pipe it straight in:

kubox admin aws policy --identity runner --plane-account 123456789012 ... |
aws iam put-role-policy --role-name KuboxRunner \
\--policy-name KuboxRunner --policy-document file:///dev/stdin

Inline rather than managed, so there is no five-version ceiling to hit and
the document cannot be attached to some other role by accident.

```
kubox admin aws policy [flags]
```

### Options

```
      --allow-region stringArray   a region these identities may act in; repeatable (default: --region alone)
      --artifact-key string        KMS key ARN protecting sealed artifacts; the runner writes it, the unsealer reads it
      --ci-role string             GitHub OIDC role that builds the plane's own cluster on day zero (trust policy only)
      --external-id string         binds a target-account role to one tenant (trust policy only)
  -h, --help                       help for policy
      --hosted-zone string         Route53 zone the build may publish records in
      --identity string            which identity: a name from --list; or trust, the build role's trust policy; tenant-sealer-trust / tenant-unsealer-trust, the trust on the tenant's artifact roles; or boundary, the cap every Kubox role carries
      --list                       list the identities and what each one is for
      --operator stringArray       ARN of a user or role that may assume the build role directly, for a laptop build; repeatable (trust policy only)
      --plane-account string       AWS account the management plane runs in
      --region string              primary region, substituted into resource ARNs
      --stack-key string           KMS key ARN protecting the Pulumi checkpoint; the build both writes and reads it
      --state-backend string       Pulumi state backend, e.g. s3://bucket/prefix
      --target-account string      AWS account a cluster is built into (default: the plane's own)
      --tenant stringArray         a tenant the artifact roles seal for: the cloud connection's namespace (kubox-system for Kubox's own account); repeatable, and required for the tenant artifact identities
      --workload-issuer string     the identity plane's issuer, e.g. https://oidc-exp.kubox.cloud; required
```

### Global options

See [global options](/cli-reference/kubox#global-options).

### SEE ALSO

* [kubox admin aws](/cli-reference/kubox_admin_aws)	 - Render and verify the IAM policies a Kubox deployment needs
