> ## Documentation Index
> Fetch the complete documentation index at: https://docs.kubox.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# kubox admin aws verify

Ask AWS what a Kubox role can do, and what it must not

### Synopsis

Simulates each identity's expected permissions against the role that carries
them, and reports both directions.

The denials are the point. Every other tool reports what a principal CAN do;
the failure this catches is a principal that can do too much -- a runner that
has quietly gained kms:Decrypt answers every positive check correctly.

Needs only iam:SimulatePrincipalPolicy. IAM is eventually consistent, so a
verdict can lag a policy change by a minute or so.

```
kubox admin aws verify [flags]
```

### Options

```
      --all                        check every identity
      --allow-region stringArray   a region these identities may act in; repeatable (default: --region alone)
      --artifact-key string        KMS key ARN protecting sealed artifacts; the runner writes it, the unsealer reads it
      --ci-role string             GitHub OIDC role that builds the plane's own cluster on day zero (trust policy only)
      --external-id string         binds a target-account role to one tenant (trust policy only)
  -h, --help                       help for verify
      --hosted-zone string         Route53 zone the build may publish records in
      --identity string            which identity to check
      --operator stringArray       ARN of a user or role that may assume the build role directly, for a laptop build; repeatable (trust policy only)
      --plane-account string       AWS account the management plane runs in
      --region string              primary region, substituted into resource ARNs
      --role string                the role carrying it (default: derived from the account flags and the identity's role name)
      --stack-key string           KMS key ARN protecting the Pulumi checkpoint; the build both writes and reads it
      --state-backend string       Pulumi state backend, e.g. s3://bucket/prefix
      --target-account string      AWS account a cluster is built into (default: the plane's own)
      --tenant stringArray         a tenant the artifact roles seal for: the cloud connection's namespace (kubox-system for Kubox's own account); repeatable, and required for the tenant artifact identities
      --workload-issuer string     the identity plane's issuer, e.g. https://oidc-exp.kubox.cloud; required
```

### Global options

See [global options](/cli-reference/kubox#global-options).

### SEE ALSO

* [kubox admin aws](/cli-reference/kubox_admin_aws)	 - Render and verify the IAM policies a Kubox deployment needs
