$npx skillfedfor your agent

aws-cdk.aws-iam

CDK routines for easily assigning correct and minimal IAM permissions

SkipPyPI Build ToolsReleased Jun 2023197.7K downloads / moApache-2.0Pure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — aws_cdk.aws_iam-1.204.0-py3-none-any.whl
v1.204.0 · released 2023-06-19 · Python ~=3.7 · 7 runtime deps: aws-cdk.core, aws-cdk.cx-api, aws-cdk.region-info, constructs, jsii, publication, typeguard

No—do not install for new projects. This package is end-of-support as of 2023-06-01 and will not receive security updates or bug fixes. AWS CDK v2 is the actively maintained replacement. Install only if you are maintaining an existing CDK v1 codebase that cannot yet migrate, and plan a migration timeline.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires AWS CDK v1 core library (aws-cdk.core) and Python 3.7 or later; CDK v1 is end-of-support as of 2023-06-01.
  • Low install friction with pure Python wheel distribution.
  • However, the package is no longer being updated—AWS CDK v1 reached end-of-support on 2023-06-01.

License · maintenance · safety

Apache-2.0 (permissive) — Licensed under Apache-2.0 (permissive), allowing use in commercial and open-source projects with minimal restrictions.

last release 2023-06-19 (1152 days) · last repo commit 2026-08-14 · 12,868 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 197,666 downloads/mo, #9,752 on PyPI

Verify before relying

pip install aws-cdk.aws-iam

from aws_cdk.aws_iam import Role, ServicePrincipal, PolicyStatement

role = Role(self, "MyRole",
    assumed_by=ServicePrincipal("sns.amazonaws.com")
)
role.add_to_policy(PolicyStatement(
    resources=["*"],
    actions=["lambda:InvokeFunction"]
))
  • Whether existing CDK v1 deployments remain stable in production without active maintenance.
  • Compatibility of this package with newer AWS service IAM features added after 2023-06-01.
Same gist for agents: .md · .json

What it is and what it does

This package is the IAM construct library for AWS CDK v1, a framework for defining cloud infrastructure using Python code. It lets you declare IAM roles, policies, users, and groups as reusable constructs and automatically generates least-privilege permission policies when you wire those constructs together with other AWS resources. For example, if you attach a Lambda function to a DynamoDB table, CDK will automatically grant the Lambda's execution role the minimum permissions needed to read or write to that table.

The package includes helpers for common patterns: attaching managed policies, importing existing IAM roles by ARN, configuring external IDs for cross-account access, and defining principals (service accounts, AWS accounts, federated identities) for assume-role policies. However, CDK v1 reached end-of-support on 2023-06-01 and is no longer receiving updates; AWS recommends migrating to CDK v2 for new projects and ongoing support.

Use it for

  • Define and attach IAM roles to Lambda functions, EC2 instances, and other AWS services in CDK v1 stacks.
  • Automatically grant minimal permissions between resources (e.g., allow a Lambda to write to a DynamoDB table).
  • Create inline and managed policies for users and groups in infrastructure-as-code form.
  • Import and reuse existing IAM roles from your AWS account without recreating them.
  • Configure cross-account role assumption with external IDs for third-party integrations.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Skip

No—do not install for new projects.

This package is end-of-support as of 2023-06-01 and will not receive security updates or bug fixes. AWS CDK v2 is the actively maintained replacement. Install only if you are maintaining an existing CDK v1 codebase that cannot yet migrate, and plan a migration timeline.

Install

aws-cdk-aws-iam on PyPI

Before you install

Low install friction with pure Python wheel distribution. However, the package is no longer being updated—AWS CDK v1 reached end-of-support on 2023-06-01. Users should plan migration to AWS CDK v2 for ongoing support and security updates.

Requires AWS CDK v1 core library (aws-cdk.core) and Python 3.7 or later; CDK v1 is end-of-support as of 2023-06-01.

License in practice

Licensed under Apache-2.0 (permissive), allowing use in commercial and open-source projects with minimal restrictions.

Quickstart

pip install aws-cdk.aws-iam

from aws_cdk.aws_iam import Role, ServicePrincipal, PolicyStatement

role = Role(self, "MyRole",
    assumed_by=ServicePrincipal("sns.amazonaws.com")
)
role.add_to_policy(PolicyStatement(
    resources=["*"],
    actions=["lambda:InvokeFunction"]
))

Verify before relying

  • Whether existing CDK v1 deployments remain stable in production without active maintenance.
  • Compatibility of this package with newer AWS service IAM features added after 2023-06-01.

Package facts

LicenseApache-2.0 permissive
Python supportSupports the current Python release ~=3.7
Install frictionLow. Pure-Python wheel
Runtime dependencies
7 packages
aws-cdk.coreaws-cdk.cx-apiaws-cdk.region-infoconstructsjsiipublicationtypeguard
MaintenanceActively maintained 1,152 days since the last release
Last repo commit
First released
Downloads197,666 / month, #9,752 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 7 - InactiveFramework :: AWS CDKFramework :: AWS CDK :: 1Intended Audience :: DevelopersLicense :: OSI ApprovedOperating System :: OS IndependentProgramming Language :: JavaScriptProgramming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Typing :: Typed

Evidence: aws_cdk.aws_iam-1.204.0-py3-none-any.whl

Tags

Capabilities
aws iam role policy constructcdk iam permissions managementaws identity access management pythoninfrastructure as code iamaws cdk role definitionleast privilege policy automationiam principal grant permissions
Topics
aws-cdkiam-managementend-of-life

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “aws iam role policy construct”

  • aws-cdk.aws-iamProvides Python constructs for defining AWS IAM roles, policies,…
  • awacsawacs generates AWS IAM policy JSON from Python code, with built-in…
  • cloudsplainingCloudsplaining scans AWS IAM policies to identify violations of least…

Give your agent the search over MCP, or paste the wish link into any chat.

More Build Tools packages

packaging Worth it
PyPI · Build Tools · released Aug 2026

Provides reusable utilities for Python packaging interoperability, including version handling, specifiers, markers, requirements, tags, and metadata parsing according to standards like PEP 440 and PEP 425.

Apache-2.0 OR BSD-2-Clausepure Python · 3.9+
2.2Bdownloads / mo
tqdm Worth it
PyPI · Libraries · released Jul 2026

Wraps any iterable to display a real-time progress bar in the terminal or Jupyter notebook, showing iteration count, elapsed time, and estimated time remaining.

copyleftpure Python · 3.8+
648.6Mdownloads / mo
pip Worth it
PyPI · Build Tools · released Aug 2026

pip is the standard installer for Python packages, enabling you to download and install packages from the Python Package Index and other indexes into your Python environment.

MITpure Python · 3.10+
617.5Mdownloads / mo
hatchling Worth it
PyPI · Python Modules · released Aug 2026

Hatchling is a standards-compliant Python build backend that handles packaging, metadata, and distribution of Python projects when configured in a project's pyproject.toml file.

MITpure Python · 3.10+
484.2Mdownloads / mo
grpcio-tools Worth it
PyPI · Build Tools · released Jul 2026

Generates Python gRPC service stubs and message classes from Protocol Buffer definitions, enabling developers to build gRPC clients and servers.

Apache-2.0compiled wheel · 3.10+
278.2Mdownloads / mo
pre-commit Worth it
PyPI · Build Tools · released Aug 2026

pre-commit is a framework for installing and running git hooks written in any language before commits are made, automating code quality and validation checks across multi-language projects.

Install it if your team needs consistent, automated validation at commit time.

permissive licensepure Python · 3.10+
179.9Mdownloads / mo

See also aws-cdk.aws-kms · cdk-iam-floyd · cloudsec-audit · awacs · policy-sentry · aws-cdk.aws-secretsmanager · iamdata · policyuniverse · aws-cdk.region-info · cloudsplaining