From 735579baaae4d7c5760aa23fe36e467612ae26b5 Mon Sep 17 00:00:00 2001 From: Quetzalli Date: Thu, 23 Jul 2026 16:05:51 +0200 Subject: [PATCH] DOC-315: Document RAM ram:RequestedAllowsExternalPrincipals condition key Add an IAM Condition Keys section to the RAM docs, mirroring the existing EC2 pattern, covering the new condition key that gates CreateResourceShare/UpdateResourceShare based on allowExternalPrincipals. --- src/content/docs/aws/services/ram.mdx | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) diff --git a/src/content/docs/aws/services/ram.mdx b/src/content/docs/aws/services/ram.mdx index 79eaadbb0..eff34da89 100644 --- a/src/content/docs/aws/services/ram.mdx +++ b/src/content/docs/aws/services/ram.mdx @@ -44,6 +44,25 @@ No IAM policies are created or attached, and no permission enforcement takes pla For all other resource types, the functionality is limited to mocking. +## IAM Condition Keys + +When [IAM Policy Enforcement](/aws/developer-tools/security-testing/iam-policy-enforcement/) is enabled, LocalStack supports the following RAM-specific condition key, matching the behavior described in the [AWS condition keys reference](https://docs.aws.amazon.com/service-authorization/latest/reference/list_awsresourceaccessmanager.html#awsresourceaccessmanager-policy-keys): + +- `ram:RequestedAllowsExternalPrincipals` — the `allowExternalPrincipals` value of a `CreateResourceShare` or `UpdateResourceShare` request, useful for restricting resource shares to principals within your organization. + +For example, the following policy statement only allows creating or updating a resource share when it does not allow external principals: + +```json +{ + "Effect": "Allow", + "Action": ["ram:CreateResourceShare", "ram:UpdateResourceShare"], + "Resource": "*", + "Condition": { + "Bool": { "ram:RequestedAllowsExternalPrincipals": "false" } + } +} +``` + ## API Coverage