本文属于机器翻译版本。若本译文内容与英语原文存在差异,则一律以英文原文为准。
Amazon 的托管策略 Amazon Config
Amazon 托管策略是由创建和管理的独立策略 Amazon。 Amazon 托管策略旨在为许多常见用例提供权限,以便您可以开始为用户、组和角色分配权限。
请记住, Amazon 托管策略可能不会为您的特定用例授予最低权限权限,因为它们可供所有 Amazon 客户使用。我们建议通过定义特定于使用案例的客户管理型策略来进一步减少权限。
您无法更改 Amazon 托管策略中定义的权限。如果 Amazon 更新 Amazon 托管策略中定义的权限,则更新会影响该策略所关联的所有委托人身份(用户、组和角色)。 Amazon 最有可能在启动新的 API 或现有服务可以使用新 Amazon Web Services 服务 的 API 操作时更新 Amazon 托管策略。
有关更多信息,请参阅《IAM 用户指南》中的 Amazon 托管式策略。
Amazon 托管策略:AWSConfigServiceRolePolicy
Amazon Config 使用名AWSServiceRoleForConfig为的服务关联角色代表您呼叫其他 Amazon 服务。使用 Amazon Web Services 管理控制台 进行设置时 Amazon Config, Amazon Config 如果您选择使用 SLR 而不是您自己的 Amazon Identity and Access Management (IAM) 服务角色,则会自动创建此 Amazon Config SLR。
AWSServiceRoleForConfig SLR 包含托管策略。AWSConfigServiceRolePolicy此托管策略包含 Amazon Config 资源的只读和只写权限,以及其他支持的服务中资源的只读权限。 Amazon Config 该策略提供全面的访问权限,用于监控和记录整个 Amazon 基础架构的配置更改,包括计算、存储、联网、安全、分析和机器学习服务等 100 Amazon 多种服务的权限。
该策略包括以下服务类别的权限:
-
access-analyzer— 允许委托人分析访问模式并检索安全发现。 -
account— 允许委托人检索账户联系信息。 -
acm和acm-pca— 允许委托人管理 SSL/TLS 证书和私有证书颁发机构。 -
airflow— 允许委托人监视托管的 Apache Airflow 环境。 -
amplify和amplifyuibuilder— 允许委托人监视 Web 应用程序和用户界面组件。 -
aoss— 允许委托人监控 OpenSearch 无服务器集合和安全配置。 -
app-integrations— 允许委托人监视应用程序集成配置。 -
appconfig— 允许委托人监视应用程序配置部署。 -
appflow— 允许委托人监视应用程序之间的数据流配置。 -
application-autoscaling和application-signals— 允许委托人监控自动缩放策略和应用程序性能指标。 -
appmesh— 允许委托人监视服务网格配置。 -
apprunner— 允许委托人监控容器化的 Web 应用程序和服务。 -
appstream— 允许委托人监视应用程序流配置。 -
appsync— 允许委托人监控 GraphQL API 配置。 -
aps— 允许委托人监视 Prometheus 的监控配置。 -
apptest— 允许校长监视应用程序测试配置。 -
arc-zonal-shift— 允许校长监控分区班配置的可用性。 -
athena— 允许委托人监视查询引擎配置和数据目录。 -
auditmanager— 允许校长监控审计和合规性评估。 -
autoscaling和autoscaling-plans— 允许委托人监控自动缩放组和扩展计划。 -
b2bi— 允许委托人监视 business-to-business集成配置。 -
backup和backup-gateway— 允许委托人监视备份策略和网关配置。 -
batch— 允许委托人监视批处理计算环境和作业队列。 -
bcm-data-exports— 允许委托人监控账单和成本管理数据的导出。 -
bedrock和bedrock-agentcore— 允许委托人监控基础模型和 AI 代理配置。 -
billingconductor— 允许委托人监控账单组配置。 -
budgets— 允许委托人监控预算配置和操作。 -
cassandra— 允许委托人查询托管 Cassandra 数据库配置。 -
ce— 允许委托人监控成本和使用情况报告配置。 -
cleanrooms和cleanrooms-ml— 允许校长监控数据协作和机器学习配置。 -
cloud9— 允许委托人监控云开发环境配置。 -
cloudformation— 允许委托人将基础架构作为代码堆栈配置进行监视。 -
cloudfront— 允许委托人监控内容分发网络配置。 -
cloudtrail— 允许委托人监控 API 日志记录和审计跟踪配置。 -
cloudwatch— 允许委托人监控指标、警报和仪表板配置。 -
codeartifact— 允许委托人监视软件包存储库配置。 -
codebuild— 允许委托人监视生成项目配置。 -
codecommit— 允许委托人监视源代码存储库的配置。 -
codeconnections— 允许委托人监视第三方源连接。 -
codedeploy— 允许委托人监视应用程序部署配置。 -
codeguru-profiler和codeguru-reviewer— 允许委托人监视代码分析和性能分析配置。 -
codepipeline— 允许委托人监控持续集成和部署管道配置。 -
codestar-connections— 允许委托人监视开发者工具的连接。 -
cognito-identity和cognito-idp— 允许委托人监控身份和用户池配置。 -
comprehend— 允许委托人监视自然语言处理配置。 -
config— 允许委托人管理配置记录和合规性监控。 -
connect— 允许校长监控联络中心配置。
有关支持的资源类型的更多信息,请参阅支持的资源类型 Amazon Config和将服务相关角色用于 Amazon Config。
要查看有关策略(包括 JSON 策略文档的最新版本)的更多信息,请参阅《Amazon 托管式策略参考指南》中的 AWSConfigServiceRolePolicy。
推荐:使用服务相关角色
除非您有特定的使用案例,否则建议您使用服务相关角色。服务相关角色可添加 Amazon Config 按预期运行所需的所有必要权限。某些功能(例如服务相关配置记录器)要求您使用服务相关角色。
Amazon 托管策略:AWS_ConfigRole
要记录您的 Amazon 资源配置, Amazon Config 需要 IAM 权限才能获取有关您的资源的配置详细信息。如果要为 Amazon Config创建 IAM 角色,可以使用管理型策略 AWS_ConfigRole 并将其附加到 IAM 角色。
每次 Amazon Config 添加对 Amazon 资源类型的支持时,此 IAM 策略都会更新。这意味着,只要 AWS_ConfiGrole 角色附加了此托管策略,它 Amazon Config 将继续拥有记录所支持资源类型的配置数据所需的权限。该策略提供全面的访问权限,用于监控和记录整个 Amazon 基础架构的配置更改,包括计算、存储、联网、安全、分析和机器学习服务等 100 Amazon 多种服务的权限。有关更多信息,请参阅支持的资源类型 Amazon Config和分配给的 IAM 角色的权限 Amazon Config。
要查看有关该策略的更多详细信息,包括最新版本的 JSON 策略文档,请参阅《Amazon 托管策略参考指南》中的 AWS_ConfiGrole。
Amazon 托管策略:AWSConfigUserAccess
此 IAM 政策提供使用权限 Amazon Config,包括按资源标签搜索和读取所有标签。这不提供配置权限 Amazon Config,而配置权限需要管理权限。
查看策略:AWSConfigUserAccess。
Amazon 托管策略:ConfigConformsServiceRolePolicy
要部署和管理一致性包, Amazon Config 需要 IAM 权限和其他 Amazon 服务的特定权限。它们允许您部署和管理具有完整功能的一致性包,并且每次都会更新,为一致性包 Amazon Config 添加新功能。有关合规包的更多信息,请参阅合规包。
查看策略:ConfigConformsServiceRolePolicy。
Amazon 托管策略:AWSConfigRulesExecutionRole
要部署 Amazon 自定义 Lambda 规则, Amazon Config 需要 IAM 权限和其他 Amazon 服务的特定权限。它们允许 Amazon Lambda 函数访问定期发送到 Amazon S3 的 Amazon Config Amazon Config API 和配置快照。评估 Amazon 自定义 Lambda 规则的配置更改的函数需要此访问权限,并且每次 Amazon Config 添加新功能时都会更新。有关 Amazon 自定义 Lambda 规则的更多信息,请参阅创建自定义 Amazon Config Lambda 规则。有关配置快照的更多信息,请参阅概念 | 配置快照。有关传输配置快照的更多信息,请参阅管理传输通道。
查看策略:AWSConfigRulesExecutionRole。
Amazon 托管策略:AWSConfigMultiAccountSetupPolicy
要在组织中的成员账户中集中部署、更新和删除 Amazon Config 规则和合规包 Amazon Organizations, Amazon Config 需要 IAM 权限和其他 Amazon 服务的特定权限。每次 Amazon Config 为多账户设置添加新功能时,都会更新此托管策略。有关更多信息,请参阅管理组织中所有账户的 Amazon Config 规则和管理组织中所有账户的合规包。
查看策略:AWSConfigMultiAccountSetupPolicy。
Amazon 托管策略:AWSConfigRoleForOrganizations
Amazon Config 要允许只读调用 Amazon Organizations APIs, Amazon Config 需要 IAM 权限和其他 Amazon 服务的特定权限。每次 Amazon Config 为多账户设置添加新功能时,都会更新此托管策略。有关更多信息,请参阅管理组织中所有账户的 Amazon Config 规则和管理组织中所有账户的合规包。
查看策略:AWSConfigRoleForOrganizations。
Amazon 托管式策略:AWSConfigRemediationServiceRolePolicy
Amazon Config 要允许代表您修复NON_COMPLIANT资源, Amazon Config
需要 IAM 权限和其他 Amazon 服务的特定权限。每次 Amazon Config 添加新的补救功能时,都会更新此托管策略。有关修复的更多信息,请参阅使用规则修复不合规的 Amazon Config 资源。有关启动可能的 Amazon Config 评估结果的条件的更多信息,请参阅概念 | Amazon Config 规则。
查看策略:AWSConfigRemediationServiceRolePolicy。
Amazon ConfigAmazon 托管策略的更新
查看 Amazon Config 自该服务开始跟踪这些更改以来 Amazon 托管策略更新的详细信息。要获得有关此页面变更的自动提醒,请订阅 “ Amazon Config 文档历史记录” 页面上的 RSS feed。
| 更改 | 描述 | 日期 |
|---|---|---|
|
AWS_ConfigRole— 添加 “s3tables:ListTagsForResource”、“s3tables:”、“s3tables:GetTableBucketMetricsConfiguration” GetTableBucketStorageClass |
此策略现在支持 S3Tables 的额外权限。 |
2026年1月9日 |
|
AWSConfigServiceRolePolicy— 添加 “s3tables:ListTagsForResource”、“s3tables:”、“s3tables:GetTableBucketMetricsConfiguration” GetTableBucketStorageClass |
此策略现在支持 S3Tables 的额外权限。 |
2026年1月9日 |
|
AWS_ConfigRole— 添加 “lightsail:GetActiveNames” “lightsail:GetOperations” “s3:” GetBucketAbac |
该政策现在支持亚马逊 Lightsail 和亚马逊简单存储服务 (Amazon S3) 的额外权限。 |
2025 年 11 月 20 日 |
|
AWSConfigServiceRolePolicy— 添加 “lightsail:GetActiveNames” “lightsail:GetOperations” “s3:” GetBucketAbac |
该政策现在支持亚马逊 Lightsail 和亚马逊简单存储服务 (Amazon S3) 的额外权限。 |
2025 年 11 月 20 日 |
|
AWSConfigServiceRolePolicy— 更新了托管策略,具有在 100 多种 Amazon 服务(包括计算、存储、联网、安全、分析和机器学习服务)中记录 Amazon 资源配置的全面权限。 |
现在,该策略提供了有关服务权限的增强文档,并支持对所有 Amazon Config 支持配置记录的 Amazon 服务进行全面监控。 |
2025 年 11 月 11 日 |
|
AWS_ConfigRole— 更新了托管策略,具有跨多种服务记录 Amazon 资源配置的全面权限 Amazon Identity and Access Management,包括亚马逊弹性计算云、亚马逊简单存储服务 Amazon Lambda、Amazon Relational Database Service 等。 |
此策略现在支持额外权限,以便在所有支持的 Amazon 服务中进行全面的 Amazon 资源配置记录和监控。 |
2025 年 11 月 10 日 |
|
AWS_ConfigRole— 添加 “放大:” “放大:GetDomainAssociation” “放大:” “appsync:ListDomainAssociations” “appsync:ListTagsForResource” “bedrock:GetSourceApiAssociation” “bedrock:ListSourceApiAssociations” “bedrock:GetFlow” “bedrock:ListAgentCollaborators” “cloudFormation:ListFlows” “codeartifact:ListPrompts” “codeartifact:GetResourcePolicy” “codeartifact:DescribePublisherDescribePackageGroup” “codepipeline:ListAllowedRepositoriesForGroup” “codepipeline:ListPackageGroups” “codepipeline:ListActionTypes” “connect:ListTagsForResource” “截止日期:ListWebhooks” “ec2:” “ec2:DescribeTrafficDistributionGroup” “ec2:” ListTrafficDistributionGroups ListFarms GetTransitGatewayRouteTablePropagations SearchLocalGatewayRoutesSearchTransitGatewayMulticastGroups” “实体分辨率:” “实体分辨率:GetMatchingWorkflow” “iotsitewise:” “iotsitewise:ListMatchingWorkflows” “iotsitewise:” “iotsitewise:ListAssetModelCompositeModels” “iotsitewise:ListAssetModelProperties” “ivs:” “lambda:” “lambda:” “lambda:ListAssetProperties” “pipes:” “pipes:ListAssociatedAssets” “quicksight:” “quicksight:ListPublicKeys” “redshift-serverlessift:GetRuntimeManagementConfig” “redshift:” “redshift:ListFunctionEventInvokeConfigs” “redshift:ListFunctionUrlConfigs”:” “rolesanywhere:DescribePipe” “rolesanywhere:ListPipes” “sagemaker:DescribeRefreshSchedule” “sagemaker:” “sagemaker:ListRefreshSchedules” “sagemaker:” “GetProvisionedConcurrencyConfigListSnapshotCopyConfigurationsGetResourcePolicyGetCrlListCrlsDescribeAppDescribeUserProfileListApps” “sagemaker:ListModelPackages” “sagemaker:” “securitymanager:ListUserProfiles” “securitylake:GetResourcePolicy” “servicecatalog:ListSubscribersListTagsForResource” “servicecatalog:” “ssemcatalog:DescribeServiceAction” “ssm:” ssm:“ssm:ListApplications” “ssm:” “ssm:ListAssociatedResources” “ssm:ListProtectionGroups” “ssm:ListTagsForResource”:” “ssm:” “ssm:GetReplicationSet” “wafv2:” “bedrock-agentcore:ListReplicationSets” “bedro DescribeAssociation ck-agentcore:DescribePatchBaselines” “bedrock-agentcore:GetDefaultPatchBaseline” “bedrock GetPatchBaseline GetResourcePolicies ListAssociations ListResourceDataSync ListLoggingConfigurations ListCodeInterpreters GetCodeInterpreter-agentcore:” “bedrock-agentcore:ListBrowsers” “bedrock-agentcore:” “bedrock-agentcore:GetBrowser” “bedrock-agentcore:” “bedrock-agentcore:” “bedrock-agentcore:ListAgentRuntimes” GetAgentRuntime ListAgentRuntimeEndpoints GetAgentRuntimeEndpoint |
该政策现在支持、、Amazon Bedrock Amazon Amplify、 Amazon AppSync、、、、、Amazon Connect Amazon CloudTrail Amazon CloudFormation Amazon CodeArtifact、 Amazon CodePipeline、、、亚马逊、、 Amazon Deadline Cloud、、亚马逊 EC2、 Amazon Entity Resolution 数据匹配服务 Amazon IoT SiteWise、Amazon Quick Suite、 Amazon Lambda A EventBridge mazon Redshift、Serverless、、、亚马逊 Amazon Identity and Access Management Roles Anywhere、、、 SageMaker亚马逊安全湖 Amazon Service Catalog、、、 Amazon Secrets Manager、Amazon Systems Manager 和。 Amazon Shield EC2 Amazon WAFV2 |
2025 年 10 月 1 日 |
|
AWSConfigServiceRolePolicy— 添加 “放大:” “放大:GetDomainAssociation” “放大:” “appsync:ListDomainAssociations” “appsync:ListTagsForResource” “bedrock:GetSourceApiAssociation” “bedrock:ListSourceApiAssociations” “bedrock:GetFlow” “bedrock:ListAgentCollaborators” “cloudFormation:ListFlows” “codeartifact:ListPrompts” “codeartifact:GetResourcePolicy” “codeartifact:DescribePublisherDescribePackageGroup” “codepipeline:ListAllowedRepositoriesForGroup” “codepipeline:ListPackageGroups” “codepipeline:ListActionTypes” “connect:ListTagsForResource” “截止日期:ListWebhooks” “ec2:” “ec2:DescribeTrafficDistributionGroup” “ec2:” ListTrafficDistributionGroups ListFarms GetTransitGatewayRouteTablePropagations SearchLocalGatewayRoutesSearchTransitGatewayMulticastGroups” “实体分辨率:” “实体分辨率:GetMatchingWorkflow” “iotsitewise:” “iotsitewise:ListMatchingWorkflows” “iotsitewise:” “iotsitewise:ListAssetModelCompositeModels” “iotsitewise:ListAssetModelProperties” “ivs:” “lambda:” “lambda:” “lambda:ListAssetProperties” “pipes:” “pipes:ListAssociatedAssets” “quicksight:” “quicksight:ListPublicKeys” “redshift-serverlessift:GetRuntimeManagementConfig” “redshift:” “redshift:ListFunctionEventInvokeConfigs” “redshift:ListFunctionUrlConfigs”:” “rolesanywhere:DescribePipe” “rolesanywhere:ListPipes” “sagemaker:DescribeRefreshSchedule” “sagemaker:” “sagemaker:ListRefreshSchedules” “sagemaker:” “GetProvisionedConcurrencyConfigListSnapshotCopyConfigurationsGetResourcePolicyGetCrlListCrlsDescribeAppDescribeUserProfileListApps” “sagemaker:ListModelPackages” “sagemaker:” “securitymanager:ListUserProfiles” “securitylake:GetResourcePolicy” “servicecatalog:ListSubscribersListTagsForResource” “servicecatalog:” “ssemcatalog:DescribeServiceAction” “ssm:” ssm:“ssm:ListApplications” “ssm:” “ssm:ListAssociatedResources” “ssm:ListProtectionGroups” “ssm:ListTagsForResource”:” “ssm:” “ssm:GetReplicationSet” “wafv2:” “bedrock-agentcore:ListReplicationSets” “bedro DescribeAssociation ck-agentcore:DescribePatchBaselines” “bedrock-agentcore:GetDefaultPatchBaseline” “bedrock GetPatchBaseline GetResourcePolicies ListAssociations ListResourceDataSync ListLoggingConfigurations ListCodeInterpreters GetCodeInterpreter-agentcore:” “bedrock-agentcore:ListBrowsers” “bedrock-agentcore:” “bedrock-agentcore:GetBrowser” “bedrock-agentcore:” “bedrock-agentcore:” “bedrock-agentcore:ListAgentRuntimes” GetAgentRuntime ListAgentRuntimeEndpoints GetAgentRuntimeEndpoint |
该政策现在支持、、Amazon Bedrock Amazon Amplify、 Amazon AppSync、、、、、Amazon Connect Amazon CloudTrail Amazon CloudFormation Amazon CodeArtifact、 Amazon CodePipeline、、、亚马逊、、 Amazon Deadline Cloud、、亚马逊 EC2、 Amazon Entity Resolution 数据匹配服务 Amazon IoT SiteWise、Amazon Quick Suite、 Amazon Lambda A EventBridge mazon Redshift、Serverless、、、亚马逊 Amazon Identity and Access Management Roles Anywhere、、、 SageMaker亚马逊安全湖 Amazon Service Catalog、、、 Amazon Secrets Manager、Amazon Systems Manager 和。 Amazon Shield EC2 Amazon WAFV2 |
2025 年 10 月 1 日 |
|
AWS_ConfigRole— 添加”arc-zonal-shift:GetAutoshiftObserverNotificationStatus“、“基石:”、“cloudtrail:”、GetModelInvocationLoggingConfiguration “codeartifact:”、GetEventConfiguration “codeartifaction:”、“截止日期:”、DescribeDomain “截止日期:”、“截止日期:”、GetDomainPermissionsPolicy “dms:”、“dms:”、GetFleet “glue:”、GetQueueFleetAssociation “kafkaconnect:”、ListFleets “kafkaconnect:”、ListQueueFleetAssociations “kafkaconnect:”、ListTagsForResource “kafkaconnect:DescribeDataMigrations”、“kafkaconnect:”、“kafkaconnect:”、ListMigrationProjects “kafkaconnect:”、GetDataCatalogEncryptionSettings “kafect:”、“kafkaconnect:DescribeCustomPlugin”、“kafkaconnect:DescribeWorkerConfiguration”、“lakeformation:”、“medialive:”、“medialive:ListCustomPlugins”、“medialive:”、“m ListTagsForResource ListWorkerConfigurations DescribeLakeFormationIdentityCenterConfiguration DescribeMultiplexProgramListMultiplexPrograms“,” mediapackagev2:”、“mediapackagev2:GetChannelGroup”、“rds:”、“rolesanywhere:ListChannelGroups”、“rolesanywhere:DescribeEngineDefaultParameters”、“anywhere:”、“rolesanywhere:GetProfile”、“s3:”、“securitylake:GetTrustAnchor”、“securitylake:ListProfiles”、“securitylake:”、“anywhere:ListTagsForResource”、“securitylake:”、ListTrustAnchors “securitylake:GetAccessGrant”、“securitylake:ListAccessGrants”、“securitylake:“、“servicecatalog:DescribeSecret”、“servicecatalog:ListDataLakeExceptions”、“servicecatalog:ListDataLakes”、“servicecatalog:”、“ses:ListLogSources”、“ses:”、“ses:”、“ses:GetAttributeGroup“,” ListAttributeGroups ListServiceActions ListServiceActionsForProvisioningArtifact GetTrafficPolicy ListTagsForResourceses:ListTrafficPolicies“、“xray:”、“xray:GetGroup”、“xray:GetGroups”、“xray:”、“xray:GetSamplingRules”、“xray:”、ListResourcePolicies “xray:” ListTagsForResource |
该政策现在支持亚马逊贝德罗克 Amazon ARC - Zonal Shift、、、、、、、、 Amazon CloudTrail、 Amazon CodeArtifact、 Amazon Deadline Cloud、、 Amazon Database Migration Service Amazon Glue Amazon Identity and Access Management、Amazon Managed Streaming Amazon Lake Formation、、、 CloudWatch Amazon AWS Elemental MediaLive Logs AWS Elemental MediaPackage、、、、亚马逊关系数据库服务、亚马逊简单存储服务 Amazon Secrets Manager、、亚马逊安全湖 Amazon Service Catalog、、亚马逊简单电子邮件服务和。 Amazon X-Ray |
2025 年 7 月 28 日 |
|
AWSConfigServiceRolePolicy— 添加 “arc-zonal-shift:”、GetAutoshiftObserverNotificationStatus “基石:”、“cloudtrail:GetModelInvocationLoggingConfiguration”、“codeartifact:GetEventConfiguration”、“codeartifact:DescribeDomain”、“截止日期:”、“截止日期:GetDomainPermissionsPolicy”、“截止日期:”、“dms:GetFleet”、“dms:”、“glue:GetQueueFleetAssociation”、“iam:ListFleets”、“kafkaconnect:ListQueueFleetAssociations”、“kafkaconnect:ListTagsForResource”、“kafkaconnect:DescribeDataMigrations”,“kafkaconnect:ListMigrationProjects”,“kafkaconnect:GetDataCatalogEncryptionSettings”,“kafkaconnect:ListPolicies”,“kafconnect:”、“kafkaconnect:DescribeCustomPlugin”、“kafkaconnect:DescribeWorkerConfiguration”、“lakeformation:”、“logs:”、“logs:ListCustomPlugins”、“logs:”、“logs:ListTagsForResource”、“medialive:ListWorkerConfigurationsDescribeLakeFormationIdentityCenterConfigurationDescribeIndexPoliciesListTagsForResourceDescribeMultiplexProgram“,” medialive:ListMultiplexPrograms”、“mediapackagev2:”、“mediapackagev2:GetChannelGroup”、“rds:”、“rolesanywhere:”、“rolesanywhere:ListChannelGroups”、“rolesanywhere:DescribeEngineDefaultParameters”、“rolesanywhere:”、“rolesanywhere:”、GetProfile “rolesanywhere:GetTrustAnchor”、“rolesanywhere:”、“rolesanywhere:”、ListProfiles “rolesanywhere:ListTagsForResource”、“rolesanywhere:”、ListTrustAnchors “rolesanywhere:”、““、GetAccessGrant “securitylake:ListAccessGrants”、“servicecatalog:”、“servicecatalog:DescribeSecret”、“servicecatalog:ListDataLakeExceptions”、“servicecatalog:”、ListDataLakes “servicecatalog:”、“ses:ListLogSourcesGetAttributeGroupListAttributeGroupsListServiceActionsListServiceActionsForProvisioningArtifactGetTrafficPolicy“、“ses:”、“ses:ListTagsForResource”、“xray:”、“xray:ListTrafficPolicies”、“xray:”、“xray:GetGroup”、“xray:”、“xray:”、GetGroups “arn: aws: apigateway:: /accountGetSamplingRules”、“arn: aws:: /usageplans/”、ListResourcePolicies “arn: aws:: ListTagsForResource /usageplans”、“arn: aws: apigateway:: /usageplans/”。 |
该政策现在支持对亚马逊 Bedrock Amazon ARC - Zonal Shift、、、、、、 Amazon CloudTrail、、 Amazon CodeArtifact、 Amazon Deadline Cloud、 Amazon Database Migration Service Amazon Glue Amazon Identity and Access Management、Amazon Managed Streaming Amazon Lake Formation、、、 CloudWatch Amazon L AWS Elemental MediaLive ogs AWS Elemental MediaPackage、、、、、亚马逊关系数据库服务、亚马逊简单存储服务 Amazon Secrets Manager、、亚马逊安全湖 Amazon Service Catalog、亚马逊简单电子邮件 Amazon X-Ray服务和亚马逊 API Gateway 的额外权限。 |
2025 年 7 月 28 日 |
|
AWSConfigServiceRolePolicy— 添加 “backup-gateway:”、GetHypervisor “backup-gatewaybcm-data-exports:”、ListHypervisors GetExport “、”bcm-data-exports:ListExports“、”、“基岩bcm-data-exports:”、ListTagsForResource “基岩:”、“基岩:”、GetAgent “基岩:”、GetAgentActionGroup “基岩:”、“基岩:”、GetAgentKnowledgeBase “基岩:”、“基岩:”、GetDataSource “基岩:”、“基岩:”、GetFlowAlias “基岩:”、GetFlowVersion “基岩:”、“基岩:ListAgentActionGroups”,“cloudformation:ListAgentKnowledgeBases”,“cloudformation:ListDataSources”,“cloudformation:ListFlowVersions”,“cloudformati ListFlowAliases BatchDescribeTypeConfigurations DescribeStackInstance DescribeStackSet ListStackInstancescloudformation:”、ListStackSets “cloudfront:”、GetPublicKey “cloudfront:GetRealtimeLogConfig”、“cloudfront:ListPublicKeys”、“实体分辨率:”、ListRealtimeLogConfigs “实体分辨率:”、“实体分辨率:”、“实体分辨率:GetIdMappingWorkflow”、“iotdeviceAdvisor:GetSchemaMapping”、“iotdeviceAdvisor:”、ListIdMappingWorkflows “iotdeviceAdvisor:”、ListSchemaMappings “lambda:ListTagsForResource”、“lambda:”,“” mediapackagev2:GetSuiteDefinition“,” mediapackagev2:ListSuiteDefinitions“,” networkmanager:GetEventSourceMapping“,” networkmanager:ListEventSourceMappings“,”:“,” GetChannel ListChannels GetTransitGatewayPeering ListPeerings pca-connector-ad GetDirectoryRegistrationpca-connector-ad: ListDirectoryRegistrations “,”: “、“rdspca-connector-ad: ListTagsForResource Describe G DBShard roups”、“rds:”、“redshift:DescribeIntegrations”、“s3tables:”、“s3tables:”、DescribeIntegrations “s3tables:”、“s3tables:”、GetTableBucket “ssm-quicksetup:”、GetTableBucketEncryption “ssm-quicksetup:”,GetTableBucketMaintenanceConfiguration“ssm-quicksetup:” ListTableBuckets GetConfigurationManager ListConfigurationManagers |
该策略现在支持对、、Amazon Bedrock Amazon Backup gateway Amazon 账单与成本管理、、、Amazon、 Amazon CloudFormation、、、 CloudFront、、、 Amazon Entity Resolution 数据匹配服务、 Amazon IoT Core Device Advisor、 Amazon Lambda Amazon Network Manager Amazon 私有证书颁发机构、Amazon Redshift、Amazon S3 Tables 等的额外权限。 Amazon Systems Manager 快速设置功能 |
2025 年 6 月 18 日 |
AWS_ConfigRole— 添加 “backup-gateway:”、GetHypervisor “backup-gatewaybcm-data-exports:”、ListHypervisors GetExport “、”bcm-data-exports:ListExports“、”、“基岩bcm-data-exports:”、ListTagsForResource “基岩:”、“基岩:”、GetAgent “基岩:”、GetAgentActionGroup “基岩:”、“基岩:”、GetAgentKnowledgeBase “基岩:”、“基岩:”、GetDataSource “基岩:”、“基岩:”、GetFlowAlias “基岩:”、GetFlowVersion “基岩:”、“基岩:ListAgentActionGroups”,“cloudformation:ListAgentKnowledgeBases”,“cloudformation:ListDataSources”,“cloudformation:ListFlowVersions”,“cloudformati ListFlowAliases BatchDescribeTypeConfigurations DescribeStackInstance DescribeStackSet ListStackInstancescloudformation:”、ListStackSets “cloudfront:”、GetPublicKey “cloudfront:”、GetRealtimeLogConfig “cloudfront:”、ListPublicKeys “实体分辨率:ListRealtimeLogConfigs”、“实体分辨率:”、“实体分辨率:GetIdMappingWorkflow”、“实体分辨率:”、GetSchemaMapping “iotdeviceAdvisor:”、ListIdMappingWorkflows “iotdeviceAdvisor:ListSchemaMappings”、“iotdeviceAdvisor:ListTagsForResource”、“lambda:”、“lambda:GetSuiteDefinition”,“” networkmanager:ListSuiteDefinitions“,”,“networkmanager:”,GetEventSourceMapping”:“,”:“,”:ListEventSourceMappings“,” rds:GetTransitGatewayPeeringListPeeringspca-connector-adGetDirectoryRegistrationpca-connector-adListDirectoryRegistrationspca-connector-adListTagsForResource描述DBShard群组”、“rds:”、“redshift:”、DescribeIntegrations “s3tables:”、“s3tables:”、DescribeIntegrations “s3tables:”、“s3tables:”、GetTableBucket “s3tables:”、GetTableBucketEncryption “ssm-quicksetup:”、“ssm-quicksetup:”、GetTableBucketMaintenanceConfiguration “ssm-quickset ListTableBuckets up:”,GetConfigurationManagerListConfigurationManagers |
该策略现在支持对、、Amazon Bedrock Amazon Backup gateway Amazon 账单与成本管理、、、Amazon、 Amazon CloudFormation、、、 CloudFront、、、 Amazon Entity Resolution 数据匹配服务、 Amazon IoT Core Device Advisor、 Amazon Lambda Amazon Network Manager Amazon 私有证书颁发机构、Amazon Redshift、Amazon S3 Tables 等的额外权限。 Amazon Systems Manager 快速设置功能 |
2025 年 6 月 18 日 |
|
AWS_ConfigRole – 添加 "bedrock:GetGuardrail", "bedrock:GetInferenceProfile", "bedrock:GetKnowledgeBase", "bedrock:ListGuardrails", "bedrock:ListInferenceProfiles", "bedrock:ListKnowledgeBases", "bedrock:ListTagsForResource" |
此策略现在支持为 Amazon Bedrock 授予更多权限。 |
2025 年 5 月 27 日 |
|
AWSConfigServiceRolePolicy – 添加 "bedrock:GetGuardrail", "bedrock:GetInferenceProfile", "bedrock:GetKnowledgeBase", "bedrock:ListGuardrails", "bedrock:ListInferenceProfiles", "bedrock:ListKnowledgeBases", "bedrock:ListTagsForResource" |
此策略现在支持为 Amazon Bedrock 授予更多权限。 |
2025 年 5 月 27 日 |
|
AWS_ConfigRole – 添加 "b2bi:GetPartnership", "b2bi:GetProfile", "b2bi:ListPartnerships", "b2bi:ListProfiles", "bedrock:ListAgents", "cleanrooms:GetConfiguredTable", "cleanrooms:GetConfiguredTableAnalysisRule", "cleanrooms:GetMembership", "cleanrooms:GetPrivacyBudgetTemplate", "cleanrooms:ListConfiguredTables", "cleanrooms:ListMemberships", "cleanrooms:ListPrivacyBudgetTemplates", "codeconnections:GetConnection", "codeconnections:ListConnections", "codeconnections:ListTagsForResource", "directconnect:DescribeConnections", "dms:DescribeReplicationConfigs", "logs:DescribeAccountPolicies", "logs:DescribeResourcePolicies", "macie2:ListAutomatedDiscoveryAccounts", "managedblockchain:GetAccessor", "managedblockchain:ListAccessors", "qbusiness:GetApplication", "qbusiness:ListApplications", "qbusiness:ListTagsForResource", "route53profiles:GetProfile", "route53profiles:GetProfileAssociation", "route53profiles:ListProfileAssociations", "route53profiles:ListProfiles", "route53profiles:ListTagsForResource", "s3:GetAccessGrantsInstance", "s3:GetAccessGrantsLocation", "s3:ListAccessGrantsInstances", "s3:ListAccessGrantsLocations", "sagemaker:DescribeCluster", "sagemaker:DescribeMlflowTrackingServer", "sagemaker:DescribeStudioLifecycleConfig", "sagemaker:ListClusters", "sagemaker:ListMlflowTrackingServers", "sagemaker:ListStudioLifecycleConfigs", "securityhub:DescribeStandardsControls", "securityhub:GetEnabledStandards", "ssm-contacts:GetContact", "ssm-contacts:GetContactChannel", "ssm-contacts:ListContactChannels", "ssm-contacts:ListContacts", "ssm-incidents:GetResponsePlan", "ssm-incidents:ListResponsePlans", "ssm-incidents:ListTagsForResource", "ssm:DescribeInstanceInformation" |
该政策现在支持对亚马逊 Bedrock Amazon B2B Data Interchange、、、、、 Amazon Database Migration Service (Amazon DMS)、Amazon L CloudWatch ogs Amazon Clean Rooms Amazon CodeConnections Amazon Direct Connect、Amazon Macie、Amazon Managed Blockchain、Amazon Q Business、Route 53 Profiles、亚马逊简单存储服务 (Amazon S3)、Amazon A SageMaker I Amazon Security Hub CSPM、 Amazon Systems Manager Incident Manager以及联系人等的额外权限。 Amazon Systems Manager Incident Manager Amazon Systems Manager |
2025 年 4 月 8 日 |
|
AWSConfigServiceRolePolicy – 添加 "b2bi:GetPartnership", "b2bi:GetProfile", "b2bi:ListPartnerships", "b2bi:ListProfiles", "bedrock:ListAgents", "cleanrooms:GetConfiguredTable", "cleanrooms:GetConfiguredTableAnalysisRule", "cleanrooms:GetMembership", "cleanrooms:GetPrivacyBudgetTemplate", "cleanrooms:ListConfiguredTables", "cleanrooms:ListMemberships", "cleanrooms:ListPrivacyBudgetTemplates", "codeconnections:GetConnection", "codeconnections:ListConnections", "codeconnections:ListTagsForResource", "directconnect:DescribeConnections", "dms:DescribeReplicationConfigs", "logs:DescribeAccountPolicies", "logs:DescribeResourcePolicies", "macie2:ListAutomatedDiscoveryAccounts", "managedblockchain:GetAccessor", "managedblockchain:ListAccessors", "qbusiness:GetApplication", "qbusiness:ListApplications", "qbusiness:ListTagsForResource", "route53profiles:GetProfile", "route53profiles:GetProfileAssociation", "route53profiles:ListProfileAssociations", "route53profiles:ListProfiles", "route53profiles:ListTagsForResource", "s3:GetAccessGrantsInstance", "s3:GetAccessGrantsLocation", "s3:ListAccessGrantsInstances", "s3:ListAccessGrantsLocations", "sagemaker:DescribeCluster", "sagemaker:DescribeMlflowTrackingServer", "sagemaker:DescribeStudioLifecycleConfig", "sagemaker:ListClusters", "sagemaker:ListMlflowTrackingServers", "sagemaker:ListStudioLifecycleConfigs", "securityhub:DescribeStandardsControls", "securityhub:GetEnabledStandards", "ssm-contacts:GetContact", "ssm-contacts:GetContactChannel", "ssm-contacts:ListContactChannels", "ssm-contacts:ListContacts", "ssm-incidents:GetResponsePlan", "ssm-incidents:ListResponsePlans", "ssm-incidents:ListTagsForResource", "ssm:DescribeInstanceInformation" |
该政策现在支持对亚马逊 Bedrock Amazon B2B Data Interchange、、、、、 Amazon Database Migration Service (Amazon DMS)、Amazon L CloudWatch ogs Amazon Clean Rooms Amazon CodeConnections Amazon Direct Connect、Amazon Macie、Amazon Managed Blockchain、Amazon Q Business、Route 53 Profiles、亚马逊简单存储服务 (Amazon S3)、Amazon A SageMaker I Amazon Security Hub CSPM、 Amazon Systems Manager Incident Manager以及联系人等的额外权限。 Amazon Systems Manager Incident Manager
Amazon Systems Manager此策略现在还支持通过包含资源模式“ |
2025 年 4 月 8 日 |
|
AWS_ConfigRole – 添加 "ec2:GetAllowedImagesSettings" |
该策略现在支持亚马逊弹性计算云 (Amazon EC2) 的额外权限。 |
2025 年 3 月 4 日 |
|
AWSConfigServiceRolePolicy – 添加 "ec2:GetAllowedImagesSettings" |
该策略现在支持亚马逊弹性计算云 (Amazon EC2) 的额外权限。 |
2025 年 3 月 4 日 |
|
AWS_ConfigRole – 添加 "cleanrooms-ml:GetTrainingDataset", "cleanrooms-ml:ListTrainingDatasets", "comprehend:DescribeFlywheel", "comprehend:ListFlywheels", "comprehend:ListTagsForResource", "ec2:GetSnapshotBlockPublicAccessState", "omics:GetAnnotationStore", "omics:GetRunGroup", "omics:GetSequenceStore", "omics:GetVariantStore", "omics:ListAnnotationStores", "omics:ListRunGroups", "omics:ListSequenceStores", "omics:ListTagsForResource", "omics:ListVariantStores", "s3express:GetEncryptionConfiguration", "s3express:GetLifecycleConfiguration", "ses:GetDedicatedIpPool", "ses:GetDedicatedIps", and "ses:ListDedicatedIpPools" |
该政策现在支持亚马逊Comprehend Amazon Clean Rooms、亚马逊弹性计算云 EC2(亚马逊)、亚马逊简单存储服务(Amazon S3 Amazon HealthOmics)和亚马逊简单电子邮件服务(Amazon SES)的额外权限。 |
2025 年 1 月 16 日 |
|
AWSConfigServiceRolePolicy – 添加 "cleanrooms-ml:GetTrainingDataset", "cleanrooms-ml:ListTrainingDatasets", "comprehend:DescribeFlywheel", "comprehend:ListFlywheels", "comprehend:ListTagsForResource", "ec2:GetSnapshotBlockPublicAccessState", "omics:GetAnnotationStore", "omics:GetRunGroup", "omics:GetSequenceStore", "omics:GetVariantStore", "omics:ListAnnotationStores", "omics:ListRunGroups", "omics:ListSequenceStores", "omics:ListTagsForResource", "omics:ListVariantStores", "s3express:GetEncryptionConfiguration", "s3express:GetLifecycleConfiguration", "ses:GetDedicatedIpPool", "ses:GetDedicatedIps", and "ses:ListDedicatedIpPools" |
该政策现在支持亚马逊Comprehend Amazon Clean Rooms、亚马逊弹性计算云 EC2(亚马逊)、亚马逊简单存储服务(Amazon S3 Amazon HealthOmics)和亚马逊简单电子邮件服务(Amazon SES)的额外权限。 |
2025 年 1 月 16 日 |
|
AWSConfigServiceRolePolicy – 添加 "organizations:ListAWSServiceAccessForOrganization" |
此策略现在支持为 Amazon Organizations授予更多权限。 |
2024 年 12 月 18 日 |
|
AWS_ConfigRole – 添加 "app-integrations:GetApplication", "app-integrations:ListApplications", "app-integrations:ListTagsForResource", "appconfig:GetExtension", "appconfig:ListExtensions", "cloudtrail:GetInsightSelectors", "connect:DescribeQueue", "connect:DescribeRoutingProfile", "connect:DescribeSecurityProfile", "connect:ListQueueQuickConnects", "connect:ListQueues", "connect:ListRoutingProfileQueues", "connect:ListRoutingProfiles", "connect:ListSecurityProfileApplications", "connect:ListSecurityProfilePermissions", "connect:ListSecurityProfiles", "datazone:GetDomain", "datazone:ListDomains", "devops-guru:ListNotificationChannels", "glue:GetRegistry", "glue:ListRegistries", "identitystore:DescribeGroup", "identitystore:DescribeGroupMembership" "identitystore:ListGroupMemberships", "identitystore:ListGroups", "iot:DescribeThingGroup", "iot:DescribeThingType", "iot:ListThingGroups", "iot:ListThingTypes", "iotfleetwise:GetDecoderManifest", "iotfleetwise:GetFleet", "iotfleetwise:GetModelManifest", "iotfleetwise:GetSignalCatalog", "iotfleetwise:GetVehicle", "iotfleetwise:ListDecoderManifestNetworkInterfaces", "iotfleetwise:ListDecoderManifests", "iotfleetwise:ListDecoderManifestSignals", "iotfleetwise:ListFleets", "iotfleetwise:ListModelManifestNodes", "iotfleetwise:ListModelManifests", "iotfleetwise:ListSignalCatalogNodes", "iotfleetwise:ListSignalCatalogs", "iotfleetwise:ListTagsForResource", "iotfleetwise:ListVehicles", "iotwireless:GetDestination", "iotwireless:GetDeviceProfile", "iotwireless:GetWirelessGateway", "iotwireless:ListDestinations", "iotwireless:ListDeviceProfiles", "iotwireless:ListWirelessGateways", "ivschat:GetLoggingConfiguration", "ivschat:GetRoom" "ivschat:ListLoggingConfigurations", "ivschat:ListRooms", "ivschat:ListTagsForResource", "logs:GetLogAnomalyDetector", "logs:ListLogAnomalyDetectors", "oam:GetSink" "oam:GetSinkPolicy", "oam:ListSinks", "payment-cryptography:GetAlias", "payment-cryptography:GetKey", "payment-cryptography:ListAliases", "payment-cryptography:ListKeys", "payment-cryptography:ListTagsForResource", "rds:DescribeDBProxyTargetGroups", "rds:DescribeDBProxyTargets", "rekognition:DescribeProjects", "s3:GetStorageLensGroup", "s3:ListStorageLensGroups", "s3:ListTagsForResource", "scheduler:GetScheduleGroup", "scheduler:ListScheduleGroups", "scheduler:ListTagsForResource", "ssm:GetServiceSetting", "vpc-lattice:GetAccessLogSubscription", "vpc-lattice:GetService", "vpc-lattice:GetServiceNetwork", "vpc-lattice:GetTargetGroup", "vpc-lattice:ListAccessLogSubscriptions", "vpc-lattice:ListServiceNetworks", "vpc-lattice:ListServices", "vpc-lattice:ListTagsForResource", "vpc-lattice:ListTargetGroups", and "vpc-lattice:ListTargets" |
该政策现在支持、、Amazon Connect Amazon AppConfig Amazon CloudTrail、Amazon、Amazon DevOps Guru DataZone、、Identity Store Amazon Glue、、、、 Amazon IoT Amazon IoT FleetWise Amazon IoT Wireless、亚马逊互动视频服务 (Amazon IVS)、亚马逊 CloudWatch 日志、亚马逊可观察性访问管理器、、亚马逊关系 Amazon Payment Cryptography数据库服务 (Amazon RDS)、 CloudWatch Amazon Rekognition、亚马逊简单存储服务 (Amazon S3) 的额外权限 Service S3S、Amazon Scheduler 和 Amazon VPC Lattice。 EventBridge Amazon Systems Manager |
2024 年 11 月 7 日 |
|
AWSConfigServiceRolePolicy – 添加 "app-integrations:GetApplication", "app-integrations:ListApplications", "app-integrations:ListTagsForResource", "appconfig:GetExtension", "appconfig:ListExtensions", "cloudtrail:GetInsightSelectors", "connect:DescribeQueue", "connect:DescribeRoutingProfile", "connect:DescribeSecurityProfile", "connect:ListQueueQuickConnects", "connect:ListQueues", "connect:ListRoutingProfileQueues", "connect:ListRoutingProfiles", "connect:ListSecurityProfileApplications", "connect:ListSecurityProfilePermissions", "connect:ListSecurityProfiles", "datazone:GetDomain", "datazone:ListDomains", "devops-guru:ListNotificationChannels", "glue:GetRegistry", "glue:ListRegistries", "identitystore:DescribeGroup", "identitystore:DescribeGroupMembership" "identitystore:ListGroupMemberships", "identitystore:ListGroups", "iot:DescribeThingGroup", "iot:DescribeThingType", "iot:ListThingGroups", "iot:ListThingTypes", "iotfleetwise:GetDecoderManifest", "iotfleetwise:GetFleet", "iotfleetwise:GetModelManifest", "iotfleetwise:GetSignalCatalog", "iotfleetwise:GetVehicle", "iotfleetwise:ListDecoderManifestNetworkInterfaces", "iotfleetwise:ListDecoderManifests", "iotfleetwise:ListDecoderManifestSignals", "iotfleetwise:ListFleets", "iotfleetwise:ListModelManifestNodes", "iotfleetwise:ListModelManifests", "iotfleetwise:ListSignalCatalogNodes", "iotfleetwise:ListSignalCatalogs", "iotfleetwise:ListTagsForResource", "iotfleetwise:ListVehicles", "iotwireless:GetDestination", "iotwireless:GetDeviceProfile", "iotwireless:GetWirelessGateway", "iotwireless:ListDestinations", "iotwireless:ListDeviceProfiles", "iotwireless:ListWirelessGateways", "ivschat:GetLoggingConfiguration", "ivschat:GetRoom" "ivschat:ListLoggingConfigurations", "ivschat:ListRooms", "ivschat:ListTagsForResource", "logs:GetLogAnomalyDetector", "logs:ListLogAnomalyDetectors", "oam:GetSink" "oam:GetSinkPolicy", "oam:ListSinks", "payment-cryptography:GetAlias", "payment-cryptography:GetKey", "payment-cryptography:ListAliases", "payment-cryptography:ListKeys", "payment-cryptography:ListTagsForResource", "rds:DescribeDBProxyTargetGroups", "rds:DescribeDBProxyTargets", "rekognition:DescribeProjects", "s3:GetStorageLensGroup", "s3:ListStorageLensGroups", "s3:ListTagsForResource", "scheduler:GetScheduleGroup", "scheduler:ListScheduleGroups", "scheduler:ListTagsForResource", "ssm:GetServiceSetting", "vpc-lattice:GetAccessLogSubscription", "vpc-lattice:GetService", "vpc-lattice:GetServiceNetwork", "vpc-lattice:GetTargetGroup", "vpc-lattice:ListAccessLogSubscriptions", "vpc-lattice:ListServiceNetworks", "vpc-lattice:ListServices", "vpc-lattice:ListTagsForResource", "vpc-lattice:ListTargetGroups", and "vpc-lattice:ListTargets" |
该政策现在支持、、Amazon Connect Amazon AppConfig Amazon CloudTrail、Amazon、Amazon DevOps Guru DataZone、、Identity Store Amazon Glue、、、、 Amazon IoT Amazon IoT FleetWise Amazon IoT Wireless、亚马逊互动视频服务 (Amazon IVS)、亚马逊 CloudWatch 日志、亚马逊可观察性访问管理器、、亚马逊关系 Amazon Payment Cryptography数据库服务 (Amazon RDS)、 CloudWatch Amazon Rekognition、亚马逊简单存储服务 (Amazon S3) 的额外权限 Service S3S、Amazon Scheduler 和 Amazon VPC Lattice。 EventBridge Amazon Systems Manager |
2024 年 11 月 7 日 |
|
AWS_ConfigRole – 添加 "aoss:BatchGetCollection," "aoss:BatchGetLifecyclePolicy," "aoss:BatchGetVpcEndpoint," "aoss:GetAccessPolicy," "aoss:GetSecurityConfig," "aoss:GetSecurityPolicy," "aoss:ListAccessPolicies," "aoss:ListCollections," "aoss:ListLifecyclePolicies," "aoss:ListSecurityConfigs," "aoss:ListSecurityPolicies," "aoss:ListVpcEndpoints," "appstream:DescribeAppBlockBuilders," "backup:GetRestoreTestingPlan," "backup:GetRestoreTestingSelection", "backup:ListRestoreTestingPlans," "backup:ListRestoreTestingSelections," "cloudTrail:GetChannel, "cloudTrail:ListChannels," "glue:GetTrigger," "glue:ListTriggers, "imagebuilder:GetLifecyclePolicy," "imagebuilder:ListLifecyclePolicies," "iot:DescribeBillingGroup," "iot:ListBillingGroups," "ivs:GetEncoderConfiguration," "ivs:GetPlaybackRestrictionPolicy," "ivs:GetStage," "ivs:GetStorageConfiguration," "ivs:ListEncoderConfigurations," "ivs:ListPlaybackRestrictionPolicies," "ivs:ListStages," "ivs:ListStorageConfigurations," "mediaconnect:DescribeBridge", "mediaconnect:DescribeGatewa," "mediaconnect:ListBridges," "mediaconnect:ListGateways", "mediatailor:DescribeChannel," "mediatailor:DescribeLiveSource," "mediatailor:DescribeSourceLocation," "mediatailor:DescribeVodSource", "mediatailor:ListChannels," "mediatailor:ListLiveSources", "mediatailor:ListSourceLocations," "mediatailor:ListVodSources," "omics:GetWorkflow," "omics:ListWorkflows," "scheduler:GetSchedule," and "scheduler:ListSchedules" |
该政策现在支持亚马逊 OpenSearch 服务 Severless、、、、、、Im EC2 age Builder AppStream、 Amazon Backup Amazon CloudTrail Amazon Glue、Amazon Interactive Video Service (Amazon IVS)、、、 AWS Elemental MediaConnect AWS Elemental MediaTailor、 Amazon HealthOmics和 Amazon Scheduler 的额外权限。 Amazon IoT EventBridge |
2024 年 9 月 16 日 |
|
AWSConfigServiceRolePolicy – 添加 "aoss:BatchGetCollection," "aoss:BatchGetLifecyclePolicy," "aoss:BatchGetVpcEndpoint," "aoss:GetAccessPolicy," "aoss:GetSecurityConfig," "aoss:GetSecurityPolicy," "aoss:ListAccessPolicies," "aoss:ListCollections," "aoss:ListLifecyclePolicies," "aoss:ListSecurityConfigs," "aoss:ListSecurityPolicies," "aoss:ListVpcEndpoints," "appstream:DescribeAppBlockBuilders," "backup:GetRestoreTestingPlan," "backup:GetRestoreTestingSelection", "backup:ListRestoreTestingPlans," "backup:ListRestoreTestingSelections," "cloudTrail:GetChannel, "cloudTrail:ListChannels," "glue:GetTrigger," "glue:ListTriggers, "imagebuilder:GetLifecyclePolicy," "imagebuilder:ListLifecyclePolicies," "iot:DescribeBillingGroup," "iot:ListBillingGroups," "ivs:GetEncoderConfiguration," "ivs:GetPlaybackRestrictionPolicy," "ivs:GetStage," "ivs:GetStorageConfiguration," "ivs:ListEncoderConfigurations," "ivs:ListPlaybackRestrictionPolicies," "ivs:ListStages," "ivs:ListStorageConfigurations," "mediaconnect:DescribeBridge", "mediaconnect:DescribeGatewa," "mediaconnect:ListBridges," "mediaconnect:ListGateways", "mediatailor:DescribeChannel," "mediatailor:DescribeLiveSource," "mediatailor:DescribeSourceLocation," "mediatailor:DescribeVodSource", "mediatailor:ListChannels," "mediatailor:ListLiveSources", "mediatailor:ListSourceLocations," "mediatailor:ListVodSources," "omics:GetWorkflow," "omics:ListWorkflows," "scheduler:GetSchedule," and "scheduler:ListSchedules" |
该政策现在支持亚马逊 OpenSearch 服务 Severless、、、、、、Im EC2 age Builder AppStream、 Amazon Backup Amazon CloudTrail Amazon Glue、Amazon Interactive Video Service (Amazon IVS)、、、 AWS Elemental MediaConnect AWS Elemental MediaTailor、 Amazon HealthOmics和 Amazon Scheduler 的额外权限。 Amazon IoT EventBridge |
2024 年 9 月 16 日 |
|
AWS_ConfigRole – 添加 "elasticfilesystem:DescribeTags," "redshift:DescribeTags," and "ssm-sap:ListTagsForResource" |
该政策现在支持亚马逊弹性文件系统(亚马逊 EFS)、亚马逊 Redshift 和。 适用于 SAP 的 Amazon Systems Manager |
2024 年 6 月 17 日 |
|
AWSConfigServiceRolePolicy – 添加 "elasticfilesystem:DescribeTags," "redshift:DescribeTags," and "ssm-sap:ListTagsForResource" |
该政策现在支持亚马逊弹性文件系统(亚马逊 EFS)、亚马逊 Redshift 和。 适用于 SAP 的 Amazon Systems Manager |
2024 年 6 月 17 日 |
| AWS_ConfigRole – 添加 "aps:DescribeAlertManagerDefinition," "cloudwatch:DescribeAlarmsForMetric," "cognito-identity:DescribeIdentityPool, "cognito-identity:GetPrincipalTagAttributeMap," "elasticache:DescribeCacheSecurityGroups," "elasticache:DescribeUserGroups," "elasticache:DescribeUsers," "elasticache:DescribeGlobalReplicationGroups," "fsx:DescribeDataRepositoryAssociations," "glue:GetDatabase," "glue:GetDatabases," "iam:ListUsers," "lambda:GetLayerVersion," "lambda:ListLayers," "lambda:ListLayerVersions," "ram:GetPermission," "ram:ListPermissionAssociations," "ram:ListPermissions," "ram:ListPermissionVersions," "redshift-serverless:GetNamespace," "redshift-serverless:GetWorkgroup," "redshift-serverless:ListNamespaces," "redshift-serverless:ListTagsForResource," "redshift-serverless:ListWorkgroups," "sagemaker:DescribeInferenceExperiment," "sagemaker:ListInferenceExperiments," and "sns:GetSMSSandboxAccountStatus" |
该政策现在支持亚马逊托管服务 Prometheus、亚马逊、亚马逊 Cognito、亚马逊、亚马逊、(IAM) CloudWatch、、、、Amazon Redshift Serverless、Amazon AI 和 ElastiCache亚马逊简单通知服务 ( FSxAmaz Amazon Glue on Amazon Identity and Access Management SNS) Simple Notificati Amazon RAM on Serverless Amazon Lambda、Amazon AI 和亚马逊简单通知服务 ( SageMaker Amazon SNS) 的额外权限。 |
2024 年 2 月 22 日 |
| AWSConfigServiceRolePolicy – 添加 "aps:DescribeAlertManagerDefinition," "cloudwatch:DescribeAlarmsForMetric," "cognito-identity:DescribeIdentityPool, "cognito-identity:GetPrincipalTagAttributeMap," "elasticache:DescribeCacheSecurityGroups," "elasticache:DescribeUserGroups," "elasticache:DescribeUsers," "elasticache:DescribeGlobalReplicationGroups," "fsx:DescribeDataRepositoryAssociations," "glue:GetDatabase," "glue:GetDatabases," "iam:ListUsers," "lambda:GetLayerVersion," "lambda:ListLayers," "lambda:ListLayerVersions," "ram:GetPermission," "ram:ListPermissionAssociations," "ram:ListPermissions," "ram:ListPermissionVersions," "redshift-serverless:GetNamespace," "redshift-serverless:GetWorkgroup," "redshift-serverless:ListNamespaces," "redshift-serverless:ListTagsForResource," "redshift-serverless:ListWorkgroups," "sagemaker:DescribeInferenceExperiment," "sagemaker:ListInferenceExperiments," and "sns:GetSMSSandboxAccountStatus" |
该政策现在支持亚马逊托管服务 Prometheus、亚马逊、亚马逊 Cognito、亚马逊、亚马逊、(IAM) CloudWatch、、、、Amazon Redshift Serverless、Amazon AI 和 ElastiCache亚马逊简单通知服务 ( FSxAmaz Amazon Glue on Amazon Identity and Access Management SNS) Simple Notificati Amazon RAM on Serverless Amazon Lambda、Amazon AI 和亚马逊简单通知服务 ( SageMaker Amazon SNS) 的额外权限。 |
2024 年 2 月 22 日 |
|
AWSConfigUserAccess— Amazon Config 开始跟踪此 Amazon 托管策略的更改 |
此政策提供使用权限 Amazon Config,包括按资源标签搜索和读取所有标签。这不提供配置权限 Amazon Config,而配置权限需要管理权限。 |
2024 年 2 月 22 日 |
| AWS_ConfigRole – 添加 "appconfig:GetExtensionAssociation," "appconfig:ListExtensionAssociations," "aps:DescribeLoggingConfiguration," "dms:DescribeReplicationTaskAssessmentRuns," "iam:GetOpenIDConnectProvider," "iam:ListOpenIDConnectProviders," "kafka:DescribeVpcConnection," "kafka:GetClusterPolicy," "kafka:ListVpcConnections," "logs:DescribeMetricFilters," "organizations:ListDelegatedAdministrators," "s3:GetBucketPolicyStatus," "s3express:GetBucketPolicy," and "s3express:ListAllMyDirectoryBuckets" |
该政策现在支持适用于 Prometheus 的亚马逊托管服务 Amazon AppConfig、Amazon DMS()、() IAM Amazon Database Migration Service 、适用于 Apache Kafka 的亚马逊托管流媒体(亚马逊 MSK Amazon Identity and Access Management)、亚马逊 Amazon Organizations日志和亚马逊简单存储服务 (Amazon S3) Simple Storage Service 的额外权限。 CloudWatch |
2023 年 12 月 5 日 |
| AWSConfigServiceRolePolicy – 添加 "appconfig:GetExtensionAssociation," "appconfig:ListExtensionAssociations," "aps:DescribeLoggingConfiguration," "dms:DescribeReplicationTaskAssessmentRuns," "iam:GetOpenIDConnectProvider," "iam:ListOpenIDConnectProviders," "kafka:DescribeVpcConnection," "kafka:GetClusterPolicy," "kafka:ListVpcConnections," "logs:DescribeMetricFilters," "organizations:ListDelegatedAdministrators," "s3:GetBucketPolicyStatus," "s3express:GetBucketPolicy," and "s3express:ListAllMyDirectoryBuckets" |
该政策现在支持适用于 Prometheus 的亚马逊托管服务 Amazon AppConfig、Amazon DMS()、() IAM Amazon Database Migration Service 、适用于 Apache Kafka 的亚马逊托管流媒体(亚马逊 MSK Amazon Identity and Access Management)、亚马逊 Amazon Organizations日志和亚马逊简单存储服务 (Amazon S3) Simple Storage Service 的额外权限。 CloudWatch |
2023 年 12 月 5 日 |
| AWS_ConfigRole – 添加 "backup:DescribeProtectedResource," "cognito-identity:GetIdentityPoolRoles," "cognito-identity:ListIdentityPools," "cognito-identity:ListTagsForResource," "cognito-idp:DescribeIdentityProvider," "cognito-idp:DescribeResourceServer," "cognito-idp:DescribeUserPool," "cognito-idp:DescribeUserPoolClient," "cognito-idp:DescribeUserPoolDomain," "cognito-idp:GetGroup," "cognito-idp:GetUserPoolMfaConfig," "cognito-idp:ListGroups," "cognito-idp:ListIdentityProviders," "cognito-idp:ListResourceServers," "cognito-idp:ListUserPoolClients," "cognito-idp:ListUserPools," "cognito-idp:ListTagsForResource," "connect:DescribeEvaluationForm," "connect:DescribeInstanceStorageConfig," "connect:DescribePrompt," "connect:DescribeRule," "connect:DescribeUser," "connect:GetTaskTemplate," "connect:ListApprovedOrigins," "connect:ListEvaluationForms," "connect:ListInstanceStorageConfigs," "connect:ListIntegrationAssociations," "connect:ListPrompts," "connect:ListRules," "connect:ListSecurityKeys," "connect:ListTagsForResource," "connect:ListTaskTemplates," "connect:ListUsers," "emr-containers:DescribeVirtualCluster," "emr-containers:ListVirtualClusters," "emr-serverless:GetApplication," "emr-serverless:ListApplications," "groundstation:GetDataflowEndpointGroup," "groundstation:ListDataflowEndpointGroups," "m2:GetEnvironment," "m2:ListEnvironments," "m2:ListTagsForResource," "memorydb:DescribeAcls," "memorydb:DescribeClusters," "memorydb:DescribeParameterGroups," "memorydb:DescribeParameters," "memorydb:DescribeSubnetGroups," "organizations:ListRoots," "quicksight:DescribeAccountSubscription," "quicksight:DescribeDataSetRefreshProperties," "rds:DescribeEngineDefaultClusterParameters," "redshift:DescribeEndpointAccess," "redshift:DescribeEndpointAuthorization," "route53:GetChange," "route53:ListCidrBlocks," "route53:ListCidrLocations," "serviceCatalog:DescribePortfolioShares," "transfer:DescribeProfile," and "transfer:ListProfiles" |
该政策现在支持亚马逊 Cognito、Amazon Connect、亚马逊 EMR、、、Amazon MemoryDB、 Amazon Ground Station、 Amazon Mainframe Modernization Amazon Quick Suite Amazon Organizations、亚马逊关系数据库服务(亚马逊 RDS)、亚马逊 Redshift、亚马逊 Rodshift、Amazon Route 53 和。 Amazon Service Catalog Amazon Transfer Family |
2023 年 11 月 17 日 |
| AWS_ConfigRole – 添加 "Sid": "AWSConfigServiceRolePolicyStatementID," "Sid": "AWSConfigSLRLogStatementID," "Sid": "AWSConfigSLRLogEventStatementID," and "Sid": "AWSConfigSLRApiGatewayStatementID" |
此策略现在为 |
2023 年 11 月 17 日 |
| AWSConfigServiceRolePolicy – 添加 "backup:DescribeProtectedResource," "cognito-identity:GetIdentityPoolRoles," "cognito-identity:ListIdentityPools," "cognito-identity:ListTagsForResource," "cognito-idp:DescribeIdentityProvider," "cognito-idp:DescribeResourceServer," "cognito-idp:DescribeUserPool," "cognito-idp:DescribeUserPoolClient," "cognito-idp:DescribeUserPoolDomain," "cognito-idp:GetGroup," "cognito-idp:GetUserPoolMfaConfig," "cognito-idp:ListGroups," "cognito-idp:ListIdentityProviders," "cognito-idp:ListResourceServers," "cognito-idp:ListUserPoolClients," "cognito-idp:ListUserPools," "cognito-idp:ListTagsForResource," "connect:DescribeEvaluationForm," "connect:DescribeInstanceStorageConfig," "connect:DescribePrompt," "connect:DescribeRule," "connect:DescribeUser," "connect:GetTaskTemplate," "connect:ListApprovedOrigins," "connect:ListEvaluationForms," "connect:ListInstanceStorageConfigs," "connect:ListIntegrationAssociations," "connect:ListPrompts," "connect:ListRules," "connect:ListSecurityKeys," "connect:ListTagsForResource," "connect:ListTaskTemplates," "connect:ListUsers," "emr-containers:DescribeVirtualCluster," "emr-containers:ListVirtualClusters," "emr-serverless:GetApplication," "emr-serverless:ListApplications," "groundstation:GetDataflowEndpointGroup," "groundstation:ListDataflowEndpointGroups," "m2:GetEnvironment," "m2:ListEnvironments," "m2:ListTagsForResource," "memorydb:DescribeAcls," "memorydb:DescribeClusters," "memorydb:DescribeParameterGroups," "memorydb:DescribeParameters," "memorydb:DescribeSubnetGroups," "organizations:ListRoots," "quicksight:DescribeAccountSubscription," "quicksight:DescribeDataSetRefreshProperties," "rds:DescribeEngineDefaultClusterParameters," "redshift:DescribeEndpointAccess," "redshift:DescribeEndpointAuthorization," "route53:GetChange," "route53:ListCidrBlocks," "route53:ListCidrLocations," "serviceCatalog:DescribePortfolioShares," "transfer:DescribeProfile," and "transfer:ListProfiles" |
该政策现在支持亚马逊 Cognito、Amazon Connect、亚马逊 EMR、、、Amazon MemoryDB、 Amazon Ground Station、 Amazon Mainframe Modernization Amazon Quick Suite Amazon Organizations、亚马逊关系数据库服务(亚马逊 RDS)、亚马逊 Redshift、亚马逊 Rodshift、Amazon Route 53 和。 Amazon Service Catalog Amazon Transfer Family |
2023 年 11 月 17 日 |
| AWSConfigServiceRolePolicy – 添加 "Sid": "AWSConfigServiceRolePolicyStatementID," "Sid": "AWSConfigSLRLogStatementID," "Sid": "AWSConfigSLRLogEventStatementID," and "Sid": "AWSConfigSLRApiGatewayStatementID" |
此策略现在为 |
2023 年 11 月 17 日 |
| AWS_ConfigRole – 添加 "acm-pca:GetCertificateAuthorityCertificate," "appmesh:DescribeMesh," "appmesh:ListGatewayRoutes," "connect:DescribeInstance," "connect:DescribeQuickConnect," "connect:ListQuickConnects," "ecs:DescribeCapacityProviders," "evidently:GetSegment," "evidently:ListSegments," "grafana:DescribeWorkspace," "grafana:DescribeWorkspaceAuthentication," "grafana:DescribeWorkspaceConfiguration," "grafana:DescribeWorkspaceConfiguration," "guardduty:GetMemberDetectors," "inspector2:BatchGetAccountStatus," "inspector2:GetDelegatedAdminAccount," "inspector2:ListMembers," "iot:DescribeCACertificate," "iot:ListCACertificates," "iot:ListTagsForResource," "iottwinmaker:GetSyncJob," "iottwinmaker:ListSyncJobs," "kafka:ListTagsForResource," "kafkaconnect:DescribeConnector," "kafkaconnect:ListConnectors," "lambda:GetCodeSigningConfig," "lambda:ListCodeSigningConfigs," "lambda:ListTags," "networkmanager:GetConnectPeer," "organizations:DescribeOrganization," "organizations:ListTargetsForPolicy," "sagemaker:DescribeDataQualityJob," "sagemaker:DescribeModelExplainabilityJob," "sagemaker:ListDataQualityJob," and "sagemaker:ExplainabilityJob" |
该政策现在支持、、Amazon Connect Amazon 私有 CA Amazon App Mesh、亚马逊弹性容器服务 (Amazon ECS)、Amazon Evicently、Ama CloudWatch zon Managed Grafana、亚马逊、Amazon Insp Amazon IoT TwinMaker ector、 GuardDuty、、、Amazon Kafka Managed Streaming( Amazon IoT亚马逊 MSK)、、、和亚马逊人工智能的额外权限。 Amazon Lambda Amazon Network Manager Amazon Organizations SageMaker |
2023 年 10 月 4 日 |
| AWSConfigServiceRolePolicy – 添加 "acm-pca:GetCertificateAuthorityCertificate," "appmesh:DescribeMesh," "appmesh:ListGatewayRoutes," "connect:DescribeInstance," "connect:DescribeQuickConnect," "connect:ListQuickConnects," "ecs:DescribeCapacityProviders," "evidently:GetSegment," "evidently:ListSegments," "grafana:DescribeWorkspace," "grafana:DescribeWorkspaceAuthentication," "grafana:DescribeWorkspaceConfiguration," "grafana:DescribeWorkspaceConfiguration," "guardduty:GetMemberDetectors," "inspector2:BatchGetAccountStatus," "inspector2:GetDelegatedAdminAccount," "inspector2:ListMembers," "iot:DescribeCACertificate," "iot:ListCACertificates," "iot:ListTagsForResource," "iottwinmaker:GetSyncJob," "iottwinmaker:ListSyncJobs," "kafka:ListTagsForResource," "kafkaconnect:DescribeConnector," "kafkaconnect:ListConnectors," "lambda:GetCodeSigningConfig," "lambda:ListCodeSigningConfigs," "lambda:ListTags," "networkmanager:GetConnectPeer," "organizations:DescribeOrganization," "organizations:ListTargetsForPolicy," "sagemaker:DescribeDataQualityJob," "sagemaker:DescribeModelExplainabilityJob," "sagemaker:ListDataQualityJob," and "sagemaker:ExplainabilityJob" |
该政策现在支持、、Amazon Connect Amazon 私有 CA Amazon App Mesh、亚马逊弹性容器服务 (Amazon ECS)、Amazon Evicently、Ama CloudWatch zon Managed Grafana、亚马逊、Amazon Insp Amazon IoT TwinMaker ector、 GuardDuty、、、Amazon Kafka Managed Streaming( Amazon IoT亚马逊 MSK)、、、和亚马逊人工智能的额外权限。 Amazon Lambda Amazon Network Manager Amazon Organizations SageMaker |
2023 年 10 月 4 日 |
| AWSConfigServiceRolePolicy – 移除 "ssm:GetParameter" |
此策略现在会移除 Amazon Systems Manager (Systems Manager)的权限。 |
2023 年 9 月 6 日 |
| AWS_ConfigRole – 添加 "appmesh:DescribeGatewayRoute","appstream:DescribeStacks", "aps:ListTagsForResource", "cloudfront:GetFunction", "cloudfront:GetOriginAccessControl", "cloudfront:ListFunctions", "cloudfront:ListOriginAccessControls", "codeartifact:ListPackages", "codeartifact:ListPackageVersions", "codebuild:BatchGetReportGroups", "codebuild:ListReportGroups", "connect:ListInstanceAttributes", "connect:ListInstances", "glue:GetPartition", "glue:GetPartitions", "guardduty:GetAdministratorAccount", "iam:ListInstanceProfileTags", "inspector2:ListFilters", "iot:DescribeJobTemplate", "iot:DescribeProvisioningTemplate", "iot:ListJobTemplates", "iot:ListProvisioningTemplates", "iottwinmaker:GetComponentType", "iottwinmaker:ListComponentTypes", "iotwireless:GetFuotaTask", "iotwireless:GetMulticastGroup", "iotwireless:ListFuotaTasks", "iotwireless:ListMulticastGroups", "kafka:ListScramSecrets", "macie2:ListTagsForResource", "mediaconnect:ListTagsForResource", "networkmanager:GetConnectPeer", "networkmanager:ListConnectPeers", "organizations:DescribeEffectivePolicy", "organizations:DescribeResourcePolicy", "resource-explorer-2:GetIndex", "resource-explorer-2:ListIndexes", "resource-explorer-2:ListTagsForResource", "route53:ListCidrCollections", "s3:GetMultiRegionAccessPointPolicy", "s3:GetMultiRegionAccessPointPolicyStatus", and "sns:GetDataProtectionPolicy" |
该政策现在支持、、亚马逊、、、Amazon Connect Amazon App Mesh Amazon CloudFormation、、亚马逊 CloudFront Amazon CodeArtifact Amazon CodeBuild、 Amazon Identity and Access Management (IAM) Amazon Glue、Amazon Inspector GuardDuty、、、、Amazon Inspector Amazon IoT、 Amazon IoT TwinMaker、、 Amazon IoT Wireless、、Amazon Macie、、、、、Amazon Route 53、亚马逊简单存储服务 (Amazon S3) AWS Elemental MediaConnect Amazon Network Manager Amazon Organizations Amazon 资源探索器、亚马逊简单存储服务 (Amazon S3) 和亚马逊简单通知服务 (Amazon SNS) 的额外权限) Simple Service Amazon。 |
2023 年 7 月 28 日 |
| AWSConfigServiceRolePolicy – 添加 "appmesh:DescribeGatewayRoute", "appstream:DescribeStacks", "aps:ListTagsForResource", "cloudfront:GetFunction", "cloudfront:GetOriginAccessControl", "cloudfront:ListFunctions", "cloudfront:ListOriginAccessControls", "codeartifact:ListPackages", "codeartifact:ListPackageVersions", "codebuild:BatchGetReportGroups", "codebuild:ListReportGroups", "connect:ListInstanceAttributes", "connect:ListInstances", "glue:GetPartition", "glue:GetPartitions", "guardduty:GetAdministratorAccount", "iam:ListInstanceProfileTags", "inspector2:ListFilters", "iot:DescribeJobTemplate", "iot:DescribeProvisioningTemplate", "iot:ListJobTemplates", "iot:ListProvisioningTemplates", "iottwinmaker:GetComponentType", "iottwinmaker:ListComponentTypes", "iotwireless:GetFuotaTask", "iotwireless:GetMulticastGroup", "iotwireless:ListFuotaTasks", "iotwireless:ListMulticastGroups", "kafka:ListScramSecrets", "macie2:ListTagsForResource", "mediaconnect:ListTagsForResource", "networkmanager:GetConnectPeer", "networkmanager:ListConnectPeers", "organizations:DescribeEffectivePolicy", "organizations:DescribeResourcePolicy", "resource-explorer-2:GetIndex", "resource-explorer-2:ListIndexes", "resource-explorer-2:ListTagsForResource", "route53:ListCidrCollections", "s3:GetMultiRegionAccessPointPolicy", "s3:GetMultiRegionAccessPointPolicyStatus", "sns:GetDataProtectionPolicy", "ssm:DescribeParameters", "ssm:GetParameter", and "ssm:ListTagsForResource" |
该政策现在支持亚马逊 WorkSpaces 应用程序 Amazon App Mesh、、亚马逊、、、、、Amazon Connect CloudFront Amazon CodeArtifact、 Amazon CodeBuild、亚马逊、 Amazon Glue Amazon Identity and Access Management (IAM) GuardDuty、Amazon Inspector、、 Amazon IoT、 Amazon IoT TwinMaker、 Amazon IoT Wireless、Amazon Macie、、、、、、Amazon Route 53 AWS Elemental MediaConnect Amazon Network Manager Amazon Organizations、 Amazon 资源探索器亚马逊简单存储服务 (Amazon S3)、亚马逊简单通知服务的额外权限(亚马逊 SNS)Service 和亚马逊 Systems Manager (SSM)。 Amazon CloudFormation EC2 |
2023 年 7 月 28 日 |
| AWS_ConfigRole – 添加 "amplify:GetBranch", "amplify:ListBranches", "app-integrations:GetEventIntegration", "app-integrations:ListEventIntegrationAssociations", "app-integrations:ListEventIntegrations", "appmesh:DescribeRoute", "appmesh:ListRoutes", "aps:ListRuleGroupsNamespaces", "athena:GetPreparedStatement", "athena:ListPreparedStatements", "batch:DescribeSchedulingPolicies", "batch:ListSchedulingPolicies", "cloudformation:ListTypes", "cloudtrail:ListTrails", "codeartifact:ListDomains", "codeguru-profiler:DescribeProfilingGroup", "codeguru-profiler:GetNotificationConfiguration", "codeguru-profiler:GetPolicy", "codeguru-profiler:ListProfilingGroups", "ds:DescribeDomainControllers", “dynamodb:DescribeTableReplicaAutoScaling" "dynamodb:DescribeTimeToLive", "ec2:DescribeTrafficMirrorFilters", "evidently:GetLaunch", "evidently:ListLaunches", "forecast:DescribeDatasetGroup", "forecast:ListDatasetGroups", "greengrass:DescribeComponent", "greengrass:GetComponent", "greengrass:ListComponents", "greengrass:ListComponentVersions", "groundstation:GetMissionProfile", "groundstation:ListMissionProfiles", "iam:ListGroups", "iam:ListRoles", "kafka:DescribeConfiguration", "kafka:DescribeConfigurationRevision", "kafka:ListConfigurations", "lightsail:GetRelationalDatabases" "logs:ListTagsLogGroup", "mediaconnect:DescribeFlow", "mediaconnect:ListFlows", "mediatailor:GetPlaybackConfiguration", "mediatailor:ListPlaybackConfigurations", "mobiletargeting:GetApplicationSettings", "mobiletargeting:GetEmailTemplate", "mobiletargeting:GetEventStream", "mobiletargeting:ListTemplates", "networkmanager:GetCustomerGatewayAssociations", "networkmanager:GetLinkAssociations", "organizations:DescribeAccount", "organizations:DescribeOrganizationalUnit", "organizations:ListAccounts", "organizations:ListAccountsForParent", "organizations:ListOrganizationalUnitsForParent", "organizations:ListTagsForResource", "personalize:DescribeDataset", "personalize:DescribeDatasetGroup", "personalize:DescribeSchema", "personalize:DescribeSolution", "personalize:ListDatasetGroups", "personalize:ListDatasetImportJobs", "personalize:ListDatasets", "personalize:ListSchemas", "personalize:ListSolutions", "personalize:ListTagsForResource", "quicksight:ListTemplates", "refactor-spaces:GetEnvironment", "refactor-spaces:GetService", "refactor-spaces:ListApplications", "refactor-spaces:ListEnvironments", "refactor-spaces:ListServices", "s3:GetAccessPointPolicyStatusForObjectLambda", "sagemaker:DescribeDeviceFleet", "sagemaker:DescribeFeatureGroup", "sagemaker:ListDeviceFleets", "sagemaker:ListFeatureGroups", "sagemaker:ListModels", and "transfer:ListTagsForResource" |
该政策现在支持 Amazon Connect Amazon Amplify、、Prometheus 的亚马逊托管服务 Amazon App Mesh、亚马逊 Athena、、、、、、、、、亚马逊、、、亚马逊 DynamoDB Amazon CloudFormation、亚马逊弹性计算云(亚马逊 CodeGuru) Amazon CloudTrail Amazon CodeArtifact、 Amazon Batch Amazon Evicently、Amazon Forecast、、( Amazon Identity and Access Management IAM) CloudWatch 、A EC2 mazon M Amazon IoT Greengrass anaged Streaming 的额外权限 Kafka( Amazon Ground Station亚马逊 MSK)、亚马逊 Lightsail、Amazon Logs、、、Amazon Pinpoint、亚马逊虚拟私有云( Amazon Directory Service Amazon Organizations CloudWatch AWS Elemental MediaConnect AWS Elemental MediaTailor亚马逊 VPC)、Amazon Personalize、Amazon Quick Suite Amazon Migration Hub Refactor Spaces、亚马逊简单存储服务 (Amazon S3)、Amazon AI、A SageMaker mazon AI 等。 Amazon Transfer Family |
2023 年 6 月 13 日 |
| AWSConfigServiceRolePolicy – 添加 "amplify:GetBranch", "amplify:ListBranches", "app-integrations:GetEventIntegration", "app-integrations:ListEventIntegrationAssociations", "app-integrations:ListEventIntegrations", "appmesh:DescribeRoute", "appmesh:ListRoutes", "aps:ListRuleGroupsNamespaces", "athena:GetPreparedStatement", "athena:ListPreparedStatements", "batch:DescribeSchedulingPolicies", "batch:ListSchedulingPolicies", "cloudformation:ListTypes", "cloudtrail:ListTrails", "codeartifact:ListDomains", "codeguru-profiler:DescribeProfilingGroup", "codeguru-profiler:GetNotificationConfiguration", "codeguru-profiler:GetPolicy", "codeguru-profiler:ListProfilingGroups", "ds:DescribeDomainControllers", "dynamodb:DescribeTableReplicaAutoScaling", "dynamodb:DescribeTimeToLive", "ec2:DescribeTrafficMirrorFilters", "evidently:GetLaunch", "evidently:ListLaunches", "forecast:DescribeDatasetGroup", "forecast:ListDatasetGroups", "greengrass:DescribeComponent", "greengrass:GetComponent", "greengrass:ListComponents", "greengrass:ListComponentVersions", "groundstation:GetMissionProfile", "groundstation:ListMissionProfiles", "iam:ListGroups", "iam:ListRoles", "kafka:DescribeConfiguration", "kafka:DescribeConfigurationRevision", "kafka:ListConfigurations", "lightsail:GetRelationalDatabases", "logs:ListTagsLogGroup", "mediaconnect:DescribeFlow", "mediaconnect:ListFlows", "mediatailor:GetPlaybackConfiguration", "mediatailor:ListPlaybackConfigurations", "mobiletargeting:GetApplicationSettings", "mobiletargeting:GetEmailTemplate", "mobiletargeting:GetEventStream", "mobiletargeting:ListTemplates", "networkmanager:GetCustomerGatewayAssociations", "networkmanager:GetLinkAssociations", "organizations:DescribeAccount", "organizations:DescribeOrganizationalUnit", "organizations:ListAccounts", "organizations:ListAccountsForParent", "organizations:ListOrganizationalUnitsForParent", "organizations:ListTagsForResource", "personalize:DescribeDataset", "personalize:DescribeDatasetGroup", "personalize:DescribeSchema", "personalize:DescribeSolution", "personalize:ListDatasetGroups", "personalize:ListDatasetImportJobs", "personalize:ListDatasets", "personalize:ListSchemas", "personalize:ListSolutions", "personalize:ListTagsForResource", "quicksight:ListTemplates", "refactor-spaces:GetEnvironment", "refactor-spaces:GetService", "refactor-spaces:ListApplications", "refactor-spaces:ListEnvironments", "refactor-spaces:ListServices", "s3:GetAccessPointPolicyStatusForObjectLambda", "sagemaker:DescribeDeviceFleet", "sagemaker:DescribeFeatureGroup", "sagemaker:ListDeviceFleets", "sagemaker:ListFeatureGroups", "sagemaker:ListModels", and "transfer:ListTagsForResource" |
该政策现在支持 Amazon Connect Amazon Amplify、、Prometheus 的亚马逊托管服务 Amazon App Mesh、亚马逊 Athena、、、、、、、、、亚马逊、、、亚马逊 DynamoDB Amazon CloudFormation、亚马逊弹性计算云(亚马逊 CodeGuru) Amazon CloudTrail Amazon CodeArtifact、 Amazon Batch Amazon Evicently、Amazon Forecast、、( Amazon Identity and Access Management IAM) CloudWatch 、A EC2 mazon M Amazon IoT Greengrass anaged Streaming 的额外权限 Kafka( Amazon Ground Station亚马逊 MSK)、亚马逊 Lightsail、Amazon Logs、、、Amazon Pinpoint、亚马逊虚拟私有云( Amazon Directory Service Amazon Organizations CloudWatch AWS Elemental MediaConnect AWS Elemental MediaTailor亚马逊 VPC)、Amazon Personalize、Amazon Quick Suite Amazon Migration Hub Refactor Spaces、亚马逊简单存储服务 (Amazon S3)、Amazon AI、A SageMaker mazon AI 等。 Amazon Transfer Family |
2023 年 6 月 13 日 |
| AWSConfigServiceRolePolicy – 添加 amplify:GetApp, amplify:ListApps, appmesh:DescribeVirtualGateway, appmesh:DescribeVirtualNode, appmesh:DescribeVirtualRouter, appmesh:DescribeVirtualService, appmesh:ListMeshes, appmesh:ListTagsForResource, appmesh:ListVirtualGateways, appmesh:ListVirtualNodes, appmesh:ListVirtualRouters, appmesh:ListVirtualServices, apprunner:DescribeVpcConnector, apprunner:ListVpcConnectors, cloudformation:ListTypes, cloudfront:ListResponseHeadersPolicies, codeartifact:ListRepositories, ds:DescribeEventTopics, ds:ListLogSubscriptions, GetInstanceTypesFromInstanceRequirement ec2:GetManagedPrefixListEntries, kendra:DescribeIndex, kendra:ListIndices, kendra:ListTagsForResource, logs:DescribeDestinations, logs:GetDataProtectionPolicy, macie2:DescribeOrganizationConfiguration, macie2:GetAutomatedDiscoveryConfiguration, macie2:GetClassificationExportConfiguration, macie2:GetCustomDataIdentifier, macie2:GetFindingsPublicationConfiguration, macie2:ListCustomDataIdentifiers, mobiletargeting:GetEmailChannel, refactor-spaces:GetEnvironment, refactor-spaces:ListEnvironments, resiliencehub:ListTagsForResource, route53:GetDNSSEC, sagemaker:DescribeDomain, sagemaker:DescribeModelBiasJobDefinition, sagemaker:DescribeModelQualityJobDefinition, sagemaker:DescribePipeline, sagemaker:DescribeProject, sagemaker:ListDomains, sagemaker:ListModelBiasJobDefinitions, sagemaker:ListModelQualityJobDefinitions, sagemaker:ListPipelines, sagemaker:ListProjects, transfer:DescribeAgreement, transfer:DescribeCertificate, transfer:ListAgreements, transfer:ListCertificates, and waf-regional:ListLoggingConfigurations |
该政策现在支持亚马逊托管工作流程的额外权限,包括、、、亚马逊 Amazon Amplify、、亚马逊弹性计算云 Amazon App Mesh Amazon App Runner CloudFront、亚马逊 Kendra Amazon CodeArtifact、亚马逊 Macie、亚马逊 Route 53、亚马逊 A Amazon Transfer Family I、Amazon Pinpoint、、 SageMaker Resilience Hub、亚马逊 Amazon Migration Hub Amazon 、Di Amazon rectory Service 和。 CloudWatch Amazon WAF |
2023 年 4 月 13 日 |
| AWS_ConfigRole – 添加 amplify:GetApp, amplify:ListApps, appmesh:DescribeVirtualGateway, appmesh:DescribeVirtualNode, appmesh:DescribeVirtualRouter, appmesh:DescribeVirtualService, appmesh:ListMeshes, appmesh:ListTagsForResource, appmesh:ListVirtualGateways, appmesh:ListVirtualNodes, appmesh:ListVirtualRouters, appmesh:ListVirtualServices, apprunner:DescribeVpcConnector, apprunner:ListVpcConnectors, cloudformation:ListTypes, cloudfront:ListResponseHeadersPolicies, codeartifact:ListRepositories, ds:DescribeEventTopics, ds:ListLogSubscriptions, ec2:GetInstanceTypesFromInstanceRequirement, ec2:GetManagedPrefixListEntries, kendra:DescribeIndex, kendra:ListIndices, kendra:ListTagsForResource, logs:DescribeDestinations, logs:GetDataProtectionPolicy, macie2:DescribeOrganizationConfiguration, macie2:GetAutomatedDiscoveryConfiguration, macie2:GetClassificationExportConfiguration, macie2:GetCustomDataIdentifier, macie2:GetFindingsPublicationConfiguration, macie2:ListCustomDataIdentifiers, mobiletargeting:GetEmailChannel, refactor-spaces:GetEnvironment, refactor-spaces:ListEnvironments, resiliencehub:ListTagsForResource, route53:GetDNSSEC, sagemaker:DescribeDomain, sagemaker:DescribeModelBiasJobDefinition, sagemaker:DescribeModelQualityJobDefinition, sagemaker:DescribePipeline, sagemaker:DescribeProject, sagemaker:ListDomains, sagemaker:ListModelBiasJobDefinitions, sagemaker:ListModelQualityJobDefinitions, sagemaker:ListPipelines, sagemaker:ListProjects, transfer:DescribeAgreement, transfer:DescribeCertificate, transfer:ListAgreements, transfer:ListCertificates, and waf-regional:ListLoggingConfigurations |
该政策现在支持亚马逊托管工作流程的额外权限,包括、、、亚马逊 Amazon Amplify、、亚马逊弹性计算云 Amazon App Mesh Amazon App Runner CloudFront、亚马逊 Kendra Amazon CodeArtifact、亚马逊 Macie、亚马逊 Route 53、亚马逊 A Amazon Transfer Family I、Amazon Pinpoint、、 SageMaker Resilience Hub、亚马逊 Amazon Migration Hub Amazon 、Di Amazon rectory Service 和。 CloudWatch Amazon WAF |
2023 年 4 月 13 日 |
| AWSConfigServiceRolePolicy – 添加 appflow:DescribeFlow, appflow:ListFlows, appflow:ListTagsForResource, apprunner:DescribeService, apprunner:ListServices, apprunner:ListTagsForResource, appstream:DescribeApplications, appstream:DescribeFleets, cloudfront:GetResponseHeadersPolicy, cloudwatch:ListTagsForResource, codeartifact:DescribeRepository, codeartifact:GetRepositoryPermissionsPolicy, codeartifact:ListTagsForResource, codecommit:GetRepository, codecommit:GetRepositoryTriggers, codecommit:ListRepositories, codecommit:ListTagsForResource, devicefarm:GetInstanceProfile, devicefarm:ListInstanceProfiles, devicefarm:ListProjects, evidently:GetProject, evidently:ListProjects, evidently:ListTagsForResource, forecast:DescribeDataset, forecast:ListDatasets, forecast:ListTagsForResource, groundstation:GetConfig, groundstation:ListConfigs, groundstation:ListTagsForResource, iam:GetInstanceProfile, iam:GetSAMLProvider, iam:GetServerCertificate, iam:ListAccessKeys, iam:ListGroups, iam:ListInstanceProfiles, iam:ListMFADevices, iam:ListMFADeviceTags, iam:ListRoles, iam:ListSAMLProviders, iot:DescribeFleetMetric, iot:ListFleetMetrics, memorydb:DescribeUsers, memorydb:ListTags, mobiletargeting:GetApp, mobiletargeting:GetCampaigns, networkmanager:GetDevices, networkmanager:GetLinks, networkmanager:GetSites, panorama:ListNodes, rds:DescribeDBProxyEndpoints, redshift:DescribeScheduledActions, sagemaker:DescribeAppImageConfig, sagemaker:DescribeImage, sagemaker:DescribeImageVersion, sagemaker:ListAppImageConfigs, sagemaker:ListImages, and sagemaker:ListImageVersions |
该政策现在支持亚马逊、亚马逊 WorkSpaces 应用程序、亚马逊、亚马逊 AppFlow、、、、亚马逊、、 Amazon App Runner、Amazon CloudWatch Evicently CloudFront、Amazon F CloudWatch orecast Amazon CodeArtifact Amazon CodeCommit Amazon Device Farm、 Amazon Identity and Access Management (IAM)、、Amazon MemoryDB Amazon IoT、Amazon Pinpoint、、、、亚马逊关系数据库 Amazon Panorama服务 (Amazon RDS) Amazon Network Manager、Amazon Redshift 和亚马逊 AI 的额外权限。 Amazon Ground Station SageMaker |
2023 年 3 月 30 日 |
| AWS_ConfigRole – 添加 appflow:DescribeFlow, appflow:ListFlows, appflow:ListTagsForResource, apprunner:DescribeService, apprunner:ListServices, apprunner:ListTagsForResource, appstream:DescribeApplications, appstream:DescribeFleets, cloudformation:ListTypes, cloudfront:GetResponseHeadersPolicy, cloudfront:ListDistributions, cloudwatch:ListTagsForResource, codeartifact:DescribeRepository, codeartifact:GetRepositoryPermissionsPolicy, codeartifact:ListTagsForResource, codecommit:GetRepository, codecommit:GetRepositoryTriggers, codecommit:ListRepositories, codecommit:ListTagsForResource, devicefarm:GetInstanceProfile, devicefarm:ListInstanceProfiles, devicefarm:ListProjects, ec2:DescribeTrafficMirrorFilters, evidently:GetProject, evidently:ListProjects, evidently:ListTagsForResource, forecast:DescribeDataset, forecast:ListDatasets, forecast:ListTagsForResource, groundstation:GetConfig, groundstation:ListConfigs, groundstation:ListTagsForResource, iam:GetInstanceProfile, iam:GetSAMLProvider, iam:GetServerCertificate, iam:ListAccessKeys, iam:ListGroups, iam:ListInstanceProfiles, iam:ListMFADevices, iam:ListMFADeviceTags, iam:ListRoles, iam:ListSAMLProviders, iot:DescribeFleetMetric, iot:ListFleetMetrics, memorydb:DescribeUsers, memorydb:ListTags, mobiletargeting:GetApp, mobiletargeting:GetCampaigns, networkmanager:GetDevices, networkmanager:GetLinks, networkmanager:GetSites, panorama:ListNodes, rds:DescribeDBProxyEndpoints, redshift:DescribeScheduledActions, sagemaker:DescribeAppImageConfig, sagemaker:DescribeImage, sagemaker:DescribeImageVersion, sagemaker:ListAppImageConfigs, sagemaker:ListImages, and sagemaker:ListImageVersions |
该政策现在支持亚马逊、亚马逊 WorkSpaces 应用程序、亚马逊、亚马逊 AppFlow、、、、 Amazon App Runner、亚马逊弹性计算云(亚马逊) Amazon CloudFormation CloudFront、亚马逊 CloudWatch Evicently CloudWatch Amazon CodeArtifact Amazon CodeCommit Amazon Device Farm、Amazon Forecast、 Amazon Identity and Access Management (IAM EC2)、、Amazon MemoryDB Amazon Ground Station、Amazon Pinpoint Amazon IoT、、、、亚马逊关系数据库 Amazon Panorama服务(亚马逊 RDS) Amazon Network Manager、亚马逊 Redshift 和亚马逊的额外权限人工智能。 SageMaker |
2023 年 3 月 30 日 |
|
AWSConfigRulesExecutionRole— Amazon Config 开始跟踪此 Amazon 托管策略的更改 |
此策略允许 Amazon Lambda 函数访问定期发送到 Amazon S3 的 Amazon Config Amazon Config API 和配置快照。评估 Amazon 自定义 Lambda 规则的配置更改的函数需要此访问权限。 |
2023 年 3 月 7 日 |
|
AWSConfigRoleForOrganizations— Amazon Config 开始跟踪此 Amazon 托管策略的更改 |
此策略 Amazon Config 允许只读调用 Amazon Organizations APIs。 |
2023 年 3 月 7 日 |
|
AWSConfigRemediationServiceRolePolicy— Amazon Config 开始跟踪此 Amazon 托管策略的更改 |
此政策 Amazon Config 允许代表您修复 |
2023 年 3 月 7 日 |
|
AWSConfigServiceRolePolicy – 添加 auditmanager:GetAccountStatus |
此策略现在授予返回 Amazon Audit Manager中的账户注册状态的权限。 |
2023 年 3 月 3 日 |
|
AWS_ConfigRole – 添加 auditmanager:GetAccountStatus |
此策略现在授予返回 Amazon Audit Manager中的账户注册状态的权限。 |
2023 年 3 月 3 日 |
|
AWSConfigMultiAccountSetupPolicy— Amazon Config 开始跟踪此 Amazon 托管策略的更改 |
此策略 Amazon Config 允许使用调用 Amazon 服务并在整个组织中部署 Amazon Config 资源 Amazon Organizations。 |
2023 年 2 月 27 日 |
|
AWSConfigServiceRolePolicy – 添加 airflow:ListTagsForResource, iot:ListCustomMetrics, iot:DescribeCustomMetric, appstream:DescribeDirectoryConfigs, appstream:ListTagsForResource, codeguru-reviewer:DescribeRepositoryAssociation, codeguru-reviewer:ListRepositoryAssociations, healthlake:ListFHIRDatastores, healthlake:DescribeFHIRDatastore, healthlake:ListTagsForResource, kinesisvideo:DescribeStream, kinesisvideo:ListStreams, kinesisvideo:ListTagsForStream, kinesisvideo:DescribeSignalingChannel, kinesisvideo:ListTagsForResource, kinesisvideo:ListSignalingChannels, route53-recovery-control-config:DescribeCluster, route53-recovery-control-config:DescribeRoutingControl, route53-recovery-control-config:DescribeSafetyRule, route53-recovery-control-config:ListClusters, route53-recovery-control-config:ListRoutingControls, route53-recovery-control-config:ListSafetyRules, devicefarm:GetTestGridProject, devicefarm:ListTestGridProjects, ec2:DescribeCapacityReservationFleets, ec2:DescribeIpamPools, ec2:DescribeIpams, ec2:GetInstanceTypesFromInstanceRequirement, mobiletargeting:GetApplicationSettings, mobiletargeting:ListTagsForResource, ecr:BatchGetRepositoryScanningConfiguration, iam:ListServerCertificates, guardduty:ListPublishingDestinations, guardduty:DescribePublishingDestination, logs:GetLogDelivery, and logs:ListLogDeliveries |
该政策现在支持Apache Airflow、Amazon Applications Amazon IoT、Amazon WorkSpaces Reviewer Amazon HealthLake、Ama CodeGuru zon Kinesis Video Streams、亚马逊应用程序恢复控制器 (ARC)、亚马逊弹性计算云 (亚马逊) Amazon Device Farm、亚马逊 Pinpoin Amazon Identity and Access Management t、(IAM EC2)、亚马逊和亚马逊日志的亚马逊托管工作流程的额外权限。 GuardDuty CloudWatch |
2023 年 2 月 1 日 |
|
AWS_ConfigRole – 添加 airflow:ListTagsForResource, iot:ListCustomMetrics, iot:DescribeCustomMetric, appstream:DescribeDirectoryConfigs, appstream:ListTagsForResource, codeguru-reviewer:DescribeRepositoryAssociation, codeguru-reviewer:ListRepositoryAssociations, healthlake:ListFHIRDatastores, healthlake:DescribeFHIRDatastore, healthlake:ListTagsForResource, kinesisvideo:DescribeStream, kinesisvideo:ListStreams, kinesisvideo:ListTagsForStream, kinesisvideo:DescribeSignalingChannel, kinesisvideo:ListTagsForResource, kinesisvideo:ListSignalingChannels, route53-recovery-control-config:DescribeCluster, route53-recovery-control-config:DescribeRoutingControl, route53-recovery-control-config:DescribeSafetyRule, route53-recovery-control-config:ListClusters, route53-recovery-control-config:ListRoutingControls, route53-recovery-control-config:ListSafetyRules, devicefarm:GetTestGridProject, devicefarm:ListTestGridProjects, ec2:DescribeCapacityReservationFleets, ec2:DescribeIpamPools, ec2:DescribeIpams, ec2:GetInstanceTypesFromInstanceRequirement, mobiletargeting:GetApplicationSettings, mobiletargeting:ListTagsForResource, ecr:BatchGetRepositoryScanningConfiguration, iam:ListServerCertificates, guardduty:ListPublishingDestinations, guardduty:DescribePublishingDestination, logs:GetLogDelivery, and logs:ListLogDeliveries |
该政策现在支持Apache Airflow、Amazon Applications Amazon IoT、Amazon WorkSpaces Reviewer Amazon HealthLake、Ama CodeGuru zon Kinesis Video Streams、亚马逊应用程序恢复控制器 (ARC)、亚马逊弹性计算云 (亚马逊) Amazon Device Farm、亚马逊 Pinpoin Amazon Identity and Access Management t、(IAM EC2)、亚马逊和亚马逊日志的亚马逊托管工作流程的额外权限。 GuardDuty CloudWatch |
2023 年 2 月 1 日 |
|
ConfigConformsServiceRolePolicy – 更新 config:DescribeConfigRules |
作为安全最佳实践,此策略现在取消了对 |
2023 年 1 月 12 日 |
|
AWSConfigServiceRolePolicy – 添加 APS:DescribeRuleGroupsNamespace, APS:DescribeWorkspace, APS:ListWorkspaces, auditmanager:GetAssessment, auditmanager:ListAssessments, devicefarm:GetNetworkProfile, Amazon Transfer Family devicefarm:GetProject, devicefarm:ListNetworkProfiles, devicefarm:ListTagsForResource, dms:DescribeEndpoints, ds:ListTagsForResource, ec2:DescribeTags, ec2:DescribeTrafficMirrorSessions, ec2:DescribeTrafficMirrorTargets, ec2:GetIpamPoolAllocations, ec2:GetIpamPoolCidrs, glue:GetMLTransform, glue:GetMLTransforms, glue:ListMLTransforms, iot:DescribeScheduledAudit, iot:ListScheduledAudits, ivs:GetChannel, lightsail:GetRelationalDatabases, mediapackage-vod:DescribePackagingConfiguration, mediapackage-vod:ListPackagingConfigurations, networkmanager:DescribeGlobalNetworks, networkmanager:GetTransitGatewayRegistrations, networkmanager:ListTagsForResource, quicksight:DescribeDashboard, quicksight:DescribeDashboardPermissions, quicksight:DescribeTemplate, quicksight:DescribeTemplatePermissions, quicksight:ListDashboards, quicksight:ListTemplates, ram:ListResources, route53-recovery-control-config:DescribeControlPanel, route53-recovery-control-config:ListControlPanels, route53-recovery-control-config:ListTagsForResource, route53resolver:GetResolverQueryLogConfigAssociation, route53resolver:ListResolverQueryLogConfigAssociations, s3:GetAccessPointForObjectLambda, s3:GetAccessPointPolicyForObjectLambda, s3:GetAccessPointPolicyStatusForObjectLambda, s3:GetMultiRegionAccessPoint, s3:ListAccessPointsForObjectLambda, s3:ListMultiRegionAccessPoints, timestream:DescribeEndpoints, transfer:DescribeConnector, transfer:ListConnectors, and transfer:ListTagsForResource |
该政策现在支持亚马逊托管服务 Prometheus、、、、、、、、、、亚马逊弹性计算云 Amazon Database Migration Service (亚马逊Amazon DMS) Amazon Audit Manager Amazon Device Farm、、 Amazon Directory Service、Amazon Lightsail、、 Amazon Glue、 EC2 Ama Amazon IoT zon Quick Suite、 AWS Elemental MediaPackage、 Amazon Network Manager亚马逊应用程序恢复控制器 (ARC) Amazon Resource Access Manager、亚马逊简单存储服务 (Amazon S3) 和亚马逊 Timestream 的额外权限。 |
2022 年 12 月 15 日 |
|
AWS_ConfigRole – 添加 APS:DescribeRuleGroupsNamespace, APS:DescribeWorkspace, APS:ListWorkspaces, auditmanager:GetAssessment, auditmanager:ListAssessments, devicefarm:GetNetworkProfile, devicefarm:GetProject, devicefarm:ListNetworkProfiles, devicefarm:ListTagsForResource, dms:DescribeEndpoints, ds:ListTagsForResource, ec2:DescribeTags, ec2:DescribeTrafficMirrorSessions, ec2:DescribeTrafficMirrorTargets, ec2:GetIpamPoolAllocations, ec2:GetIpamPoolCidrs, glue:GetMLTransform, glue:GetMLTransforms, glue:ListMLTransforms, iot:DescribeScheduledAudit, iot:ListScheduledAudits, ivs:GetChannel, lightsail:GetRelationalDatabases, mediapackage-vod:DescribePackagingConfiguration, mediapackage-vod:ListPackagingConfigurations, networkmanager:DescribeGlobalNetworks, networkmanager:GetTransitGatewayRegistrations, networkmanager:ListTagsForResource, quicksight:DescribeDashboard, quicksight:DescribeDashboardPermissions, quicksight:DescribeTemplate, quicksight:DescribeTemplatePermissions, quicksight:ListDashboards, quicksight:ListTemplates, ram:ListResources, route53-recovery-control-config:DescribeControlPanel, route53-recovery-control-config:ListControlPanels, route53-recovery-control-config:ListTagsForResource, route53resolver:GetResolverQueryLogConfigAssociation, route53resolver:ListResolverQueryLogConfigAssociations, s3:GetAccessPointForObjectLambda, s3:GetAccessPointPolicyForObjectLambda, s3:GetAccessPointPolicyStatusForObjectLambda, s3:GetMultiRegionAccessPoint, s3:ListAccessPointsForObjectLambda, s3:ListMultiRegionAccessPoints, timestream:DescribeEndpoints, transfer:DescribeConnector, transfer:ListConnectors, and transfer:ListTagsForResource |
该政策现在支持亚马逊托管服务 Prometheus、、、、、、、、、、亚马逊弹性计算云 Amazon Database Migration Service (亚马逊Amazon DMS) Amazon Audit Manager Amazon Device Farm、、 Amazon Directory Service、Amazon Lightsail、、 Amazon Glue、 EC2 Ama Amazon IoT zon Quick Suite、 AWS Elemental MediaPackage、 Amazon Network Manager亚马逊应用程序恢复控制器 (ARC) Amazon Resource Access Manager、亚马逊简单存储服务 (Amazon S3) 和亚马逊 Timestream 的额外权限。 |
2022 年 12 月 15 日 |
|
AWSConfigServiceRolePolicy – 添加 cloudformation:ListStackResources and cloudformation:ListStacks |
现在,此策略允许返回指定 Amazon CloudFormation 堆栈中所有资源的描述并返回状态与指定StackStatusFilter堆栈的摘要信息。 |
2022 年 11 月 7 日 |
|
AWS_ConfigRole – 添加 cloudformation:ListStackResources and cloudformation:ListStacks |
现在,此策略允许返回指定 Amazon CloudFormation 堆栈中所有资源的描述并返回状态与指定StackStatusFilter堆栈的摘要信息。 |
2022 年 11 月 7 日 |
|
AWSConfigServiceRolePolicy – 添加 acm-pca:GetCertificateAuthorityCsr, acm-pca:ListCertificateAuthorities, acm-pca:ListTags, airflow:GetEnvironment, airflow:ListEnvironments, amplifyuibuilder:ListThemes, appconfig:ListConfigurationProfiles, appconfig:ListDeployments, appconfig:ListDeploymentStrategies, appconfig:ListEnvironments, appconfig:ListHostedConfigurationVersions, cassandra:Select, cloudwatch:DescribeAnomalyDetectors, cloudwatch:GetDashboard, cloudwatch:ListDashboards, connect:DescribePhoneNumber, connect:ListPhoneNumbers, connect:ListPhoneNumbersV2, connect:SearchAvailablePhoneNumbers, databrew:DescribeDataset, databrew:DescribeJob, databrew:DescribeProject, databrew:DescribeRecipe, databrew:DescribeRuleset, databrew:DescribeSchedule, databrew:ListDatasets, databrew:ListJobs, databrew:ListProjects, databrew:ListRecipes, databrew:ListRecipeVersions, databrew:ListRulesets, databrew:ListSchedules, ec2:DescribeRouteTables, eks:DescribeAddon, eks:DescribeIdentityProviderConfig, eks:ListAddons, eks:ListIdentityProviderConfigs, events:DescribeConnection, events:ListApiDestinations, events:ListConnections, fis:GetExperimentTemplate, fis:ListExperimentTemplates, frauddetector:GetRules, fsx:DescribeBackups, fsx:DescribeSnapshots, fsx:DescribeStorageVirtualMachines, gamelift:DescribeMatchmakingRuleSets, gamelift:DescribeVpcPeeringConnections, geo:ListGeofenceCollections, geo:ListPlaceIndexes, geo:ListRouteCalculators, geo:ListTrackers, iot:DescribeAccountAuditConfiguration, iot:DescribeAuthorizer, iot:DescribeDomainConfiguration, iot:DescribeMitigationAction, iot:ListAuthorizers, iot:ListDomainConfigurations, iot:ListMitigationActions, iotsitewise:DescribeAssetModel, iotsitewise:DescribeDashboard, iotsitewise:DescribeGateway, iotsitewise:DescribePortal, iotsitewise:DescribeProject, iotsitewise:ListAssetModels, iotsitewise:ListDashboards, iotsitewise:ListGateways, iotsitewise:ListPortals, iotsitewise:ListProjectAssets, iotsitewise:ListProjects, iotsitewise:ListTagsForResource, iotwireless:GetServiceProfile, iotwireless:GetWirelessDevice, iotwireless:GetWirelessGatewayTaskDefinition, iotwireless:ListServiceProfiles, iotwireless:ListTagsForResource, iotwireless:ListWirelessDevices, iotwireless:ListWirelessGatewayTaskDefinitions, lex:DescribeBotVersion, lex:ListBotVersions, lightsail:GetContainerServices, lightsail:GetDistributions, lightsail:GetRelationalDatabase, lightsail:GetRelationalDatabaseParameters, mobiletargeting:GetApps, mobiletargeting:GetCampaign, mobiletargeting:GetSegment, mobiletargeting:GetSegments, opsworks:DescribeInstances, opsworks:DescribeTimeBasedAutoScaling, opsworks:DescribeVolumes, panorama:DescribeApplicationInstance, panorama:DescribeApplicationInstanceDetails, panorama:DescribePackage, panorama:DescribePackageVersion, panorama:ListApplicationInstances, panorama:ListPackages, quicksight:ListDataSources, ram:ListResourceSharePermissions, rds:DescribeDBProxies, rds:DescribeGlobalClusters, rekognition:ListStreamProcessors, resource-groups:GetGroup, resource-groups:GetGroupConfiguration, resource-groups:GetGroupQuery, resource-groups:GetTags, resource-groups:ListGroupResources, resource-groups:ListGroups, robomaker:ListRobotApplications, robomaker:ListSimulationApplications, route53resolver:GetResolverDnssecConfig, route53resolver:ListResolverDnssecConfigs, s3:ListStorageLensConfigurations, schemas:GetResourcePolicy, servicediscovery:ListInstances, sts:GetCallerIdentity, synthetics:GetGroup, synthetics:ListAssociatedGroups, synthetics:ListGroupResources, and synthetics:ListGroups |
该政策现在支持以下方面的额外权限:Apache Airflow Amazon Certificate Manager、、、亚马逊密钥空间 Amazon Amplify、 Amazon AppConfig亚马逊、Amazon Connect CloudWatch、亚马逊弹性计算云(亚马逊) Amazon Glue DataBrew、亚马逊弹性 Kubernetes 服务( EC2亚马逊 EKS)、亚马逊、、亚马逊欺诈探测器、亚马逊、亚马逊服务器、亚马逊定位服务、、Amazon Lex EventBridge、 Amazon Fault Injection Service Amazon Lightsail FSx、A GameLift mazon Pinpoint Amazon IoT、、、、Amazon Quick Suite、亚马逊关系数据库 Amazon OpsWorks Amazon Panorama Amazon Resource Access Manager服务(亚马逊 RDS)、亚马逊 Amazon RoboMaker Rekognition、、、Amazon Route 53 Amazon Resource Groups、亚马逊简单存储服务 Amazon Cloud Map(Amazon S3) Simple Service 和。 Amazon Security Token Service |
2022 年 10 月 19 日 |
|
AWS_ConfigRole – 添加 acm-pca:GetCertificateAuthorityCsr, acm-pca:ListCertificateAuthorities, acm-pca:ListTags, airflow:GetEnvironment, airflow:ListEnvironments, amplifyuibuilder:ListThemes, appconfig:ListConfigurationProfiles, appconfig:ListDeployments, appconfig:ListDeploymentStrategies, appconfig:ListEnvironments, appconfig:ListHostedConfigurationVersions, cassandra:Select, cloudwatch:DescribeAnomalyDetectors, cloudwatch:GetDashboard, cloudwatch:ListDashboards, connect:DescribePhoneNumber, connect:ListPhoneNumbers, connect:ListPhoneNumbersV2, connect:SearchAvailablePhoneNumbers, databrew:DescribeDataset, databrew:DescribeJob, databrew:DescribeProject, databrew:DescribeRecipe, databrew:DescribeRuleset, databrew:DescribeSchedule, databrew:ListDatasets, databrew:ListJobs, databrew:ListProjects, databrew:ListRecipes, databrew:ListRecipeVersions, databrew:ListRulesets, databrew:ListSchedules, ec2:DescribeRouteTables, eks:DescribeAddon, eks:DescribeIdentityProviderConfig, eks:ListAddons, eks:ListIdentityProviderConfigs, events:DescribeConnection, events:ListApiDestinations, events:ListConnections, fis:GetExperimentTemplate, fis:ListExperimentTemplates, frauddetector:GetRules, fsx:DescribeBackups, fsx:DescribeSnapshots, fsx:DescribeStorageVirtualMachines, gamelift:DescribeMatchmakingRuleSets, gamelift:DescribeVpcPeeringConnections, geo:ListGeofenceCollections, geo:ListPlaceIndexes, geo:ListRouteCalculators, geo:ListTrackers, iot:DescribeAccountAuditConfiguration, iot:DescribeAuthorizer, iot:DescribeDomainConfiguration, iot:DescribeMitigationAction, iot:ListAuthorizers, iot:ListDomainConfigurations, iot:ListMitigationActions, iotsitewise:DescribeAssetModel, iotsitewise:DescribeDashboard, iotsitewise:DescribeGateway, iotsitewise:DescribePortal, iotsitewise:DescribeProject, iotsitewise:ListAssetModels, iotsitewise:ListDashboards, iotsitewise:ListGateways, iotsitewise:ListPortals, iotsitewise:ListProjectAssets, iotsitewise:ListProjects, iotsitewise:ListTagsForResource, iotwireless:GetServiceProfile, iotwireless:GetWirelessDevice, iotwireless:GetWirelessGatewayTaskDefinition, iotwireless:ListServiceProfiles, iotwireless:ListTagsForResource, iotwireless:ListWirelessDevices, iotwireless:ListWirelessGatewayTaskDefinitions, lex:DescribeBotVersion, lex:ListBotVersions, lightsail:GetContainerServices, lightsail:GetDistributions, lightsail:GetRelationalDatabase, lightsail:GetRelationalDatabaseParameters, mobiletargeting:GetApps, mobiletargeting:GetCampaign, mobiletargeting:GetSegment, mobiletargeting:GetSegments, opsworks:DescribeInstances, opsworks:DescribeTimeBasedAutoScaling, opsworks:DescribeVolumes, panorama:DescribeApplicationInstance, panorama:DescribeApplicationInstanceDetails, panorama:DescribePackage, panorama:DescribePackageVersion, panorama:ListApplicationInstances, panorama:ListPackages, quicksight:ListDataSources, ram:ListResourceSharePermissions, rds:DescribeDBProxies, rds:DescribeGlobalClusters, rekognition:ListStreamProcessors, resource-groups:GetGroup, resource-groups:GetGroupConfiguration, resource-groups:GetGroupQuery, resource-groups:GetTags, resource-groups:ListGroupResources, resource-groups:ListGroups, robomaker:ListRobotApplications, robomaker:ListSimulationApplications, route53resolver:GetResolverDnssecConfig, route53resolver:ListResolverDnssecConfigs, s3:ListStorageLensConfigurations, schemas:GetResourcePolicy, servicediscovery:ListInstances, sts:GetCallerIdentity, synthetics:GetGroup, synthetics:ListAssociatedGroups, synthetics:ListGroupResources, and synthetics:ListGroups |
该政策现在支持以下方面的额外权限:Apache Airflow Amazon Certificate Manager、、、亚马逊密钥空间 Amazon Amplify、 Amazon AppConfig亚马逊、Amazon Connect CloudWatch、亚马逊弹性计算云(亚马逊) Amazon Glue DataBrew、亚马逊弹性 Kubernetes 服务( EC2亚马逊 EKS)、亚马逊、、亚马逊欺诈探测器、亚马逊、亚马逊服务器、亚马逊定位服务、、Amazon Lex EventBridge、 Amazon Fault Injection Service Amazon Lightsail FSx、A GameLift mazon Pinpoint Amazon IoT、、、、Amazon Quick Suite、亚马逊关系数据库 Amazon OpsWorks Amazon Panorama Amazon Resource Access Manager服务(亚马逊 RDS)、亚马逊 Amazon RoboMaker Rekognition、、、Amazon Route 53 Amazon Resource Groups、亚马逊简单存储服务 Amazon Cloud Map(Amazon S3) Simple Service 和。 Amazon Security Token Service |
2022 年 10 月 19 日 |
|
AWSConfigServiceRolePolicy – 添加 Glue::GetTable |
现在,此策略授予在数据目录中检索指定 Amazon Glue 表的表定义的权限。 |
2022 年 9 月 14 日 |
|
AWS_ConfigRole – 添加 Glue::GetTable |
现在,此策略授予在数据目录中检索指定 Amazon Glue 表的表定义的权限。 |
2022 年 9 月 14 日 |
|
AWSConfigServiceRolePolicy – 添加 appconfig:ListApplications, appflow:DescribeConnectorProfiles, appsync:GetApiCache, autoscaling-plans:DescribeScalingPlanResources, autoscaling-plans:DescribeScalingPlans, autoscaling-plans:GetScalingPlanResourceForecastData, autoscaling:DescribeWarmPool, backup:DescribeFramework, backup:DescribeReportPlan, backup:ListFrameworks, backup:ListReportPlans, budgets:DescribeBudgetAction, budgets:DescribeBudgetActionsForAccount, budgets:DescribeBudgetActionsForBudget, budgets:ViewBudget, ce:GetAnomalyMonitors, ce:GetAnomalySubscriptions, cloud9:DescribeEnvironmentMemberships, cloud9:DescribeEnvironments, cloud9:ListEnvironments, cloud9:ListTagsForResource, cloudwatch:GetMetricStream, cloudwatch:ListMetricStreams, datasync:DescribeLocationFsxWindows, devops-guru:GetResourceCollection, ds:DescribeDirectories, ec2:DescribeTrafficMirrorFilters, ec2:DescribeTrafficMirrorTargets, ec2:GetNetworkInsightsAccessScopeAnalysisFindings, ec2:GetNetworkInsightsAccessScopeContent, elasticmapreduce:DescribeStudio, elasticmapreduce:GetStudioSessionMapping, elasticmapreduce:ListStudios, elasticmapreduce:ListStudioSessionMappings, events:DescribeEndpoint, events:DescribeEventBus, events:DescribeRule, events:ListArchives, events:ListEndpoints, events:ListEventBuses, events:ListRules, events:ListTagsForResource, events:ListTargetsByRule, finspace:GetEnvironment, finspace:ListEnvironments, frauddetector:GetDetectors, frauddetector:GetDetectorVersion, frauddetector:GetEntityTypes, frauddetector:GetEventTypes, frauddetector:GetExternalModels, frauddetector:GetLabels, frauddetector:GetModels, frauddetector:GetOutcomes, frauddetector:GetVariables, frauddetector:ListTagsForResource, gamelift:DescribeAlias, gamelift:DescribeBuild, gamelift:DescribeFleetAttributes, gamelift:DescribeFleetCapacity, gamelift:DescribeFleetLocationAttributes, gamelift:DescribeFleetLocationCapacity, gamelift:DescribeFleetPortSettings, gamelift:DescribeGameServerGroup, gamelift:DescribeGameSessionQueues, gamelift:DescribeMatchmakingConfigurations, gamelift:DescribeMatchmakingRuleSets, gamelift:DescribeRuntimeConfiguration, gamelift:DescribeScript, gamelift:DescribeVpcPeeringAuthorizations, gamelift:ListAliases, gamelift:ListBuilds, gamelift:ListFleets, gamelift:ListGameServerGroups, gamelift:ListScripts, gamelift:ListTagsForResource, geo:ListMaps, glue:GetClassifier, glue:GetClassifiers, imagebuilder:GetContainerRecipe, imagebuilder:GetImage, imagebuilder:GetImagePipeline, imagebuilder:GetImageRecipe, imagebuilder:ListContainerRecipes, imagebuilder:ListImageBuildVersions, imagebuilder:ListImagePipelines, imagebuilder:ListImageRecipes, imagebuilder:ListImages, iot:DescribeCertificate, iot:DescribeDimension, iot:DescribeRoleAlias, iot:DescribeSecurityProfile, iot:GetPolicy, iot:GetTopicRule, iot:GetTopicRuleDestination, iot:ListCertificates, iot:ListDimensions, iot:ListPolicies, iot:ListRoleAliases, iot:ListSecurityProfiles, iot:ListSecurityProfilesForTarget, iot:ListTagsForResource, iot:ListTargetsForSecurityProfile, iot:ListTopicRuleDestinations, iot:ListTopicRules, iot:ListV2LoggingLevels, iot:ValidateSecurityProfileBehaviors, iotanalytics:DescribeChannel, iotanalytics:DescribeDataset, iotanalytics:DescribeDatastore, iotanalytics:DescribePipeline, iotanalytics:ListChannels, iotanalytics:ListDatasets, iotanalytics:ListDatastores, iotanalytics:ListPipelines, iotanalytics:ListTagsForResource, iotevents:DescribeAlarmModel, iotevents:DescribeDetectorModel, iotevents:DescribeInput, iotevents:ListAlarmModels, iotevents:ListDetectorModels, iotevents:ListInputs, iotevents:ListTagsForResource, iotsitewise:DescribeAccessPolicy, iotsitewise:DescribeAsset, iotsitewise:ListAccessPolicies, iotsitewise:ListAssets, iottwinmaker:GetEntity, iottwinmaker:GetScene, iottwinmaker:GetWorkspace, iottwinmaker:ListEntities, iottwinmaker:ListScenes, iottwinmaker:ListTagsForResource, iottwinmaker:ListWorkspaces, ivs:GetPlaybackKeyPair, ivs:GetRecordingConfiguration, ivs:GetStreamKey, ivs:ListChannels, ivs:ListPlaybackKeyPairs, ivs:ListRecordingConfigurations, ivs:ListStreamKeys, ivs:ListTagsForResource, kinesisanalytics:ListApplications, lakeformation:DescribeResource, lakeformation:GetDataLakeSettings, lakeformation:ListPermissions, lakeformation:ListResources, lex:DescribeBot, lex:DescribeBotAlias, lex:DescribeResourcePolicy, lex:ListBotAliases, lex:ListBotLocales, lex:ListBots, lex:ListTagsForResource, license-manager:GetGrant, license-manager:GetLicense, license-manager:ListDistributedGrants, license-manager:ListLicenses, license-manager:ListReceivedGrants, lightsail:GetAlarms, lightsail:GetBuckets, lightsail:GetCertificates, lightsail:GetDisk, lightsail:GetDisks, lightsail:GetInstance, lightsail:GetInstances, lightsail:GetKeyPair, lightsail:GetLoadBalancer, lightsail:GetLoadBalancers, lightsail:GetLoadBalancerTlsCertificates, lightsail:GetStaticIp, lightsail:GetStaticIps, lookoutequipment:DescribeInferenceScheduler, lookoutequipment:ListTagsForResource, lookoutmetrics:DescribeAlert, lookoutmetrics:DescribeAnomalyDetector, lookoutmetrics:ListAlerts, lookoutmetrics:ListAnomalyDetectors, lookoutmetrics:ListMetricSets, lookoutmetrics:ListTagsForResource, lookoutvision:DescribeProject, lookoutvision:ListProjects, managedblockchain:GetMember, managedblockchain:GetNetwork, managedblockchain:GetNode, managedblockchain:ListInvitations, managedblockchain:ListMembers, managedblockchain:ListNodes, mediapackage-vod:DescribePackagingGroup, mediapackage-vod:ListPackagingGroups, mediapackage-vod:ListTagsForResource, mobiletargeting:GetInAppTemplate, mobiletargeting:ListTemplates, mq:DescribeBroker, mq:ListBrokers, nimble:GetLaunchProfile, nimble:GetLaunchProfileDetails, nimble:GetStreamingImage, nimble:GetStudio, nimble:GetStudioComponent, nimble:ListLaunchProfiles, nimble:ListStreamingImages, nimble:ListStudioComponents, nimble:ListStudios, profile:GetDomain, profile:GetIntegration, profile:GetProfileObjectType, profile:ListDomains, profile:ListIntegrations, profile:ListProfileObjectTypes, profile:ListTagsForResource, quicksight:DescribeAnalysis, quicksight:DescribeAnalysisPermissions, quicksight:DescribeDataSet, quicksight:DescribeDataSetPermissions, quicksight:DescribeTheme, quicksight:DescribeThemePermissions, quicksight:ListAnalyses, quicksight:ListDataSets, quicksight:ListThemes, resiliencehub:DescribeApp, resiliencehub:DescribeAppVersionTemplate, resiliencehub:DescribeResiliencyPolicy, resiliencehub:ListApps, resiliencehub:ListAppVersionResourceMappings, resiliencehub:ListResiliencyPolicies, route53-recovery-readiness:GetCell, route53-recovery-readiness:GetReadinessCheck, route53-recovery-readiness:GetRecoveryGroup, route53-recovery-readiness:GetResourceSet, route53-recovery-readiness:ListCells, route53-recovery-readiness:ListReadinessChecks, route53-recovery-readiness:ListRecoveryGroups, route53-recovery-readiness:ListResourceSets, route53resolver:GetFirewallDomainList, route53resolver:GetFirewallRuleGroup, route53resolver:GetFirewallRuleGroupAssociation, route53resolver:GetResolverQueryLogConfig, route53resolver:ListFirewallDomainLists, route53resolver:ListFirewallDomains, route53resolver:ListFirewallRuleGroupAssociations, route53resolver:ListFirewallRuleGroups, route53resolver:ListFirewallRules, route53resolver:ListResolverQueryLogConfigs, rum:GetAppMonitor, rum:GetAppMonitorData, rum:ListAppMonitors, rum:ListTagsForResource, s3-outposts:GetAccessPoint, s3-outposts:GetAccessPointPolicy, s3-outposts:GetBucket, s3-outposts:GetBucketPolicy, s3-outposts:GetBucketTagging, s3-outposts:GetLifecycleConfiguration, s3-outposts:ListAccessPoints, s3-outposts:ListEndpoints, s3-outposts:ListRegionalBuckets, schemas:DescribeDiscoverer, schemas:DescribeRegistry, schemas:DescribeSchema, schemas:ListDiscoverers, schemas:ListRegistries, schemas:ListSchemas, sdb:GetAttributes, sdb:ListDomains, ses:ListEmailTemplates, ses:ListReceiptFilters, ses:ListReceiptRuleSets, ses:ListTemplates, signer:GetSigningProfile, signer:ListProfilePermissions, signer:ListSigningProfiles, synthetics:DescribeCanaries, synthetics:DescribeCanariesLastRun, synthetics:DescribeRuntimeVersions, synthetics:GetCanary, synthetics:GetCanaryRuns, synthetics:ListTagsForResource, timestream:DescribeDatabase, timestream:DescribeTable, timestream:ListDatabases, timestream:ListTables, timestream:ListTagsForResource, transfer:DescribeServer, transfer:DescribeUser, transfer:DescribeWorkflow, transfer:ListServers, transfer:ListUsers, transfer:ListWorkflows, voiceid:DescribeDomain, and voiceid:ListTagsForResource |
该政策现在支持亚马逊 AppFlow、亚马逊、亚马 CloudWatch逊 R CloudWatch UM、Amazon S CloudWatch ynthetics、Amazon Connect 客户档案、Amazon Connect 语音识别码、亚马逊 DevOps Guru、亚马逊弹性计算云(亚马逊)、Amazon Aut EC2 o Scaling EC2、亚马逊 EMR、亚马逊、亚马逊架构、亚马逊欺诈 Amazon FinSpace探测器、亚马逊 GameLift 服务器、 EventBridge亚马逊互动视频服务( EventBridge 亚马逊 IVS)) Interactive Service、适用于 Apache Flink 的亚马逊托管服务、Image Builder、Amazon Lex、Amazon Lightsail、 EC2 亚马逊定位服务、亚马逊 Lookout for Equipment、亚马逊 Lookout for Metrics、亚马逊 Lookout for Vision、亚马逊托管区块链、亚马逊 MQ、亚马逊 Nimble Pinp StudioAmazon oint、亚马逊快速套件、亚马逊应用程序恢复控制器 (ARC Amazon Route 53 Resolver)、亚马逊简单存储服务 (Amazon S3)、亚马逊 SimpleDB、亚马逊简单电子邮件服务 (Amazon SES)、亚马逊 Timestream、、、、、、、、、、、、、、、、、、、、、、、、、、、 Amazon AppConfig Amazon AppSync Amazon Auto Scaling Amazon Backup Amazon Budgets Amazon Cost Explorer Amazon Cloud9 Amazon Directory Service Amazon DataSync AWS Elemental MediaPackage Amazon Glue Amazon IoT Amazon IoT Analytics Amazon IoT Events Amazon IoT SiteWise、 Amazon IoT TwinMaker、 Amazon Lake Formation、 Amazon License Manager、 Amazon Resilience Hub、 Amazon Signer、和 Amazon Transfer Family。 |
2022 年 9 月 7 日 |
|
AWS_ConfigRole – 添加 appconfig:ListApplications, appflow:DescribeConnectorProfiles, appsync:GetApiCache, autoscaling-plans:DescribeScalingPlanResources, autoscaling-plans:DescribeScalingPlans, autoscaling-plans:GetScalingPlanResourceForecastData, autoscaling:DescribeWarmPool, backup:DescribeFramework, backup:DescribeReportPlan, backup:ListFrameworks, backup:ListReportPlans, budgets:DescribeBudgetAction, budgets:DescribeBudgetActionsForAccount, budgets:DescribeBudgetActionsForBudget, budgets:ViewBudget, ce:GetAnomalyMonitors, ce:GetAnomalySubscriptions, cloud9:DescribeEnvironmentMemberships, cloud9:DescribeEnvironments, cloud9:ListEnvironments, cloud9:ListTagsForResource, cloudwatch:GetMetricStream, cloudwatch:ListMetricStreams, datasync:DescribeLocationFsxWindows, devops-guru:GetResourceCollection, ds:DescribeDirectories, ec2:DescribeTrafficMirrorTargets, ec2:GetNetworkInsightsAccessScopeAnalysisFindings, ec2:GetNetworkInsightsAccessScopeContent, elasticmapreduce:DescribeStudio, elasticmapreduce:GetStudioSessionMapping, elasticmapreduce:ListStudios, elasticmapreduce:ListStudioSessionMappings, events:DescribeEndpoint, events:DescribeEventBus, events:DescribeRule, events:ListArchives, events:ListEndpoints, events:ListEventBuses, events:ListRules, events:ListTagsForResource, events:ListTargetsByRule, finspace:GetEnvironment, finspace:ListEnvironments, frauddetector:GetDetectors, frauddetector:GetDetectorVersion, frauddetector:GetEntityTypes, frauddetector:GetEventTypes, frauddetector:GetExternalModels, frauddetector:GetLabels, frauddetector:GetModels, frauddetector:GetOutcomes, frauddetector:GetVariables, frauddetector:ListTagsForResource, gamelift:DescribeAlias, gamelift:DescribeBuild, gamelift:DescribeFleetAttributes, gamelift:DescribeFleetCapacity, gamelift:DescribeFleetLocationAttributes, gamelift:DescribeFleetLocationCapacity, gamelift:DescribeFleetPortSettings, gamelift:DescribeGameServerGroup, gamelift:DescribeGameSessionQueues, gamelift:DescribeMatchmakingConfigurations, gamelift:DescribeMatchmakingRuleSets, gamelift:DescribeRuntimeConfiguration, gamelift:DescribeScript, gamelift:DescribeVpcPeeringAuthorizations, gamelift:ListAliases, gamelift:ListBuilds, gamelift:ListFleets, gamelift:ListGameServerGroups, gamelift:ListScripts, gamelift:ListTagsForResource, geo:ListMaps, glue:GetClassifier, glue:GetClassifiers, imagebuilder:GetContainerRecipe, imagebuilder:GetImage, imagebuilder:GetImagePipeline, imagebuilder:GetImageRecipe, imagebuilder:ListContainerRecipes, imagebuilder:ListImageBuildVersions, imagebuilder:ListImagePipelines, imagebuilder:ListImageRecipes, imagebuilder:ListImages, iot:DescribeCertificate, iot:DescribeDimension, iot:DescribeRoleAlias, iot:DescribeSecurityProfile, iot:GetPolicy, iot:GetTopicRule, iot:GetTopicRuleDestination, iot:ListCertificates, iot:ListDimensions, iot:ListPolicies, iot:ListRoleAliases, iot:ListSecurityProfiles, iot:ListSecurityProfilesForTarget, iot:ListTagsForResource, iot:ListTargetsForSecurityProfile, iot:ListTopicRuleDestinations, iot:ListTopicRules, iot:ListV2LoggingLevels, iot:ValidateSecurityProfileBehaviors, iotanalytics:DescribeChannel, iotanalytics:DescribeDataset, iotanalytics:DescribeDatastore, iotanalytics:DescribePipeline, iotanalytics:ListChannels, iotanalytics:ListDatasets, iotanalytics:ListDatastores, iotanalytics:ListPipelines, iotanalytics:ListTagsForResource, iotevents:DescribeAlarmModel, iotevents:DescribeDetectorModel, iotevents:DescribeInput, iotevents:ListAlarmModels, iotevents:ListDetectorModels, iotevents:ListInputs, iotevents:ListTagsForResource, iotsitewise:DescribeAccessPolicy, iotsitewise:DescribeAsset, iotsitewise:ListAccessPolicies, iotsitewise:ListAssets, iottwinmaker:GetEntity, iottwinmaker:GetScene, iottwinmaker:GetWorkspace, iottwinmaker:ListEntities, iottwinmaker:ListScenes, iottwinmaker:ListTagsForResource, iottwinmaker:ListWorkspaces, ivs:GetPlaybackKeyPair, ivs:GetRecordingConfiguration, ivs:GetStreamKey, ivs:ListChannels, ivs:ListPlaybackKeyPairs, ivs:ListRecordingConfigurations, ivs:ListStreamKeys, ivs:ListTagsForResource, kinesisanalytics:ListApplications, lakeformation:DescribeResource, lakeformation:GetDataLakeSettings, lakeformation:ListPermissions, lakeformation:ListResources, lex:DescribeBot, lex:DescribeBotAlias, lex:DescribeResourcePolicy, lex:ListBotAliases, lex:ListBotLocales, lex:ListBots, lex:ListTagsForResource, license-manager:GetGrant, license-manager:GetLicense, license-manager:ListDistributedGrants, license-manager:ListLicenses, license-manager:ListReceivedGrants, lightsail:GetAlarms, lightsail:GetBuckets, lightsail:GetCertificates, lightsail:GetDisk, lightsail:GetDisks, lightsail:GetInstance, lightsail:GetInstances, lightsail:GetKeyPair, lightsail:GetLoadBalancer, lightsail:GetLoadBalancers, lightsail:GetLoadBalancerTlsCertificates, lightsail:GetStaticIp, lightsail:GetStaticIps, lookoutequipment:DescribeInferenceScheduler, lookoutequipment:ListTagsForResource, lookoutmetrics:DescribeAlert, lookoutmetrics:DescribeAnomalyDetector, lookoutmetrics:ListAlerts, lookoutmetrics:ListAnomalyDetectors, lookoutmetrics:ListMetricSets, lookoutmetrics:ListTagsForResource, lookoutvision:DescribeProject, lookoutvision:ListProjects, managedblockchain:GetMember, managedblockchain:GetNetwork, managedblockchain:GetNode, managedblockchain:ListInvitations, managedblockchain:ListMembers, managedblockchain:ListNodes, mediapackage-vod:DescribePackagingGroup, mediapackage-vod:ListPackagingGroups, mediapackage-vod:ListTagsForResource, mobiletargeting:GetInAppTemplate, mobiletargeting:ListTemplates, mq:DescribeBroker, mq:ListBrokers, nimble:GetLaunchProfile, nimble:GetLaunchProfileDetails, nimble:GetStreamingImage, nimble:GetStudio, nimble:GetStudioComponent, nimble:ListLaunchProfiles, nimble:ListStreamingImages, nimble:ListStudioComponents, nimble:ListStudios, profile:GetDomain, profile:GetIntegration, profile:GetProfileObjectType, profile:ListDomains, profile:ListIntegrations, profile:ListProfileObjectTypes, profile:ListTagsForResource, quicksight:DescribeAnalysis, quicksight:DescribeAnalysisPermissions, quicksight:DescribeDataSet, quicksight:DescribeDataSetPermissions, quicksight:DescribeTheme, quicksight:DescribeThemePermissions, quicksight:ListAnalyses, quicksight:ListDataSets, quicksight:ListThemes, resiliencehub:DescribeApp, resiliencehub:DescribeAppVersionTemplate, resiliencehub:DescribeResiliencyPolicy, resiliencehub:ListApps, resiliencehub:ListAppVersionResourceMappings, resiliencehub:ListResiliencyPolicies, route53-recovery-readiness:GetCell, route53-recovery-readiness:GetReadinessCheck, route53-recovery-readiness:GetRecoveryGroup, route53-recovery-readiness:GetResourceSet, route53-recovery-readiness:ListCells, route53-recovery-readiness:ListReadinessChecks, route53-recovery-readiness:ListRecoveryGroups, route53-recovery-readiness:ListResourceSets, route53resolver:GetFirewallDomainList, route53resolver:GetFirewallRuleGroup, route53resolver:GetFirewallRuleGroupAssociation, route53resolver:GetResolverQueryLogConfig, route53resolver:ListFirewallDomainLists, route53resolver:ListFirewallDomains, route53resolver:ListFirewallRuleGroupAssociations, route53resolver:ListFirewallRuleGroups, route53resolver:ListFirewallRules, route53resolver:ListResolverQueryLogConfigs, rum:GetAppMonitor, rum:GetAppMonitorData, rum:ListAppMonitors, rum:ListTagsForResource, s3-outposts:GetAccessPoint, s3-outposts:GetAccessPointPolicy, s3-outposts:GetBucket, s3-outposts:GetBucketPolicy, s3-outposts:GetBucketTagging, s3-outposts:GetLifecycleConfiguration, s3-outposts:ListAccessPoints, s3-outposts:ListEndpoints, s3-outposts:ListRegionalBuckets, schemas:DescribeDiscoverer, schemas:DescribeRegistry, schemas:DescribeSchema, schemas:ListDiscoverers, schemas:ListRegistries, schemas:ListSchemas, sdb:GetAttributes, sdb:ListDomains, ses:ListEmailTemplates, ses:ListReceiptFilters, ses:ListReceiptRuleSets, ses:ListTemplates, signer:GetSigningProfile, signer:ListProfilePermissions, signer:ListSigningProfiles, synthetics:DescribeCanaries, synthetics:DescribeCanariesLastRun, synthetics:DescribeRuntimeVersions, synthetics:GetCanary, synthetics:GetCanaryRuns, synthetics:ListTagsForResource, timestream:DescribeDatabase, timestream:DescribeTable, timestream:ListDatabases, timestream:ListTables, timestream:ListTagsForResource, transfer:DescribeServer, transfer:DescribeUser, transfer:DescribeWorkflow, transfer:ListServers, transfer:ListUsers, transfer:ListWorkflows, voiceid:DescribeDomain, and voiceid:ListTagsForResource |
该政策现在支持亚马逊 AppFlow、亚马逊、亚马 CloudWatch逊 R CloudWatch UM、Amazon S CloudWatch ynthetics、Amazon Connect 客户档案、Amazon Connect 语音识别码、亚马逊 DevOps Guru、亚马逊弹性计算云(亚马逊)、Amazon Aut EC2 o Scaling EC2、亚马逊 EMR、亚马逊、亚马逊架构、亚马逊欺诈 Amazon FinSpace探测器、亚马逊 GameLift 服务器、 EventBridge亚马逊互动视频服务( EventBridge 亚马逊 IVS)) Interactive Service、适用于 Apache Flink 的亚马逊托管服务、Image Builder、Amazon Lex、Amazon Lightsail、 EC2 亚马逊定位服务、亚马逊 Lookout for Equipment、亚马逊 Lookout for Metrics、亚马逊 Lookout for Vision、亚马逊托管区块链、亚马逊 MQ、亚马逊 Nimble Pinp StudioAmazon oint、亚马逊快速套件、亚马逊应用程序恢复控制器 (ARC Amazon Route 53 Resolver)、亚马逊简单存储服务 (Amazon S3)、亚马逊 SimpleDB、亚马逊简单电子邮件服务 (Amazon SES)、亚马逊 Timestream、、、、、、、、、、、、、、、、、、、、、、、、、、、、 Amazon AppConfig Amazon AppSync Amazon Auto Scaling Amazon Backup Amazon Budgets Amazon Cost Explorer Amazon Cloud9 Amazon Directory Service Amazon DataSync AWS Elemental MediaPackage Amazon Glue Amazon IoT Amazon IoT Analytics Amazon IoT Events Amazon IoT SiteWise、 Amazon IoT TwinMaker、 Amazon Lake Formation、 Amazon License Manager、 Amazon Resilience Hub、 Amazon Signer、和 Amazon Transfer Family |
2022 年 9 月 7 日 |
| AWSConfigServiceRolePolicy – 添加 airflow:ListTagsForResource, iot:ListCustomMetrics, iot:DescribeCustomMetric, appstream:DescribeDirectoryConfigs, appstream:ListTagsForResource, codeguru-reviewer:DescribeRepositoryAssociation, codeguru-reviewer:ListRepositoryAssociations, healthlake:ListFHIRDatastores, healthlake:DescribeFHIRDatastore, healthlake:ListTagsForResource, kinesisvideo:DescribeStream, kinesisvideo:ListStreams, kinesisvideo:ListTagsForStream, kinesisvideo:DescribeSignalingChannel, kinesisvideo:ListTagsForResource, kinesisvideo:ListSignalingChannels, route53-recovery-control-config:DescribeCluster, route53-recovery-control-config:DescribeRoutingControl, route53-recovery-control-config:DescribeSafetyRule, route53-recovery-control-config:ListClusters, route53-recovery-control-config:ListRoutingControls, route53-recovery-control-config:ListSafetyRules, devicefarm:GetTestGridProject, devicefarm:ListTestGridProjects, ec2:DescribeCapacityReservationFleets, ec2:DescribeIpamPools, ec2:DescribeIpams, ec2:GetInstanceTypesFromInstanceRequirement, mobiletargeting:GetApplicationSettings, mobiletargeting:ListTagsForResource, ecr:BatchGetRepositoryScanningConfiguration, iam:ListServerCertificates, guardduty:ListPublishingDestinations, guardduty:DescribePublishingDestination, logs:GetLogDelivery, and logs:ListLogDeliveries | 该政策现在支持Apache Airflow、Amazon Applications Amazon IoT、Amazon WorkSpaces Reviewer Amazon HealthLake、Ama CodeGuru zon Kinesis Video Streams、亚马逊应用程序恢复控制器 (ARC)、亚马逊弹性计算云 (亚马逊) Amazon Device Farm、亚马逊 Pinpoin Amazon Identity and Access Management t、(IAM EC2)、亚马逊和亚马逊日志的亚马逊托管工作流程的额外权限。 GuardDuty CloudWatch | 2023 年 2 月 1 日 |
|
AWS_ConfigRole – 添加 airflow:ListTagsForResource, iot:ListCustomMetrics, iot:DescribeCustomMetric, appstream:DescribeDirectoryConfigs, appstream:ListTagsForResource, codeguru-reviewer:DescribeRepositoryAssociation, codeguru-reviewer:ListRepositoryAssociations, healthlake:ListFHIRDatastores, healthlake:DescribeFHIRDatastore, healthlake:ListTagsForResource, kinesisvideo:DescribeStream, kinesisvideo:ListStreams, kinesisvideo:ListTagsForStream, kinesisvideo:DescribeSignalingChannel, kinesisvideo:ListTagsForResource, kinesisvideo:ListSignalingChannels, route53-recovery-control-config:DescribeCluster, route53-recovery-control-config:DescribeRoutingControl, route53-recovery-control-config:DescribeSafetyRule, route53-recovery-control-config:ListClusters, route53-recovery-control-config:ListRoutingControls, route53-recovery-control-config:ListSafetyRules, devicefarm:GetTestGridProject, devicefarm:ListTestGridProjects, ec2:DescribeCapacityReservationFleets, ec2:DescribeIpamPools, ec2:DescribeIpams, ec2:GetInstanceTypesFromInstanceRequirement, mobiletargeting:GetApplicationSettings, mobiletargeting:ListTagsForResource, ecr:BatchGetRepositoryScanningConfiguration, iam:ListServerCertificates, guardduty:ListPublishingDestinations, guardduty:DescribePublishingDestination, logs:GetLogDelivery, and logs:ListLogDeliveries |
该政策现在支持Apache Airflow、Amazon Applications Amazon IoT、Amazon WorkSpaces Reviewer Amazon HealthLake、Ama CodeGuru zon Kinesis Video Streams、亚马逊应用程序恢复控制器 (ARC)、亚马逊弹性计算云 (亚马逊) Amazon Device Farm、亚马逊 Pinpoin Amazon Identity and Access Management t、(IAM EC2)、亚马逊和亚马逊日志的亚马逊托管工作流程的额外权限。 GuardDuty CloudWatch |
2023 年 2 月 1 日 |
|
ConfigConformsServiceRolePolicy – 更新 config:DescribeConfigRules |
作为安全最佳实践,此策略现在取消了对 |
2023 年 1 月 12 日 |
|
AWSConfigServiceRolePolicy – 添加 APS:DescribeRuleGroupsNamespace, APS:DescribeWorkspace, APS:ListWorkspaces, auditmanager:GetAssessment, auditmanager:ListAssessments, devicefarm:GetNetworkProfile, Amazon Transfer Family devicefarm:GetProject, devicefarm:ListNetworkProfiles, devicefarm:ListTagsForResource, dms:DescribeEndpoints, ds:ListTagsForResource, ec2:DescribeTags, ec2:DescribeTrafficMirrorSessions, ec2:DescribeTrafficMirrorTargets, ec2:GetIpamPoolAllocations, ec2:GetIpamPoolCidrs, glue:GetMLTransform, glue:GetMLTransforms, glue:ListMLTransforms, iot:DescribeScheduledAudit, iot:ListScheduledAudits, ivs:GetChannel, lightsail:GetRelationalDatabases, mediapackage-vod:DescribePackagingConfiguration, mediapackage-vod:ListPackagingConfigurations, networkmanager:DescribeGlobalNetworks, networkmanager:GetTransitGatewayRegistrations, networkmanager:ListTagsForResource, quicksight:DescribeDashboard, quicksight:DescribeDashboardPermissions, quicksight:DescribeTemplate, quicksight:DescribeTemplatePermissions, quicksight:ListDashboards, quicksight:ListTemplates, ram:ListResources, route53-recovery-control-config:DescribeControlPanel, route53-recovery-control-config:ListControlPanels, route53-recovery-control-config:ListTagsForResource, route53resolver:GetResolverQueryLogConfigAssociation, route53resolver:ListResolverQueryLogConfigAssociations, s3:GetAccessPointForObjectLambda, s3:GetAccessPointPolicyForObjectLambda, s3:GetAccessPointPolicyStatusForObjectLambda, s3:GetMultiRegionAccessPoint, s3:ListAccessPointsForObjectLambda, s3:ListMultiRegionAccessPoints, timestream:DescribeEndpoints, transfer:DescribeConnector, transfer:ListConnectors, and transfer:ListTagsForResource |
该政策现在支持亚马逊托管服务 Prometheus、、、、、、、、、、亚马逊弹性计算云 Amazon Database Migration Service (亚马逊Amazon DMS) Amazon Audit Manager Amazon Device Farm、、 Amazon Directory Service、Amazon Lightsail、、 Amazon Glue、 EC2 Ama Amazon IoT zon Quick Suite、 AWS Elemental MediaPackage、 Amazon Network Manager亚马逊应用程序恢复控制器 (ARC) Amazon Resource Access Manager、亚马逊简单存储服务 (Amazon S3) 和亚马逊 Timestream 的额外权限。 |
2022 年 12 月 15 日 |
|
AWS_ConfigRole – 添加 APS:DescribeRuleGroupsNamespace, APS:DescribeWorkspace, APS:ListWorkspaces, auditmanager:GetAssessment, auditmanager:ListAssessments, devicefarm:GetNetworkProfile, devicefarm:GetProject, devicefarm:ListNetworkProfiles, devicefarm:ListTagsForResource, dms:DescribeEndpoints, ds:ListTagsForResource, ec2:DescribeTags, ec2:DescribeTrafficMirrorSessions, ec2:DescribeTrafficMirrorTargets, ec2:GetIpamPoolAllocations, ec2:GetIpamPoolCidrs, glue:GetMLTransform, glue:GetMLTransforms, glue:ListMLTransforms, iot:DescribeScheduledAudit, iot:ListScheduledAudits, ivs:GetChannel, lightsail:GetRelationalDatabases, mediapackage-vod:DescribePackagingConfiguration, mediapackage-vod:ListPackagingConfigurations, networkmanager:DescribeGlobalNetworks, networkmanager:GetTransitGatewayRegistrations, networkmanager:ListTagsForResource, quicksight:DescribeDashboard, quicksight:DescribeDashboardPermissions, quicksight:DescribeTemplate, quicksight:DescribeTemplatePermissions, quicksight:ListDashboards, quicksight:ListTemplates, ram:ListResources, route53-recovery-control-config:DescribeControlPanel, route53-recovery-control-config:ListControlPanels, route53-recovery-control-config:ListTagsForResource, route53resolver:GetResolverQueryLogConfigAssociation, route53resolver:ListResolverQueryLogConfigAssociations, s3:GetAccessPointForObjectLambda, s3:GetAccessPointPolicyForObjectLambda, s3:GetAccessPointPolicyStatusForObjectLambda, s3:GetMultiRegionAccessPoint, s3:ListAccessPointsForObjectLambda, s3:ListMultiRegionAccessPoints, timestream:DescribeEndpoints, transfer:DescribeConnector, transfer:ListConnectors, and transfer:ListTagsForResource |
该政策现在支持亚马逊托管服务 Prometheus、、、、、、、、、、亚马逊弹性计算云 Amazon Database Migration Service (亚马逊Amazon DMS) Amazon Audit Manager Amazon Device Farm、、 Amazon Directory Service、Amazon Lightsail、、 Amazon Glue、 EC2 Ama Amazon IoT zon Quick Suite、 AWS Elemental MediaPackage、 Amazon Network Manager亚马逊应用程序恢复控制器 (ARC) Amazon Resource Access Manager、亚马逊简单存储服务 (Amazon S3) 和亚马逊 Timestream 的额外权限。 |
2022 年 12 月 15 日 |
|
AWSConfigServiceRolePolicy – 添加 cloudformation:ListStackResources and cloudformation:ListStacks |
现在,此策略允许返回指定 Amazon CloudFormation 堆栈中所有资源的描述并返回状态与指定StackStatusFilter堆栈的摘要信息。 |
2022 年 11 月 7 日 |
|
AWS_ConfigRole – 添加 cloudformation:ListStackResources and cloudformation:ListStacks |
现在,此策略允许返回指定 Amazon CloudFormation 堆栈中所有资源的描述并返回状态与指定StackStatusFilter堆栈的摘要信息。 |
2022 年 11 月 7 日 |
|
AWSConfigServiceRolePolicy – 添加 acm-pca:GetCertificateAuthorityCsr, acm-pca:ListCertificateAuthorities, acm-pca:ListTags, airflow:GetEnvironment, airflow:ListEnvironments, amplifyuibuilder:ListThemes, appconfig:ListConfigurationProfiles, appconfig:ListDeployments, appconfig:ListDeploymentStrategies, appconfig:ListEnvironments, appconfig:ListHostedConfigurationVersions, cassandra:Select, cloudwatch:DescribeAnomalyDetectors, cloudwatch:GetDashboard, cloudwatch:ListDashboards, connect:DescribePhoneNumber, connect:ListPhoneNumbers, connect:ListPhoneNumbersV2, connect:SearchAvailablePhoneNumbers, databrew:DescribeDataset, databrew:DescribeJob, databrew:DescribeProject, databrew:DescribeRecipe, databrew:DescribeRuleset, databrew:DescribeSchedule, databrew:ListDatasets, databrew:ListJobs, databrew:ListProjects, databrew:ListRecipes, databrew:ListRecipeVersions, databrew:ListRulesets, databrew:ListSchedules, ec2:DescribeRouteTables, eks:DescribeAddon, eks:DescribeIdentityProviderConfig, eks:ListAddons, eks:ListIdentityProviderConfigs, events:DescribeConnection, events:ListApiDestinations, events:ListConnections, fis:GetExperimentTemplate, fis:ListExperimentTemplates, frauddetector:GetRules, fsx:DescribeBackups, fsx:DescribeSnapshots, fsx:DescribeStorageVirtualMachines, gamelift:DescribeMatchmakingRuleSets, gamelift:DescribeVpcPeeringConnections, geo:ListGeofenceCollections, geo:ListPlaceIndexes, geo:ListRouteCalculators, geo:ListTrackers, iot:DescribeAccountAuditConfiguration, iot:DescribeAuthorizer, iot:DescribeDomainConfiguration, iot:DescribeMitigationAction, iot:ListAuthorizers, iot:ListDomainConfigurations, iot:ListMitigationActions, iotsitewise:DescribeAssetModel, iotsitewise:DescribeDashboard, iotsitewise:DescribeGateway, iotsitewise:DescribePortal, iotsitewise:DescribeProject, iotsitewise:ListAssetModels, iotsitewise:ListDashboards, iotsitewise:ListGateways, iotsitewise:ListPortals, iotsitewise:ListProjectAssets, iotsitewise:ListProjects, iotsitewise:ListTagsForResource, iotwireless:GetServiceProfile, iotwireless:GetWirelessDevice, iotwireless:GetWirelessGatewayTaskDefinition, iotwireless:ListServiceProfiles, iotwireless:ListTagsForResource, iotwireless:ListWirelessDevices, iotwireless:ListWirelessGatewayTaskDefinitions, lex:DescribeBotVersion, lex:ListBotVersions, lightsail:GetContainerServices, lightsail:GetDistributions, lightsail:GetRelationalDatabase, lightsail:GetRelationalDatabaseParameters, mobiletargeting:GetApps, mobiletargeting:GetCampaign, mobiletargeting:GetSegment, mobiletargeting:GetSegments, opsworks:DescribeInstances, opsworks:DescribeTimeBasedAutoScaling, opsworks:DescribeVolumes, panorama:DescribeApplicationInstance, panorama:DescribeApplicationInstanceDetails, panorama:DescribePackage, panorama:DescribePackageVersion, panorama:ListApplicationInstances, panorama:ListPackages, quicksight:ListDataSources, ram:ListResourceSharePermissions, rds:DescribeDBProxies, rds:DescribeGlobalClusters, rekognition:ListStreamProcessors, resource-groups:GetGroup, resource-groups:GetGroupConfiguration, resource-groups:GetGroupQuery, resource-groups:GetTags, resource-groups:ListGroupResources, resource-groups:ListGroups, robomaker:ListRobotApplications, robomaker:ListSimulationApplications, route53resolver:GetResolverDnssecConfig, route53resolver:ListResolverDnssecConfigs, s3:ListStorageLensConfigurations, schemas:GetResourcePolicy, servicediscovery:ListInstances, sts:GetCallerIdentity, synthetics:GetGroup, synthetics:ListAssociatedGroups, synthetics:ListGroupResources, and synthetics:ListGroups |
该政策现在支持以下方面的额外权限:Apache Airflow Amazon Certificate Manager、、、亚马逊密钥空间 Amazon Amplify、 Amazon AppConfig亚马逊、Amazon Connect CloudWatch、亚马逊弹性计算云(亚马逊) Amazon Glue DataBrew、亚马逊弹性 Kubernetes 服务( EC2亚马逊 EKS)、亚马逊、、亚马逊欺诈探测器、亚马逊、亚马逊服务器、亚马逊定位服务、、Amazon Lex EventBridge、 Amazon Fault Injection Service Amazon Lightsail FSx、A GameLift mazon Pinpoint Amazon IoT、、、、Amazon Quick Suite、亚马逊关系数据库 Amazon OpsWorks Amazon Panorama Amazon Resource Access Manager服务(亚马逊 RDS)、亚马逊 Amazon RoboMaker Rekognition、、、Amazon Route 53 Amazon Resource Groups、亚马逊简单存储服务 Amazon Cloud Map(Amazon S3) Simple Service 和。 Amazon Security Token Service |
2022 年 10 月 19 日 |
|
AWS_ConfigRole – 添加 acm-pca:GetCertificateAuthorityCsr, acm-pca:ListCertificateAuthorities, acm-pca:ListTags, airflow:GetEnvironment, airflow:ListEnvironments, amplifyuibuilder:ListThemes, appconfig:ListConfigurationProfiles, appconfig:ListDeployments, appconfig:ListDeploymentStrategies, appconfig:ListEnvironments, appconfig:ListHostedConfigurationVersions, cassandra:Select, cloudwatch:DescribeAnomalyDetectors, cloudwatch:GetDashboard, cloudwatch:ListDashboards, connect:DescribePhoneNumber, connect:ListPhoneNumbers, connect:ListPhoneNumbersV2, connect:SearchAvailablePhoneNumbers, databrew:DescribeDataset, databrew:DescribeJob, databrew:DescribeProject, databrew:DescribeRecipe, databrew:DescribeRuleset, databrew:DescribeSchedule, databrew:ListDatasets, databrew:ListJobs, databrew:ListProjects, databrew:ListRecipes, databrew:ListRecipeVersions, databrew:ListRulesets, databrew:ListSchedules, ec2:DescribeRouteTables, eks:DescribeAddon, eks:DescribeIdentityProviderConfig, eks:ListAddons, eks:ListIdentityProviderConfigs, events:DescribeConnection, events:ListApiDestinations, events:ListConnections, fis:GetExperimentTemplate, fis:ListExperimentTemplates, frauddetector:GetRules, fsx:DescribeBackups, fsx:DescribeSnapshots, fsx:DescribeStorageVirtualMachines, gamelift:DescribeMatchmakingRuleSets, gamelift:DescribeVpcPeeringConnections, geo:ListGeofenceCollections, geo:ListPlaceIndexes, geo:ListRouteCalculators, geo:ListTrackers, iot:DescribeAccountAuditConfiguration, iot:DescribeAuthorizer, iot:DescribeDomainConfiguration, iot:DescribeMitigationAction, iot:ListAuthorizers, iot:ListDomainConfigurations, iot:ListMitigationActions, iotsitewise:DescribeAssetModel, iotsitewise:DescribeDashboard, iotsitewise:DescribeGateway, iotsitewise:DescribePortal, iotsitewise:DescribeProject, iotsitewise:ListAssetModels, iotsitewise:ListDashboards, iotsitewise:ListGateways, iotsitewise:ListPortals, iotsitewise:ListProjectAssets, iotsitewise:ListProjects, iotsitewise:ListTagsForResource, iotwireless:GetServiceProfile, iotwireless:GetWirelessDevice, iotwireless:GetWirelessGatewayTaskDefinition, iotwireless:ListServiceProfiles, iotwireless:ListTagsForResource, iotwireless:ListWirelessDevices, iotwireless:ListWirelessGatewayTaskDefinitions, lex:DescribeBotVersion, lex:ListBotVersions, lightsail:GetContainerServices, lightsail:GetDistributions, lightsail:GetRelationalDatabase, lightsail:GetRelationalDatabaseParameters, mobiletargeting:GetApps, mobiletargeting:GetCampaign, mobiletargeting:GetSegment, mobiletargeting:GetSegments, opsworks:DescribeInstances, opsworks:DescribeTimeBasedAutoScaling, opsworks:DescribeVolumes, panorama:DescribeApplicationInstance, panorama:DescribeApplicationInstanceDetails, panorama:DescribePackage, panorama:DescribePackageVersion, panorama:ListApplicationInstances, panorama:ListPackages, quicksight:ListDataSources, ram:ListResourceSharePermissions, rds:DescribeDBProxies, rds:DescribeGlobalClusters, rekognition:ListStreamProcessors, resource-groups:GetGroup, resource-groups:GetGroupConfiguration, resource-groups:GetGroupQuery, resource-groups:GetTags, resource-groups:ListGroupResources, resource-groups:ListGroups, robomaker:ListRobotApplications, robomaker:ListSimulationApplications, route53resolver:GetResolverDnssecConfig, route53resolver:ListResolverDnssecConfigs, s3:ListStorageLensConfigurations, schemas:GetResourcePolicy, servicediscovery:ListInstances, sts:GetCallerIdentity, synthetics:GetGroup, synthetics:ListAssociatedGroups, synthetics:ListGroupResources, and synthetics:ListGroups |
该政策现在支持以下方面的额外权限:Apache Airflow Amazon Certificate Manager、、、亚马逊密钥空间 Amazon Amplify、 Amazon AppConfig亚马逊、Amazon Connect CloudWatch、亚马逊弹性计算云(亚马逊) Amazon Glue DataBrew、亚马逊弹性 Kubernetes 服务( EC2亚马逊 EKS)、亚马逊、、亚马逊欺诈探测器、亚马逊、亚马逊服务器、亚马逊定位服务、、Amazon Lex EventBridge、 Amazon Fault Injection Service Amazon Lightsail FSx、A GameLift mazon Pinpoint Amazon IoT、、、、Amazon Quick Suite、亚马逊关系数据库 Amazon OpsWorks Amazon Panorama Amazon Resource Access Manager服务(亚马逊 RDS)、亚马逊 Amazon RoboMaker Rekognition、、、Amazon Route 53 Amazon Resource Groups、亚马逊简单存储服务 Amazon Cloud Map(Amazon S3) Simple Service 和。 Amazon Security Token Service |
2022 年 10 月 19 日 |
|
AWSConfigServiceRolePolicy – 添加 Glue::GetTable |
现在,此策略授予在数据目录中检索指定 Amazon Glue 表的表定义的权限。 |
2022 年 9 月 14 日 |
|
AWS_ConfigRole – 添加 Glue::GetTable |
现在,此策略授予在数据目录中检索指定 Amazon Glue 表的表定义的权限。 |
2022 年 9 月 14 日 |
|
AWSConfigServiceRolePolicy – 添加 appconfig:ListApplications, appflow:DescribeConnectorProfiles, appsync:GetApiCache, autoscaling-plans:DescribeScalingPlanResources, autoscaling-plans:DescribeScalingPlans, autoscaling-plans:GetScalingPlanResourceForecastData, autoscaling:DescribeWarmPool, backup:DescribeFramework, backup:DescribeReportPlan, backup:ListFrameworks, backup:ListReportPlans, budgets:DescribeBudgetAction, budgets:DescribeBudgetActionsForAccount, budgets:DescribeBudgetActionsForBudget, budgets:ViewBudget, ce:GetAnomalyMonitors, ce:GetAnomalySubscriptions, cloud9:DescribeEnvironmentMemberships, cloud9:DescribeEnvironments, cloud9:ListEnvironments, cloud9:ListTagsForResource, cloudwatch:GetMetricStream, cloudwatch:ListMetricStreams, datasync:DescribeLocationFsxWindows, devops-guru:GetResourceCollection, ds:DescribeDirectories, ec2:DescribeTrafficMirrorFilters, ec2:DescribeTrafficMirrorTargets, ec2:GetNetworkInsightsAccessScopeAnalysisFindings, ec2:GetNetworkInsightsAccessScopeContent, elasticmapreduce:DescribeStudio, elasticmapreduce:GetStudioSessionMapping, elasticmapreduce:ListStudios, elasticmapreduce:ListStudioSessionMappings, events:DescribeEndpoint, events:DescribeEventBus, events:DescribeRule, events:ListArchives, events:ListEndpoints, events:ListEventBuses, events:ListRules, events:ListTagsForResource, events:ListTargetsByRule, finspace:GetEnvironment, finspace:ListEnvironments, frauddetector:GetDetectors, frauddetector:GetDetectorVersion, frauddetector:GetEntityTypes, frauddetector:GetEventTypes, frauddetector:GetExternalModels, frauddetector:GetLabels, frauddetector:GetModels, frauddetector:GetOutcomes, frauddetector:GetVariables, frauddetector:ListTagsForResource, gamelift:DescribeAlias, gamelift:DescribeBuild, gamelift:DescribeFleetAttributes, gamelift:DescribeFleetCapacity, gamelift:DescribeFleetLocationAttributes, gamelift:DescribeFleetLocationCapacity, gamelift:DescribeFleetPortSettings, gamelift:DescribeGameServerGroup, gamelift:DescribeGameSessionQueues, gamelift:DescribeMatchmakingConfigurations, gamelift:DescribeMatchmakingRuleSets, gamelift:DescribeRuntimeConfiguration, gamelift:DescribeScript, gamelift:DescribeVpcPeeringAuthorizations, gamelift:ListAliases, gamelift:ListBuilds, gamelift:ListFleets, gamelift:ListGameServerGroups, gamelift:ListScripts, gamelift:ListTagsForResource, geo:ListMaps, glue:GetClassifier, glue:GetClassifiers, imagebuilder:GetContainerRecipe, imagebuilder:GetImage, imagebuilder:GetImagePipeline, imagebuilder:GetImageRecipe, imagebuilder:ListContainerRecipes, imagebuilder:ListImageBuildVersions, imagebuilder:ListImagePipelines, imagebuilder:ListImageRecipes, imagebuilder:ListImages, iot:DescribeCertificate, iot:DescribeDimension, iot:DescribeRoleAlias, iot:DescribeSecurityProfile, iot:GetPolicy, iot:GetTopicRule, iot:GetTopicRuleDestination, iot:ListCertificates, iot:ListDimensions, iot:ListPolicies, iot:ListRoleAliases, iot:ListSecurityProfiles, iot:ListSecurityProfilesForTarget, iot:ListTagsForResource, iot:ListTargetsForSecurityProfile, iot:ListTopicRuleDestinations, iot:ListTopicRules, iot:ListV2LoggingLevels, iot:ValidateSecurityProfileBehaviors, iotanalytics:DescribeChannel, iotanalytics:DescribeDataset, iotanalytics:DescribeDatastore, iotanalytics:DescribePipeline, iotanalytics:ListChannels, iotanalytics:ListDatasets, iotanalytics:ListDatastores, iotanalytics:ListPipelines, iotanalytics:ListTagsForResource, iotevents:DescribeAlarmModel, iotevents:DescribeDetectorModel, iotevents:DescribeInput, iotevents:ListAlarmModels, iotevents:ListDetectorModels, iotevents:ListInputs, iotevents:ListTagsForResource, iotsitewise:DescribeAccessPolicy, iotsitewise:DescribeAsset, iotsitewise:ListAccessPolicies, iotsitewise:ListAssets, iottwinmaker:GetEntity, iottwinmaker:GetScene, iottwinmaker:GetWorkspace, iottwinmaker:ListEntities, iottwinmaker:ListScenes, iottwinmaker:ListTagsForResource, iottwinmaker:ListWorkspaces, ivs:GetPlaybackKeyPair, ivs:GetRecordingConfiguration, ivs:GetStreamKey, ivs:ListChannels, ivs:ListPlaybackKeyPairs, ivs:ListRecordingConfigurations, ivs:ListStreamKeys, ivs:ListTagsForResource, kinesisanalytics:ListApplications, lakeformation:DescribeResource, lakeformation:GetDataLakeSettings, lakeformation:ListPermissions, lakeformation:ListResources, lex:DescribeBot, lex:DescribeBotAlias, lex:DescribeResourcePolicy, lex:ListBotAliases, lex:ListBotLocales, lex:ListBots, lex:ListTagsForResource, license-manager:GetGrant, license-manager:GetLicense, license-manager:ListDistributedGrants, license-manager:ListLicenses, license-manager:ListReceivedGrants, lightsail:GetAlarms, lightsail:GetBuckets, lightsail:GetCertificates, lightsail:GetDisk, lightsail:GetDisks, lightsail:GetInstance, lightsail:GetInstances, lightsail:GetKeyPair, lightsail:GetLoadBalancer, lightsail:GetLoadBalancers, lightsail:GetLoadBalancerTlsCertificates, lightsail:GetStaticIp, lightsail:GetStaticIps, lookoutequipment:DescribeInferenceScheduler, lookoutequipment:ListTagsForResource, lookoutmetrics:DescribeAlert, lookoutmetrics:DescribeAnomalyDetector, lookoutmetrics:ListAlerts, lookoutmetrics:ListAnomalyDetectors, lookoutmetrics:ListMetricSets, lookoutmetrics:ListTagsForResource, lookoutvision:DescribeProject, lookoutvision:ListProjects, managedblockchain:GetMember, managedblockchain:GetNetwork, managedblockchain:GetNode, managedblockchain:ListInvitations, managedblockchain:ListMembers, managedblockchain:ListNodes, mediapackage-vod:DescribePackagingGroup, mediapackage-vod:ListPackagingGroups, mediapackage-vod:ListTagsForResource, mobiletargeting:GetInAppTemplate, mobiletargeting:ListTemplates, mq:DescribeBroker, mq:ListBrokers, nimble:GetLaunchProfile, nimble:GetLaunchProfileDetails, nimble:GetStreamingImage, nimble:GetStudio, nimble:GetStudioComponent, nimble:ListLaunchProfiles, nimble:ListStreamingImages, nimble:ListStudioComponents, nimble:ListStudios, profile:GetDomain, profile:GetIntegration, profile:GetProfileObjectType, profile:ListDomains, profile:ListIntegrations, profile:ListProfileObjectTypes, profile:ListTagsForResource, quicksight:DescribeAnalysis, quicksight:DescribeAnalysisPermissions, quicksight:DescribeDataSet, quicksight:DescribeDataSetPermissions, quicksight:DescribeTheme, quicksight:DescribeThemePermissions, quicksight:ListAnalyses, quicksight:ListDataSets, quicksight:ListThemes, resiliencehub:DescribeApp, resiliencehub:DescribeAppVersionTemplate, resiliencehub:DescribeResiliencyPolicy, resiliencehub:ListApps, resiliencehub:ListAppVersionResourceMappings, resiliencehub:ListResiliencyPolicies, route53-recovery-readiness:GetCell, route53-recovery-readiness:GetReadinessCheck, route53-recovery-readiness:GetRecoveryGroup, route53-recovery-readiness:GetResourceSet, route53-recovery-readiness:ListCells, route53-recovery-readiness:ListReadinessChecks, route53-recovery-readiness:ListRecoveryGroups, route53-recovery-readiness:ListResourceSets, route53resolver:GetFirewallDomainList, route53resolver:GetFirewallRuleGroup, route53resolver:GetFirewallRuleGroupAssociation, route53resolver:GetResolverQueryLogConfig, route53resolver:ListFirewallDomainLists, route53resolver:ListFirewallDomains, route53resolver:ListFirewallRuleGroupAssociations, route53resolver:ListFirewallRuleGroups, route53resolver:ListFirewallRules, route53resolver:ListResolverQueryLogConfigs, rum:GetAppMonitor, rum:GetAppMonitorData, rum:ListAppMonitors, rum:ListTagsForResource, s3-outposts:GetAccessPoint, s3-outposts:GetAccessPointPolicy, s3-outposts:GetBucket, s3-outposts:GetBucketPolicy, s3-outposts:GetBucketTagging, s3-outposts:GetLifecycleConfiguration, s3-outposts:ListAccessPoints, s3-outposts:ListEndpoints, s3-outposts:ListRegionalBuckets, schemas:DescribeDiscoverer, schemas:DescribeRegistry, schemas:DescribeSchema, schemas:ListDiscoverers, schemas:ListRegistries, schemas:ListSchemas, sdb:GetAttributes, sdb:ListDomains, ses:ListEmailTemplates, ses:ListReceiptFilters, ses:ListReceiptRuleSets, ses:ListTemplates, signer:GetSigningProfile, signer:ListProfilePermissions, signer:ListSigningProfiles, synthetics:DescribeCanaries, synthetics:DescribeCanariesLastRun, synthetics:DescribeRuntimeVersions, synthetics:GetCanary, synthetics:GetCanaryRuns, synthetics:ListTagsForResource, timestream:DescribeDatabase, timestream:DescribeTable, timestream:ListDatabases, timestream:ListTables, timestream:ListTagsForResource, transfer:DescribeServer, transfer:DescribeUser, transfer:DescribeWorkflow, transfer:ListServers, transfer:ListUsers, transfer:ListWorkflows, voiceid:DescribeDomain, and voiceid:ListTagsForResource |
该政策现在支持亚马逊 AppFlow、亚马逊、亚马 CloudWatch逊 R CloudWatch UM、Amazon S CloudWatch ynthetics、Amazon Connect 客户档案、Amazon Connect 语音识别码、亚马逊 DevOps Guru、亚马逊弹性计算云(亚马逊)、Amazon Aut EC2 o Scaling EC2、亚马逊 EMR、亚马逊 EMR、亚马逊 Fraud Detector、亚马逊 GameLift 服务器、亚马逊交互式视频服务 ( EventBridge亚马逊 IVS) 的额外权限) Interactive Servic EventBridge e、适用于 Apache Flink 的亚马逊托管服务、Image Builder、Amazon Lex、Amazon Lightsail、 Amazon FinSpace EC2 亚马逊定位服务、亚马逊 Lookout for Equipment、亚马逊 Lookout for Metrics、亚马逊 Lookout for Vision、亚马逊托管区块链、亚马逊 MQ、亚马逊 Nimble Pinp StudioAmazon oint、亚马逊快速套件、亚马逊应用程序恢复控制器 (ARC Amazon Route 53 Resolver)、亚马逊简单存储服务 (Amazon S3)、亚马逊 SimpleDB、亚马逊简单电子邮件服务 (Amazon SES)、亚马逊 Timestream、、、、、、、、、、、、、、、、、、、、、、、、、、、、 Amazon AppConfig Amazon AppSync Amazon Auto Scaling Amazon Backup Amazon Budgets Amazon Cost Explorer Amazon Cloud9 Amazon Directory Service Amazon DataSync AWS Elemental MediaPackage Amazon Glue Amazon IoT Amazon IoT Analytics Amazon IoT Events Amazon IoT SiteWise、 Amazon IoT TwinMaker、 Amazon Lake Formation、 Amazon License Manager、 Amazon Resilience Hub、 Amazon Signer、和 Amazon Transfer Family。 |
2022 年 9 月 7 日 |
|
AWS_ConfigRole – 添加 appconfig:ListApplications, appflow:DescribeConnectorProfiles, appsync:GetApiCache, autoscaling-plans:DescribeScalingPlanResources, autoscaling-plans:DescribeScalingPlans, autoscaling-plans:GetScalingPlanResourceForecastData, autoscaling:DescribeWarmPool, backup:DescribeFramework, backup:DescribeReportPlan, backup:ListFrameworks, backup:ListReportPlans, budgets:DescribeBudgetAction, budgets:DescribeBudgetActionsForAccount, budgets:DescribeBudgetActionsForBudget, budgets:ViewBudget, ce:GetAnomalyMonitors, ce:GetAnomalySubscriptions, cloud9:DescribeEnvironmentMemberships, cloud9:DescribeEnvironments, cloud9:ListEnvironments, cloud9:ListTagsForResource, cloudwatch:GetMetricStream, cloudwatch:ListMetricStreams, datasync:DescribeLocationFsxWindows, devops-guru:GetResourceCollection, ds:DescribeDirectories, ec2:DescribeTrafficMirrorTargets, ec2:GetNetworkInsightsAccessScopeAnalysisFindings, ec2:GetNetworkInsightsAccessScopeContent, elasticmapreduce:DescribeStudio, elasticmapreduce:GetStudioSessionMapping, elasticmapreduce:ListStudios, elasticmapreduce:ListStudioSessionMappings, events:DescribeEndpoint, events:DescribeEventBus, events:DescribeRule, events:ListArchives, events:ListEndpoints, events:ListEventBuses, events:ListRules, events:ListTagsForResource, events:ListTargetsByRule, finspace:GetEnvironment, finspace:ListEnvironments, frauddetector:GetDetectors, frauddetector:GetDetectorVersion, frauddetector:GetEntityTypes, frauddetector:GetEventTypes, frauddetector:GetExternalModels, frauddetector:GetLabels, frauddetector:GetModels, frauddetector:GetOutcomes, frauddetector:GetVariables, frauddetector:ListTagsForResource, gamelift:DescribeAlias, gamelift:DescribeBuild, gamelift:DescribeFleetAttributes, gamelift:DescribeFleetCapacity, gamelift:DescribeFleetLocationAttributes, gamelift:DescribeFleetLocationCapacity, gamelift:DescribeFleetPortSettings, gamelift:DescribeGameServerGroup, gamelift:DescribeGameSessionQueues, gamelift:DescribeMatchmakingConfigurations, gamelift:DescribeMatchmakingRuleSets, gamelift:DescribeRuntimeConfiguration, gamelift:DescribeScript, gamelift:DescribeVpcPeeringAuthorizations, gamelift:ListAliases, gamelift:ListBuilds, gamelift:ListFleets, gamelift:ListGameServerGroups, gamelift:ListScripts, gamelift:ListTagsForResource, geo:ListMaps, glue:GetClassifier, glue:GetClassifiers, imagebuilder:GetContainerRecipe, imagebuilder:GetImage, imagebuilder:GetImagePipeline, imagebuilder:GetImageRecipe, imagebuilder:ListContainerRecipes, imagebuilder:ListImageBuildVersions, imagebuilder:ListImagePipelines, imagebuilder:ListImageRecipes, imagebuilder:ListImages, iot:DescribeCertificate, iot:DescribeDimension, iot:DescribeRoleAlias, iot:DescribeSecurityProfile, iot:GetPolicy, iot:GetTopicRule, iot:GetTopicRuleDestination, iot:ListCertificates, iot:ListDimensions, iot:ListPolicies, iot:ListRoleAliases, iot:ListSecurityProfiles, iot:ListSecurityProfilesForTarget, iot:ListTagsForResource, iot:ListTargetsForSecurityProfile, iot:ListTopicRuleDestinations, iot:ListTopicRules, iot:ListV2LoggingLevels, iot:ValidateSecurityProfileBehaviors, iotanalytics:DescribeChannel, iotanalytics:DescribeDataset, iotanalytics:DescribeDatastore, iotanalytics:DescribePipeline, iotanalytics:ListChannels, iotanalytics:ListDatasets, iotanalytics:ListDatastores, iotanalytics:ListPipelines, iotanalytics:ListTagsForResource, iotevents:DescribeAlarmModel, iotevents:DescribeDetectorModel, iotevents:DescribeInput, iotevents:ListAlarmModels, iotevents:ListDetectorModels, iotevents:ListInputs, iotevents:ListTagsForResource, iotsitewise:DescribeAccessPolicy, iotsitewise:DescribeAsset, iotsitewise:ListAccessPolicies, iotsitewise:ListAssets, iottwinmaker:GetEntity, iottwinmaker:GetScene, iottwinmaker:GetWorkspace, iottwinmaker:ListEntities, iottwinmaker:ListScenes, iottwinmaker:ListTagsForResource, iottwinmaker:ListWorkspaces, ivs:GetPlaybackKeyPair, ivs:GetRecordingConfiguration, ivs:GetStreamKey, ivs:ListChannels, ivs:ListPlaybackKeyPairs, ivs:ListRecordingConfigurations, ivs:ListStreamKeys, ivs:ListTagsForResource, kinesisanalytics:ListApplications, lakeformation:DescribeResource, lakeformation:GetDataLakeSettings, lakeformation:ListPermissions, lakeformation:ListResources, lex:DescribeBot, lex:DescribeBotAlias, lex:DescribeResourcePolicy, lex:ListBotAliases, lex:ListBotLocales, lex:ListBots, lex:ListTagsForResource, license-manager:GetGrant, license-manager:GetLicense, license-manager:ListDistributedGrants, license-manager:ListLicenses, license-manager:ListReceivedGrants, lightsail:GetAlarms, lightsail:GetBuckets, lightsail:GetCertificates, lightsail:GetDisk, lightsail:GetDisks, lightsail:GetInstance, lightsail:GetInstances, lightsail:GetKeyPair, lightsail:GetLoadBalancer, lightsail:GetLoadBalancers, lightsail:GetLoadBalancerTlsCertificates, lightsail:GetStaticIp, lightsail:GetStaticIps, lookoutequipment:DescribeInferenceScheduler, lookoutequipment:ListTagsForResource, lookoutmetrics:DescribeAlert, lookoutmetrics:DescribeAnomalyDetector, lookoutmetrics:ListAlerts, lookoutmetrics:ListAnomalyDetectors, lookoutmetrics:ListMetricSets, lookoutmetrics:ListTagsForResource, lookoutvision:DescribeProject, lookoutvision:ListProjects, managedblockchain:GetMember, managedblockchain:GetNetwork, managedblockchain:GetNode, managedblockchain:ListInvitations, managedblockchain:ListMembers, managedblockchain:ListNodes, mediapackage-vod:DescribePackagingGroup, mediapackage-vod:ListPackagingGroups, mediapackage-vod:ListTagsForResource, mobiletargeting:GetInAppTemplate, mobiletargeting:ListTemplates, mq:DescribeBroker, mq:ListBrokers, nimble:GetLaunchProfile, nimble:GetLaunchProfileDetails, nimble:GetStreamingImage, nimble:GetStudio, nimble:GetStudioComponent, nimble:ListLaunchProfiles, nimble:ListStreamingImages, nimble:ListStudioComponents, nimble:ListStudios, profile:GetDomain, profile:GetIntegration, profile:GetProfileObjectType, profile:ListDomains, profile:ListIntegrations, profile:ListProfileObjectTypes, profile:ListTagsForResource, quicksight:DescribeAnalysis, quicksight:DescribeAnalysisPermissions, quicksight:DescribeDataSet, quicksight:DescribeDataSetPermissions, quicksight:DescribeTheme, quicksight:DescribeThemePermissions, quicksight:ListAnalyses, quicksight:ListDataSets, quicksight:ListThemes, resiliencehub:DescribeApp, resiliencehub:DescribeAppVersionTemplate, resiliencehub:DescribeResiliencyPolicy, resiliencehub:ListApps, resiliencehub:ListAppVersionResourceMappings, resiliencehub:ListResiliencyPolicies, route53-recovery-readiness:GetCell, route53-recovery-readiness:GetReadinessCheck, route53-recovery-readiness:GetRecoveryGroup, route53-recovery-readiness:GetResourceSet, route53-recovery-readiness:ListCells, route53-recovery-readiness:ListReadinessChecks, route53-recovery-readiness:ListRecoveryGroups, route53-recovery-readiness:ListResourceSets, route53resolver:GetFirewallDomainList, route53resolver:GetFirewallRuleGroup, route53resolver:GetFirewallRuleGroupAssociation, route53resolver:GetResolverQueryLogConfig, route53resolver:ListFirewallDomainLists, route53resolver:ListFirewallDomains, route53resolver:ListFirewallRuleGroupAssociations, route53resolver:ListFirewallRuleGroups, route53resolver:ListFirewallRules, route53resolver:ListResolverQueryLogConfigs, rum:GetAppMonitor, rum:GetAppMonitorData, rum:ListAppMonitors, rum:ListTagsForResource, s3-outposts:GetAccessPoint, s3-outposts:GetAccessPointPolicy, s3-outposts:GetBucket, s3-outposts:GetBucketPolicy, s3-outposts:GetBucketTagging, s3-outposts:GetLifecycleConfiguration, s3-outposts:ListAccessPoints, s3-outposts:ListEndpoints, s3-outposts:ListRegionalBuckets, schemas:DescribeDiscoverer, schemas:DescribeRegistry, schemas:DescribeSchema, schemas:ListDiscoverers, schemas:ListRegistries, schemas:ListSchemas, sdb:GetAttributes, sdb:ListDomains, ses:ListEmailTemplates, ses:ListReceiptFilters, ses:ListReceiptRuleSets, ses:ListTemplates, signer:GetSigningProfile, signer:ListProfilePermissions, signer:ListSigningProfiles, synthetics:DescribeCanaries, synthetics:DescribeCanariesLastRun, synthetics:DescribeRuntimeVersions, synthetics:GetCanary, synthetics:GetCanaryRuns, synthetics:ListTagsForResource, timestream:DescribeDatabase, timestream:DescribeTable, timestream:ListDatabases, timestream:ListTables, timestream:ListTagsForResource, transfer:DescribeServer, transfer:DescribeUser, transfer:DescribeWorkflow, transfer:ListServers, transfer:ListUsers, transfer:ListWorkflows, voiceid:DescribeDomain, and voiceid:ListTagsForResource |
该政策现在支持亚马逊 AppFlow、亚马逊、亚马 CloudWatch逊 R CloudWatch UM、Amazon S CloudWatch ynthetics、Amazon Connect 客户档案、Amazon Connect 语音识别码、亚马逊 DevOps Guru、亚马逊弹性计算云(亚马逊)、Amazon Aut EC2 o Scaling EC2、亚马逊 EMR、亚马逊 EMR、亚马逊 Fraud Detector、亚马逊 GameLift 服务器、亚马逊交互式视频服务 ( EventBridge亚马逊 IVS) 的额外权限) Interactive Servic EventBridge e、适用于 Apache Flink 的亚马逊托管服务、Image Builder、Amazon Lex、Amazon Lightsail、 Amazon FinSpace EC2 亚马逊定位服务、亚马逊 Lookout for Equipment、亚马逊 Lookout for Metrics、亚马逊 Lookout for Vision、亚马逊托管区块链、亚马逊 MQ、亚马逊 Nimble Pinp StudioAmazon oint、亚马逊快速套件、亚马逊应用程序恢复控制器 (ARC Amazon Route 53 Resolver)、亚马逊简单存储服务 (Amazon S3)、亚马逊 SimpleDB、亚马逊简单电子邮件服务 (Amazon SES)、亚马逊 Timestream、、、、、、、、、、、、、、、、、、、、、、、、、、、、 Amazon AppConfig Amazon AppSync Amazon Auto Scaling Amazon Backup Amazon Budgets Amazon Cost Explorer Amazon Cloud9 Amazon Directory Service Amazon DataSync AWS Elemental MediaPackage Amazon Glue Amazon IoT Amazon IoT Analytics Amazon IoT Events Amazon IoT SiteWise、 Amazon IoT TwinMaker、 Amazon Lake Formation、 Amazon License Manager、 Amazon Resilience Hub、 Amazon Signer、和 Amazon Transfer Family |
2022 年 9 月 7 日 |
|
AWSConfigServiceRolePolicy – 添加 datasync:ListAgents, datasync:ListLocations, datasync:ListTasks, servicediscovery:ListNamespaces, servicediscovery:ListServices, and ses:ListContactLists |
此策略现在允许返回中 Amazon DataSync 代理人、 DataSync 来源和目标位置以及 DataSync 任务的列表 Amazon Web Services 账户;列出与中一个或多个指定命名空间关联的 Amazon Cloud Map 命名空间和服务的摘要信息 Amazon Web Services 账户;以及列出中所有可用的 Amazon Simple Email Service (Amazon SES) 联系人列表。 Amazon Web Services 账户 |
2022 年 8 月 22 日 |
|
AWS_ConfigRole – 添加 datasync:ListAgents, datasync:ListLocations, datasync:ListTasks, servicediscovery:ListNamespaces, servicediscovery:ListServices, and ses:ListContactLists |
此策略现在允许返回中 Amazon DataSync 代理人、 DataSync 来源和目标位置以及 DataSync 任务的列表 Amazon Web Services 账户;列出与中一个或多个指定命名空间关联的 Amazon Cloud Map 命名空间和服务的摘要信息 Amazon Web Services 账户;以及列出中所有可用的 Amazon Simple Email Service (Amazon SES) 联系人列表。 Amazon Web Services 账户 |
2022 年 8 月 22 日 |
|
ConfigConformsServiceRolePolicy – 添加 cloudwatch:PutMetricData |
该政策现在授予向 Amazon 发布指标数据点的权限 CloudWatch。 |
2022 年 7 月 25 日 |
|
AWSConfigServiceRolePolicy – 添加 amplifyuibuilder:ExportThemes, amplifyuibuilder:GetTheme, appconfig:GetApplication, appconfig:GetApplication, appconfig:GetConfigurationProfile, appconfig:GetConfigurationProfile, appconfig:GetDeployment, appconfig:GetDeploymentStrategy, appconfig:GetEnvironment, appconfig:GetHostedConfigurationVersion, appconfig:ListTagsForResource, appsync:GetGraphqlApi, appsync:ListGraphqlApis, billingconductor: ListPricingRulesAssociatedToPricingPlan, billingconductor:ListAccountAssociations, billingconductor:ListBillingGroups, billingconductor:ListCustomLineItems, billingconductor:ListPricingPlans, billingconductor:ListPricingRules, billingconductor:ListTagsForResource, datasync:DescribeAgent, datasync:DescribeLocationEfs, datasync:DescribeLocationFsxLustre, datasync:DescribeLocationHdfs, datasync:DescribeLocationNfs, datasync:DescribeLocationObjectStorage, datasync:DescribeLocationS3, datasync:DescribeLocationSmb, datasync:DescribeTask, datasync:ListTagsForResource, ecr:DescribePullThroughCacheRules, ecr:DescribeRegistry, ecr:GetRegistryPolicy, elasticache:DescribeCacheParameters, elasticloadbalancing:DescribeListenerCertificates, elasticloadbalancing:DescribeTargetGroupAttributes, elasticloadbalancing:DescribeTargetGroups, elasticloadbalancing:DescribeTargetHealth, events:DescribeApiDestination, events:DescribeArchive, fms:GetNotificationChannel, fms:GetPolicy, fms:ListPolicies, fms:ListTagsForResource, fsx:DescribeVolumes, geo:DescribeGeofenceCollection, geo:DescribeMap, geo:DescribePlaceIndex, geo:DescribeRouteCalculator, geo:DescribeTracker, geo:ListTrackerConsumers, glue:BatchGetJobs, glue:BatchGetWorkflows, glue:GetCrawler, glue:GetCrawlers, glue:GetJob, glue:GetJobs, glue:GetWorkflow, imagebuilder: GetComponent, imagebuilder: ListComponentBuildVersions, imagebuilder: ListComponents, imagebuilder:GetDistributionConfiguration, imagebuilder:GetInfrastructureConfiguration, imagebuilder:ListDistributionConfigurations, imagebuilder:ListInfrastructureConfigurations, kafka:DescribeClusterV2, kafka:ListClustersV2, kinesisanalytics:DescribeApplication, kinesisanalytics:ListTagsForResource, quicksight:DescribeDataSource, quicksight:DescribeDataSourcePermissions, quicksight:ListTagsForResource, rekognition:DescribeStreamProcessor, rekognition:ListTagsForResource, robomaker:DescribeRobotApplication, robomaker:DescribeSimulationApplication, s3:GetStorageLensConfiguration, s3:GetStorageLensConfigurationTagging, servicediscovery:GetInstance, servicediscovery:GetNamespace, servicediscovery:GetService, servicediscovery:ListTagsForResource, ses:DescribeReceiptRule, ses:DescribeReceiptRuleSet, ses:GetContactList, ses:GetEmailTemplate, ses:GetTemplate, and sso:GetInlinePolicyForPermissionSet |
该政策现在支持亚马逊弹性容器服务 (Amazon ECS)、亚马逊、亚马逊、亚马逊、亚马逊、适用于 A ElastiCache pache Flink 的亚马逊托管服务 FSx、亚马逊定位服务、适用于 Apache Kafka 的亚马逊托管流媒体、亚马逊 Quick Suite、亚马逊 Rekognition、亚马逊简单存储服务 (Amazon S3) 的额外权限 Service、 Amazon RoboMaker亚马逊简单电子邮件服务 (Amazon SES)、、、、、、、、、、(IAM 身份中心) Amazon Amplify Amazon DataSync、 Amazon Firewall Manager Image Bu Amazon AppConfig il Amazon AppSync der 和 Elastic Load EventBridge Amazon Billing Conductor Amazon Glue Amazon IAM Identity Center EC2 平衡。 |
2022 年 7 月 15 日 |
|
AWS_ConfigRole – 添加 amplifyuibuilder:ExportThemes, amplifyuibuilder:GetTheme, appconfig:GetApplication, appconfig:GetApplication, appconfig:GetConfigurationProfile, appconfig:GetConfigurationProfile, appconfig:GetDeployment, appconfig:GetDeploymentStrategy, appconfig:GetEnvironment, appconfig:GetHostedConfigurationVersion, appconfig:ListTagsForResource, appsync:GetGraphqlApi, appsync:ListGraphqlApis, billingconductor: ListPricingRulesAssociatedToPricingPlan, billingconductor:ListAccountAssociations, billingconductor:ListBillingGroups, billingconductor:ListCustomLineItems, billingconductor:ListPricingPlans, billingconductor:ListPricingRules, billingconductor:ListTagsForResource, datasync:DescribeAgent, datasync:DescribeLocationEfs, datasync:DescribeLocationFsxLustre, datasync:DescribeLocationHdfs, datasync:DescribeLocationNfs, datasync:DescribeLocationObjectStorage, datasync:DescribeLocationS3, datasync:DescribeLocationSmb, datasync:DescribeTask, datasync:ListTagsForResource, ecr:DescribePullThroughCacheRules, ecr:DescribeRegistry, ecr:GetRegistryPolicy, elasticache:DescribeCacheParameters, elasticloadbalancing:DescribeListenerCertificates, elasticloadbalancing:DescribeTargetGroupAttributes, elasticloadbalancing:DescribeTargetGroups, elasticloadbalancing:DescribeTargetHealth, events:DescribeApiDestination, events:DescribeArchive, fms:GetNotificationChannel, fms:GetPolicy, fms:ListPolicies, fms:ListTagsForResource, fsx:DescribeVolumes, geo:DescribeGeofenceCollection, geo:DescribeMap, geo:DescribePlaceIndex, geo:DescribeRouteCalculator, geo:DescribeTracker, geo:ListTrackerConsumers, glue:BatchGetJobs, glue:BatchGetWorkflows, glue:GetCrawler, glue:GetCrawlers, glue:GetJob, glue:GetJobs, glue:GetWorkflow, imagebuilder: GetComponent, imagebuilder: ListComponentBuildVersions, imagebuilder: ListComponents, imagebuilder:GetDistributionConfiguration, imagebuilder:GetInfrastructureConfiguration, imagebuilder:ListDistributionConfigurations, imagebuilder:ListInfrastructureConfigurations, kafka:DescribeClusterV2, kafka:ListClustersV2, kinesisanalytics:DescribeApplication, kinesisanalytics:ListTagsForResource, quicksight:DescribeDataSource, quicksight:DescribeDataSourcePermissions, quicksight:ListTagsForResource, rekognition:DescribeStreamProcessor, rekognition:ListTagsForResource, robomaker:DescribeRobotApplication, robomaker:DescribeSimulationApplication, s3:GetStorageLensConfiguration, s3:GetStorageLensConfigurationTagging, servicediscovery:GetInstance, servicediscovery:GetNamespace, servicediscovery:GetService, servicediscovery:ListTagsForResource, ses:DescribeReceiptRule, ses:DescribeReceiptRuleSet, ses:GetContactList, ses:GetEmailTemplate, ses:GetTemplate, and sso:GetInlinePolicyForPermissionSet |
该政策现在支持亚马逊弹性容器服务 (Amazon ECS)、亚马逊、亚马逊、亚马逊、亚马逊、适用于 A ElastiCache pache Flink 的亚马逊托管服务 FSx、亚马逊定位服务、适用于 Apache Kafka 的亚马逊托管流媒体、亚马逊 Quick Suite、亚马逊 Rekognition、亚马逊简单存储服务 (Amazon S3) 的额外权限 Service、 Amazon RoboMaker亚马逊简单电子邮件服务 (Amazon SES)、、、、、、、、、、(IAM 身份中心) Amazon Amplify Amazon DataSync、 Amazon Firewall Manager Image Bu Amazon AppConfig il Amazon AppSync der 和 Elastic Load EventBridge Amazon Billing Conductor Amazon Glue Amazon IAM Identity Center EC2 平衡。 |
2022 年 7 月 15 日 |
|
AWSConfigServiceRolePolicy – 添加 athena:GetDataCatalog, athena:ListDataCatalogs, athena:ListTagsForResource, detective:ListGraphs, detective:ListTagsForResource, glue:BatchGetDevEndpoints, glue:GetDevEndpoint, glue:GetDevEndpoints, glue:GetSecurityConfiguration, glue:GetSecurityConfigurations, glue:GetTags glue:GetWorkGroup, glue:ListCrawlers, glue:ListDevEndpoints, glue:ListJobs, glue:ListMembers, glue:ListWorkflows, glue:ListWorkGroups, guardduty:GetFilter, guardduty:GetIPSet, guardduty:GetThreatIntelSet, guardduty:GetMembers, guardduty:ListFilters, guardduty:ListIPSets, guardduty:ListTagsForResource, guardduty:ListThreatIntelSets, macie:GetMacieSession, ram:GetResourceShareAssociations, ram:GetResourceShares, ses:GetConfigurationSet, ses:GetConfigurationSetEventDestinations, ses:ListConfigurationSets, sso:DescribeInstanceAccessControlAttributeConfiguration, sso:DescribePermissionSet, sso:ListManagedPoliciesInPermissionSet, sso:ListPermissionSets, and sso:ListTagsForResource |
此政策现在授予以下权限:获取指定的 Amazon Athena 数据目录 Amazon Web Services 账户、在中列出 Athena 数据目录以及列出与 Athena 工作组或数据目录资源关联的标签;获取 Amazon Detective 行为图列表并列出侦探行为图的标签;获取给定开发终端节点名称列表的资源元数据列表,获取有关指定开发的信息端点,获取所有开发端点,检索 Amazon Glue 指定的安全 Amazon Glue Amazon Glue
Amazon Web Services 账户 Amazon Glue 配置,获取所有 Amazon Glue 安全配置,获取与 Amazon Glue 资源关联的标签列表,获取有关具有指定名称 Amazon Glue 的工作组的信息,检索 Amazon
账户中所有 Amazon Glue 爬虫资源的名称,获取中所有 Amazon Glue |
2022 年 5 月 31 日 |
|
AWS_ConfigRole – 添加 athena:GetDataCatalog, athena:ListDataCatalogs, athena:ListTagsForResource, detective:ListGraphs, detective:ListTagsForResource, glue:BatchGetDevEndpoints, glue:GetDevEndpoint, glue:GetDevEndpoints, glue:GetSecurityConfiguration, glue:GetSecurityConfigurations, glue:GetTags glue:GetWorkGroup, glue:ListCrawlers, glue:ListDevEndpoints, glue:ListJobs, glue:ListMembers, glue:ListWorkflows, glue:ListWorkGroups, guardduty:GetFilter, guardduty:GetIPSet, guardduty:GetThreatIntelSet, guardduty:GetMembers, guardduty:ListFilters, guardduty:ListIPSets, guardduty:ListTagsForResource, guardduty:ListThreatIntelSets, macie:GetMacieSession, ram:GetResourceShareAssociations, ram:GetResourceShares, ses:GetConfigurationSet, ses:GetConfigurationSetEventDestinations, ses:ListConfigurationSets, sso:DescribeInstanceAccessControlAttributeConfiguration, sso:DescribePermissionSet, sso:ListManagedPoliciesInPermissionSet, sso:ListPermissionSets, and sso:ListTagsForResource |
此政策现在授予以下权限:获取指定的 Amazon Athena 数据目录 Amazon Web Services 账户、在中列出 Athena 数据目录以及列出与 Athena 工作组或数据目录资源关联的标签;获取 Amazon Detective 行为图列表并列出侦探行为图的标签;获取给定开发终端节点名称列表的资源元数据列表,获取有关指定开发的信息端点,获取所有开发端点,检索 Amazon Glue 指定的安全 Amazon Glue Amazon Glue
Amazon Web Services 账户 Amazon Glue 配置,获取所有 Amazon Glue 安全配置,获取与 Amazon Glue 资源关联的标签列表,获取有关具有指定名称 Amazon Glue 的工作组的信息,检索 Amazon
账户中所有 Amazon Glue 爬虫资源的名称,获取中所有 Amazon Glue |
2022 年 5 月 31 日 |
|
AWSConfigServiceRolePolicy – 添加 cloudformation:GetResource, cloudformation:ListResources, cloudtrail:GetEventDataStore, cloudtrail:ListEventDataStores, dax:DescribeParameterGroups, dax:DescribeParameters, dax:DescribeSubnetGroups, DMS:DescribeReplicationTasks, and organizations:ListPolicies |
此策略现在授予以下权限:获取有关所有或指定 Amazon CloudTrail 事件数据存储 (EDS) 的信息、获取有关全部或指定 Amazon CloudFormation 资源的信息、获取 DynamoDB 加速器 (DAX) 参数组或子网组的列表、获取 Amazon Database Migration Service 有关当前正在访问的区域中您的账户的Amazon DMS() 复制任务的信息,以及获取指定类型的所有策略的列表。 Amazon Organizations |
2022 年 4 月 7 日 |
|
AWS_ConfigRole – 添加 cloudformation:GetResource, cloudformation:ListResources, cloudtrail:GetEventDataStore, cloudtrail:ListEventDataStores, dax:DescribeParameterGroups, dax:DescribeParameters, dax:DescribeSubnetGroups, DMS:DescribeReplicationTasks, and organizations:ListPolicies |
此策略现在授予以下权限:获取有关所有或指定 Amazon CloudTrail 事件数据存储 (EDS) 的信息、获取有关全部或指定 Amazon CloudFormation 资源的信息、获取 DynamoDB 加速器 (DAX) 参数组或子网组的列表、获取 Amazon Database Migration Service 有关当前正在访问的区域中您的账户的Amazon DMS() 复制任务的信息,以及获取指定类型的所有策略的列表。 Amazon Organizations |
2022 年 4 月 7 日 |
|
AWSConfigServiceRolePolicy – 添加 backup-gateway:ListTagsForResource, backup-gateway:ListVirtualMachines, batch:DescribeComputeEnvironments, batch:DescribeJobQueues, batch:ListTagsForResource, dax:ListTags, dms:DescribeCertificates, dynamodb:DescribeGlobalTable, dynamodb:DescribeGlobalTableSettings, ec2:DescribeClientVpnAuthorizationRules, ec2:DescribeClientVpnEndpoints, ec2:DescribeDhcpOptions, ec2:DescribeFleets, ec2:DescribeNetworkAcls, ec2:DescribePlacementGroups, ec2:DescribeSpotFleetRequests, ec2:DescribeVolumeAttribute, ec2:DescribeVolumes, eks:DescribeFargateProfile, eks:ListFargateProfiles, eks:ListTagsForResource, fsx:ListTagsForResource, guardduty:ListOrganizationAdminAccounts, kms:ListAliases, opsworks:DescribeLayers, opsworks:DescribeStacks, opsworks:ListTags, rds:DescribeDBClusterParameterGroups, rds:DescribeDBClusterParameters, states:DescribeActivity, states:ListActivities, wafv2:GetRuleGroup, wafv2:ListRuleGroups, wafv2:ListTagsForResource, workspaces:DescribeConnectionAliases, workspaces:DescribeTags, and workspaces:DescribeWorkspaces |
该策略现在支持、、DynamoDB 加速器 Amazon Backup Amazon Batch、亚马逊 DynamoDB、 Amazon Database Migration Service亚马逊弹性计算云( EC2亚马逊)、亚马逊 Elastic Kubernetes Service、亚马逊、、、、亚马逊关系数据库服务、V2 和 FSx亚马逊的额外权限。 GuardDuty Amazon Key Management Service Amazon OpsWorks Amazon WAF WorkSpaces |
2022 年 3 月 14 日 |
|
AWS_ConfigRole – 添加 backup-gateway:ListTagsForResource, backup-gateway:ListVirtualMachines, batch:DescribeComputeEnvironments, batch:DescribeJobQueues, batch:ListTagsForResource, dax:ListTags, dms:DescribeCertificates, dynamodb:DescribeGlobalTable, dynamodb:DescribeGlobalTableSettings, ec2:DescribeClientVpnAuthorizationRules, ec2:DescribeClientVpnEndpoints, ec2:DescribeDhcpOptions, ec2:DescribeFleets, ec2:DescribeNetworkAcls, ec2:DescribePlacementGroups, ec2:DescribeSpotFleetRequests, ec2:DescribeVolumeAttribute, ec2:DescribeVolumes, eks:DescribeFargateProfile, eks:ListFargateProfiles, eks:ListTagsForResource, fsx:ListTagsForResource, guardduty:ListOrganizationAdminAccounts, kms:ListAliases, opsworks:DescribeLayers, opsworks:DescribeStacks, opsworks:ListTags, rds:DescribeDBClusterParameterGroups, rds:DescribeDBClusterParameters, states:DescribeActivity, states:ListActivities, wafv2:GetRuleGroup, wafv2:ListRuleGroups, wafv2:ListTagsForResource, workspaces:DescribeConnectionAliases, workspaces:DescribeTags, and workspaces:DescribeWorkspaces |
该策略现在支持、、DynamoDB 加速器 Amazon Backup Amazon Batch、亚马逊 DynamoDB、 Amazon Database Migration Service亚马逊弹性计算云( EC2亚马逊)、亚马逊 Elastic Kubernetes Service、亚马逊、、、、亚马逊关系数据库服务、V2 和 FSx亚马逊的额外权限。 GuardDuty Amazon Key Management Service Amazon OpsWorks Amazon WAF WorkSpaces |
2022 年 3 月 14 日 |
|
AWSConfigServiceRolePolicy – 添加 elasticbeanstalk:DescribeEnvironments, elasticbeanstalk:DescribeConfigurationSettings, account:GetAlternateContact, organizations:DescribePolicy, organizations:ListParents, organizations:ListPoliciesForTarget, es:GetCompatibleElasticsearchVersions, rds:DescribeOptionGroups, rds:DescribeOptionGroups, es:GetCompatibleVersions, codedeploy:GetDeploymentConfig, ecr-public:GetRepositoryPolicy, access-analyzer:GetArchiveRule, and ecs:ListTaskDefinitionFamilies |
现在,该策略允许获取有关 Elastic Beanstalk 环境的详细信息以及指定 Elastic Beanstalk 配置集的设置描述、获取或 Elasticsearch 版本 OpenSearch 的地图、描述数据库可用的 Amazon RDS 选项组以及获取有关部署配置的信息。 CodeDeploy 该策略现在还授予以下权限:检索附加到的指定备用联系人 Amazon Web Services 账户、检索有关 Amazon Organizations 策略的信息、检索 Amazon ECR 存储库策略、检索有关存档 Amazon Config 规则的信息、检索 Amazon ECS 任务定义系列列表、列出指定子 OU 或账户的根或上级组织单位 (OUs),以及列出附加到指定目标根目录、组织单位或账户的策略。 |
2022 年 2 月 10 日 |
|
AWS_ConfigRole – 添加 elasticbeanstalk:DescribeEnvironments, elasticbeanstalk:DescribeConfigurationSettings, account:GetAlternateContact, organizations:DescribePolicy, organizations:ListParents, organizations:ListPoliciesForTarget, es:GetCompatibleElasticsearchVersions, rds:DescribeOptionGroups, rds:DescribeOptionGroups, es:GetCompatibleVersions, codedeploy:GetDeploymentConfig, ecr-public:GetRepositoryPolicy, access-analyzer:GetArchiveRule, and ecs:ListTaskDefinitionFamilies |
现在,该策略允许获取有关 Elastic Beanstalk 环境的详细信息以及指定 Elastic Beanstalk 配置集的设置描述、获取或 Elasticsearch 版本 OpenSearch 的地图、描述数据库可用的 Amazon RDS 选项组以及获取有关部署配置的信息。 CodeDeploy 该策略现在还授予以下权限:检索附加到的指定备用联系人 Amazon Web Services 账户、检索有关 Amazon Organizations 策略的信息、检索 Amazon ECR 存储库策略、检索有关存档 Amazon Config 规则的信息、检索 Amazon ECS 任务定义系列列表、列出指定子 OU 或账户的根或上级组织单位 (OUs),以及列出附加到指定目标根目录、组织单位或账户的策略。 |
2022 年 2 月 10 日 |
|
AWSConfigServiceRolePolicy – 添加 logs:CreateLogStream, logs:CreateLogGroup, and logs:PutLogEvent |
该策略现在授予创建 Amazon CloudWatch 日志组和流以及向已创建的日志流写入日志的权限。 |
2021 年 12 月 15 日 |
|
AWS_ConfigRole – 添加 logs:CreateLogStream, logs:CreateLogGroup, and logs:PutLogEvent |
该策略现在授予创建 Amazon CloudWatch 日志组和流以及向已创建的日志流写入日志的权限。 |
2021 年 12 月 15 日 |
|
AWSConfigServiceRolePolicy – 添加 es:DescribeDomain, es:DescribeDomains, rds:DescribeDBParameters, and, elasticache:DescribeSnapshots |
该策略现在授予获取有关亚马逊 OpenSearch 服务(OpenSearch 服务)的详细信息 domain/domains 以及获取特定亚马逊关系数据库服务 (Amazon RDS) 数据库参数组的详细参数列表的权限。该政策还授予获取有关Ama ElastiCache zon快照的详细信息的权限。 |
2021 年 9 月 8 日 |
|
AWS_ConfigRole – 添加 es:DescribeDomain, es:DescribeDomains, rds:DescribeDBParameters, and, elasticache:DescribeSnapshots |
该策略现在授予获取有关亚马逊 OpenSearch 服务(OpenSearch 服务)的详细信息 domain/domains 以及获取特定亚马逊关系数据库服务 (Amazon RDS) 数据库参数组的详细参数列表的权限。该政策还授予获取有关Ama ElastiCache zon快照的详细信息的权限。 |
2021 年 9 月 8 日 |
|
AWSConfigServiceRolePolicy— 添加logs:ListTagsLogGroup, states:ListTagsForResource, states:ListStateMachines, states:DescribeStateMachine Amazon 资源类型以及其他权限 |
此策略现在授予列出日志组的标签,列出状态机的标签,以及列出所有状态机的权限。此策略现在授予获取有关状态机的详细信息的权限。该政策现在还支持亚马逊 EC2 系统管理器 (SSM)、亚马逊弹性容器注册表、亚马逊、亚马逊数据 Firehose FSx、亚马逊管理流媒体 Kafka(亚马逊 MSK)、亚马逊关系数据库服务(亚马逊 RDS)、亚马逊 Route 53、亚马逊 AI SageMaker 、亚马逊简单通知服务、和。 Amazon Database Migration Service Amazon Global Accelerator Amazon Storage Gateway |
2021 年 7 月 28 日 |
|
AWS_ConfigRole— 添加 l ogs:ListTagsLogGroup, states:ListTagsForResource, states:ListStateMachines, states:DescribeStateMachine 以及 Amazon 资源类型的其他权限 |
此策略现在授予列出日志组的标签,列出状态机的标签,以及列出所有状态机的权限。此策略现在授予获取有关状态机的详细信息的权限。该政策现在还支持亚马逊 EC2 系统管理器 (SSM)、亚马逊弹性容器注册表、亚马逊、亚马逊数据 Firehose FSx、亚马逊管理流媒体 Kafka(亚马逊 MSK)、亚马逊关系数据库服务(亚马逊 RDS)、亚马逊 Route 53、亚马逊 AI SageMaker 、亚马逊简单通知服务、和。 Amazon Database Migration Service Amazon Global Accelerator Amazon Storage Gateway |
2021 年 7 月 28 日 |
|
AWSConfigServiceRolePolicy— 为 Amazon 资源类型添加ssm:DescribeDocumentPermission权限和其他权限 |
此策略现在授予查看有关 IAM Access Analyzer 的 Amazon Systems Manager 文档和信息的权限。该政策现在支持亚马逊 Kinesis、亚马逊、亚马逊 EMR、 ElastiCache亚马逊 Route 53 和 Amazon Network Firewall亚马逊关系数据库服务 (Amazon RDS) 的其他 Amazon 资源类型。这些权限更改 Amazon Config 允许调用支持这些资源类型APIs 所需的只读权限。此策略现在还支持筛选lambda-inside-vpc Amazon Config 托管规则的 Lambda @Edge 函数。 |
2021 年 6 月 8 日 |
|
AWS_ConfigRole— 为 Amazon 资源类型添加ssm:DescribeDocumentPermission权限和其他权限 |
此策略现在授予查看有关 IAM Access Analyzer 的 Amazon Systems Manager 文档和信息的权限。该政策现在支持亚马逊 Kinesis、亚马逊、亚马逊 EMR、 ElastiCache亚马逊 Route 53 和 Amazon Network Firewall亚马逊关系数据库服务 (Amazon RDS) 的其他 Amazon 资源类型。这些权限更改 Amazon Config 允许调用支持这些资源类型APIs 所需的只读权限。此策略现在还支持筛选lambda-inside-vpc Amazon Config 托管规则的 Lambda @Edge 函数。 |
2021 年 6 月 8 日 |
|
AWSConfigServiceRolePolicy— 添加apigateway:GET对 API Gateway 进行只读 GET 调用的s3:GetAccessPointPolicys3:GetAccessPointPolicyStatus权限以及只读调用 Amazon S3 的权限和权限 APIs |
现在,此策略授予 Amazon Config 允许对 API Gateway 进行只读 GET 调用的权限,以支持 API 网关的 Amazon Config 规则。该策略还增加了允许 Amazon Config 以 APIs只读方式调用 Amazon Simple Storage Service (Amazon S3) 的权限,这些权限是支持 |
2021 年 5 月 10 日 |
|
AWS_ConfiGrole — 添加apigateway:GET对 API Gateway 进行只读 GET 调用的s3:GetAccessPointPolicy权限以及只读调用 Amazon S3 的s3:GetAccessPointPolicyStatus权限和权限 APIs |
现在,此策略授予的权限 Amazon Config 允许对 API Gateway 进行只读 GET 调用, Amazon Config 以支持 API 网关。该策略还增加了允许 Amazon Config 以 APIs只读方式调用 Amazon Simple Storage Service (Amazon S3) 的权限,这些权限是支持 |
2021 年 5 月 10 日 |
|
AWSConfigServiceRolePolicy— 为 Amazon 资源类型添加ssm:ListDocuments权限和其他权限 |
此策略现在授予查看有关 Amazon Systems Manager 指定文档信息的权限 该政策现在还支持亚马逊弹性文件系统 Amazon Backup、亚马逊、亚马逊简单存储服务 (Amazon S3) ElastiCache、亚马逊弹性计算云 (亚马逊)、Amazon Kinesis、Amazon AI 和 EC2亚马逊 SageMaker Route 53 的其他 Amazon 资源类型。 Amazon Database Migration Service这些权限更改 Amazon Config 允许调用支持这些资源类型 APIs 所需的只读权限。 |
2021 年 4 月 1 日 |
|
AWS_ConfigRole— 为 Amazon 资源类型添加ssm:ListDocuments权限和其他权限 |
此策略现在授予查看有关 Amazon Systems Manager 指定文档信息的权限 该政策现在还支持亚马逊弹性文件系统 Amazon Backup、亚马逊、亚马逊简单存储服务 (Amazon S3) ElastiCache、亚马逊弹性计算云 (亚马逊)、Amazon Kinesis、Amazon AI 和 EC2亚马逊 SageMaker Route 53 的其他 Amazon 资源类型。 Amazon Database Migration Service这些权限更改 Amazon Config 允许调用支持这些资源类型 APIs 所需的只读权限。 |
2021 年 4 月 1 日 |
|
|
|
2021 年 4 月 1 日 |
|
Amazon Config 已开始跟踪更改 |
Amazon Config 开始跟踪其 Amazon 托管策略的更改。 |
2021 年 4 月 1 日 |