Reviewing shared CloudWatch dashboard permissions and changing permission scope
Use the steps in this section if you want to review the permissions of the users of your shared dashboards, or change the scope of shared dashboard permissions.
To review shared dashboard permissions
Open the CloudWatch console at https://console.amazonaws.cn/cloudwatch/
. In the navigation pane, choose Dashboards.
Choose the name of the shared dashboard.
Choose Actions, Share dashboard.
Under Resources, choose IAM Role.
In the IAM console, choose the displayed policy.
(Optional) To limit which alarms that shared dashboard users can see, choose Edit policy and move the
cloudwatch:DescribeAlarmspermission from its current position to a newAllowstatement that lists the ARNs of only the alarms that you want to be seen by shared dashboard users. See the following example.{ "Effect": "Allow", "Action": "cloudwatch:DescribeAlarms", "Resource": [ "AlarmARN1", "AlarmARN2" ] }If you do this, be sure to remove the
cloudwatch:DescribeAlarmspermission from a section of the current policy that looks like this:{ "Effect": "Allow", "Action": [ "cloudwatch:GetInsightRuleReport", "cloudwatch:GetMetricData", "cloudwatch:DescribeAlarms", "ec2:DescribeTags" ], "Resource": "*" }(Optional) To limit the scope of what Contributor Insights rules that shared dashboard users can see, choose Edit policy and move the
cloudwatch:GetInsightRuleReportfrom its current position to a newAllowstatement that lists the ARNs of only the Contributor Insights rules that you want to be seen by shared dashboard users. See the following example.{ "Effect": "Allow", "Action": "cloudwatch:GetInsightRuleReport", "Resource": [ "PublicContributorInsightsRuleARN1", "PublicContributorInsightsRuleARN2" ] }If you do this, be sure to remove
cloudwatch:GetInsightRuleReportfrom a section of the current policy that looks like this:{ "Effect": "Allow", "Action": [ "cloudwatch:GetInsightRuleReport", "cloudwatch:GetMetricData", "cloudwatch:DescribeAlarms", "ec2:DescribeTags" ], "Resource": "*" }