AWSConfigRemediation-EnableAPIGatewayTracing
Description
The
AWSConfigRemediation-EnableAPIGatewayTracing
runbook enables
tracing on an Amazon API Gateway (API Gateway) stage. Amazon Config must be enabled in the Amazon Web Services Region
where you run this automation.
Document type
Automation
Owner
Amazon
Platforms
Linux, macOS, Windows
Parameters
-
AutomationAssumeRole
Type: String
Allowed values: ^arn:(?:aws|aws-us-gov|aws-cn):iam::\d{12}:role\/[\w+=,.@/-]+$
Description: (Required) The Amazon Resource Name (ARN) of the Amazon Identity and Access Management (IAM) role that allows Systems Manager Automation to perform the actions on your behalf.
-
StageArn
Type: String
Description: (Required) The Amazon Resource Name (ARN) of the API Gateway stage you want to enable tracing on.
Required IAM permissions
The AutomationAssumeRole
parameter requires the following actions to
successfully use the runbook.
-
ssm:GetAutomationExecution
-
ssm:StartAutomationExecution
-
config:GetResourceConfigHistory
-
apigateway:GET
-
apigateway:PATCH
Document Steps
-
aws:executeScript
- Enables tracing on the API Gateway stage specified in theStageArn
parameter.