

本文属于机器翻译版本。若本译文内容与英语原文存在差异，则一律以英文原文为准。

# Sy Amazon stems Manager 的操作、资源和条件键
<a name="list_awssystemsmanager"></a>

Amazon Systems Manager（服务前缀:`ssm`）提供以下特定于服务的资源、操作和条件上下文密钥，供在 IAM 权限策略中使用。

参考：
+ 了解如何[配置该服务](https://docs.amazonaws.cn/systems-manager/latest/userguide/what-is-systems-manager.html)。
+ 查看[适用于该服务的 API 操作列表](https://docs.amazonaws.cn/systems-manager/latest/APIReference/Welcome.html)。
+ 了解如何[使用 IAM](https://docs.amazonaws.cn/systems-manager/latest/userguide/security-iam.html) 权限策略保护该服务及其资源。

**Topics**
+ [由 S Amazon ystems Manager 定义的操作](#awssystemsmanager-actions-as-permissions)
+ [由 S Amazon ystems Manager 定义的资源类型](#awssystemsmanager-resources-for-iam-policies)
+ [Sy Amazon stems Manager 的条件密钥](#awssystemsmanager-policy-keys)

## 由 S Amazon ystems Manager 定义的操作
<a name="awssystemsmanager-actions-as-permissions"></a>

您可以在 IAM 策略语句的 `Action` 元素中指定以下操作。可以使用策略授予在 Amazon中执行操作的权限。您在策略中使用一项操作时，通常使用相同的名称允许或拒绝对 API 操作或 CLI 命令的访问。但在某些情况下，单一动作可控制对多项操作的访问。还有某些操作需要多种不同的动作。

操作表的**访问级别**列描述如何对操作进行分类（列出、读取、权限管理或标记）。此分类可以帮助您了解当您在策略中使用操作时，相应操作授予的访问级别。有关访问级别的更多信息，请参阅[策略摘要中的访问级别](https://docs.amazonaws.cn/IAM/latest/UserGuide/access_policies_understand-policy-summary-access-level-summaries.html)。

操作表的**资源类型**列指示每项操作是否支持资源级权限。如果该列没有任何值，您必须在策略语句的 `Resource` 元素中指定策略应用的所有资源（“\*”）。通过在 IAM policy 中使用条件来筛选访问权限，以控制是否可以在资源或请求中使用特定标签键。如果操作具有一个或多个必需资源，则调用方必须具有使用这些资源来使用该操作的权限。必需资源在表中以星号 (\*) 表示。如果您在 IAM policy 中使用 `Resource` 元素限制资源访问权限，则必须为每种必需的资源类型添加 ARN 或模式。某些操作支持多种资源类型。如果资源类型是可选的（未指示为必需），则可以选择使用一种可选资源类型。

操作表的**条件键**列包括可以在策略语句的 `Condition` 元素中指定的键。有关与服务资源关联的条件键的更多信息，请参阅资源类型表的**条件键**列。

操作表的**依赖操作**列显示成功调用操作可能需要的其他权限。除了操作本身的权限以外，可能还需要这些权限。若某个操作指定依赖操作，则这些依赖关系可能适用于为该操作定义的其他资源，而不仅仅是表中列出的第一个资源。

**注意**  
资源条件键在[资源类型](#awssystemsmanager-resources-for-iam-policies)表中列出。您可以在操作表的**资源类型（\* 为必需）**列中找到应用于某项操作的资源类型的链接。资源类型表中的资源类型包括**条件密钥**列，这是应用于操作表中操作的资源条件键。

有关下表中各列的详细信息，请参阅[操作表](reference_policies_actions-resources-contextkeys.html#actions_table)。


****  


- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_AddTagsToResource.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_AddTagsToResource.html) **
  - **描述:** 授予为指定 Amazon 资源添加或覆盖一个或多个标签的权限
  - **访问级别:** 标签
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-association](#awssystemsmanager-association)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-automation-execution](#awssystemsmanager-automation-execution)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-document](#awssystemsmanager-document)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-instance](#awssystemsmanager-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-maintenancewindow](#awssystemsmanager-maintenancewindow)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-managed-instance](#awssystemsmanager-managed-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-opsitem](#awssystemsmanager-opsitem)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-opsmetadata](#awssystemsmanager-opsmetadata)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-parameter](#awssystemsmanager-parameter)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-patchbaseline](#awssystemsmanager-patchbaseline)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-task](#awssystemsmanager-task)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_) <br /> [#awssystemsmanager-aws_RequestTag___TagKey_](#awssystemsmanager-aws_RequestTag___TagKey_) <br /> [#awssystemsmanager-aws_TagKeys](#awssystemsmanager-aws_TagKeys)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_AssociateOpsItemRelatedItem.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_AssociateOpsItemRelatedItem.html) **
  - **描述:** 授予与关联 RelatedItem 的权限 OpsItem
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-opsitem](#awssystemsmanager-opsitem) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_CancelCommand.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_CancelCommand.html) **
  - **描述:** 授予权限以取消指定的 Run Command 命令
  - **访问级别:** Write
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_CancelMaintenanceWindowExecution.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_CancelMaintenanceWindowExecution.html) **
  - **描述:** 授予权限以取消进行中的维护时段执行
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-maintenancewindow](#awssystemsmanager-maintenancewindow) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_CreateActivation.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_CreateActivation.html) **
  - **描述:** 授予权限以创建用于将本地服务器和虚拟机 (VM) 注册到 Systems Manager 的激活
  - **访问级别:** Write
  - **资源类型（\* 为必需）:** 
  - **条件键:**  [#awssystemsmanager-aws_RequestTag___TagKey_](#awssystemsmanager-aws_RequestTag___TagKey_) <br /> [#awssystemsmanager-aws_TagKeys](#awssystemsmanager-aws_TagKeys) 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_CreateAssociation.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_CreateAssociation.html) **
  - **描述:** 授予权限以将指定的 Systems Manager 文档与指定的实例或其他目标关联
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-association](#awssystemsmanager-association)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-document](#awssystemsmanager-document)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-instance](#awssystemsmanager-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-managed-instance](#awssystemsmanager-managed-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_) <br /> [#awssystemsmanager-aws_RequestTag___TagKey_](#awssystemsmanager-aws_RequestTag___TagKey_) <br /> [#awssystemsmanager-aws_TagKeys](#awssystemsmanager-aws_TagKeys)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_CreateAssociationBatch.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_CreateAssociationBatch.html) **
  - **描述:** 授予在单个命令中合并多个 CreateAssociation 操作条目的权限
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-document](#awssystemsmanager-document)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-instance](#awssystemsmanager-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-managed-instance](#awssystemsmanager-managed-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_) <br /> [#awssystemsmanager-aws_RequestTag___TagKey_](#awssystemsmanager-aws_RequestTag___TagKey_) <br /> [#awssystemsmanager-aws_TagKeys](#awssystemsmanager-aws_TagKeys)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_CreateDocument.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_CreateDocument.html) **
  - **描述:** 授予权限以创建 Systems Manager SSM 文档
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-document](#awssystemsmanager-document)  / **条件键:**  / **相关操作:**  iam:PassRole 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-aws_RequestTag___TagKey_](#awssystemsmanager-aws_RequestTag___TagKey_) <br /> [#awssystemsmanager-aws_TagKeys](#awssystemsmanager-aws_TagKeys) <br /> [#awssystemsmanager-ssm_DocumentType](#awssystemsmanager-ssm_DocumentType)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_CreateMaintenanceWindow.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_CreateMaintenanceWindow.html) **
  - **描述:** 授予权限以创建维护时段
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:** 
  - **条件键:**  [#awssystemsmanager-aws_RequestTag___TagKey_](#awssystemsmanager-aws_RequestTag___TagKey_) <br /> [#awssystemsmanager-aws_TagKeys](#awssystemsmanager-aws_TagKeys) 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_CreateOpsItem.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_CreateOpsItem.html) **
  - **描述:** 授予 OpsItem 在中创建的权限 OpsCenter
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:** 
  - **条件键:**  [#awssystemsmanager-aws_RequestTag___TagKey_](#awssystemsmanager-aws_RequestTag___TagKey_) <br /> [#awssystemsmanager-aws_TagKeys](#awssystemsmanager-aws_TagKeys) 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_CreateOpsMetadata.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_CreateOpsMetadata.html) **
  - **描述:** 授予为 Amazon 资源创建 OpsMetadata 对象的权限
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:** 
  - **条件键:**  [#awssystemsmanager-aws_RequestTag___TagKey_](#awssystemsmanager-aws_RequestTag___TagKey_) <br /> [#awssystemsmanager-aws_TagKeys](#awssystemsmanager-aws_TagKeys) 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_CreatePatchBaseline.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_CreatePatchBaseline.html) **
  - **描述:** 授予权限以创建修补程序基准
  - **访问级别:** Write
  - **资源类型（\* 为必需）:** 
  - **条件键:**  [#awssystemsmanager-aws_RequestTag___TagKey_](#awssystemsmanager-aws_RequestTag___TagKey_) <br /> [#awssystemsmanager-aws_TagKeys](#awssystemsmanager-aws_TagKeys) 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_CreateResourceDataSync.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_CreateResourceDataSync.html) **
  - **描述:** 授予权限以创建资源数据同步配置，该配置定期从托管实例收集清单数据并更新 Amazon S3 存储桶中的数据
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-resourcedatasync](#awssystemsmanager-resourcedatasync)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-ssm_SyncType](#awssystemsmanager-ssm_SyncType)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DeleteActivation.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DeleteActivation.html) **
  - **描述:** 授予权限以删除托管实例的指定激活
  - **访问级别:** Write
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DeleteAssociation.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DeleteAssociation.html) **
  - **描述:** 授予权限以从指定实例解除与指定 SSM 文档的关联
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-association](#awssystemsmanager-association)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-document](#awssystemsmanager-document)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-instance](#awssystemsmanager-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-managed-instance](#awssystemsmanager-managed-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DeleteDocument.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DeleteDocument.html) **
  - **描述:** 授予权限以删除指定 SSM 文档及其实例关联
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-document](#awssystemsmanager-document)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-ssm_DocumentType](#awssystemsmanager-ssm_DocumentType)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DeleteInventory.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DeleteInventory.html) **
  - **描述:** 授予权限以删除指定的自定义清单类型或者与自定义清单类型关联的数据
  - **访问级别:** Write
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DeleteMaintenanceWindow.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DeleteMaintenanceWindow.html) **
  - **描述:** 授予权限以删除指定的维护时段
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-maintenancewindow](#awssystemsmanager-maintenancewindow) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DeleteOpsItem.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DeleteOpsItem.html) **
  - **描述:** 授予删除的权限 OpsItem
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-opsitem](#awssystemsmanager-opsitem) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DeleteOpsMetadata.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DeleteOpsMetadata.html) **
  - **描述:** 授予删除 OpsMetadata 对象的权限
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-opsmetadata](#awssystemsmanager-opsmetadata) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DeleteParameter.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DeleteParameter.html) **
  - **描述:** 授予权限以删除一个指定的 SSM 参数
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-parameter](#awssystemsmanager-parameter)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DeleteParameters.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DeleteParameters.html) **
  - **描述:** 授予权限以删除多个指定的 SSM 参数
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-parameter](#awssystemsmanager-parameter)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DeletePatchBaseline.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DeletePatchBaseline.html) **
  - **描述:** 授予权限以删除指定的补丁基准
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-patchbaseline](#awssystemsmanager-patchbaseline) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DeleteResourceDataSync.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DeleteResourceDataSync.html) **
  - **描述:** 授予权限以删除指定的资源数据同步
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-resourcedatasync](#awssystemsmanager-resourcedatasync)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-ssm_SyncType](#awssystemsmanager-ssm_SyncType)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DeleteResourcePolicy.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DeleteResourcePolicy.html) **
  - **描述:** 授予删除 Systems Manager 资源策略的权限
  - **访问级别:** 权限管理
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-document](#awssystemsmanager-document)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-opsitemgroup](#awssystemsmanager-opsitemgroup)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-parameter](#awssystemsmanager-parameter)  / **条件键:**  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DeregisterManagedInstance.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DeregisterManagedInstance.html) **
  - **描述:** 授予权限以从 Systems Manager 取消注册指定的本地服务器或虚拟机 (VM)
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-managed-instance](#awssystemsmanager-managed-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-ssm_resourceTag_tag-key](#awssystemsmanager-ssm_resourceTag_tag-key)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DeregisterPatchBaselineForPatchGroup.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DeregisterPatchBaselineForPatchGroup.html) **
  - **描述:** 授予权限以便为指定的补丁组取消注册作为默认补丁基准的指定补丁基准
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-patchbaseline](#awssystemsmanager-patchbaseline) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DeregisterTargetFromMaintenanceWindow.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DeregisterTargetFromMaintenanceWindow.html) **
  - **描述:** 授予权限以从维护时段取消注册指定的目标
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-maintenancewindow](#awssystemsmanager-maintenancewindow)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-windowtarget](#awssystemsmanager-windowtarget)  / **条件键:**  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DeregisterTaskFromMaintenanceWindow.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DeregisterTaskFromMaintenanceWindow.html) **
  - **描述:** 授予权限以从维护时段取消注册指定的任务
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-maintenancewindow](#awssystemsmanager-maintenancewindow)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-windowtask](#awssystemsmanager-windowtask)  / **条件键:**  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeActivations.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeActivations.html) **
  - **描述:** 授予权限以查看有关指定托管实例激活的详细信息，例如其创建时间和使用激活注册的实例数
  - **访问级别:** Read
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeAssociation.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeAssociation.html) **
  - **描述:** 授予权限以查看指定实例或目标的指定关联的相关详细信息
  - **访问级别:** Read
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-association](#awssystemsmanager-association)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-document](#awssystemsmanager-document)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-instance](#awssystemsmanager-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-managed-instance](#awssystemsmanager-managed-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeAssociationExecutionTargets.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeAssociationExecutionTargets.html) **
  - **描述:** 授予权限以查看有关指定关联执行情况的信息
  - **访问级别:** Read
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-association](#awssystemsmanager-association)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeAssociationExecutions.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeAssociationExecutions.html) **
  - **描述:** 授予权限以查看指定关联的所有执行
  - **访问级别:** Read
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-association](#awssystemsmanager-association)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeAutomationExecutions.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeAutomationExecutions.html) **
  - **描述:** 授予权限以查看所有活动和已终止的 Automation 执行的相关详细信息
  - **访问级别:** Read
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeAutomationStepExecutions.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeAutomationStepExecutions.html) **
  - **描述:** 授予权限以查看 Automation 工作流程中所有活动和已终止的步骤执行信息
  - **访问级别:** Read
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-automation-execution](#awssystemsmanager-automation-execution) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeAvailablePatches.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeAvailablePatches.html) **
  - **描述:** 授予权限以查看符合包含在补丁基准中的条件的所有补丁
  - **访问级别:** Read
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeDocument.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeDocument.html) **
  - **描述:** 授予权限以查看有关指定 SSM 文档的详细信息
  - **访问级别:** Read
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-document](#awssystemsmanager-document)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-ssm_DocumentType](#awssystemsmanager-ssm_DocumentType)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/userguide/systems-manager-setting-up-messageAPIs.html](https://docs.amazonaws.cn/systems-manager/latest/userguide/systems-manager-setting-up-messageAPIs.html) **
  - **描述:** 授予权限以在 Systems Manager 控制台中显示有关 SSM 文档参数的信息（内部 Systems Manager 操作）
  - **访问级别:** Read
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-document](#awssystemsmanager-document) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeDocumentPermission.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeDocumentPermission.html) **
  - **描述:** 授予权限以查看指定 SSM 文档的权限
  - **访问级别:** Read
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-document](#awssystemsmanager-document)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-ssm_DocumentType](#awssystemsmanager-ssm_DocumentType)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeEffectiveInstanceAssociations.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeEffectiveInstanceAssociations.html) **
  - **描述:** 授予权限以查看指定实例的所有当前关联
  - **访问级别:** Read
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-instance](#awssystemsmanager-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-managed-instance](#awssystemsmanager-managed-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeEffectivePatchesForPatchBaseline.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeEffectivePatchesForPatchBaseline.html) **
  - **描述:** 授予权限以查看当前与指定补丁基准关联的补丁的相关详细信息（仅 Windows）
  - **访问级别:** Read
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-patchbaseline](#awssystemsmanager-patchbaseline) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeInstanceAssociationsStatus.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeInstanceAssociationsStatus.html) **
  - **描述:** 授予权限以查看指定实例的关联的状态
  - **访问级别:** Read
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-instance](#awssystemsmanager-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-managed-instance](#awssystemsmanager-managed-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeInstanceInformation.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeInstanceInformation.html) **
  - **描述:** 授予权限以查看有关指定实例的详细信息
  - **访问级别:** Read
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeInstancePatchStates.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeInstancePatchStates.html) **
  - **描述:** 授予权限以查看指定实例上有关补丁的状态详细信息
  - **访问级别:** Read
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-instance](#awssystemsmanager-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-managed-instance](#awssystemsmanager-managed-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_) <br /> [#awssystemsmanager-ssm_resourceTag___TagKey_](#awssystemsmanager-ssm_resourceTag___TagKey_)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeInstancePatchStatesForPatchGroup.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeInstancePatchStatesForPatchGroup.html) **
  - **描述:** 授予权限以描述指定修补程序组中实例的高级修补程序状态
  - **访问级别:** Read
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeInstancePatches.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeInstancePatches.html) **
  - **描述:** 授予权限以查看有关指定实例上补丁的一般详细信息
  - **访问级别:** Read
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-instance](#awssystemsmanager-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-managed-instance](#awssystemsmanager-managed-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_) <br /> [#awssystemsmanager-ssm_resourceTag___TagKey_](#awssystemsmanager-ssm_resourceTag___TagKey_)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/userguide/systems-manager-setting-up-messageAPIs.html](https://docs.amazonaws.cn/systems-manager/latest/userguide/systems-manager-setting-up-messageAPIs.html) **
  - **描述:** 向用户的 Amazon EC2 控制台授予权限以呈现托管实例节点
  - **访问级别:** Read
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeInventoryDeletions.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeInventoryDeletions.html) **
  - **描述:** 授予权限以查看有关指定库存删除的详细信息
  - **访问级别:** Read
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeMaintenanceWindowExecutionTaskInvocations.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeMaintenanceWindowExecutionTaskInvocations.html) **
  - **描述:** 授予权限以查看某个维护时段的指定任务执行的详细信息
  - **访问级别:** List
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeMaintenanceWindowExecutionTasks.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeMaintenanceWindowExecutionTasks.html) **
  - **描述:** 授予权限以查看在指定维护时段执行期间运行的任务的相关详细信息
  - **访问级别:** List
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeMaintenanceWindowExecutions.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeMaintenanceWindowExecutions.html) **
  - **描述:** 授予权限以查看指定维护时段的执行
  - **访问级别:** List
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-maintenancewindow](#awssystemsmanager-maintenancewindow) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeMaintenanceWindowSchedule.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeMaintenanceWindowSchedule.html) **
  - **描述:** 授予权限以查看有关指定维护时段即将开始的执行的详细信息
  - **访问级别:** List
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeMaintenanceWindowTargets.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeMaintenanceWindowTargets.html) **
  - **描述:** 授予权限以查看与指定维护时段关联的目标的列表
  - **访问级别:** List
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-maintenancewindow](#awssystemsmanager-maintenancewindow) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeMaintenanceWindowTasks.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeMaintenanceWindowTasks.html) **
  - **描述:** 授予权限以查看与指定维护时段关联的任务的列表
  - **访问级别:** List
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-maintenancewindow](#awssystemsmanager-maintenancewindow) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeMaintenanceWindows.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeMaintenanceWindows.html) **
  - **描述:** 授予权限以查看有关所有维护时段或指定维护时段的信息
  - **访问级别:** List
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeMaintenanceWindowsForTarget.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeMaintenanceWindowsForTarget.html) **
  - **描述:** 授予权限以查看与指定实例关联的维护时段目标和任务相关的信息
  - **访问级别:** 列表
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeOpsItems.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeOpsItems.html) **
  - **描述:** 授予权限以查看有关指定内容的详细信息 OpsItems
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeParameters.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeParameters.html) **
  - **描述:** 授予权限以查看有关指定 SSM 参数的详细信息
  - **访问级别:** List
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribePatchBaselines.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribePatchBaselines.html) **
  - **描述:** 授予权限以查看符合指定条件的补丁基准的信息
  - **访问级别:** List
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribePatchGroupState.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribePatchGroupState.html) **
  - **描述:** 授予权限以查看指定补丁组的补丁的聚合状态详细信息
  - **访问级别:** 列表
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribePatchGroups.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribePatchGroups.html) **
  - **描述:** 授予权限以查看指定补丁组的补丁基准相关信息
  - **访问级别:** List
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribePatchProperties.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribePatchProperties.html) **
  - **描述:** 授予权限以查看指定操作系统和补丁属性的可用补丁的详细信息
  - **访问级别:** List
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeSessions.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DescribeSessions.html) **
  - **描述:** 授予权限以查看满足指定搜索条件的近期会话管理器会话的列表
  - **访问级别:** 列表
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DisassociateOpsItemRelatedItem.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_DisassociateOpsItemRelatedItem.html) **
  - **描述:** 授予取消关联 RelatedItem 的权限 OpsItem
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-opsitem](#awssystemsmanager-opsitem) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/userguide/systems-manager-setting-up-messageAPIs.html#systems-manager-namespace-other-API-operations](https://docs.amazonaws.cn/systems-manager/latest/userguide/systems-manager-setting-up-messageAPIs.html#systems-manager-namespace-other-API-operations) **
  - **描述:** 向 Systems Manager 委派的管理员授予权限，使其能够查看中 OpsItems 多个 Amazon 账户的相关资源详细信息 Amazon Web Services 管理控制台
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetAccessToken.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetAccessToken.html) **
  - **描述:** 授予权限以返回与即时节点访问一并使用的凭证集
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-opsitem](#awssystemsmanager-opsitem) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_AutomationExecution.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_AutomationExecution.html) **
  - **描述:** 授予权限以查看指定 Automation 执行的详细信息
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-automation-execution](#awssystemsmanager-automation-execution)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/userguide/systems-manager-change-calendar-prereqs.html](https://docs.amazonaws.cn/systems-manager/latest/userguide/systems-manager-change-calendar-prereqs.html) [仅权限]**
  - **描述:** 授予查看特定日历详细信息的权限
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-document](#awssystemsmanager-document) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetCalendarState.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetCalendarState.html) **
  - **描述:** 授予权限以查看更改日历或更改日历列表的日历状态
  - **访问级别:** Read
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-document](#awssystemsmanager-document) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetCommandInvocation.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetCommandInvocation.html) **
  - **描述:** 授予权限以查看有关指定调用或插件的命令执行的详细信息
  - **访问级别:** Read
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetConnectionStatus.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetConnectionStatus.html) **
  - **描述:** 授予权限以查看指定托管实例的会话管理器连接状态
  - **访问级别:** Read
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-instance](#awssystemsmanager-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-managed-instance](#awssystemsmanager-managed-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-task](#awssystemsmanager-task)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-ssm_resourceTag___TagKey_](#awssystemsmanager-ssm_resourceTag___TagKey_) <br /> [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetDefaultPatchBaseline.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetDefaultPatchBaseline.html) **
  - **描述:** 授予权限以查看指定操作系统类型的当前默认补丁基准
  - **访问级别:** Read
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-patchbaseline](#awssystemsmanager-patchbaseline) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetDeployablePatchSnapshotForInstance.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetDeployablePatchSnapshotForInstance.html) **
  - **描述:** 授予权限以检索指定实例的当前补丁基准快照
  - **访问级别:** Read
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetDocument.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetDocument.html) **
  - **描述:** 授予权限以查看指定 SSM 文档的内容
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-document](#awssystemsmanager-document)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-ssm_DocumentCategories](#awssystemsmanager-ssm_DocumentCategories) <br /> [#awssystemsmanager-ssm_DocumentType](#awssystemsmanager-ssm_DocumentType)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetExecutionPreview.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetExecutionPreview.html) **
  - **描述:** 授予权限以检索现有预览，该预览显示运行指定自动化运行手册会对目标资源产生的影响
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetInventory.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetInventory.html) **
  - **描述:** 授予权限以根据指定条件查看实例清单详细信息
  - **访问级别:** Read
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetInventorySchema.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetInventorySchema.html) **
  - **描述:** 授予权限以查看指定清单项目类型的清单类型或属性名称的列表
  - **访问级别:** Read
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetMaintenanceWindow.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetMaintenanceWindow.html) **
  - **描述:** 授予权限以查看有关指定维护时段的详细信息
  - **访问级别:** Read
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-maintenancewindow](#awssystemsmanager-maintenancewindow) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetMaintenanceWindowExecution.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetMaintenanceWindowExecution.html) **
  - **描述:** 授予权限以查看有关指定维护时段执行的详细信息
  - **访问级别:** Read
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetMaintenanceWindowExecutionTask.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetMaintenanceWindowExecutionTask.html) **
  - **描述:** 授予权限以查看有关指定维护时段执行任务的详细信息
  - **访问级别:** Read
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetMaintenanceWindowExecutionTaskInvocation.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetMaintenanceWindowExecutionTaskInvocation.html) **
  - **描述:** 授予权限以查看在特定目标上运行的特定维护时段任务的详细信息
  - **访问级别:** Read
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetMaintenanceWindowTask.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetMaintenanceWindowTask.html) **
  - **描述:** 授予权限以查看在指定维护时段中注册的任务的详细信息
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-maintenancewindow](#awssystemsmanager-maintenancewindow) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/userguide/systems-manager-setting-up-messageAPIs.html](https://docs.amazonaws.cn/systems-manager/latest/userguide/systems-manager-setting-up-messageAPIs.html) [仅权限]**
  - **描述:** 为 Systems Manager 和 SSM Agent 授予权限以确定实例的包安装要求（内部 Systems Manager 调用）
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetOpsItem.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetOpsItem.html) **
  - **描述:** 授予查看有关指定信息的权限 OpsItem
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-opsitem](#awssystemsmanager-opsitem) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetOpsMetadata.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetOpsMetadata.html) **
  - **描述:** 授予检索 OpsMetadata 对象的权限
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-opsmetadata](#awssystemsmanager-opsmetadata) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetOpsSummary.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetOpsSummary.html) **
  - **描述:**  OpsItems 根据指定的筛选器和聚合器授予查看有关摘要信息的权限
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-resourcedatasync](#awssystemsmanager-resourcedatasync) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetParameter.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetParameter.html) **
  - **描述:** 授予权限以查看有关指定参数的信息
  - **访问级别:** Read
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-parameter](#awssystemsmanager-parameter)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetParameterHistory.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetParameterHistory.html) **
  - **描述:** 授予权限以查看指定参数的详细信息和更改
  - **访问级别:** Read
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-parameter](#awssystemsmanager-parameter)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetParameters.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetParameters.html) **
  - **描述:** 授予权限以查看有关多个指定参数的信息
  - **访问级别:** Read
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-parameter](#awssystemsmanager-parameter)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetParametersByPath.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetParametersByPath.html) **
  - **描述:** 授予权限以查看指定层次结构中参数的信息
  - **访问级别:** Read
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-parameter](#awssystemsmanager-parameter)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-ssm_Recursive](#awssystemsmanager-ssm_Recursive)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetPatchBaseline.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetPatchBaseline.html) **
  - **描述:** 授予权限以查看有关指定补丁基准的信息
  - **访问级别:** Read
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-patchbaseline](#awssystemsmanager-patchbaseline) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetPatchBaselineForPatchGroup.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetPatchBaselineForPatchGroup.html) **
  - **描述:** 授予权限以查看指定补丁组的当前补丁基准的 ID
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetResourcePolicies.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetResourcePolicies.html) **
  - **描述:** 授予检索 Systems Manager 资源策略列表的权限
  - **访问级别:** 列表
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-document](#awssystemsmanager-document)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-opsitemgroup](#awssystemsmanager-opsitemgroup)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-parameter](#awssystemsmanager-parameter)  / **条件键:**  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetServiceSetting.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_GetServiceSetting.html) **
  - **描述:** 授予查看服务的账户级别设置的权限 Amazon 
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-servicesetting](#awssystemsmanager-servicesetting) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_LabelParameterVersion.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_LabelParameterVersion.html) **
  - **描述:** 授予权限以将标识标签应用于参数的指定版本
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-parameter](#awssystemsmanager-parameter)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ListAssociationVersions.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ListAssociationVersions.html) **
  - **描述:** 授予权限以列出指定关联的版本
  - **访问级别:** List
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-association](#awssystemsmanager-association)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ListAssociations.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ListAssociations.html) **
  - **描述:** 授予权限以列出指定 SSM 文档或托管实例的关联
  - **访问级别:** List
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ListCommandInvocations.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ListCommandInvocations.html) **
  - **描述:** 授予权限以列出有关发送到指定实例的命令调用的信息
  - **访问级别:** 列表
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ListCommands.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ListCommands.html) **
  - **描述:** 授予权限以列出发送到指定实例的命令
  - **访问级别:** 列表
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ListComplianceItems.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ListComplianceItems.html) **
  - **描述:** 授予权限以列出指定资源上指定资源类型的合规性状态
  - **访问级别:** List
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ListComplianceSummaries.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ListComplianceSummaries.html) **
  - **描述:** 授予权限以列出对于指定的合规性类型，合规以及不合规资源的摘要计数
  - **访问级别:** List
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ListDocumentMetadataHistory.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ListDocumentMetadataHistory.html) **
  - **描述:** 授予查看有关指定 SSM 文档的元数据历史记录的权限
  - **访问级别:** 列表
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-document](#awssystemsmanager-document)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-ssm_DocumentType](#awssystemsmanager-ssm_DocumentType)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ListDocumentVersions.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ListDocumentVersions.html) **
  - **描述:** 授予权限以列出指定文档的所有版本
  - **访问级别:** List
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-document](#awssystemsmanager-document)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-ssm_DocumentType](#awssystemsmanager-ssm_DocumentType)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ListDocuments.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ListDocuments.html) **
  - **描述:** 授予权限以查看指定 SSM 文档的相关信息
  - **访问级别:** 列表
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/userguide/systems-manager-setting-up-messageAPIs.html](https://docs.amazonaws.cn/systems-manager/latest/userguide/systems-manager-setting-up-messageAPIs.html) **
  - **描述:** 授予 SSM Agent 检查新的 State Manager 关联（内部 Systems Manager 调用）的权限
  - **访问级别:** 列表
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-instance](#awssystemsmanager-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-managed-instance](#awssystemsmanager-managed-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ListInventoryEntries.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ListInventoryEntries.html) **
  - **描述:** 授予权限以查看指定实例的指定清单类型的列表
  - **访问级别:** 列表
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ListNodes.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ListNodes.html) **
  - **描述:** 授予权限以查看有关基于指定筛选器的托管式节点的详细信息
  - **访问级别:** 列表
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-resourcedatasync](#awssystemsmanager-resourcedatasync) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ListNodesSummary.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ListNodesSummary.html) **
  - **描述:** 授予权限以基于指定筛选器和聚合器查看有关托管式节点的摘要信息
  - **访问级别:** 列表
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-resourcedatasync](#awssystemsmanager-resourcedatasync) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ListOpsItemEvents.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ListOpsItemEvents.html) **
  - **描述:** 授予查看相关详细信息的权限 OpsItemEvents
  - **访问级别:** 列表
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ListOpsItemRelatedItems.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ListOpsItemRelatedItems.html) **
  - **描述:** 授予查看相关详细信息的权限 OpsItem RelatedItems
  - **访问级别:** 列表
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ListOpsMetadata.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ListOpsMetadata.html) **
  - **描述:** 授予查看 OpsMetadata 对象列表的权限
  - **访问级别:** 列表
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ListResourceComplianceSummaries.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ListResourceComplianceSummaries.html) **
  - **描述:** 授予权限以列出资源级摘要计数
  - **访问级别:** List
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ListResourceDataSync.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ListResourceDataSync.html) **
  - **描述:** 授予权限以列出有关账户中资源数据同步配置的信息
  - **访问级别:** List
  - **资源类型（\* 为必需）:** 
  - **条件键:**  [#awssystemsmanager-ssm_SyncType](#awssystemsmanager-ssm_SyncType) 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ListTagsForResource.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ListTagsForResource.html) **
  - **描述:** 授予权限以查看指定资源的资源标签的列表
  - **访问级别:** 列表
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-association](#awssystemsmanager-association)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-automation-execution](#awssystemsmanager-automation-execution)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-document](#awssystemsmanager-document)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-maintenancewindow](#awssystemsmanager-maintenancewindow)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-managed-instance](#awssystemsmanager-managed-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-opsitem](#awssystemsmanager-opsitem)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-opsmetadata](#awssystemsmanager-opsmetadata)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-parameter](#awssystemsmanager-parameter)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-patchbaseline](#awssystemsmanager-patchbaseline)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ModifyDocumentPermission.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ModifyDocumentPermission.html) **
  - **描述:** 授予与指定 Amazon 账户公开或私下共享自定义 SSM 文档的权限
  - **访问级别:** 权限管理
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-document](#awssystemsmanager-document)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-ssm_DocumentType](#awssystemsmanager-ssm_DocumentType)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/userguide/systems-manager-change-calendar-prereqs.html](https://docs.amazonaws.cn/systems-manager/latest/userguide/systems-manager-change-calendar-prereqs.html) [仅权限]**
  - **描述:** 授予对 create/edit 特定日历的权限
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-document](#awssystemsmanager-document) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_PutComplianceItems.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_PutComplianceItems.html) **
  - **描述:** 授予权限以在指定资源上注册合规性类型和其他合规性详细信息
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-instance](#awssystemsmanager-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-managed-instance](#awssystemsmanager-managed-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-ssm_SourceInstanceARN](#awssystemsmanager-ssm_SourceInstanceARN) <br /> [#awssystemsmanager-ec2_SourceInstanceARN](#awssystemsmanager-ec2_SourceInstanceARN)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/userguide/systems-manager-setting-up-messageAPIs.html](https://docs.amazonaws.cn/systems-manager/latest/userguide/systems-manager-setting-up-messageAPIs.html) [仅权限]**
  - **描述:** 为 SSM Agent 授予权限以生成特定代理请求结果的报告（内部 Systems Manager 调用）
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_PutInventory.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_PutInventory.html) **
  - **描述:** 授予权限以在多个指定的托管实例上添加或更新清单项目
  - **访问级别:** Write
  - **资源类型（\* 为必需）:** 
  - **条件键:**  [#awssystemsmanager-ssm_InventoryTypeName](#awssystemsmanager-ssm_InventoryTypeName) 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_PutParameter.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_PutParameter.html) **
  - **描述:** 授予权限以创建 SSM 参数
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-parameter](#awssystemsmanager-parameter)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-aws_RequestTag___TagKey_](#awssystemsmanager-aws_RequestTag___TagKey_) <br /> [#awssystemsmanager-aws_TagKeys](#awssystemsmanager-aws_TagKeys) <br /> [#awssystemsmanager-ssm_Overwrite](#awssystemsmanager-ssm_Overwrite) <br /> [#awssystemsmanager-ssm_Policies](#awssystemsmanager-ssm_Policies)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_PutResourcePolicy.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_PutResourcePolicy.html) **
  - **描述:** 授予创建或更新 Systems Manager 资源策略的权限
  - **访问级别:** 权限管理
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-document](#awssystemsmanager-document)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-opsitemgroup](#awssystemsmanager-opsitemgroup)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-parameter](#awssystemsmanager-parameter)  / **条件键:**  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_RegisterDefaultPatchBaseline.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_RegisterDefaultPatchBaseline.html) **
  - **描述:** 授予权限以便为操作系统类型指定默认补丁基准
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-patchbaseline](#awssystemsmanager-patchbaseline) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/userguide/systems-manager-setting-up-messageAPIs.html](https://docs.amazonaws.cn/systems-manager/latest/userguide/systems-manager-setting-up-messageAPIs.html) **
  - **描述:** 授予注册 Systems Manager Agent 的权限
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:** 
  - **条件键:**  [#awssystemsmanager-aws_RequestTag___TagKey_](#awssystemsmanager-aws_RequestTag___TagKey_) <br /> [#awssystemsmanager-aws_TagKeys](#awssystemsmanager-aws_TagKeys) 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_RegisterPatchBaselineForPatchGroup.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_RegisterPatchBaselineForPatchGroup.html) **
  - **描述:** 授予权限以便为指定的补丁组指定默认补丁基准
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-patchbaseline](#awssystemsmanager-patchbaseline) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_RegisterTargetWithMaintenanceWindow.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_RegisterTargetWithMaintenanceWindow.html) **
  - **描述:** 授予权限以将目标注册到指定的维护时段
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-maintenancewindow](#awssystemsmanager-maintenancewindow) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_RegisterTaskWithMaintenanceWindow.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_RegisterTaskWithMaintenanceWindow.html) **
  - **描述:** 授予权限以将任务注册到指定的维护时段
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-maintenancewindow](#awssystemsmanager-maintenancewindow) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_RemoveTagsFromResource.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_RemoveTagsFromResource.html) **
  - **描述:** 授予权限以从指定资源中删除指定标签键
  - **访问级别:** 标签
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-association](#awssystemsmanager-association)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-automation-execution](#awssystemsmanager-automation-execution)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-document](#awssystemsmanager-document)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-instance](#awssystemsmanager-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-maintenancewindow](#awssystemsmanager-maintenancewindow)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-managed-instance](#awssystemsmanager-managed-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-opsitem](#awssystemsmanager-opsitem)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-opsmetadata](#awssystemsmanager-opsmetadata)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-parameter](#awssystemsmanager-parameter)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-patchbaseline](#awssystemsmanager-patchbaseline)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-task](#awssystemsmanager-task)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_) <br /> [#awssystemsmanager-aws_TagKeys](#awssystemsmanager-aws_TagKeys)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ResetServiceSetting.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ResetServiceSetting.html) **
  - **描述:** 授予将的服务设置重置 Amazon Web Services 账户 为默认值的权限
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-servicesetting](#awssystemsmanager-servicesetting) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ResumeSession.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_ResumeSession.html) **
  - **描述:** 授予权限以将会话管理器会话重新连接到托管实例
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-session](#awssystemsmanager-session)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-ssm_resourceTag_aws_ssmmessages_session-id](#awssystemsmanager-ssm_resourceTag_aws_ssmmessages_session-id) <br /> [#awssystemsmanager-ssm_resourceTag_aws_ssmmessages_target-id](#awssystemsmanager-ssm_resourceTag_aws_ssmmessages_target-id)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_SendAutomationSignal.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_SendAutomationSignal.html) **
  - **描述:** 授予权限以发送信号，更改指定 Automation 执行的当前行为或状态
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-automation-execution](#awssystemsmanager-automation-execution)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_SendCommand.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_SendCommand.html) **
  - **描述:** 授予权限以在一个或多个指定托管实例上运行命令
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-document](#awssystemsmanager-document)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-bucket](#awssystemsmanager-bucket)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-instance](#awssystemsmanager-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-managed-instance](#awssystemsmanager-managed-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_) <br /> [#awssystemsmanager-ssm_resourceTag___TagKey_](#awssystemsmanager-ssm_resourceTag___TagKey_)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_StartAccessRequest.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_StartAccessRequest.html) **
  - **描述:** 授予权限以启动即时节点访问会话的工作流
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-instance](#awssystemsmanager-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-managed-instance](#awssystemsmanager-managed-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-aws_RequestTag___TagKey_](#awssystemsmanager-aws_RequestTag___TagKey_) <br /> [#awssystemsmanager-aws_TagKeys](#awssystemsmanager-aws_TagKeys)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_StartAssociationsOnce.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_StartAssociationsOnce.html) **
  - **描述:** 授予权限以手动运行指定关联
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-association](#awssystemsmanager-association)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_StartAutomationExecution.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_StartAutomationExecution.html) **
  - **描述:** 授予权限以启动 Automation 文档的执行
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-automation-execution](#awssystemsmanager-automation-execution)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-document](#awssystemsmanager-document)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-automation-definition](#awssystemsmanager-automation-definition)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-aws_RequestTag___TagKey_](#awssystemsmanager-aws_RequestTag___TagKey_) <br /> [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_) <br /> [#awssystemsmanager-aws_TagKeys](#awssystemsmanager-aws_TagKeys) <br /> [#awssystemsmanager-ssm_DocumentVersion](#awssystemsmanager-ssm_DocumentVersion)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_StartChangeRequestExecution.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_StartChangeRequestExecution.html) **
  - **描述:** 授予启动 Automation Change Template 文档的执行的权限
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-automation-execution](#awssystemsmanager-automation-execution)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-document](#awssystemsmanager-document)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-automation-definition](#awssystemsmanager-automation-definition)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-aws_RequestTag___TagKey_](#awssystemsmanager-aws_RequestTag___TagKey_) <br /> [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_) <br /> [#awssystemsmanager-aws_TagKeys](#awssystemsmanager-aws_TagKeys) <br /> [#awssystemsmanager-ssm_AutoApprove](#awssystemsmanager-ssm_AutoApprove) <br /> [#awssystemsmanager-ssm_DocumentVersion](#awssystemsmanager-ssm_DocumentVersion)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_StartExecutionPreview.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_StartExecutionPreview.html) **
  - **描述:** 授予权限以创建预览，该预览显示运行指定自动化运行手册会对目标资源产生的影响
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_StartSession.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_StartSession.html) **
  - **描述:** 授予权限以便为会话管理器会话启动与指定目标的连接
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-document](#awssystemsmanager-document)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-instance](#awssystemsmanager-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-managed-instance](#awssystemsmanager-managed-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-task](#awssystemsmanager-task)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-ssm_SessionDocumentAccessCheck](#awssystemsmanager-ssm_SessionDocumentAccessCheck) <br /> [#awssystemsmanager-ssm_resourceTag___TagKey_](#awssystemsmanager-ssm_resourceTag___TagKey_) <br /> [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_) <br /> [#awssystemsmanager-ssm_AccessRequestId](#awssystemsmanager-ssm_AccessRequestId)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_StopAutomationExecution.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_StopAutomationExecution.html) **
  - **描述:** 授予权限以停止已在进行的指定 Automation 执行
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-automation-execution](#awssystemsmanager-automation-execution)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_TerminateSession.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_TerminateSession.html) **
  - **描述:** 授予权限以永久结束与实例的会话管理器连接
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-session](#awssystemsmanager-session)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-ssm_resourceTag_aws_ssmmessages_session-id](#awssystemsmanager-ssm_resourceTag_aws_ssmmessages_session-id) <br /> [#awssystemsmanager-ssm_resourceTag_aws_ssmmessages_target-id](#awssystemsmanager-ssm_resourceTag_aws_ssmmessages_target-id)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_UnlabelParameterVersion.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_UnlabelParameterVersion.html) **
  - **描述:** 授予从参数的指定版本移除标识标签的权限
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-parameter](#awssystemsmanager-parameter)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_UpdateAssociation.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_UpdateAssociation.html) **
  - **描述:** 授予权限以更新关联并立即在指定目标上运行关联
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-association](#awssystemsmanager-association)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-document](#awssystemsmanager-document)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-instance](#awssystemsmanager-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-managed-instance](#awssystemsmanager-managed-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_UpdateAssociationStatus.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_UpdateAssociationStatus.html) **
  - **描述:** 授予权限以更新与指定实例关联的 SSM 文档的状态
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-document](#awssystemsmanager-document)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-instance](#awssystemsmanager-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-managed-instance](#awssystemsmanager-managed-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-ssm_SourceInstanceARN](#awssystemsmanager-ssm_SourceInstanceARN) <br /> [#awssystemsmanager-ec2_SourceInstanceARN](#awssystemsmanager-ec2_SourceInstanceARN) <br /> [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_UpdateDocument.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_UpdateDocument.html) **
  - **描述:** 授予权限以更新 SSM 文档的一个或多个值
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-document](#awssystemsmanager-document)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-ssm_DocumentType](#awssystemsmanager-ssm_DocumentType)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_UpdateDocumentDefaultVersion.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_UpdateDocumentDefaultVersion.html) **
  - **描述:** 授予权限以更改 SSM 文档的默认版本
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-document](#awssystemsmanager-document)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-ssm_DocumentType](#awssystemsmanager-ssm_DocumentType)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_UpdateDocumentMetadata.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_UpdateDocumentMetadata.html) **
  - **描述:** 授予更新 SSM 文档元数据的权限
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-document](#awssystemsmanager-document)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-ssm_DocumentType](#awssystemsmanager-ssm_DocumentType)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/userguide/systems-manager-setting-up-messageAPIs.html](https://docs.amazonaws.cn/systems-manager/latest/userguide/systems-manager-setting-up-messageAPIs.html) [仅权限]**
  - **描述:** 为 SSM Agent 授予权限以更新当前正在运行的关联的状态（内部 Systems Manager 调用）
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-association](#awssystemsmanager-association)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-instance](#awssystemsmanager-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-managed-instance](#awssystemsmanager-managed-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-ssm_SourceInstanceARN](#awssystemsmanager-ssm_SourceInstanceARN) <br /> [#awssystemsmanager-ec2_SourceInstanceARN](#awssystemsmanager-ec2_SourceInstanceARN) <br /> [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/userguide/systems-manager-setting-up-messageAPIs.html](https://docs.amazonaws.cn/systems-manager/latest/userguide/systems-manager-setting-up-messageAPIs.html) **
  - **描述:** 为 SSM Agent 授予权限以向云中的 Systems Manager 服务发送检测信号
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-instance](#awssystemsmanager-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-managed-instance](#awssystemsmanager-managed-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-ssm_SourceInstanceARN](#awssystemsmanager-ssm_SourceInstanceARN) <br /> [#awssystemsmanager-ec2_SourceInstanceARN](#awssystemsmanager-ec2_SourceInstanceARN)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_UpdateMaintenanceWindow.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_UpdateMaintenanceWindow.html) **
  - **描述:** 授予权限以更新指定的维护时段
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-maintenancewindow](#awssystemsmanager-maintenancewindow) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_UpdateMaintenanceWindowTarget.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_UpdateMaintenanceWindowTarget.html) **
  - **描述:** 授予权限以更新指定的维护时段目标
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-maintenancewindow](#awssystemsmanager-maintenancewindow)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-windowtarget](#awssystemsmanager-windowtarget)  / **条件键:**  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_UpdateMaintenanceWindowTask.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_UpdateMaintenanceWindowTask.html) **
  - **描述:** 授予权限以更新指定的维护时段任务
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-maintenancewindow](#awssystemsmanager-maintenancewindow)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-windowtask](#awssystemsmanager-windowtask)  / **条件键:**  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_UpdateManagedInstanceRole.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_UpdateManagedInstanceRole.html) **
  - **描述:** 授予权限以分配或更改分配给指定托管实例的 IAM 角色
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-iam-role](#awssystemsmanager-iam-role)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-managed-instance](#awssystemsmanager-managed-instance)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-ssm_resourceTag_tag-key](#awssystemsmanager-ssm_resourceTag_tag-key)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_UpdateOpsItem.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_UpdateOpsItem.html) **
  - **描述:** 授予编辑或更改的权限 OpsItem
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-opsitem](#awssystemsmanager-opsitem) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_UpdateOpsMetadata.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_UpdateOpsMetadata.html) **
  - **描述:** 授予更新 OpsMetadata 对象的权限
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-opsmetadata](#awssystemsmanager-opsmetadata) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_UpdatePatchBaseline.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_UpdatePatchBaseline.html) **
  - **描述:** 授予权限以更新指定的补丁基准
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-patchbaseline](#awssystemsmanager-patchbaseline) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_UpdateResourceDataSync.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_UpdateResourceDataSync.html) **
  - **描述:** 授予权限以更新资源数据同步
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-resourcedatasync](#awssystemsmanager-resourcedatasync)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#awssystemsmanager-ssm_SyncType](#awssystemsmanager-ssm_SyncType)  / **相关操作:** 

- **  [https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_UpdateServiceSetting.html](https://docs.amazonaws.cn/systems-manager/latest/APIReference/API_UpdateServiceSetting.html) **
  - **描述:** 授予更新服务设置的权限 Amazon Web Services 账户
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#awssystemsmanager-servicesetting](#awssystemsmanager-servicesetting) 
  - **条件键:** 
  - **相关操作:** 



## 由 S Amazon ystems Manager 定义的资源类型
<a name="awssystemsmanager-resources-for-iam-policies"></a>

以下资源类型是由该服务定义的，可以在 IAM 权限策略语句的 `Resource` 元素中使用这些资源类型。[操作表](#awssystemsmanager-actions-as-permissions)中的每个操作指定了可以使用该操作指定的资源类型。您也可以在策略中包含条件键，从而定义资源类型。这些键显示在资源类型表的最后一列。有关下表中各列的详细信息，请参阅[资源类型表](reference_policies_actions-resources-contextkeys.html#resources_table)。

**注意**  
某些 State Manager API 参数已被弃用。这可能会导致意外行为。有关更多信息，请参阅[使用 IAM 处理关联](https://docs.amazonaws.cn/systems-manager/latest/userguide/systems-manager-state-manager-iam.html)。


****  

| 资源类型 | ARN | 条件键 | 
| --- | --- | --- | 
|   [https://docs.amazonaws.cn/systems-manager/latest/userguide/what-is-systems-manager.html](https://docs.amazonaws.cn/systems-manager/latest/userguide/what-is-systems-manager.html)  |  arn:${Partition}:ssm:${Region}:${Account}:association/${AssociationId}  |  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_)  | 
|   [https://docs.amazonaws.cn/systems-manager/latest/userguide/running-simple-automations.html](https://docs.amazonaws.cn/systems-manager/latest/userguide/running-simple-automations.html)  |  arn:${Partition}:ssm:${Region}:${Account}:automation-execution/${AutomationExecutionId}  |  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_) <br /> [#awssystemsmanager-ssm_resourceTag_tag-key](#awssystemsmanager-ssm_resourceTag_tag-key)  | 
|   [https://docs.amazonaws.cn/systems-manager/latest/userguide/automation-documents.html](https://docs.amazonaws.cn/systems-manager/latest/userguide/automation-documents.html)  |  arn:${Partition}:ssm:${Region}:${Account}:automation-definition/${AutomationDefinitionName}:${VersionId}  |  [#awssystemsmanager-ssm_DocumentType](#awssystemsmanager-ssm_DocumentType)  | 
|   [https://docs.amazonaws.cn/AmazonS3/latest/dev/UsingBucket.html](https://docs.amazonaws.cn/AmazonS3/latest/dev/UsingBucket.html)  |  arn:${Partition}:s3:::${BucketName}  |  | 
|   [https://docs.amazonaws.cn/systems-manager/latest/userguide/documents.html](https://docs.amazonaws.cn/systems-manager/latest/userguide/documents.html)  |  arn:${Partition}:ssm:${Region}:${Account}:document/${DocumentName}  |  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_) <br /> [#awssystemsmanager-ssm_DocumentCategories](#awssystemsmanager-ssm_DocumentCategories) <br /> [#awssystemsmanager-ssm_DocumentType](#awssystemsmanager-ssm_DocumentType) <br /> [#awssystemsmanager-ssm_resourceTag___TagKey_](#awssystemsmanager-ssm_resourceTag___TagKey_)  | 
|   [https://docs.amazonaws.cn/IAM/latest/UserGuide/id_roles.html](https://docs.amazonaws.cn/IAM/latest/UserGuide/id_roles.html)  |  arn:${Partition}:iam::${Account}:role/${RoleName}  |  | 
|   [https://docs.amazonaws.cn/AWSEC2/latest/UserGuide/iam-policy-structure.html#EC2_ARN_Format](https://docs.amazonaws.cn/AWSEC2/latest/UserGuide/iam-policy-structure.html#EC2_ARN_Format)  |  arn:${Partition}:ec2:${Region}:${Account}:instance/${InstanceId}  |  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_) <br /> [#awssystemsmanager-ssm_resourceTag___TagKey_](#awssystemsmanager-ssm_resourceTag___TagKey_)  | 
|   [https://docs.amazonaws.cn/systems-manager/latest/userguide/systems-manager-maintenance.html](https://docs.amazonaws.cn/systems-manager/latest/userguide/systems-manager-maintenance.html)  |  arn:${Partition}:ssm:${Region}:${Account}:maintenancewindow/${ResourceId}  |  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_) <br /> [#awssystemsmanager-ssm_resourceTag_tag-key](#awssystemsmanager-ssm_resourceTag_tag-key)  | 
|   [https://docs.amazonaws.cn/systems-manager/latest/userguide/what-is-systems-manager.html](https://docs.amazonaws.cn/systems-manager/latest/userguide/what-is-systems-manager.html)  |  arn:${Partition}:ssm:${Region}:${Account}:managed-instance/${InstanceId}  |  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_) <br /> [#awssystemsmanager-ssm_resourceTag_tag-key](#awssystemsmanager-ssm_resourceTag_tag-key)  | 
|   [https://docs.amazonaws.cn/systems-manager/latest/userguide/sysman-inventory-configuring.html](https://docs.amazonaws.cn/systems-manager/latest/userguide/sysman-inventory-configuring.html)  |  arn:${Partition}:ssm:${Region}:${Account}:managed-instance-inventory/${InstanceId}  |  | 
|   [https://docs.amazonaws.cn/systems-manager/latest/userguide/OpsCenter-working-with-OpsItems.html](https://docs.amazonaws.cn/systems-manager/latest/userguide/OpsCenter-working-with-OpsItems.html)  |  arn:${Partition}:ssm:${Region}:${Account}:opsitem/${ResourceId}  |  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_)  | 
|   [https://docs.amazonaws.cn/systems-manager/latest/userguide/OpsCenter-working-with-OpsItems.html](https://docs.amazonaws.cn/systems-manager/latest/userguide/OpsCenter-working-with-OpsItems.html)  |  arn:${Partition}:ssm:${Region}:${Account}:opsitemgroup/default  |  | 
|   [https://docs.amazonaws.cn/systems-manager/latest/userguide/application-manager.html](https://docs.amazonaws.cn/systems-manager/latest/userguide/application-manager.html)  |  arn:${Partition}:ssm:${Region}:${Account}:opsmetadata/${ResourceId}  |  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_) <br /> [#awssystemsmanager-ssm_resourceTag___TagKey_](#awssystemsmanager-ssm_resourceTag___TagKey_)  | 
|   [https://docs.amazonaws.cn/systems-manager/latest/userguide/systems-manager-parameter-store.html](https://docs.amazonaws.cn/systems-manager/latest/userguide/systems-manager-parameter-store.html)  |  arn:${Partition}:ssm:${Region}:${Account}:parameter/${ParameterNameWithoutLeadingSlash}  |  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_) <br /> [#awssystemsmanager-ssm_resourceTag_tag-key](#awssystemsmanager-ssm_resourceTag_tag-key)  | 
|   [https://docs.amazonaws.cn/systems-manager/latest/userguide/patch-manager.html](https://docs.amazonaws.cn/systems-manager/latest/userguide/patch-manager.html)  |  arn:${Partition}:ssm:${Region}:${Account}:patchbaseline/${PatchBaselineIdResourceId}  |  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_) <br /> [#awssystemsmanager-ssm_resourceTag_tag-key](#awssystemsmanager-ssm_resourceTag_tag-key)  | 
|   [https://docs.amazonaws.cn/systems-manager/latest/userguide/session-manager.html](https://docs.amazonaws.cn/systems-manager/latest/userguide/session-manager.html)  |  arn:${Partition}:ssm:${Region}:${Account}:session/${SessionId}  |  [#awssystemsmanager-ssm_resourceTag_aws_ssmmessages_session-id](#awssystemsmanager-ssm_resourceTag_aws_ssmmessages_session-id) <br /> [#awssystemsmanager-ssm_resourceTag_aws_ssmmessages_target-id](#awssystemsmanager-ssm_resourceTag_aws_ssmmessages_target-id)  | 
|   [https://docs.amazonaws.cn/systems-manager/latest/userguide/sysman-inventory-datasync.html](https://docs.amazonaws.cn/systems-manager/latest/userguide/sysman-inventory-datasync.html)  |  arn:${Partition}:ssm:${Region}:${Account}:resource-data-sync/${SyncName}  |  | 
|   [https://docs.amazonaws.cn/systems-manager/latest/userguide/what-is-systems-manager.html](https://docs.amazonaws.cn/systems-manager/latest/userguide/what-is-systems-manager.html)  |  arn:${Partition}:ssm:${Region}:${Account}:servicesetting/${ResourceId}  |  | 
|   [https://docs.amazonaws.cn/systems-manager/latest/userguide/sysman-maintenance-assign-targets.html](https://docs.amazonaws.cn/systems-manager/latest/userguide/sysman-maintenance-assign-targets.html)  |  arn:${Partition}:ssm:${Region}:${Account}:windowtarget/${WindowTargetId}  |  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_) <br /> [#awssystemsmanager-ssm_resourceTag_tag-key](#awssystemsmanager-ssm_resourceTag_tag-key)  | 
|   [https://docs.amazonaws.cn/systems-manager/latest/userguide/sysman-maintenance-assign-tasks.html](https://docs.amazonaws.cn/systems-manager/latest/userguide/sysman-maintenance-assign-tasks.html)  |  arn:${Partition}:ssm:${Region}:${Account}:windowtask/${WindowTaskId}  |  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_) <br /> [#awssystemsmanager-ssm_resourceTag_tag-key](#awssystemsmanager-ssm_resourceTag_tag-key)  | 
|   [https://docs.amazonaws.cn/AmazonECS/latest/developerguide/scheduling_tasks.html](https://docs.amazonaws.cn/AmazonECS/latest/developerguide/scheduling_tasks.html)  |  arn:${Partition}:ecs:${Region}:${Account}:task/${TaskId}  |  [#awssystemsmanager-aws_ResourceTag___TagKey_](#awssystemsmanager-aws_ResourceTag___TagKey_)  | 

## Sy Amazon stems Manager 的条件密钥
<a name="awssystemsmanager-policy-keys"></a>

Amazon Systems Manager 定义了以下可以在 IAM 策略`Condition`元素中使用的条件键。您可以使用这些键进一步细化应用策略语句的条件。有关下表中各列的详细信息，请参阅[条件键表](reference_policies_actions-resources-contextkeys.html#context_keys_table)。

要查看适用于所有服务的全局条件键，请参阅 [Amazon 全局条件上下文键](https://docs.amazonaws.cn/IAM/latest/UserGuide/reference_policies_condition-keys.html)。


****  

| 条件键 | 描述 | Type | 
| --- | --- | --- | 
|   [https://docs.amazonaws.cn/systems-manager/latest/userguide/auth-and-access-control-iam-access-control-identity-based.html#policy-conditions](https://docs.amazonaws.cn/systems-manager/latest/userguide/auth-and-access-control-iam-access-control-identity-based.html#policy-conditions)  | 根据指定标签的允许值集按“创建”请求筛选访问权限 | 字符串 | 
|   [https://docs.amazonaws.cn/systems-manager/latest/userguide/auth-and-access-control-iam-access-control-identity-based.html#policy-conditions](https://docs.amazonaws.cn/systems-manager/latest/userguide/auth-and-access-control-iam-access-control-identity-based.html#policy-conditions)  | 根据分配给资源的标签键值对筛选访问权限 Amazon  | 字符串 | 
|   [https://docs.amazonaws.cn/systems-manager/latest/userguide/auth-and-access-control-iam-access-control-identity-based.html#policy-conditions](https://docs.amazonaws.cn/systems-manager/latest/userguide/auth-and-access-control-iam-access-control-identity-based.html#policy-conditions)  | 根据请求中是否具有必需标签按“创建”请求筛选访问权限 | ArrayOfString | 
|   [https://docs.amazonaws.cn/AWSEC2/latest/UserGuide/iam-policy-structure.html#amazon-ec2-keys](https://docs.amazonaws.cn/AWSEC2/latest/UserGuide/iam-policy-structure.html#amazon-ec2-keys)  | 按发起请求的实例的 ARN 筛选访问 | 进行筛选 | 
|   [https://docs.amazonaws.cn/systems-manager/latest/userguide/auth-and-access-control-iam-access-control-identity-based.html#policy-conditions](https://docs.amazonaws.cn/systems-manager/latest/userguide/auth-and-access-control-iam-access-control-identity-based.html#policy-conditions)  | 通过验证用户是否有权访问请求中指定的请求 ID 来筛选访问权限 | 字符串 | 
|   [https://docs.amazonaws.cn/systems-manager/latest/userguide/change-manager-auto-approval-access.html](https://docs.amazonaws.cn/systems-manager/latest/userguide/change-manager-auto-approval-access.html)  | 通过验证用户是否有权启动 Change Manager 工作流而不执行某个审核步骤（变更冻结事件除外）来筛选访问权限 | 布尔型 | 
|   [https://docs.amazonaws.cn/systems-manager/latest/userguide/auth-and-access-control-iam-access-control-identity-based.html#policy-conditions](https://docs.amazonaws.cn/systems-manager/latest/userguide/auth-and-access-control-iam-access-control-identity-based.html#policy-conditions)  | 通过验证用户是否有权访问属于特定类别的文档来筛选访问权限 | ArrayOfString | 
|   [https://docs.amazonaws.cn/systems-manager/latest/userguide/auth-and-access-control-iam-access-control-identity-based.html#policy-conditions](https://docs.amazonaws.cn/systems-manager/latest/userguide/auth-and-access-control-iam-access-control-identity-based.html#policy-conditions)  | 通过验证用户是否有权访问属于特定文档类型的文档来筛选访问权限。仅在“aws”、“aws-cn”和“aws-us-gov”分区中可用 | 字符串 | 
|   [https://docs.amazonaws.cn/systems-manager/latest/userguide/auth-and-access-control-iam-access-control-identity-based.html#policy-conditions](https://docs.amazonaws.cn/systems-manager/latest/userguide/auth-and-access-control-iam-access-control-identity-based.html#policy-conditions)  | 通过验证用户是否有权访问文档的特定版本来筛选访问权限 | ArrayOfString | 
|   [https://docs.amazonaws.cn/systems-manager/latest/userguide/auth-and-access-control-iam-access-control-identity-based.html#policy-conditions](https://docs.amazonaws.cn/systems-manager/latest/userguide/auth-and-access-control-iam-access-control-identity-based.html#policy-conditions)  | 通过验证用户是否也可以访问请求中 InventoryType 指定的内容来筛选访问权限 | ArrayOfString | 
|   [https://docs.amazonaws.cn/systems-manager/latest/userguide/parameter-store-policy-conditions.html#overwrite-condition](https://docs.amazonaws.cn/systems-manager/latest/userguide/parameter-store-policy-conditions.html#overwrite-condition)  | 按控制是否可以覆盖 Systems Manager 参数筛选访问权限 | 字符串 | 
|   [https://docs.amazonaws.cn/systems-manager/latest/userguide/parameter-store-policy-conditions.html#parameter-policies-condition](https://docs.amazonaws.cn/systems-manager/latest/userguide/parameter-store-policy-conditions.html#parameter-policies-condition)  | 通过控制 IAM 实体（用户或角色）是否可以创建或更新包含参数策略的参数来筛选访问权限 | 字符串 | 
|   [https://docs.amazonaws.cn/systems-manager/latest/userguide/parameter-store-policy-conditions.html#recursive-condition](https://docs.amazonaws.cn/systems-manager/latest/userguide/parameter-store-policy-conditions.html#recursive-condition)  | 按在某个层次结构中创建的 Systems Manager 参数筛选访问权限 | 字符串 | 
|   [https://docs.amazonaws.cn/systems-manager/latest/userguide/getting-started-sessiondocumentaccesscheck.html](https://docs.amazonaws.cn/systems-manager/latest/userguide/getting-started-sessiondocumentaccesscheck.html)  | 验证用户是否有权访问默认会话管理器配置文档或在请求中指定的自定义配置文档，从而筛选访问 | 布尔型 | 
|   [https://docs.amazonaws.cn/service-authorization/latest/reference/list_awssystemsmanager.html#awssystemsmanager-policy-keys](https://docs.amazonaws.cn/service-authorization/latest/reference/list_awssystemsmanager.html#awssystemsmanager-policy-keys)  | 通过验证发出请求的 Amazon 系统管理员托管实例的 Amazon 资源名称 (ARN) 来筛选访问权限。如果发出请求的托管实例使用与 EC2 实例配置文件关联的 IAM 角色进行身份验证，则此密钥不会出现 | 进行筛选 | 
|   [https://docs.amazonaws.cn/systems-manager/latest/userguide/auth-and-access-control-iam-access-control-identity-based.html#policy-conditions](https://docs.amazonaws.cn/systems-manager/latest/userguide/auth-and-access-control-iam-access-control-identity-based.html#policy-conditions)  | 通过验证用户是否也可以访问请求中 ResourceDataSync SyncType 指定的内容来筛选访问权限 | 字符串 | 
|   [https://docs.amazonaws.cn/systems-manager/latest/userguide/security_iam_service-with-iam.html#policy-conditions](https://docs.amazonaws.cn/systems-manager/latest/userguide/security_iam_service-with-iam.html#policy-conditions)  | 按分配给 Systems Manager 资源的标签键值对筛选访问权限 | 字符串 | 
|   [https://docs.amazonaws.cn/systems-manager/latest/userguide/auth-and-access-control-iam-access-control-identity-based.html#policy-conditions](https://docs.amazonaws.cn/systems-manager/latest/userguide/auth-and-access-control-iam-access-control-identity-based.html#policy-conditions)  | 根据分配给 Systems Manager 会话资源的标签键/值对筛选访问权限 | 字符串 | 
|   [https://docs.amazonaws.cn/systems-manager/latest/userguide/auth-and-access-control-iam-access-control-identity-based.html#policy-conditions](https://docs.amazonaws.cn/systems-manager/latest/userguide/auth-and-access-control-iam-access-control-identity-based.html#policy-conditions)  | 根据分配给 Systems Manager 会话资源的标签键/值对筛选访问权限 | 字符串 | 
|   [https://docs.amazonaws.cn/systems-manager/latest/userguide/auth-and-access-control-iam-access-control-identity-based.html#policy-conditions](https://docs.amazonaws.cn/systems-manager/latest/userguide/auth-and-access-control-iam-access-control-identity-based.html#policy-conditions)  | 根据分配给 Systems Manager 资源的标签键/值对筛选访问权限 | 字符串 | 