Actions, resources, and condition keys for Amazon Resource Explorer
Amazon Resource Explorer (service prefix: resource-explorer-2) provides the following
service-specific operations, resources, actions, and condition keys for use in IAM permission
policies.
References:
-
Learn how to configure this service.
-
View a list of the API operations available for this service.
-
Learn how to secure this service and its resources by using IAM permission policies.
-
View the programmatic service authorization reference
for this service.
Topics
API operations defined by Amazon Resource Explorer
The following table maps API operations to the IAM actions they authorize. Only condition keys that have static values for the given API and action are listed; for the full set of condition keys supported by each action, see the Actions table.
| Operation | IAM action | Condition key | Possible value(s) | Access level |
|---|---|---|---|---|
|
AssociateDefaultView |
Write |
|||
|
BatchGetView |
Read |
|||
Read |
||||
|
CreateIndex |
Write |
|||
Tagging, Write |
||||
|
CreateResourceExplorerSetup |
Write |
|||
|
CreateView |
Write |
|||
Tagging, Write |
||||
|
DeleteIndex |
Write |
|||
|
DeleteResourceExplorerSetup |
Write |
|||
|
DeleteView |
Write |
|||
|
DisassociateDefaultView |
Write |
|||
|
GetAccountLevelServiceConfiguration |
Read |
|||
|
GetDefaultView |
Read |
|||
|
GetIndex |
Read |
|||
|
GetManagedView |
Read |
|||
|
GetResourceExplorerSetup |
Read |
|||
|
GetServiceIndex |
Read |
|||
|
GetServiceView |
Read |
|||
|
GetView |
Read |
|||
|
ListIndexes |
List |
|||
|
ListIndexesForMembers |
List |
|||
|
ListManagedViews |
List |
|||
|
ListResources |
Read |
|||
|
ListServiceIndexes |
List |
|||
|
ListServiceViews |
List |
|||
|
ListStreamingAccessForServices |
List |
|||
|
ListSupportedResourceTypes |
List |
|||
|
ListTagsForResource |
Read |
|||
|
ListViews |
List |
|||
|
Search |
Read |
|||
|
TagResource |
Tagging, Write |
|||
|
UntagResource |
Tagging, Write |
|||
|
UpdateIndexType |
Write |
|||
|
UpdateView |
Write |
Actions defined by Amazon Resource Explorer
You can specify the following actions in the Action element of an IAM
policy statement. Use policies to grant permissions to perform an operation in Amazon. When
you use an action in a policy, you usually allow or deny access to the API operation or CLI
command with the same name. However, in some cases, a single action controls access to more
than one operation. Alternatively, some operations require several different actions.
| Actions | Description | Resource types (*required) | Condition keys | Access level |
|---|---|---|---|---|
Grants permission to set the specified view as the default for this Amazon Web Services Region in this Amazon Web Services account |
Write |
|||
Grants permission to retrieve details about views that you specify by a list of ARNs |
Read |
|||
Grants permission to turn on Resource Explorer in the Amazon Web Services Region in which you called this operation by creating an index |
Write |
|||
Grants permission to create resource explorer setup |
Write |
|||
Grants permission to create a view that users can query |
Write |
|||
Grants permission to turn off Resource Explorer in the specified Amazon Web Services Region by deleting the index |
Write |
|||
Grants permission to delete resource explorer setup |
Write |
|||
Grants permission to delete a view |
Write |
|||
Grants permission to remove the default view for the Amazon Web Services Region in which you call this operation |
Write |
|||
Grants permission to Resource Explorer to access account level data within your Amazon Organization |
Read |
|||
Grants permission to retrieve the Amazon resource name (ARN) of the view that is the default for the Amazon Web Services Region in which you call this operation |
Read |
|||
Grants permission to retrieve information about the index in the Amazon Web Services Region in which you call this operation |
Read |
|||
Grants permission to get managed view |
Read |
|||
Grants permission to get resource explorer setup |
Read |
|||
Grants permission to get service index |
Read |
|||
Grants permission to get service view |
Read |
|||
Grants permission to retrieve information about the specified view |
Read |
|||
Grants permission to list the indexes in all Amazon Web Services Regions |
List |
|||
Grants permission to list the organization member account's indexes in all Amazon Web Services Regions |
List |
|||
Grants permission to list managed views |
List |
|||
Grants permission to list service indexes in all Amazon Web Services Regions |
List |
|||
Grants permission to list service views in all Amazon Web Services Regions |
List |
|||
Grants permission to list streaming access for services |
List |
|||
Grants permission to retrieve a list of all resource types currently supported by Resource Explorer |
List |
|||
Grants permission to list the tags that are attached to the specified resource |
Read |
|||
Grants permission to list the Amazon resource names (ARNs) of all of the views available in the Amazon Web Services Region in which you call this operation |
List |
|||
Grants permission to search for resources and display details about all resources that match the specified criteria |
Read |
|||
Grants permission to add one or more tag key and value pairs to the specified resource |
Tagging, Write |
|||
Grants permission to remove one or more tag key and value pairs from the specified resource |
Tagging, Write |
|||
Grants permission to change the type of the index from LOCAL to AGGREGATOR or back |
Write |
|||
Grants permission to modify some of the details of a view |
Write |
Permission-only actions for Amazon Resource Explorer
The following actions are defined by Amazon Resource Explorer but are not directly invocable through any API operation. They can only be used in IAM policy statements to grant or deny permissions.
| Actions | Description | Resource types (*required) | Condition keys | Access level |
|---|---|---|---|---|
Grants permission to create managed view |
Write |
|||
Grants permission to create resource explorer streaming access |
Write |
|||
Grants permission to delete the specified view's resource policy |
Permissions management, Write |
|||
|
DeleteStreamingAccessForService |
Grants permission to delete resource explorer streaming access |
Write |
||
Grants permission to retrieve information about the specified view's resource policy |
Read |
|||
Grants permission to update the specified view's resource policy |
Permissions management, Write |
Resource types defined by Amazon Resource Explorer
The following resource types are defined by this service and can be used in the
Resource element of IAM permission policy statements.
| Resource types | ARN | Condition keys |
|---|---|---|
arn:${Partition}:resource-explorer-2:${Region}:${Account}:index/${IndexUuid} |
||
arn:${Partition}:resource-explorer-2:${Region}:${Account}:managed-view/${ManagedViewName}/${ManagedViewUuid} |
||
arn:${Partition}:resource-explorer-2:${Region}:${Account}:view/${ViewName}/${ViewUuid} |
Condition keys for Amazon Resource Explorer
Amazon Resource Explorer defines the following condition keys that can be used in the
Condition element of an IAM policy.
| Condition keys | Description | Type |
|---|---|---|
Filters access by the tag keys that are passed in the request |
String |
|
Filters access by the tag keyss attached to the resource |
String |
|
Filters access by the tag keys that are passed in the request |
ArrayOfString |
|
Filters access by the actual operation that is being invoked, available values: Search, ListResources |
String |