UNPKG

@cloud-copilot/iam-data

Version:
600 lines 18.3 kB
{ "createcentralizationrulefororganization": { "name": "CreateCentralizationRuleForOrganization", "description": "Grants permission to create a new organization centralization rule with the specified name for the organization", "accessLevel": "Write", "resourceTypes": [ { "name": "organization-centralization-rule", "required": true, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [ "aws:TagKeys", "aws:RequestTag/${TagKey}", "observabilityadmin:CentralizationSourceRegions", "observabilityadmin:CentralizationDestinationRegion", "observabilityadmin:CentralizationBackupRegion", "observabilityadmin:CentralizationRuleName", "observabilityadmin:CentralizationSourceId", "observabilityadmin:CentralizationDestinationAccount" ], "dependentActions": [] }, "creates3tableintegration": { "name": "CreateS3TableIntegration", "description": "Grants permission to create a new s3 table integration with the specified configuration", "accessLevel": "Write", "resourceTypes": [ { "name": "s3tableintegration", "required": true, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [ "aws:TagKeys", "aws:RequestTag/${TagKey}" ], "dependentActions": [] }, "createtelemetrypipeline": { "name": "CreateTelemetryPipeline", "description": "Grants permission to create a new telemetry pipeline with the specified name and configuration", "accessLevel": "Write", "resourceTypes": [ { "name": "telemetry-pipeline", "required": true, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [ "aws:TagKeys", "aws:RequestTag/${TagKey}", "observabilityadmin:SourceType" ], "dependentActions": [] }, "createtelemetryrule": { "name": "CreateTelemetryRule", "description": "Grants permission to create a new telemetry rule with the specified name for the account", "accessLevel": "Write", "resourceTypes": [ { "name": "telemetry-rule", "required": true, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [ "aws:TagKeys", "aws:RequestTag/${TagKey}", "observabilityadmin:TargetRegions" ], "dependentActions": [] }, "createtelemetryrulefororganization": { "name": "CreateTelemetryRuleForOrganization", "description": "Grants permission to create a new organization telemetry rule with the specified name for the organization", "accessLevel": "Write", "resourceTypes": [ { "name": "organization-telemetry-rule", "required": true, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [ "aws:TagKeys", "aws:RequestTag/${TagKey}", "observabilityadmin:TargetRegions" ], "dependentActions": [] }, "deletecentralizationrulefororganization": { "name": "DeleteCentralizationRuleForOrganization", "description": "Grants permission to delete an organization centralization rule with the specified name for the organization", "accessLevel": "Write", "resourceTypes": [ { "name": "organization-centralization-rule", "required": true, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [ "observabilityadmin:CentralizationRuleName" ], "dependentActions": [] }, "deletes3tableintegration": { "name": "DeleteS3TableIntegration", "description": "Grants permission to delete the s3 table integration with the specified arn", "accessLevel": "Write", "resourceTypes": [ { "name": "s3tableintegration", "required": true, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [], "dependentActions": [] }, "deletetelemetrypipeline": { "name": "DeleteTelemetryPipeline", "description": "Grants permission to delete the telemetry pipeline with the specified arn", "accessLevel": "Write", "resourceTypes": [ { "name": "telemetry-pipeline", "required": true, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [], "dependentActions": [] }, "deletetelemetryrule": { "name": "DeleteTelemetryRule", "description": "Grants permission to delete a telemetry rule with the specified name for the account", "accessLevel": "Write", "resourceTypes": [ { "name": "telemetry-rule", "required": true, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [], "dependentActions": [] }, "deletetelemetryrulefororganization": { "name": "DeleteTelemetryRuleForOrganization", "description": "Grants permission to delete an organization telemetry rule with the specified name for the organization", "accessLevel": "Write", "resourceTypes": [ { "name": "organization-telemetry-rule", "required": true, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [], "dependentActions": [] }, "getcentralizationrulefororganization": { "name": "GetCentralizationRuleForOrganization", "description": "Grants permission to retrieve the specified organization centralization rule for the organization", "accessLevel": "Read", "resourceTypes": [ { "name": "organization-centralization-rule", "required": true, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [ "observabilityadmin:CentralizationRuleName" ], "dependentActions": [] }, "gets3tableintegration": { "name": "GetS3TableIntegration", "description": "Grants permission to retrieve the specified s3 table integration for the account", "accessLevel": "Read", "resourceTypes": [ { "name": "s3tableintegration", "required": true, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [], "dependentActions": [] }, "gettelemetryenrichmentstatus": { "name": "GetTelemetryEnrichmentStatus", "description": "Grants permission to retrieve the status of the Resource tags for telemetry feature for the account", "accessLevel": "Read", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "gettelemetryevaluationstatus": { "name": "GetTelemetryEvaluationStatus", "description": "Grants permission to retrieve the Telemetry Config feature status for the account", "accessLevel": "Read", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "gettelemetryevaluationstatusfororganization": { "name": "GetTelemetryEvaluationStatusForOrganization", "description": "Grants permission to retrieve the Telemetry Config feature status for the organization", "accessLevel": "Read", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "gettelemetrypipeline": { "name": "GetTelemetryPipeline", "description": "Grants permission to Get the telemetry pipeline with the specified name or arn", "accessLevel": "Read", "resourceTypes": [ { "name": "telemetry-pipeline", "required": true, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [], "dependentActions": [] }, "gettelemetryrule": { "name": "GetTelemetryRule", "description": "Grants permission to retrieve the specified telemetry rule for the account", "accessLevel": "Read", "resourceTypes": [ { "name": "telemetry-rule", "required": true, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [], "dependentActions": [] }, "gettelemetryrulefororganization": { "name": "GetTelemetryRuleForOrganization", "description": "Grants permission to retrieve the specified organization telemetry rule for the organization", "accessLevel": "Read", "resourceTypes": [ { "name": "organization-telemetry-rule", "required": true, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [], "dependentActions": [] }, "listcentralizationrulesfororganization": { "name": "ListCentralizationRulesForOrganization", "description": "Grants permission to list the centralization rules for the organization", "accessLevel": "List", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "listresourcetelemetry": { "name": "ListResourceTelemetry", "description": "Grants permission to retrieve telemetry configurations for resources associated with the account", "accessLevel": "Read", "resourceTypes": [], "conditionKeys": [ "observabilityadmin:TargetRegions" ], "dependentActions": [] }, "listresourcetelemetryfororganization": { "name": "ListResourceTelemetryForOrganization", "description": "Grants permission to retrieve telemetry configurations for resources associated with accounts in the organization", "accessLevel": "Read", "resourceTypes": [], "conditionKeys": [ "observabilityadmin:TargetRegions" ], "dependentActions": [] }, "lists3tableintegrations": { "name": "ListS3TableIntegrations", "description": "Grants permission to list s3 table integrations for the account", "accessLevel": "List", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "listtagsforresource": { "name": "ListTagsForResource", "description": "Grants permission to list the tags for the specified resource", "accessLevel": "List", "resourceTypes": [ { "name": "organization-centralization-rule", "required": false, "conditionKeys": [], "dependentActions": [] }, { "name": "organization-telemetry-rule", "required": false, "conditionKeys": [], "dependentActions": [] }, { "name": "s3tableintegration", "required": false, "conditionKeys": [], "dependentActions": [] }, { "name": "telemetry-pipeline", "required": false, "conditionKeys": [], "dependentActions": [] }, { "name": "telemetry-rule", "required": false, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [], "dependentActions": [] }, "listtelemetrypipelines": { "name": "ListTelemetryPipelines", "description": "Grants permission to List telemetry pipelines for the account", "accessLevel": "List", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "listtelemetryrules": { "name": "ListTelemetryRules", "description": "Grants permission to list the telemetry rules for the account", "accessLevel": "List", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "listtelemetryrulesfororganization": { "name": "ListTelemetryRulesForOrganization", "description": "Grants permission to list the telemetry rules for the organization", "accessLevel": "List", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "starttelemetryenrichment": { "name": "StartTelemetryEnrichment", "description": "Grants permission to enable the Resource tags for telemetry feature for the account", "accessLevel": "Write", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "starttelemetryevaluation": { "name": "StartTelemetryEvaluation", "description": "Grants permission to start the Telemetry Config feature for the account", "accessLevel": "Write", "resourceTypes": [], "conditionKeys": [ "observabilityadmin:TargetRegions" ], "dependentActions": [] }, "starttelemetryevaluationfororganization": { "name": "StartTelemetryEvaluationForOrganization", "description": "Grants permission to start the Telemetry Config feature for the organization", "accessLevel": "Write", "resourceTypes": [], "conditionKeys": [ "observabilityadmin:TargetRegions" ], "dependentActions": [] }, "stoptelemetryenrichment": { "name": "StopTelemetryEnrichment", "description": "Grants permission to disable the Resource tags for telemetry feature for the account", "accessLevel": "Write", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "stoptelemetryevaluation": { "name": "StopTelemetryEvaluation", "description": "Grants permission to stop the Telemetry Config feature for the account", "accessLevel": "Write", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "stoptelemetryevaluationfororganization": { "name": "StopTelemetryEvaluationForOrganization", "description": "Grants permission to stop the Telemetry Config feature for the organization", "accessLevel": "Write", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "tagresource": { "name": "TagResource", "description": "Grants permission to add or update the specified tags for the specified resource", "accessLevel": "Tagging", "resourceTypes": [ { "name": "organization-centralization-rule", "required": false, "conditionKeys": [], "dependentActions": [] }, { "name": "organization-telemetry-rule", "required": false, "conditionKeys": [], "dependentActions": [] }, { "name": "s3tableintegration", "required": false, "conditionKeys": [], "dependentActions": [] }, { "name": "telemetry-pipeline", "required": false, "conditionKeys": [], "dependentActions": [] }, { "name": "telemetry-rule", "required": false, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [ "aws:TagKeys", "aws:RequestTag/${TagKey}" ], "dependentActions": [] }, "testtelemetrypipeline": { "name": "TestTelemetryPipeline", "description": "Grants permission to Test a telemetry pipeline configuration with sample data", "accessLevel": "Read", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] }, "untagresource": { "name": "UntagResource", "description": "Grants permission to remove the specified tags from the specified resource", "accessLevel": "Tagging", "resourceTypes": [ { "name": "organization-centralization-rule", "required": false, "conditionKeys": [], "dependentActions": [] }, { "name": "organization-telemetry-rule", "required": false, "conditionKeys": [], "dependentActions": [] }, { "name": "s3tableintegration", "required": false, "conditionKeys": [], "dependentActions": [] }, { "name": "telemetry-pipeline", "required": false, "conditionKeys": [], "dependentActions": [] }, { "name": "telemetry-rule", "required": false, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [ "aws:TagKeys" ], "dependentActions": [] }, "updatecentralizationrulefororganization": { "name": "UpdateCentralizationRuleForOrganization", "description": "Grants permission to update the specified centralization rule for the organization", "accessLevel": "Write", "resourceTypes": [ { "name": "organization-centralization-rule", "required": true, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [ "observabilityadmin:CentralizationSourceRegions", "observabilityadmin:CentralizationDestinationRegion", "observabilityadmin:CentralizationBackupRegion", "observabilityadmin:CentralizationRuleName", "observabilityadmin:CentralizationSourceId", "observabilityadmin:CentralizationDestinationAccount" ], "dependentActions": [] }, "updatetelemetrypipeline": { "name": "UpdateTelemetryPipeline", "description": "Grants permission to Update the telemetry pipeline with the specified arn", "accessLevel": "Write", "resourceTypes": [ { "name": "telemetry-pipeline", "required": true, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [], "dependentActions": [] }, "updatetelemetryrule": { "name": "UpdateTelemetryRule", "description": "Grants permission to update the specified telemetry rule for the account", "accessLevel": "Write", "resourceTypes": [ { "name": "telemetry-rule", "required": true, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [ "observabilityadmin:TargetRegions" ], "dependentActions": [] }, "updatetelemetryrulefororganization": { "name": "UpdateTelemetryRuleForOrganization", "description": "Grants permission to update the specified telemetry rule for the organization", "accessLevel": "Write", "resourceTypes": [ { "name": "organization-telemetry-rule", "required": true, "conditionKeys": [], "dependentActions": [] } ], "conditionKeys": [ "observabilityadmin:TargetRegions" ], "dependentActions": [] }, "validatetelemetrypipelineconfiguration": { "name": "ValidateTelemetryPipelineConfiguration", "description": "Grants permission to Validate a telemetry pipeline configuration", "accessLevel": "Read", "resourceTypes": [], "conditionKeys": [], "dependentActions": [] } }