@cloud-copilot/iam-data
Version:
600 lines • 18.3 kB
JSON
{
"createcentralizationrulefororganization": {
"name": "CreateCentralizationRuleForOrganization",
"description": "Grants permission to create a new organization centralization rule with the specified name for the organization",
"accessLevel": "Write",
"resourceTypes": [
{
"name": "organization-centralization-rule",
"required": true,
"conditionKeys": [],
"dependentActions": []
}
],
"conditionKeys": [
"aws:TagKeys",
"aws:RequestTag/${TagKey}",
"observabilityadmin:CentralizationSourceRegions",
"observabilityadmin:CentralizationDestinationRegion",
"observabilityadmin:CentralizationBackupRegion",
"observabilityadmin:CentralizationRuleName",
"observabilityadmin:CentralizationSourceId",
"observabilityadmin:CentralizationDestinationAccount"
],
"dependentActions": []
},
"creates3tableintegration": {
"name": "CreateS3TableIntegration",
"description": "Grants permission to create a new s3 table integration with the specified configuration",
"accessLevel": "Write",
"resourceTypes": [
{
"name": "s3tableintegration",
"required": true,
"conditionKeys": [],
"dependentActions": []
}
],
"conditionKeys": [
"aws:TagKeys",
"aws:RequestTag/${TagKey}"
],
"dependentActions": []
},
"createtelemetrypipeline": {
"name": "CreateTelemetryPipeline",
"description": "Grants permission to create a new telemetry pipeline with the specified name and configuration",
"accessLevel": "Write",
"resourceTypes": [
{
"name": "telemetry-pipeline",
"required": true,
"conditionKeys": [],
"dependentActions": []
}
],
"conditionKeys": [
"aws:TagKeys",
"aws:RequestTag/${TagKey}",
"observabilityadmin:SourceType"
],
"dependentActions": []
},
"createtelemetryrule": {
"name": "CreateTelemetryRule",
"description": "Grants permission to create a new telemetry rule with the specified name for the account",
"accessLevel": "Write",
"resourceTypes": [
{
"name": "telemetry-rule",
"required": true,
"conditionKeys": [],
"dependentActions": []
}
],
"conditionKeys": [
"aws:TagKeys",
"aws:RequestTag/${TagKey}",
"observabilityadmin:TargetRegions"
],
"dependentActions": []
},
"createtelemetryrulefororganization": {
"name": "CreateTelemetryRuleForOrganization",
"description": "Grants permission to create a new organization telemetry rule with the specified name for the organization",
"accessLevel": "Write",
"resourceTypes": [
{
"name": "organization-telemetry-rule",
"required": true,
"conditionKeys": [],
"dependentActions": []
}
],
"conditionKeys": [
"aws:TagKeys",
"aws:RequestTag/${TagKey}",
"observabilityadmin:TargetRegions"
],
"dependentActions": []
},
"deletecentralizationrulefororganization": {
"name": "DeleteCentralizationRuleForOrganization",
"description": "Grants permission to delete an organization centralization rule with the specified name for the organization",
"accessLevel": "Write",
"resourceTypes": [
{
"name": "organization-centralization-rule",
"required": true,
"conditionKeys": [],
"dependentActions": []
}
],
"conditionKeys": [
"observabilityadmin:CentralizationRuleName"
],
"dependentActions": []
},
"deletes3tableintegration": {
"name": "DeleteS3TableIntegration",
"description": "Grants permission to delete the s3 table integration with the specified arn",
"accessLevel": "Write",
"resourceTypes": [
{
"name": "s3tableintegration",
"required": true,
"conditionKeys": [],
"dependentActions": []
}
],
"conditionKeys": [],
"dependentActions": []
},
"deletetelemetrypipeline": {
"name": "DeleteTelemetryPipeline",
"description": "Grants permission to delete the telemetry pipeline with the specified arn",
"accessLevel": "Write",
"resourceTypes": [
{
"name": "telemetry-pipeline",
"required": true,
"conditionKeys": [],
"dependentActions": []
}
],
"conditionKeys": [],
"dependentActions": []
},
"deletetelemetryrule": {
"name": "DeleteTelemetryRule",
"description": "Grants permission to delete a telemetry rule with the specified name for the account",
"accessLevel": "Write",
"resourceTypes": [
{
"name": "telemetry-rule",
"required": true,
"conditionKeys": [],
"dependentActions": []
}
],
"conditionKeys": [],
"dependentActions": []
},
"deletetelemetryrulefororganization": {
"name": "DeleteTelemetryRuleForOrganization",
"description": "Grants permission to delete an organization telemetry rule with the specified name for the organization",
"accessLevel": "Write",
"resourceTypes": [
{
"name": "organization-telemetry-rule",
"required": true,
"conditionKeys": [],
"dependentActions": []
}
],
"conditionKeys": [],
"dependentActions": []
},
"getcentralizationrulefororganization": {
"name": "GetCentralizationRuleForOrganization",
"description": "Grants permission to retrieve the specified organization centralization rule for the organization",
"accessLevel": "Read",
"resourceTypes": [
{
"name": "organization-centralization-rule",
"required": true,
"conditionKeys": [],
"dependentActions": []
}
],
"conditionKeys": [
"observabilityadmin:CentralizationRuleName"
],
"dependentActions": []
},
"gets3tableintegration": {
"name": "GetS3TableIntegration",
"description": "Grants permission to retrieve the specified s3 table integration for the account",
"accessLevel": "Read",
"resourceTypes": [
{
"name": "s3tableintegration",
"required": true,
"conditionKeys": [],
"dependentActions": []
}
],
"conditionKeys": [],
"dependentActions": []
},
"gettelemetryenrichmentstatus": {
"name": "GetTelemetryEnrichmentStatus",
"description": "Grants permission to retrieve the status of the Resource tags for telemetry feature for the account",
"accessLevel": "Read",
"resourceTypes": [],
"conditionKeys": [],
"dependentActions": []
},
"gettelemetryevaluationstatus": {
"name": "GetTelemetryEvaluationStatus",
"description": "Grants permission to retrieve the Telemetry Config feature status for the account",
"accessLevel": "Read",
"resourceTypes": [],
"conditionKeys": [],
"dependentActions": []
},
"gettelemetryevaluationstatusfororganization": {
"name": "GetTelemetryEvaluationStatusForOrganization",
"description": "Grants permission to retrieve the Telemetry Config feature status for the organization",
"accessLevel": "Read",
"resourceTypes": [],
"conditionKeys": [],
"dependentActions": []
},
"gettelemetrypipeline": {
"name": "GetTelemetryPipeline",
"description": "Grants permission to Get the telemetry pipeline with the specified name or arn",
"accessLevel": "Read",
"resourceTypes": [
{
"name": "telemetry-pipeline",
"required": true,
"conditionKeys": [],
"dependentActions": []
}
],
"conditionKeys": [],
"dependentActions": []
},
"gettelemetryrule": {
"name": "GetTelemetryRule",
"description": "Grants permission to retrieve the specified telemetry rule for the account",
"accessLevel": "Read",
"resourceTypes": [
{
"name": "telemetry-rule",
"required": true,
"conditionKeys": [],
"dependentActions": []
}
],
"conditionKeys": [],
"dependentActions": []
},
"gettelemetryrulefororganization": {
"name": "GetTelemetryRuleForOrganization",
"description": "Grants permission to retrieve the specified organization telemetry rule for the organization",
"accessLevel": "Read",
"resourceTypes": [
{
"name": "organization-telemetry-rule",
"required": true,
"conditionKeys": [],
"dependentActions": []
}
],
"conditionKeys": [],
"dependentActions": []
},
"listcentralizationrulesfororganization": {
"name": "ListCentralizationRulesForOrganization",
"description": "Grants permission to list the centralization rules for the organization",
"accessLevel": "List",
"resourceTypes": [],
"conditionKeys": [],
"dependentActions": []
},
"listresourcetelemetry": {
"name": "ListResourceTelemetry",
"description": "Grants permission to retrieve telemetry configurations for resources associated with the account",
"accessLevel": "Read",
"resourceTypes": [],
"conditionKeys": [
"observabilityadmin:TargetRegions"
],
"dependentActions": []
},
"listresourcetelemetryfororganization": {
"name": "ListResourceTelemetryForOrganization",
"description": "Grants permission to retrieve telemetry configurations for resources associated with accounts in the organization",
"accessLevel": "Read",
"resourceTypes": [],
"conditionKeys": [
"observabilityadmin:TargetRegions"
],
"dependentActions": []
},
"lists3tableintegrations": {
"name": "ListS3TableIntegrations",
"description": "Grants permission to list s3 table integrations for the account",
"accessLevel": "List",
"resourceTypes": [],
"conditionKeys": [],
"dependentActions": []
},
"listtagsforresource": {
"name": "ListTagsForResource",
"description": "Grants permission to list the tags for the specified resource",
"accessLevel": "List",
"resourceTypes": [
{
"name": "organization-centralization-rule",
"required": false,
"conditionKeys": [],
"dependentActions": []
},
{
"name": "organization-telemetry-rule",
"required": false,
"conditionKeys": [],
"dependentActions": []
},
{
"name": "s3tableintegration",
"required": false,
"conditionKeys": [],
"dependentActions": []
},
{
"name": "telemetry-pipeline",
"required": false,
"conditionKeys": [],
"dependentActions": []
},
{
"name": "telemetry-rule",
"required": false,
"conditionKeys": [],
"dependentActions": []
}
],
"conditionKeys": [],
"dependentActions": []
},
"listtelemetrypipelines": {
"name": "ListTelemetryPipelines",
"description": "Grants permission to List telemetry pipelines for the account",
"accessLevel": "List",
"resourceTypes": [],
"conditionKeys": [],
"dependentActions": []
},
"listtelemetryrules": {
"name": "ListTelemetryRules",
"description": "Grants permission to list the telemetry rules for the account",
"accessLevel": "List",
"resourceTypes": [],
"conditionKeys": [],
"dependentActions": []
},
"listtelemetryrulesfororganization": {
"name": "ListTelemetryRulesForOrganization",
"description": "Grants permission to list the telemetry rules for the organization",
"accessLevel": "List",
"resourceTypes": [],
"conditionKeys": [],
"dependentActions": []
},
"starttelemetryenrichment": {
"name": "StartTelemetryEnrichment",
"description": "Grants permission to enable the Resource tags for telemetry feature for the account",
"accessLevel": "Write",
"resourceTypes": [],
"conditionKeys": [],
"dependentActions": []
},
"starttelemetryevaluation": {
"name": "StartTelemetryEvaluation",
"description": "Grants permission to start the Telemetry Config feature for the account",
"accessLevel": "Write",
"resourceTypes": [],
"conditionKeys": [
"observabilityadmin:TargetRegions"
],
"dependentActions": []
},
"starttelemetryevaluationfororganization": {
"name": "StartTelemetryEvaluationForOrganization",
"description": "Grants permission to start the Telemetry Config feature for the organization",
"accessLevel": "Write",
"resourceTypes": [],
"conditionKeys": [
"observabilityadmin:TargetRegions"
],
"dependentActions": []
},
"stoptelemetryenrichment": {
"name": "StopTelemetryEnrichment",
"description": "Grants permission to disable the Resource tags for telemetry feature for the account",
"accessLevel": "Write",
"resourceTypes": [],
"conditionKeys": [],
"dependentActions": []
},
"stoptelemetryevaluation": {
"name": "StopTelemetryEvaluation",
"description": "Grants permission to stop the Telemetry Config feature for the account",
"accessLevel": "Write",
"resourceTypes": [],
"conditionKeys": [],
"dependentActions": []
},
"stoptelemetryevaluationfororganization": {
"name": "StopTelemetryEvaluationForOrganization",
"description": "Grants permission to stop the Telemetry Config feature for the organization",
"accessLevel": "Write",
"resourceTypes": [],
"conditionKeys": [],
"dependentActions": []
},
"tagresource": {
"name": "TagResource",
"description": "Grants permission to add or update the specified tags for the specified resource",
"accessLevel": "Tagging",
"resourceTypes": [
{
"name": "organization-centralization-rule",
"required": false,
"conditionKeys": [],
"dependentActions": []
},
{
"name": "organization-telemetry-rule",
"required": false,
"conditionKeys": [],
"dependentActions": []
},
{
"name": "s3tableintegration",
"required": false,
"conditionKeys": [],
"dependentActions": []
},
{
"name": "telemetry-pipeline",
"required": false,
"conditionKeys": [],
"dependentActions": []
},
{
"name": "telemetry-rule",
"required": false,
"conditionKeys": [],
"dependentActions": []
}
],
"conditionKeys": [
"aws:TagKeys",
"aws:RequestTag/${TagKey}"
],
"dependentActions": []
},
"testtelemetrypipeline": {
"name": "TestTelemetryPipeline",
"description": "Grants permission to Test a telemetry pipeline configuration with sample data",
"accessLevel": "Read",
"resourceTypes": [],
"conditionKeys": [],
"dependentActions": []
},
"untagresource": {
"name": "UntagResource",
"description": "Grants permission to remove the specified tags from the specified resource",
"accessLevel": "Tagging",
"resourceTypes": [
{
"name": "organization-centralization-rule",
"required": false,
"conditionKeys": [],
"dependentActions": []
},
{
"name": "organization-telemetry-rule",
"required": false,
"conditionKeys": [],
"dependentActions": []
},
{
"name": "s3tableintegration",
"required": false,
"conditionKeys": [],
"dependentActions": []
},
{
"name": "telemetry-pipeline",
"required": false,
"conditionKeys": [],
"dependentActions": []
},
{
"name": "telemetry-rule",
"required": false,
"conditionKeys": [],
"dependentActions": []
}
],
"conditionKeys": [
"aws:TagKeys"
],
"dependentActions": []
},
"updatecentralizationrulefororganization": {
"name": "UpdateCentralizationRuleForOrganization",
"description": "Grants permission to update the specified centralization rule for the organization",
"accessLevel": "Write",
"resourceTypes": [
{
"name": "organization-centralization-rule",
"required": true,
"conditionKeys": [],
"dependentActions": []
}
],
"conditionKeys": [
"observabilityadmin:CentralizationSourceRegions",
"observabilityadmin:CentralizationDestinationRegion",
"observabilityadmin:CentralizationBackupRegion",
"observabilityadmin:CentralizationRuleName",
"observabilityadmin:CentralizationSourceId",
"observabilityadmin:CentralizationDestinationAccount"
],
"dependentActions": []
},
"updatetelemetrypipeline": {
"name": "UpdateTelemetryPipeline",
"description": "Grants permission to Update the telemetry pipeline with the specified arn",
"accessLevel": "Write",
"resourceTypes": [
{
"name": "telemetry-pipeline",
"required": true,
"conditionKeys": [],
"dependentActions": []
}
],
"conditionKeys": [],
"dependentActions": []
},
"updatetelemetryrule": {
"name": "UpdateTelemetryRule",
"description": "Grants permission to update the specified telemetry rule for the account",
"accessLevel": "Write",
"resourceTypes": [
{
"name": "telemetry-rule",
"required": true,
"conditionKeys": [],
"dependentActions": []
}
],
"conditionKeys": [
"observabilityadmin:TargetRegions"
],
"dependentActions": []
},
"updatetelemetryrulefororganization": {
"name": "UpdateTelemetryRuleForOrganization",
"description": "Grants permission to update the specified telemetry rule for the organization",
"accessLevel": "Write",
"resourceTypes": [
{
"name": "organization-telemetry-rule",
"required": true,
"conditionKeys": [],
"dependentActions": []
}
],
"conditionKeys": [
"observabilityadmin:TargetRegions"
],
"dependentActions": []
},
"validatetelemetrypipelineconfiguration": {
"name": "ValidateTelemetryPipelineConfiguration",
"description": "Grants permission to Validate a telemetry pipeline configuration",
"accessLevel": "Read",
"resourceTypes": [],
"conditionKeys": [],
"dependentActions": []
}
}