@cloud-copilot/iam-data
Version:
293 lines • 10 kB
JSON
{
"associateservicequotatemplate": {
"name": "AssociateServiceQuotaTemplate",
"description": "Grants permission to associate the Service Quotas template with your organization",
"accessLevel": "Write",
"resourceTypes": [],
"conditionKeys": [],
"dependentActions": [
"organizations:DescribeOrganization",
"organizations:EnableAWSServiceAccess"
]
},
"createsupportcase": {
"name": "CreateSupportCase",
"description": "Grants permission to submit a request to create a support case for an existing quota increase request",
"accessLevel": "Write",
"resourceTypes": [],
"conditionKeys": [],
"dependentActions": []
},
"deleteservicequotaincreaserequestfromtemplate": {
"name": "DeleteServiceQuotaIncreaseRequestFromTemplate",
"description": "Grants permission to remove the specified service quota from the service quota template",
"accessLevel": "Write",
"resourceTypes": [],
"conditionKeys": [],
"dependentActions": [
"organizations:DescribeOrganization"
]
},
"disassociateservicequotatemplate": {
"name": "DisassociateServiceQuotaTemplate",
"description": "Grants permission to disassociate the Service Quotas template from your organization",
"accessLevel": "Write",
"resourceTypes": [],
"conditionKeys": [],
"dependentActions": [
"organizations:DescribeOrganization"
]
},
"getawsdefaultservicequota": {
"name": "GetAWSDefaultServiceQuota",
"description": "Grants permission to return the details for the specified service quota, including the AWS default value",
"accessLevel": "Read",
"resourceTypes": [],
"conditionKeys": [],
"dependentActions": []
},
"getassociationforservicequotatemplate": {
"name": "GetAssociationForServiceQuotaTemplate",
"description": "Grants permission to retrieve the ServiceQuotaTemplateAssociationStatus value, which tells you if the Service Quotas template is associated with an organization",
"accessLevel": "Read",
"resourceTypes": [],
"conditionKeys": [],
"dependentActions": [
"organizations:DescribeOrganization"
]
},
"getautomanagementconfiguration": {
"name": "GetAutoManagementConfiguration",
"description": "Grants permission to retrieve the automatic management of Service Quotas configuration, including notification settings, opt-in type, and excluded quotas",
"accessLevel": "Read",
"resourceTypes": [],
"conditionKeys": [],
"dependentActions": []
},
"getquotautilizationreport": {
"name": "GetQuotaUtilizationReport",
"description": "Grants permission to view the generated report",
"accessLevel": "Read",
"resourceTypes": [],
"conditionKeys": [],
"dependentActions": []
},
"getrequestedservicequotachange": {
"name": "GetRequestedServiceQuotaChange",
"description": "Grants permission to retrieve the details for a particular service quota increase request",
"accessLevel": "Read",
"resourceTypes": [],
"conditionKeys": [],
"dependentActions": []
},
"getservicequota": {
"name": "GetServiceQuota",
"description": "Grants permission to return the details for the specified service quota, including the applied value",
"accessLevel": "Read",
"resourceTypes": [
{
"name": "quota",
"required": false,
"conditionKeys": [],
"dependentActions": [
"autoscaling:DescribeAccountLimits",
"cloudformation:DescribeAccountLimits",
"dynamodb:DescribeLimits",
"elasticloadbalancing:DescribeAccountLimits",
"iam:GetAccountSummary",
"kinesis:DescribeLimits",
"rds:DescribeAccountAttributes",
"route53:GetAccountLimit"
]
}
],
"conditionKeys": [
"servicequotas:service"
],
"dependentActions": []
},
"getservicequotaincreaserequestfromtemplate": {
"name": "GetServiceQuotaIncreaseRequestFromTemplate",
"description": "Grants permission to retrieve the details for a service quota increase request from the service quota template",
"accessLevel": "Read",
"resourceTypes": [
{
"name": "quota",
"required": false,
"conditionKeys": [],
"dependentActions": [
"organizations:DescribeOrganization"
]
}
],
"conditionKeys": [
"servicequotas:service"
],
"dependentActions": []
},
"listawsdefaultservicequotas": {
"name": "ListAWSDefaultServiceQuotas",
"description": "Grants permission to list all default service quotas for the specified AWS service",
"accessLevel": "Read",
"resourceTypes": [],
"conditionKeys": [],
"dependentActions": []
},
"listrequestedservicequotachangehistory": {
"name": "ListRequestedServiceQuotaChangeHistory",
"description": "Grants permission to request a list of the changes to quotas for a service",
"accessLevel": "Read",
"resourceTypes": [],
"conditionKeys": [],
"dependentActions": []
},
"listrequestedservicequotachangehistorybyquota": {
"name": "ListRequestedServiceQuotaChangeHistoryByQuota",
"description": "Grants permission to request a list of the changes to specific service quotas",
"accessLevel": "Read",
"resourceTypes": [
{
"name": "quota",
"required": false,
"conditionKeys": [],
"dependentActions": []
}
],
"conditionKeys": [
"servicequotas:service"
],
"dependentActions": []
},
"listservicequotaincreaserequestsintemplate": {
"name": "ListServiceQuotaIncreaseRequestsInTemplate",
"description": "Grants permission to return a list of the service quota increase requests from the service quota template",
"accessLevel": "Read",
"resourceTypes": [],
"conditionKeys": [],
"dependentActions": [
"organizations:DescribeOrganization"
]
},
"listservicequotas": {
"name": "ListServiceQuotas",
"description": "Grants permission to list all service quotas for the specified AWS service, in that account, in that Region",
"accessLevel": "Read",
"resourceTypes": [],
"conditionKeys": [],
"dependentActions": [
"autoscaling:DescribeAccountLimits",
"cloudformation:DescribeAccountLimits",
"dynamodb:DescribeLimits",
"elasticloadbalancing:DescribeAccountLimits",
"iam:GetAccountSummary",
"kinesis:DescribeLimits",
"rds:DescribeAccountAttributes",
"route53:GetAccountLimit"
]
},
"listservices": {
"name": "ListServices",
"description": "Grants permission to list the AWS services available in Service Quotas",
"accessLevel": "Read",
"resourceTypes": [],
"conditionKeys": [],
"dependentActions": []
},
"listtagsforresource": {
"name": "ListTagsForResource",
"description": "Grants permission to view the existing tags on a SQ resource",
"accessLevel": "Read",
"resourceTypes": [],
"conditionKeys": [],
"dependentActions": []
},
"putservicequotaincreaserequestintotemplate": {
"name": "PutServiceQuotaIncreaseRequestIntoTemplate",
"description": "Grants permission to define and add a quota to the service quota template",
"accessLevel": "Write",
"resourceTypes": [
{
"name": "quota",
"required": false,
"conditionKeys": [],
"dependentActions": [
"organizations:DescribeOrganization"
]
}
],
"conditionKeys": [
"servicequotas:service"
],
"dependentActions": []
},
"requestservicequotaincrease": {
"name": "RequestServiceQuotaIncrease",
"description": "Grants permission to submit the request for a service quota increase",
"accessLevel": "Write",
"resourceTypes": [
{
"name": "quota",
"required": false,
"conditionKeys": [],
"dependentActions": []
}
],
"conditionKeys": [
"servicequotas:service"
],
"dependentActions": []
},
"startautomanagement": {
"name": "StartAutoManagement",
"description": "Grants permission to enable automatic management of Service Quotas for an AWS account, including notification preferences and excluded quotas configurations",
"accessLevel": "Write",
"resourceTypes": [],
"conditionKeys": [],
"dependentActions": []
},
"startquotautilizationreport": {
"name": "StartQuotaUtilizationReport",
"description": "Grants permission to query quota utilization and create a report for your account",
"accessLevel": "Read",
"resourceTypes": [],
"conditionKeys": [],
"dependentActions": []
},
"stopautomanagement": {
"name": "StopAutoManagement",
"description": "Grants permission to stop automatic management of Service Quotas for an AWS account and remove all associated configurations",
"accessLevel": "Write",
"resourceTypes": [],
"conditionKeys": [],
"dependentActions": []
},
"tagresource": {
"name": "TagResource",
"description": "Grants permission to associate a set of tags with an existing SQ resource",
"accessLevel": "Tagging",
"resourceTypes": [],
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:TagKeys"
],
"dependentActions": []
},
"untagresource": {
"name": "UntagResource",
"description": "Grants permission to remove a set of tags from a SQ resource, where tags to be removed match a set of customer-supplied tag keys",
"accessLevel": "Tagging",
"resourceTypes": [],
"conditionKeys": [
"aws:TagKeys"
],
"dependentActions": []
},
"updateautomanagement": {
"name": "UpdateAutoManagement",
"description": "Grants permission to update the automatic management of Service Quotas configuration, including notification preferences and excluded quotas",
"accessLevel": "Write",
"resourceTypes": [],
"conditionKeys": [],
"dependentActions": []
}
}