@cloud-copilot/iam-data
Version:
657 lines • 26.3 kB
JSON
{
"accounts.google.com:aud": {
"key": "accounts.google.com:aud",
"description": "Filters access by the Google application ID",
"type": "String"
},
"accounts.google.com:google/organization_number": {
"key": "accounts.google.com:google/organization_number",
"description": "Filters access by the Google Cloud or Google Workspace organization number",
"type": "Numeric"
},
"accounts.google.com:oaud": {
"key": "accounts.google.com:oaud",
"description": "Filters access by the Google audience",
"type": "String"
},
"accounts.google.com:sub": {
"key": "accounts.google.com:sub",
"description": "Filters access by the subject of the claim (the Google user ID)",
"type": "String"
},
"agent.${domain}.buildkite.dev:build_branch": {
"key": "agent.${Domain}.buildkite.dev:build_branch",
"description": "Filters access by the git branch that triggered the Buildkite build",
"type": "String"
},
"agent.${domain}.buildkite.dev:cluster_id": {
"key": "agent.${Domain}.buildkite.dev:cluster_id",
"description": "Filters access by the Buildkite cluster ID",
"type": "String"
},
"agent.${domain}.buildkite.dev:cluster_name": {
"key": "agent.${Domain}.buildkite.dev:cluster_name",
"description": "Filters access by the Buildkite cluster name",
"type": "String"
},
"agent.${domain}.buildkite.dev:organization_id": {
"key": "agent.${Domain}.buildkite.dev:organization_id",
"description": "Filters access by the Buildkite organization ID",
"type": "String"
},
"agent.${domain}.buildkite.dev:organization_slug": {
"key": "agent.${Domain}.buildkite.dev:organization_slug",
"description": "Filters access by the Buildkite organization slug",
"type": "String"
},
"agent.${domain}.buildkite.dev:pipeline_id": {
"key": "agent.${Domain}.buildkite.dev:pipeline_id",
"description": "Filters access by the Buildkite pipeline ID",
"type": "String"
},
"agent.${domain}.buildkite.dev:pipeline_slug": {
"key": "agent.${Domain}.buildkite.dev:pipeline_slug",
"description": "Filters access by the Buildkite pipeline slug",
"type": "String"
},
"agent.${domain}.buildkite.site:build_branch": {
"key": "agent.${Domain}.buildkite.site:build_branch",
"description": "Filters access by the git branch that triggered the Buildkite build",
"type": "String"
},
"agent.${domain}.buildkite.site:cluster_id": {
"key": "agent.${Domain}.buildkite.site:cluster_id",
"description": "Filters access by the Buildkite cluster ID",
"type": "String"
},
"agent.${domain}.buildkite.site:cluster_name": {
"key": "agent.${Domain}.buildkite.site:cluster_name",
"description": "Filters access by the Buildkite cluster name",
"type": "String"
},
"agent.${domain}.buildkite.site:organization_id": {
"key": "agent.${Domain}.buildkite.site:organization_id",
"description": "Filters access by the Buildkite organization ID",
"type": "String"
},
"agent.${domain}.buildkite.site:organization_slug": {
"key": "agent.${Domain}.buildkite.site:organization_slug",
"description": "Filters access by the Buildkite organization slug",
"type": "String"
},
"agent.${domain}.buildkite.site:pipeline_id": {
"key": "agent.${Domain}.buildkite.site:pipeline_id",
"description": "Filters access by the Buildkite pipeline ID",
"type": "String"
},
"agent.${domain}.buildkite.site:pipeline_slug": {
"key": "agent.${Domain}.buildkite.site:pipeline_slug",
"description": "Filters access by the Buildkite pipeline slug",
"type": "String"
},
"agent.buildkite.com:build_branch": {
"key": "agent.buildkite.com:build_branch",
"description": "Filters access by the git branch that triggered the Buildkite build",
"type": "String"
},
"agent.buildkite.com:cluster_id": {
"key": "agent.buildkite.com:cluster_id",
"description": "Filters access by the Buildkite cluster ID",
"type": "String"
},
"agent.buildkite.com:cluster_name": {
"key": "agent.buildkite.com:cluster_name",
"description": "Filters access by the Buildkite cluster name",
"type": "String"
},
"agent.buildkite.com:organization_id": {
"key": "agent.buildkite.com:organization_id",
"description": "Filters access by the Buildkite organization ID",
"type": "String"
},
"agent.buildkite.com:organization_slug": {
"key": "agent.buildkite.com:organization_slug",
"description": "Filters access by the Buildkite organization slug",
"type": "String"
},
"agent.buildkite.com:pipeline_id": {
"key": "agent.buildkite.com:pipeline_id",
"description": "Filters access by the Buildkite pipeline ID",
"type": "String"
},
"agent.buildkite.com:pipeline_slug": {
"key": "agent.buildkite.com:pipeline_slug",
"description": "Filters access by the Buildkite pipeline slug",
"type": "String"
},
"aws:requesttag/${tagkey}": {
"key": "aws:RequestTag/${TagKey}",
"description": "Filters access by the tags that are passed in the request",
"type": "String"
},
"aws:resourcetag/${tagkey}": {
"key": "aws:ResourceTag/${TagKey}",
"description": "Filters access by the tags associated with the resource",
"type": "String"
},
"aws:tagkeys": {
"key": "aws:TagKeys",
"description": "Filters access by the tag keys that are passed in the request",
"type": "ArrayOfString"
},
"cognito-identity.amazonaws.com:amr": {
"key": "cognito-identity.amazonaws.com:amr",
"description": "Filters access by the login information for Amazon Cognito",
"type": "String"
},
"cognito-identity.amazonaws.com:aud": {
"key": "cognito-identity.amazonaws.com:aud",
"description": "Filters access by the Amazon Cognito identity pool ID",
"type": "String"
},
"cognito-identity.amazonaws.com:sub": {
"key": "cognito-identity.amazonaws.com:sub",
"description": "Filters access by the subject of the claim (the Amazon Cognito user ID)",
"type": "String"
},
"github.com/enterprises/${enterprisename}:actor": {
"key": "github.com/enterprises/${EnterpriseName}:actor",
"description": "Filters access by the personal account that initiated the workflow run",
"type": "String"
},
"github.com/enterprises/${enterprisename}:actor_id": {
"key": "github.com/enterprises/${EnterpriseName}:actor_id",
"description": "Filters access by the ID of the personal account that initiated the workflow run",
"type": "String"
},
"github.com/enterprises/${enterprisename}:enterprise_id": {
"key": "github.com/enterprises/${EnterpriseName}:enterprise_id",
"description": "Filters access by the ID of the enterprise that contains the repository from where the workflow is running",
"type": "String"
},
"github.com/enterprises/${enterprisename}:environment": {
"key": "github.com/enterprises/${EnterpriseName}:environment",
"description": "Filters access by the name of the environment used by the job",
"type": "String"
},
"github.com/enterprises/${enterprisename}:job_workflow_ref": {
"key": "github.com/enterprises/${EnterpriseName}:job_workflow_ref",
"description": "Filters access by the reference path to the reusable workflow for jobs using a reusable workflow",
"type": "String"
},
"github.com/enterprises/${enterprisename}:ref": {
"key": "github.com/enterprises/${EnterpriseName}:ref",
"description": "Filters access by the git ref (branch or tag) that triggered the workflow run",
"type": "String"
},
"github.com/enterprises/${enterprisename}:repository": {
"key": "github.com/enterprises/${EnterpriseName}:repository",
"description": "Filters access by the repository from where the workflow is running",
"type": "String"
},
"github.com/enterprises/${enterprisename}:repository_id": {
"key": "github.com/enterprises/${EnterpriseName}:repository_id",
"description": "Filters access by the ID of the repository from where the workflow is running",
"type": "String"
},
"github.com/enterprises/${enterprisename}:repository_owner_id": {
"key": "github.com/enterprises/${EnterpriseName}:repository_owner_id",
"description": "Filters access by the ID of the repository owner from where the workflow is running",
"type": "String"
},
"github.com/enterprises/${enterprisename}:workflow": {
"key": "github.com/enterprises/${EnterpriseName}:workflow",
"description": "Filters access by the name of the workflow",
"type": "String"
},
"gitlab.com:namespace_id": {
"key": "gitlab.com:namespace_id",
"description": "Filters access by the GitLab namespace (group) ID of the project running the CI/CD job",
"type": "String"
},
"gitlab.com:pipeline_source": {
"key": "gitlab.com:pipeline_source",
"description": "Filters access by the source that triggered the GitLab pipeline",
"type": "String"
},
"gitlab.com:project_id": {
"key": "gitlab.com:project_id",
"description": "Filters access by the GitLab project ID running the CI/CD job",
"type": "String"
},
"gitlab.com:ref_protected": {
"key": "gitlab.com:ref_protected",
"description": "Filters access by whether the GitLab git ref that triggered the job is protected",
"type": "String"
},
"gitlab.com:runner_environment": {
"key": "gitlab.com:runner_environment",
"description": "Filters access by the GitLab runner environment for the CI/CD job",
"type": "String"
},
"gitlab.com:user_access_level": {
"key": "gitlab.com:user_access_level",
"description": "Filters access by the GitLab user access level within the project",
"type": "String"
},
"gitlab.com:user_email": {
"key": "gitlab.com:user_email",
"description": "Filters access by the GitLab user email executing the CI/CD job",
"type": "String"
},
"gitlab.com:user_id": {
"key": "gitlab.com:user_id",
"description": "Filters access by the GitLab user ID executing the CI/CD job",
"type": "String"
},
"gitlab.com:user_login": {
"key": "gitlab.com:user_login",
"description": "Filters access by the GitLab username executing the CI/CD job",
"type": "String"
},
"graph.facebook.com:app_id": {
"key": "graph.facebook.com:app_id",
"description": "Filters access by the Facebook application ID",
"type": "String"
},
"graph.facebook.com:id": {
"key": "graph.facebook.com:id",
"description": "Filters access by the Facebook user ID",
"type": "String"
},
"iam:resourcetag/${tagkey}": {
"key": "iam:ResourceTag/${TagKey}",
"description": "Filters access by the tags that are attached to the role that is being assumed",
"type": "String"
},
"idcs-${ociuniqueidentifier}.identity.oraclecloud.com:rpst_id": {
"key": "idcs-${OciUniqueIdentifier}.identity.oraclecloud.com:rpst_id",
"description": "Filters access by the OCI resource principal session token ID",
"type": "String"
},
"oidc.circleci.com/org/${orgid}:oidc.circleci.com/project-id": {
"key": "oidc.circleci.com/org/${OrgId}:oidc.circleci.com/project-id",
"description": "Filters access by the CircleCI project ID",
"type": "String"
},
"saml:aud": {
"key": "saml:aud",
"description": "Filters access by the endpoint URL to which SAML assertions are presented",
"type": "String"
},
"saml:cn": {
"key": "saml:cn",
"description": "Filters access by the eduOrg attribute",
"type": "ArrayOfString"
},
"saml:commonname": {
"key": "saml:commonName",
"description": "Filters access by the commonName attribute",
"type": "String"
},
"saml:doc": {
"key": "saml:doc",
"description": "Filters access by on the principal that was used to assume the role",
"type": "String"
},
"saml:eduorghomepageuri": {
"key": "saml:eduorghomepageuri",
"description": "Filters access by the eduOrg attribute",
"type": "ArrayOfString"
},
"saml:eduorgidentityauthnpolicyuri": {
"key": "saml:eduorgidentityauthnpolicyuri",
"description": "Filters access by the eduOrg attribute",
"type": "ArrayOfString"
},
"saml:eduorglegalname": {
"key": "saml:eduorglegalname",
"description": "Filters access by the eduOrg attribute",
"type": "ArrayOfString"
},
"saml:eduorgsuperioruri": {
"key": "saml:eduorgsuperioruri",
"description": "Filters access by the eduOrg attribute",
"type": "ArrayOfString"
},
"saml:eduorgwhitepagesuri": {
"key": "saml:eduorgwhitepagesuri",
"description": "Filters access by the eduOrg attribute",
"type": "ArrayOfString"
},
"saml:edupersonaffiliation": {
"key": "saml:edupersonaffiliation",
"description": "Filters access by the eduPerson attribute",
"type": "ArrayOfString"
},
"saml:edupersonassurance": {
"key": "saml:edupersonassurance",
"description": "Filters access by the eduPerson attribute",
"type": "ArrayOfString"
},
"saml:edupersonentitlement": {
"key": "saml:edupersonentitlement",
"description": "Filters access by the eduPerson attribute",
"type": "ArrayOfString"
},
"saml:edupersonnickname": {
"key": "saml:edupersonnickname",
"description": "Filters access by the eduPerson attribute",
"type": "ArrayOfString"
},
"saml:edupersonorgdn": {
"key": "saml:edupersonorgdn",
"description": "Filters access by the eduPerson attribute",
"type": "String"
},
"saml:edupersonorgunitdn": {
"key": "saml:edupersonorgunitdn",
"description": "Filters access by the eduPerson attribute",
"type": "ArrayOfString"
},
"saml:edupersonprimaryaffiliation": {
"key": "saml:edupersonprimaryaffiliation",
"description": "Filters access by the eduPerson attribute",
"type": "String"
},
"saml:edupersonprimaryorgunitdn": {
"key": "saml:edupersonprimaryorgunitdn",
"description": "Filters access by the eduPerson attribute",
"type": "String"
},
"saml:edupersonprincipalname": {
"key": "saml:edupersonprincipalname",
"description": "Filters access by the eduPerson attribute",
"type": "String"
},
"saml:edupersonscopedaffiliation": {
"key": "saml:edupersonscopedaffiliation",
"description": "Filters access by the eduPerson attribute",
"type": "ArrayOfString"
},
"saml:edupersontargetedid": {
"key": "saml:edupersontargetedid",
"description": "Filters access by the eduPerson attribute",
"type": "ArrayOfString"
},
"saml:givenname": {
"key": "saml:givenName",
"description": "Filters access by the givenName attribute",
"type": "String"
},
"saml:iss": {
"key": "saml:iss",
"description": "Filters access by on the issuer, which is represented by a URN",
"type": "String"
},
"saml:mail": {
"key": "saml:mail",
"description": "Filters access by the mail attribute",
"type": "String"
},
"saml:name": {
"key": "saml:name",
"description": "Filters access by the name attribute",
"type": "String"
},
"saml:namequalifier": {
"key": "saml:namequalifier",
"description": "Filters access by the hash value of the issuer, account ID, and friendly name",
"type": "String"
},
"saml:organizationstatus": {
"key": "saml:organizationStatus",
"description": "Filters access by the organizationStatus attribute",
"type": "String"
},
"saml:primarygroupsid": {
"key": "saml:primaryGroupSID",
"description": "Filters access by the primaryGroupSID attribute",
"type": "String"
},
"saml:sub": {
"key": "saml:sub",
"description": "Filters access by the subject of the claim (the SAML user ID)",
"type": "String"
},
"saml:sub_type": {
"key": "saml:sub_type",
"description": "Filters access by the value persistent, transient, or the full Format URI",
"type": "String"
},
"saml:surname": {
"key": "saml:surname",
"description": "Filters access by the surname attribute",
"type": "String"
},
"saml:uid": {
"key": "saml:uid",
"description": "Filters access by the uid attribute",
"type": "String"
},
"saml:x500uniqueidentifier": {
"key": "saml:x500UniqueIdentifier",
"description": "Filters access by the uid attribute",
"type": "String"
},
"sts:awsservicename": {
"key": "sts:AWSServiceName",
"description": "Filters access by the service that is obtaining a bearer token",
"type": "String"
},
"sts:durationseconds": {
"key": "sts:DurationSeconds",
"description": "Filters access by the duration in seconds when getting a bearer token or a JSON Web Token (JWT) from the GetWebIdentityToken API",
"type": "Numeric"
},
"sts:externalid": {
"key": "sts:ExternalId",
"description": "Filters access by the unique identifier required when you assume a role in another account",
"type": "String"
},
"sts:identitytokenaudience": {
"key": "sts:IdentityTokenAudience",
"description": "Filters access by the audience that is passed in the request",
"type": "ArrayOfString"
},
"sts:requestcontext/${contextkey}": {
"key": "sts:RequestContext/${ContextKey}",
"description": "Filters access by the session context key-value pairs embedded in the signed context assertion retrieved from a trusted context provider",
"type": "String"
},
"sts:requestcontextproviders": {
"key": "sts:RequestContextProviders",
"description": "Filters access by the context provider ARNs",
"type": "ArrayOfARN"
},
"sts:roleauthorizedbyidp": {
"key": "sts:RoleAuthorizedByIdp",
"description": "Filters access based on whether the identity provider authorized the role via the roles claim in the OIDC token",
"type": "Bool"
},
"sts:rolesessionname": {
"key": "sts:RoleSessionName",
"description": "Filters access by the role session name required when you assume a role",
"type": "String"
},
"sts:signingalgorithm": {
"key": "sts:SigningAlgorithm",
"description": "Filters access by the signing algorithm that is passed in the request",
"type": "String"
},
"sts:sourceidentity": {
"key": "sts:SourceIdentity",
"description": "Filters access by the source identity that is passed in the request",
"type": "String"
},
"sts:taskpolicyarn": {
"key": "sts:TaskPolicyArn",
"description": "Filters access by TaskPolicyARN",
"type": "ARN"
},
"sts:transitivetagkeys": {
"key": "sts:TransitiveTagKeys",
"description": "Filters access by the transitive tag keys that are passed in the request",
"type": "ArrayOfString"
},
"token.actions.${domain}.ghe.com:actor": {
"key": "token.actions.${Domain}.ghe.com:actor",
"description": "Filters access by the personal account that initiated the workflow run",
"type": "String"
},
"token.actions.${domain}.ghe.com:actor_id": {
"key": "token.actions.${Domain}.ghe.com:actor_id",
"description": "Filters access by the ID of the personal account that initiated the workflow run",
"type": "String"
},
"token.actions.${domain}.ghe.com:enterprise_id": {
"key": "token.actions.${Domain}.ghe.com:enterprise_id",
"description": "Filters access by the ID of the enterprise that contains the repository from where the workflow is running",
"type": "String"
},
"token.actions.${domain}.ghe.com:environment": {
"key": "token.actions.${Domain}.ghe.com:environment",
"description": "Filters access by the name of the environment used by the job",
"type": "String"
},
"token.actions.${domain}.ghe.com:job_workflow_ref": {
"key": "token.actions.${Domain}.ghe.com:job_workflow_ref",
"description": "Filters access by the reference path to the reusable workflow for jobs using a reusable workflow",
"type": "String"
},
"token.actions.${domain}.ghe.com:ref": {
"key": "token.actions.${Domain}.ghe.com:ref",
"description": "Filters access by the git ref (branch or tag) that triggered the workflow run",
"type": "String"
},
"token.actions.${domain}.ghe.com:repository": {
"key": "token.actions.${Domain}.ghe.com:repository",
"description": "Filters access by the repository from where the workflow is running",
"type": "String"
},
"token.actions.${domain}.ghe.com:repository_id": {
"key": "token.actions.${Domain}.ghe.com:repository_id",
"description": "Filters access by the ID of the repository from where the workflow is running",
"type": "String"
},
"token.actions.${domain}.ghe.com:repository_owner_id": {
"key": "token.actions.${Domain}.ghe.com:repository_owner_id",
"description": "Filters access by the ID of the repository owner from where the workflow is running",
"type": "String"
},
"token.actions.${domain}.ghe.com:workflow": {
"key": "token.actions.${Domain}.ghe.com:workflow",
"description": "Filters access by the name of the workflow",
"type": "String"
},
"token.actions.githubusercontent.com/${subpath}:actor": {
"key": "token.actions.githubusercontent.com/${SubPath}:actor",
"description": "Filters access by the personal account that initiated the workflow run",
"type": "String"
},
"token.actions.githubusercontent.com/${subpath}:actor_id": {
"key": "token.actions.githubusercontent.com/${SubPath}:actor_id",
"description": "Filters access by the ID of the personal account that initiated the workflow run",
"type": "String"
},
"token.actions.githubusercontent.com/${subpath}:enterprise_id": {
"key": "token.actions.githubusercontent.com/${SubPath}:enterprise_id",
"description": "Filters access by the ID of the enterprise that contains the repository from where the workflow is running",
"type": "String"
},
"token.actions.githubusercontent.com/${subpath}:environment": {
"key": "token.actions.githubusercontent.com/${SubPath}:environment",
"description": "Filters access by the name of the environment used by the job",
"type": "String"
},
"token.actions.githubusercontent.com/${subpath}:job_workflow_ref": {
"key": "token.actions.githubusercontent.com/${SubPath}:job_workflow_ref",
"description": "Filters access by the reference path to the reusable workflow for jobs using a reusable workflow",
"type": "String"
},
"token.actions.githubusercontent.com/${subpath}:ref": {
"key": "token.actions.githubusercontent.com/${SubPath}:ref",
"description": "Filters access by the git ref (branch or tag) that triggered the workflow run",
"type": "String"
},
"token.actions.githubusercontent.com/${subpath}:repository": {
"key": "token.actions.githubusercontent.com/${SubPath}:repository",
"description": "Filters access by the repository from where the workflow is running",
"type": "String"
},
"token.actions.githubusercontent.com/${subpath}:repository_id": {
"key": "token.actions.githubusercontent.com/${SubPath}:repository_id",
"description": "Filters access by the ID of the repository from where the workflow is running",
"type": "String"
},
"token.actions.githubusercontent.com/${subpath}:repository_owner_id": {
"key": "token.actions.githubusercontent.com/${SubPath}:repository_owner_id",
"description": "Filters access by the ID of the repository owner from where the workflow is running",
"type": "String"
},
"token.actions.githubusercontent.com/${subpath}:workflow": {
"key": "token.actions.githubusercontent.com/${SubPath}:workflow",
"description": "Filters access by the name of the workflow",
"type": "String"
},
"token.actions.githubusercontent.com:actor": {
"key": "token.actions.githubusercontent.com:actor",
"description": "Filters access by the personal account that initiated the workflow run",
"type": "String"
},
"token.actions.githubusercontent.com:actor_id": {
"key": "token.actions.githubusercontent.com:actor_id",
"description": "Filters access by the ID of the personal account that initiated the workflow run",
"type": "String"
},
"token.actions.githubusercontent.com:enterprise_id": {
"key": "token.actions.githubusercontent.com:enterprise_id",
"description": "Filters access by the ID of the enterprise that contains the repository from where the workflow is running",
"type": "String"
},
"token.actions.githubusercontent.com:environment": {
"key": "token.actions.githubusercontent.com:environment",
"description": "Filters access by the name of the environment used by the job",
"type": "String"
},
"token.actions.githubusercontent.com:job_workflow_ref": {
"key": "token.actions.githubusercontent.com:job_workflow_ref",
"description": "Filters access by the reference path to the reusable workflow for jobs using a reusable workflow",
"type": "String"
},
"token.actions.githubusercontent.com:ref": {
"key": "token.actions.githubusercontent.com:ref",
"description": "Filters access by the git ref (branch or tag) that triggered the workflow run",
"type": "String"
},
"token.actions.githubusercontent.com:repository": {
"key": "token.actions.githubusercontent.com:repository",
"description": "Filters access by the repository from where the workflow is running",
"type": "String"
},
"token.actions.githubusercontent.com:repository_id": {
"key": "token.actions.githubusercontent.com:repository_id",
"description": "Filters access by the ID of the repository from where the workflow is running",
"type": "String"
},
"token.actions.githubusercontent.com:repository_owner_id": {
"key": "token.actions.githubusercontent.com:repository_owner_id",
"description": "Filters access by the ID of the repository owner from where the workflow is running",
"type": "String"
},
"token.actions.githubusercontent.com:workflow": {
"key": "token.actions.githubusercontent.com:workflow",
"description": "Filters access by the name of the workflow",
"type": "String"
},
"www.amazon.com:app_id": {
"key": "www.amazon.com:app_id",
"description": "Filters access by the Login with Amazon application ID",
"type": "String"
},
"www.amazon.com:user_id": {
"key": "www.amazon.com:user_id",
"description": "Filters access by the Login with Amazon user ID",
"type": "String"
}
}