@cloud-copilot/iam-data
Version:
1,312 lines • 40.4 kB
JSON
{
"elastic-ip": {
"key": "elastic-ip",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:elastic-ip/${AllocationId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:AllocationId",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:Domain",
"ec2:PublicIpAddress",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"capacity-reservation-fleet": {
"key": "capacity-reservation-fleet",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:capacity-reservation-fleet/${CapacityReservationFleetId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"capacity-reservation": {
"key": "capacity-reservation",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:capacity-reservation/${CapacityReservationId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:AvailabilityZone",
"ec2:AvailabilityZoneId",
"ec2:CapacityReservationFleet",
"ec2:CreateDate",
"ec2:DestinationCapacityReservationId",
"ec2:EbsOptimized",
"ec2:EndDate",
"ec2:EndDateType",
"ec2:EphemeralStorage",
"ec2:InstanceCount",
"ec2:InstanceMatchCriteria",
"ec2:InstancePlatform",
"ec2:InstanceType",
"ec2:IsLaunchTemplateResource",
"ec2:LaunchTemplate",
"ec2:OutpostArn",
"ec2:PlacementGroup",
"ec2:Region",
"ec2:ResourceTag/${TagKey}",
"ec2:SourceCapacityReservationId",
"ec2:Tenancy"
]
},
"carrier-gateway": {
"key": "carrier-gateway",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:carrier-gateway/${CarrierGatewayId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}",
"ec2:Tenancy",
"ec2:Vpc"
]
},
"certificate": {
"key": "certificate",
"arn": "arn:${Partition}:acm:${Region}:${Account}:certificate/${CertificateId}"
},
"client-vpn-endpoint": {
"key": "client-vpn-endpoint",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:client-vpn-endpoint/${ClientVpnEndpointId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:ClientRootCertificateChainArn",
"ec2:CloudwatchLogGroupArn",
"ec2:CloudwatchLogStreamArn",
"ec2:DirectoryArn",
"ec2:Region",
"ec2:ResourceTag/${TagKey}",
"ec2:SamlProviderArn",
"ec2:ServerCertificateArn"
]
},
"customer-gateway": {
"key": "customer-gateway",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:customer-gateway/${CustomerGatewayId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"declarative-policies-report": {
"key": "declarative-policies-report",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:declarative-policies-report/${DeclarativePoliciesReportId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"dedicated-host": {
"key": "dedicated-host",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:dedicated-host/${DedicatedHostId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:AutoPlacement",
"ec2:AvailabilityZone",
"ec2:HostRecovery",
"ec2:InstanceType",
"ec2:IsLaunchTemplateResource",
"ec2:LaunchTemplate",
"ec2:Quantity",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"dhcp-options": {
"key": "dhcp-options",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:dhcp-options/${DhcpOptionsId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:DhcpOptionsID",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"egress-only-internet-gateway": {
"key": "egress-only-internet-gateway",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:egress-only-internet-gateway/${EgressOnlyInternetGatewayId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"elastic-gpu": {
"key": "elastic-gpu",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:elastic-gpu/${ElasticGpuId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:ElasticGpuType",
"ec2:IsLaunchTemplateResource",
"ec2:LaunchTemplate",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"elastic-inference": {
"key": "elastic-inference",
"arn": "arn:${Partition}:elastic-inference:${Region}:${Account}:elastic-inference-accelerator/${AcceleratorId}"
},
"export-image-task": {
"key": "export-image-task",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:export-image-task/${ExportImageTaskId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"export-instance-task": {
"key": "export-instance-task",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:export-instance-task/${ExportTaskId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"fleet": {
"key": "fleet",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:fleet/${FleetId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"fpga-image": {
"key": "fpga-image",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:fpga-image/${FpgaImageId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:Owner",
"ec2:Public",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"host-reservation": {
"key": "host-reservation",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:host-reservation/${HostReservationId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"image": {
"key": "image",
"arn": "arn:${Partition}:ec2:${Region}::image/${ImageId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:ImageID",
"ec2:ImageType",
"ec2:IsLaunchTemplateResource",
"ec2:LaunchTemplate",
"ec2:Owner",
"ec2:Public",
"ec2:Region",
"ec2:ResourceTag/${TagKey}",
"ec2:RootDeviceType"
]
},
"import-image-task": {
"key": "import-image-task",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:import-image-task/${ImportImageTaskId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"import-snapshot-task": {
"key": "import-snapshot-task",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:import-snapshot-task/${ImportSnapshotTaskId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"instance-connect-endpoint": {
"key": "instance-connect-endpoint",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:instance-connect-endpoint/${InstanceConnectEndpointId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:Region",
"ec2:ResourceTag/${TagKey}",
"ec2:SubnetID"
]
},
"instance-event-window": {
"key": "instance-event-window",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:instance-event-window/${InstanceEventWindowId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"instance": {
"key": "instance",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:instance/${InstanceId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:AvailabilityZone",
"ec2:CpuOptionsAmdSevSnp",
"ec2:EbsOptimized",
"ec2:InstanceAutoRecovery",
"ec2:InstanceBandwidthWeighting",
"ec2:InstanceID",
"ec2:InstanceMarketType",
"ec2:InstanceMetadataTags",
"ec2:InstanceProfile",
"ec2:InstanceType",
"ec2:IsLaunchTemplateResource",
"ec2:LaunchTemplate",
"ec2:ManagedResourceOperator",
"ec2:MetadataHttpEndpoint",
"ec2:MetadataHttpPutResponseHopLimit",
"ec2:MetadataHttpTokens",
"ec2:NewInstanceProfile",
"ec2:PlacementGroup",
"ec2:ProductCode",
"ec2:Region",
"ec2:ResourceTag/${TagKey}",
"ec2:RootDeviceType",
"ec2:Tenancy"
]
},
"internet-gateway": {
"key": "internet-gateway",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:internet-gateway/${InternetGatewayId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:InternetGatewayID",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"ipam-external-resource-verification-token": {
"key": "ipam-external-resource-verification-token",
"arn": "arn:${Partition}:ec2::${Account}:ipam-external-resource-verification-token/${IpamExternalResourceVerificationTokenId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"ipam": {
"key": "ipam",
"arn": "arn:${Partition}:ec2::${Account}:ipam/${IpamId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"ipam-pool": {
"key": "ipam-pool",
"arn": "arn:${Partition}:ec2::${Account}:ipam-pool/${IpamPoolId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"ipam-resource-discovery-association": {
"key": "ipam-resource-discovery-association",
"arn": "arn:${Partition}:ec2::${Account}:ipam-resource-discovery-association/${IpamResourceDiscoveryAssociationId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"ipam-resource-discovery": {
"key": "ipam-resource-discovery",
"arn": "arn:${Partition}:ec2::${Account}:ipam-resource-discovery/${IpamResourceDiscoveryId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"ipam-scope": {
"key": "ipam-scope",
"arn": "arn:${Partition}:ec2::${Account}:ipam-scope/${IpamScopeId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"coip-pool": {
"key": "coip-pool",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:coip-pool/${Ipv4PoolCoipId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"ipv4pool-ec2": {
"key": "ipv4pool-ec2",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:ipv4pool-ec2/${Ipv4PoolEc2Id}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"ipv6pool-ec2": {
"key": "ipv6pool-ec2",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:ipv6pool-ec2/${Ipv6PoolEc2Id}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"key-pair": {
"key": "key-pair",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:key-pair/${KeyPairName}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:IsLaunchTemplateResource",
"ec2:KeyPairName",
"ec2:KeyPairType",
"ec2:LaunchTemplate",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"launch-template": {
"key": "launch-template",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:launch-template/${LaunchTemplateId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:IsLaunchTemplateResource",
"ec2:LaunchTemplate",
"ec2:ManagedResourceOperator",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"license-configuration": {
"key": "license-configuration",
"arn": "arn:${Partition}:license-manager:${Region}:${Account}:license-configuration:${LicenseConfigurationId}"
},
"local-gateway": {
"key": "local-gateway",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:local-gateway/${LocalGatewayId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"local-gateway-route-table-virtual-interface-group-association": {
"key": "local-gateway-route-table-virtual-interface-group-association",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:local-gateway-route-table-virtual-interface-group-association/${LocalGatewayRouteTableVirtualInterfaceGroupAssociationId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"local-gateway-route-table-vpc-association": {
"key": "local-gateway-route-table-vpc-association",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:local-gateway-route-table-vpc-association/${LocalGatewayRouteTableVpcAssociationId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"local-gateway-route-table": {
"key": "local-gateway-route-table",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:local-gateway-route-table/${LocalGatewayRoutetableId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Attribute/${AttributeName}",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"local-gateway-virtual-interface-group": {
"key": "local-gateway-virtual-interface-group",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:local-gateway-virtual-interface-group/${LocalGatewayVirtualInterfaceGroupId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"local-gateway-virtual-interface": {
"key": "local-gateway-virtual-interface",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:local-gateway-virtual-interface/${LocalGatewayVirtualInterfaceId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"mac-modification-task": {
"key": "mac-modification-task",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:mac-modification-task/${MacModificationTaskId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"natgateway": {
"key": "natgateway",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:natgateway/${NatGatewayId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"network-acl": {
"key": "network-acl",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:network-acl/${NaclId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:NetworkAclID",
"ec2:Region",
"ec2:ResourceTag/${TagKey}",
"ec2:Vpc"
]
},
"network-insights-access-scope-analysis": {
"key": "network-insights-access-scope-analysis",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:network-insights-access-scope-analysis/${NetworkInsightsAccessScopeAnalysisId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"network-insights-access-scope": {
"key": "network-insights-access-scope",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:network-insights-access-scope/${NetworkInsightsAccessScopeId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"network-insights-analysis": {
"key": "network-insights-analysis",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:network-insights-analysis/${NetworkInsightsAnalysisId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"network-insights-path": {
"key": "network-insights-path",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:network-insights-path/${NetworkInsightsPathId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"network-interface": {
"key": "network-interface",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:network-interface/${NetworkInterfaceId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:AssociatePublicIpAddress",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:AuthorizedService",
"ec2:AuthorizedUser",
"ec2:AvailabilityZone",
"ec2:IsLaunchTemplateResource",
"ec2:LaunchTemplate",
"ec2:ManagedResourceOperator",
"ec2:NetworkInterfaceID",
"ec2:Permission",
"ec2:Region",
"ec2:ResourceTag/${TagKey}",
"ec2:Subnet",
"ec2:Vpc"
]
},
"outpost-lag": {
"key": "outpost-lag",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:outpost-lag/${OutpostLagId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"placement-group": {
"key": "placement-group",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:placement-group/${PlacementGroupName}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:IsLaunchTemplateResource",
"ec2:LaunchTemplate",
"ec2:PlacementGroupName",
"ec2:PlacementGroupStrategy",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"prefix-list": {
"key": "prefix-list",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:prefix-list/${PrefixListId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"replace-root-volume-task": {
"key": "replace-root-volume-task",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:replace-root-volume-task/${ReplaceRootVolumeTaskId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"reserved-instances": {
"key": "reserved-instances",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:reserved-instances/${ReservationId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:AvailabilityZone",
"ec2:InstanceType",
"ec2:Region",
"ec2:ReservedInstancesOfferingType",
"ec2:ResourceTag/${TagKey}",
"ec2:Tenancy"
]
},
"group": {
"key": "group",
"arn": "arn:${Partition}:resource-groups:${Region}:${Account}:group/${GroupName}"
},
"role": {
"key": "role",
"arn": "arn:${Partition}:iam::${Account}:role/${RoleNameWithPath}"
},
"route-server-endpoint": {
"key": "route-server-endpoint",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:route-server-endpoint/${RouteServerEndpointId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:AvailabilityZone",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"route-server": {
"key": "route-server",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:route-server/${RouteServerId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"route-server-peer": {
"key": "route-server-peer",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:route-server-peer/${RouteServerPeerId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:AvailabilityZone",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"route-table": {
"key": "route-table",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:route-table/${RouteTableId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}",
"ec2:RouteTableID",
"ec2:Vpc"
]
},
"security-group": {
"key": "security-group",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:security-group/${SecurityGroupId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:IsLaunchTemplateResource",
"ec2:LaunchTemplate",
"ec2:Region",
"ec2:ResourceTag/${TagKey}",
"ec2:SecurityGroupID",
"ec2:Vpc"
]
},
"security-group-rule": {
"key": "security-group-rule",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:security-group-rule/${SecurityGroupRuleId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"snapshot": {
"key": "snapshot",
"arn": "arn:${Partition}:ec2:${Region}::snapshot/${SnapshotId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Add/group",
"ec2:Add/userId",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:AvailabilityZone",
"ec2:Encrypted",
"ec2:IsLaunchTemplateResource",
"ec2:LaunchTemplate",
"ec2:Location",
"ec2:OutpostArn",
"ec2:Owner",
"ec2:ParentSnapshot",
"ec2:ParentVolume",
"ec2:ProductCode",
"ec2:Region",
"ec2:Remove/group",
"ec2:Remove/userId",
"ec2:ResourceTag/${TagKey}",
"ec2:SnapshotCoolOffPeriod",
"ec2:SnapshotID",
"ec2:SnapshotLockDuration",
"ec2:SnapshotTime",
"ec2:SourceAvailabilityZone",
"ec2:SourceOutpostArn",
"ec2:VolumeSize"
]
},
"spot-fleet-request": {
"key": "spot-fleet-request",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:spot-fleet-request/${SpotFleetRequestId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"spot-instances-request": {
"key": "spot-instances-request",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:spot-instances-request/${SpotInstanceRequestId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"subnet-cidr-reservation": {
"key": "subnet-cidr-reservation",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:subnet-cidr-reservation/${SubnetCidrReservationId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"subnet": {
"key": "subnet",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:subnet/${SubnetId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:AvailabilityZone",
"ec2:Ipv4IpamPoolId",
"ec2:Ipv6IpamPoolId",
"ec2:IsLaunchTemplateResource",
"ec2:LaunchTemplate",
"ec2:Region",
"ec2:ResourceTag/${TagKey}",
"ec2:SubnetID",
"ec2:Vpc"
]
},
"traffic-mirror-filter": {
"key": "traffic-mirror-filter",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:traffic-mirror-filter/${TrafficMirrorFilterId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"traffic-mirror-filter-rule": {
"key": "traffic-mirror-filter-rule",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:traffic-mirror-filter-rule/${TrafficMirrorFilterRuleId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"traffic-mirror-session": {
"key": "traffic-mirror-session",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:traffic-mirror-session/${TrafficMirrorSessionId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"traffic-mirror-target": {
"key": "traffic-mirror-target",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:traffic-mirror-target/${TrafficMirrorTargetId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"transit-gateway-attachment": {
"key": "transit-gateway-attachment",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:transit-gateway-attachment/${TransitGatewayAttachmentId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:Region",
"ec2:ResourceTag/${TagKey}",
"ec2:transitGatewayAttachmentId"
]
},
"transit-gateway-connect-peer": {
"key": "transit-gateway-connect-peer",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:transit-gateway-connect-peer/${TransitGatewayConnectPeerId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}",
"ec2:transitGatewayConnectPeerId"
]
},
"transit-gateway": {
"key": "transit-gateway",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:transit-gateway/${TransitGatewayId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:Region",
"ec2:ResourceTag/${TagKey}",
"ec2:transitGatewayId"
]
},
"transit-gateway-multicast-domain": {
"key": "transit-gateway-multicast-domain",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:transit-gateway-multicast-domain/${TransitGatewayMulticastDomainId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}",
"ec2:transitGatewayMulticastDomainId"
]
},
"transit-gateway-policy-table": {
"key": "transit-gateway-policy-table",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:transit-gateway-policy-table/${TransitGatewayPolicyTableId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}",
"ec2:transitGatewayPolicyTableId"
]
},
"transit-gateway-route-table-announcement": {
"key": "transit-gateway-route-table-announcement",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:transit-gateway-route-table-announcement/${TransitGatewayRouteTableAnnouncementId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}",
"ec2:transitGatewayRouteTableAnnouncementId"
]
},
"transit-gateway-route-table": {
"key": "transit-gateway-route-table",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:transit-gateway-route-table/${TransitGatewayRouteTableId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:Region",
"ec2:ResourceTag/${TagKey}",
"ec2:transitGatewayRouteTableId"
]
},
"verified-access-endpoint": {
"key": "verified-access-endpoint",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:verified-access-endpoint/${VerifiedAccessEndpointId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Attribute/${AttributeName}",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"verified-access-endpoint-target": {
"key": "verified-access-endpoint-target",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:verified-access-endpoint-target/${VerifiedAccessEndpointTargetId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"verified-access-group": {
"key": "verified-access-group",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:verified-access-group/${VerifiedAccessGroupId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"verified-access-instance": {
"key": "verified-access-instance",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:verified-access-instance/${VerifiedAccessInstanceId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"verified-access-policy": {
"key": "verified-access-policy",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:verified-access-policy/${VerifiedAccessPolicyId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"verified-access-trust-provider": {
"key": "verified-access-trust-provider",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:verified-access-trust-provider/${VerifiedAccessTrustProviderId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"volume": {
"key": "volume",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:volume/${VolumeId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:AvailabilityZone",
"ec2:Encrypted",
"ec2:IsLaunchTemplateResource",
"ec2:KmsKeyId",
"ec2:LaunchTemplate",
"ec2:ManagedResourceOperator",
"ec2:ParentSnapshot",
"ec2:Region",
"ec2:ResourceTag/${TagKey}",
"ec2:VolumeID",
"ec2:VolumeIops",
"ec2:VolumeSize",
"ec2:VolumeThroughput",
"ec2:VolumeType"
]
},
"vpc-block-public-access-exclusion": {
"key": "vpc-block-public-access-exclusion",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:vpc-block-public-access-exclusion/${VpcBlockPublicAccessExclusionId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"vpc-endpoint-connection": {
"key": "vpc-endpoint-connection",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:vpc-endpoint-connection/${VpcEndpointConnectionId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"vpc-endpoint": {
"key": "vpc-endpoint",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:vpc-endpoint/${VpcEndpointId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:Region",
"ec2:ResourceTag/${TagKey}",
"ec2:VpceServiceName",
"ec2:VpceServiceOwner",
"ec2:vpceMultiRegion",
"ec2:vpceServiceRegion"
]
},
"vpc-endpoint-service": {
"key": "vpc-endpoint-service",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:vpc-endpoint-service/${VpcEndpointServiceId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:Region",
"ec2:ResourceTag/${TagKey}",
"ec2:VpceServicePrivateDnsName",
"ec2:vpceMultiRegion",
"ec2:vpceServiceRegion",
"ec2:vpceSupportedRegion"
]
},
"vpc-endpoint-service-permission": {
"key": "vpc-endpoint-service-permission",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:vpc-endpoint-service-permission/${VpcEndpointServicePermissionId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"vpc-flow-log": {
"key": "vpc-flow-log",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:vpc-flow-log/${VpcFlowLogId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
},
"vpc": {
"key": "vpc",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:vpc/${VpcId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:Ipv4IpamPoolId",
"ec2:Ipv6IpamPoolId",
"ec2:Region",
"ec2:ResourceTag/${TagKey}",
"ec2:Tenancy",
"ec2:VpcID"
]
},
"vpc-peering-connection": {
"key": "vpc-peering-connection",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:vpc-peering-connection/${VpcPeeringConnectionId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:AccepterVpc",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:Region",
"ec2:RequesterVpc",
"ec2:ResourceTag/${TagKey}",
"ec2:VpcPeeringConnectionID"
]
},
"vpn-connection-device-type": {
"key": "vpn-connection-device-type",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:vpn-connection-device-type/${VpnConnectionDeviceTypeId}",
"conditionKeys": [
"ec2:Region"
]
},
"vpn-connection": {
"key": "vpn-connection",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:vpn-connection/${VpnConnectionId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Attribute",
"ec2:Attribute/${AttributeName}",
"ec2:AuthenticationType",
"ec2:DPDTimeoutSeconds",
"ec2:GatewayType",
"ec2:IKEVersions",
"ec2:InsideTunnelCidr",
"ec2:InsideTunnelIpv6Cidr",
"ec2:Phase1DHGroup",
"ec2:Phase1EncryptionAlgorithms",
"ec2:Phase1IntegrityAlgorithms",
"ec2:Phase1LifetimeSeconds",
"ec2:Phase2DHGroup",
"ec2:Phase2EncryptionAlgorithms",
"ec2:Phase2IntegrityAlgorithms",
"ec2:Phase2LifetimeSeconds",
"ec2:Region",
"ec2:RekeyFuzzPercentage",
"ec2:RekeyMarginTimeSeconds",
"ec2:ReplayWindowSizePackets",
"ec2:ResourceTag/${TagKey}",
"ec2:RoutingType"
]
},
"vpn-gateway": {
"key": "vpn-gateway",
"arn": "arn:${Partition}:ec2:${Region}:${Account}:vpn-gateway/${VpnGatewayId}",
"conditionKeys": [
"aws:RequestTag/${TagKey}",
"aws:ResourceTag/${TagKey}",
"aws:TagKeys",
"ec2:Region",
"ec2:ResourceTag/${TagKey}"
]
}
}