UNPKG

@cloud-copilot/iam-data

Version:
1,312 lines 40.4 kB
{ "elastic-ip": { "key": "elastic-ip", "arn": "arn:${Partition}:ec2:${Region}:${Account}:elastic-ip/${AllocationId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:AllocationId", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:Domain", "ec2:PublicIpAddress", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "capacity-reservation-fleet": { "key": "capacity-reservation-fleet", "arn": "arn:${Partition}:ec2:${Region}:${Account}:capacity-reservation-fleet/${CapacityReservationFleetId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "capacity-reservation": { "key": "capacity-reservation", "arn": "arn:${Partition}:ec2:${Region}:${Account}:capacity-reservation/${CapacityReservationId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:AvailabilityZone", "ec2:AvailabilityZoneId", "ec2:CapacityReservationFleet", "ec2:CreateDate", "ec2:DestinationCapacityReservationId", "ec2:EbsOptimized", "ec2:EndDate", "ec2:EndDateType", "ec2:EphemeralStorage", "ec2:InstanceCount", "ec2:InstanceMatchCriteria", "ec2:InstancePlatform", "ec2:InstanceType", "ec2:IsLaunchTemplateResource", "ec2:LaunchTemplate", "ec2:OutpostArn", "ec2:PlacementGroup", "ec2:Region", "ec2:ResourceTag/${TagKey}", "ec2:SourceCapacityReservationId", "ec2:Tenancy" ] }, "carrier-gateway": { "key": "carrier-gateway", "arn": "arn:${Partition}:ec2:${Region}:${Account}:carrier-gateway/${CarrierGatewayId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}", "ec2:Tenancy", "ec2:Vpc" ] }, "certificate": { "key": "certificate", "arn": "arn:${Partition}:acm:${Region}:${Account}:certificate/${CertificateId}" }, "client-vpn-endpoint": { "key": "client-vpn-endpoint", "arn": "arn:${Partition}:ec2:${Region}:${Account}:client-vpn-endpoint/${ClientVpnEndpointId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:ClientRootCertificateChainArn", "ec2:CloudwatchLogGroupArn", "ec2:CloudwatchLogStreamArn", "ec2:DirectoryArn", "ec2:Region", "ec2:ResourceTag/${TagKey}", "ec2:SamlProviderArn", "ec2:ServerCertificateArn" ] }, "customer-gateway": { "key": "customer-gateway", "arn": "arn:${Partition}:ec2:${Region}:${Account}:customer-gateway/${CustomerGatewayId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "declarative-policies-report": { "key": "declarative-policies-report", "arn": "arn:${Partition}:ec2:${Region}:${Account}:declarative-policies-report/${DeclarativePoliciesReportId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "dedicated-host": { "key": "dedicated-host", "arn": "arn:${Partition}:ec2:${Region}:${Account}:dedicated-host/${DedicatedHostId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:AutoPlacement", "ec2:AvailabilityZone", "ec2:HostRecovery", "ec2:InstanceType", "ec2:IsLaunchTemplateResource", "ec2:LaunchTemplate", "ec2:Quantity", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "dhcp-options": { "key": "dhcp-options", "arn": "arn:${Partition}:ec2:${Region}:${Account}:dhcp-options/${DhcpOptionsId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:DhcpOptionsID", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "egress-only-internet-gateway": { "key": "egress-only-internet-gateway", "arn": "arn:${Partition}:ec2:${Region}:${Account}:egress-only-internet-gateway/${EgressOnlyInternetGatewayId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "elastic-gpu": { "key": "elastic-gpu", "arn": "arn:${Partition}:ec2:${Region}:${Account}:elastic-gpu/${ElasticGpuId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:ElasticGpuType", "ec2:IsLaunchTemplateResource", "ec2:LaunchTemplate", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "elastic-inference": { "key": "elastic-inference", "arn": "arn:${Partition}:elastic-inference:${Region}:${Account}:elastic-inference-accelerator/${AcceleratorId}" }, "export-image-task": { "key": "export-image-task", "arn": "arn:${Partition}:ec2:${Region}:${Account}:export-image-task/${ExportImageTaskId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "export-instance-task": { "key": "export-instance-task", "arn": "arn:${Partition}:ec2:${Region}:${Account}:export-instance-task/${ExportTaskId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "fleet": { "key": "fleet", "arn": "arn:${Partition}:ec2:${Region}:${Account}:fleet/${FleetId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "fpga-image": { "key": "fpga-image", "arn": "arn:${Partition}:ec2:${Region}:${Account}:fpga-image/${FpgaImageId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:Owner", "ec2:Public", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "host-reservation": { "key": "host-reservation", "arn": "arn:${Partition}:ec2:${Region}:${Account}:host-reservation/${HostReservationId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "image": { "key": "image", "arn": "arn:${Partition}:ec2:${Region}::image/${ImageId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:ImageID", "ec2:ImageType", "ec2:IsLaunchTemplateResource", "ec2:LaunchTemplate", "ec2:Owner", "ec2:Public", "ec2:Region", "ec2:ResourceTag/${TagKey}", "ec2:RootDeviceType" ] }, "import-image-task": { "key": "import-image-task", "arn": "arn:${Partition}:ec2:${Region}:${Account}:import-image-task/${ImportImageTaskId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "import-snapshot-task": { "key": "import-snapshot-task", "arn": "arn:${Partition}:ec2:${Region}:${Account}:import-snapshot-task/${ImportSnapshotTaskId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "instance-connect-endpoint": { "key": "instance-connect-endpoint", "arn": "arn:${Partition}:ec2:${Region}:${Account}:instance-connect-endpoint/${InstanceConnectEndpointId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:Region", "ec2:ResourceTag/${TagKey}", "ec2:SubnetID" ] }, "instance-event-window": { "key": "instance-event-window", "arn": "arn:${Partition}:ec2:${Region}:${Account}:instance-event-window/${InstanceEventWindowId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "instance": { "key": "instance", "arn": "arn:${Partition}:ec2:${Region}:${Account}:instance/${InstanceId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:AvailabilityZone", "ec2:CpuOptionsAmdSevSnp", "ec2:EbsOptimized", "ec2:InstanceAutoRecovery", "ec2:InstanceBandwidthWeighting", "ec2:InstanceID", "ec2:InstanceMarketType", "ec2:InstanceMetadataTags", "ec2:InstanceProfile", "ec2:InstanceType", "ec2:IsLaunchTemplateResource", "ec2:LaunchTemplate", "ec2:ManagedResourceOperator", "ec2:MetadataHttpEndpoint", "ec2:MetadataHttpPutResponseHopLimit", "ec2:MetadataHttpTokens", "ec2:NewInstanceProfile", "ec2:PlacementGroup", "ec2:ProductCode", "ec2:Region", "ec2:ResourceTag/${TagKey}", "ec2:RootDeviceType", "ec2:Tenancy" ] }, "internet-gateway": { "key": "internet-gateway", "arn": "arn:${Partition}:ec2:${Region}:${Account}:internet-gateway/${InternetGatewayId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:InternetGatewayID", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "ipam-external-resource-verification-token": { "key": "ipam-external-resource-verification-token", "arn": "arn:${Partition}:ec2::${Account}:ipam-external-resource-verification-token/${IpamExternalResourceVerificationTokenId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "ipam": { "key": "ipam", "arn": "arn:${Partition}:ec2::${Account}:ipam/${IpamId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "ipam-pool": { "key": "ipam-pool", "arn": "arn:${Partition}:ec2::${Account}:ipam-pool/${IpamPoolId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "ipam-resource-discovery-association": { "key": "ipam-resource-discovery-association", "arn": "arn:${Partition}:ec2::${Account}:ipam-resource-discovery-association/${IpamResourceDiscoveryAssociationId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "ipam-resource-discovery": { "key": "ipam-resource-discovery", "arn": "arn:${Partition}:ec2::${Account}:ipam-resource-discovery/${IpamResourceDiscoveryId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "ipam-scope": { "key": "ipam-scope", "arn": "arn:${Partition}:ec2::${Account}:ipam-scope/${IpamScopeId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "coip-pool": { "key": "coip-pool", "arn": "arn:${Partition}:ec2:${Region}:${Account}:coip-pool/${Ipv4PoolCoipId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "ipv4pool-ec2": { "key": "ipv4pool-ec2", "arn": "arn:${Partition}:ec2:${Region}:${Account}:ipv4pool-ec2/${Ipv4PoolEc2Id}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "ipv6pool-ec2": { "key": "ipv6pool-ec2", "arn": "arn:${Partition}:ec2:${Region}:${Account}:ipv6pool-ec2/${Ipv6PoolEc2Id}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "key-pair": { "key": "key-pair", "arn": "arn:${Partition}:ec2:${Region}:${Account}:key-pair/${KeyPairName}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:IsLaunchTemplateResource", "ec2:KeyPairName", "ec2:KeyPairType", "ec2:LaunchTemplate", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "launch-template": { "key": "launch-template", "arn": "arn:${Partition}:ec2:${Region}:${Account}:launch-template/${LaunchTemplateId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:IsLaunchTemplateResource", "ec2:LaunchTemplate", "ec2:ManagedResourceOperator", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "license-configuration": { "key": "license-configuration", "arn": "arn:${Partition}:license-manager:${Region}:${Account}:license-configuration:${LicenseConfigurationId}" }, "local-gateway": { "key": "local-gateway", "arn": "arn:${Partition}:ec2:${Region}:${Account}:local-gateway/${LocalGatewayId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "local-gateway-route-table-virtual-interface-group-association": { "key": "local-gateway-route-table-virtual-interface-group-association", "arn": "arn:${Partition}:ec2:${Region}:${Account}:local-gateway-route-table-virtual-interface-group-association/${LocalGatewayRouteTableVirtualInterfaceGroupAssociationId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "local-gateway-route-table-vpc-association": { "key": "local-gateway-route-table-vpc-association", "arn": "arn:${Partition}:ec2:${Region}:${Account}:local-gateway-route-table-vpc-association/${LocalGatewayRouteTableVpcAssociationId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "local-gateway-route-table": { "key": "local-gateway-route-table", "arn": "arn:${Partition}:ec2:${Region}:${Account}:local-gateway-route-table/${LocalGatewayRoutetableId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Attribute/${AttributeName}", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "local-gateway-virtual-interface-group": { "key": "local-gateway-virtual-interface-group", "arn": "arn:${Partition}:ec2:${Region}:${Account}:local-gateway-virtual-interface-group/${LocalGatewayVirtualInterfaceGroupId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "local-gateway-virtual-interface": { "key": "local-gateway-virtual-interface", "arn": "arn:${Partition}:ec2:${Region}:${Account}:local-gateway-virtual-interface/${LocalGatewayVirtualInterfaceId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "mac-modification-task": { "key": "mac-modification-task", "arn": "arn:${Partition}:ec2:${Region}:${Account}:mac-modification-task/${MacModificationTaskId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "natgateway": { "key": "natgateway", "arn": "arn:${Partition}:ec2:${Region}:${Account}:natgateway/${NatGatewayId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "network-acl": { "key": "network-acl", "arn": "arn:${Partition}:ec2:${Region}:${Account}:network-acl/${NaclId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:NetworkAclID", "ec2:Region", "ec2:ResourceTag/${TagKey}", "ec2:Vpc" ] }, "network-insights-access-scope-analysis": { "key": "network-insights-access-scope-analysis", "arn": "arn:${Partition}:ec2:${Region}:${Account}:network-insights-access-scope-analysis/${NetworkInsightsAccessScopeAnalysisId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "network-insights-access-scope": { "key": "network-insights-access-scope", "arn": "arn:${Partition}:ec2:${Region}:${Account}:network-insights-access-scope/${NetworkInsightsAccessScopeId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "network-insights-analysis": { "key": "network-insights-analysis", "arn": "arn:${Partition}:ec2:${Region}:${Account}:network-insights-analysis/${NetworkInsightsAnalysisId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "network-insights-path": { "key": "network-insights-path", "arn": "arn:${Partition}:ec2:${Region}:${Account}:network-insights-path/${NetworkInsightsPathId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "network-interface": { "key": "network-interface", "arn": "arn:${Partition}:ec2:${Region}:${Account}:network-interface/${NetworkInterfaceId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:AssociatePublicIpAddress", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:AuthorizedService", "ec2:AuthorizedUser", "ec2:AvailabilityZone", "ec2:IsLaunchTemplateResource", "ec2:LaunchTemplate", "ec2:ManagedResourceOperator", "ec2:NetworkInterfaceID", "ec2:Permission", "ec2:Region", "ec2:ResourceTag/${TagKey}", "ec2:Subnet", "ec2:Vpc" ] }, "outpost-lag": { "key": "outpost-lag", "arn": "arn:${Partition}:ec2:${Region}:${Account}:outpost-lag/${OutpostLagId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "placement-group": { "key": "placement-group", "arn": "arn:${Partition}:ec2:${Region}:${Account}:placement-group/${PlacementGroupName}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:IsLaunchTemplateResource", "ec2:LaunchTemplate", "ec2:PlacementGroupName", "ec2:PlacementGroupStrategy", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "prefix-list": { "key": "prefix-list", "arn": "arn:${Partition}:ec2:${Region}:${Account}:prefix-list/${PrefixListId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "replace-root-volume-task": { "key": "replace-root-volume-task", "arn": "arn:${Partition}:ec2:${Region}:${Account}:replace-root-volume-task/${ReplaceRootVolumeTaskId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "reserved-instances": { "key": "reserved-instances", "arn": "arn:${Partition}:ec2:${Region}:${Account}:reserved-instances/${ReservationId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:AvailabilityZone", "ec2:InstanceType", "ec2:Region", "ec2:ReservedInstancesOfferingType", "ec2:ResourceTag/${TagKey}", "ec2:Tenancy" ] }, "group": { "key": "group", "arn": "arn:${Partition}:resource-groups:${Region}:${Account}:group/${GroupName}" }, "role": { "key": "role", "arn": "arn:${Partition}:iam::${Account}:role/${RoleNameWithPath}" }, "route-server-endpoint": { "key": "route-server-endpoint", "arn": "arn:${Partition}:ec2:${Region}:${Account}:route-server-endpoint/${RouteServerEndpointId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:AvailabilityZone", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "route-server": { "key": "route-server", "arn": "arn:${Partition}:ec2:${Region}:${Account}:route-server/${RouteServerId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "route-server-peer": { "key": "route-server-peer", "arn": "arn:${Partition}:ec2:${Region}:${Account}:route-server-peer/${RouteServerPeerId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:AvailabilityZone", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "route-table": { "key": "route-table", "arn": "arn:${Partition}:ec2:${Region}:${Account}:route-table/${RouteTableId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}", "ec2:RouteTableID", "ec2:Vpc" ] }, "security-group": { "key": "security-group", "arn": "arn:${Partition}:ec2:${Region}:${Account}:security-group/${SecurityGroupId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:IsLaunchTemplateResource", "ec2:LaunchTemplate", "ec2:Region", "ec2:ResourceTag/${TagKey}", "ec2:SecurityGroupID", "ec2:Vpc" ] }, "security-group-rule": { "key": "security-group-rule", "arn": "arn:${Partition}:ec2:${Region}:${Account}:security-group-rule/${SecurityGroupRuleId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "snapshot": { "key": "snapshot", "arn": "arn:${Partition}:ec2:${Region}::snapshot/${SnapshotId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Add/group", "ec2:Add/userId", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:AvailabilityZone", "ec2:Encrypted", "ec2:IsLaunchTemplateResource", "ec2:LaunchTemplate", "ec2:Location", "ec2:OutpostArn", "ec2:Owner", "ec2:ParentSnapshot", "ec2:ParentVolume", "ec2:ProductCode", "ec2:Region", "ec2:Remove/group", "ec2:Remove/userId", "ec2:ResourceTag/${TagKey}", "ec2:SnapshotCoolOffPeriod", "ec2:SnapshotID", "ec2:SnapshotLockDuration", "ec2:SnapshotTime", "ec2:SourceAvailabilityZone", "ec2:SourceOutpostArn", "ec2:VolumeSize" ] }, "spot-fleet-request": { "key": "spot-fleet-request", "arn": "arn:${Partition}:ec2:${Region}:${Account}:spot-fleet-request/${SpotFleetRequestId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "spot-instances-request": { "key": "spot-instances-request", "arn": "arn:${Partition}:ec2:${Region}:${Account}:spot-instances-request/${SpotInstanceRequestId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "subnet-cidr-reservation": { "key": "subnet-cidr-reservation", "arn": "arn:${Partition}:ec2:${Region}:${Account}:subnet-cidr-reservation/${SubnetCidrReservationId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "subnet": { "key": "subnet", "arn": "arn:${Partition}:ec2:${Region}:${Account}:subnet/${SubnetId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:AvailabilityZone", "ec2:Ipv4IpamPoolId", "ec2:Ipv6IpamPoolId", "ec2:IsLaunchTemplateResource", "ec2:LaunchTemplate", "ec2:Region", "ec2:ResourceTag/${TagKey}", "ec2:SubnetID", "ec2:Vpc" ] }, "traffic-mirror-filter": { "key": "traffic-mirror-filter", "arn": "arn:${Partition}:ec2:${Region}:${Account}:traffic-mirror-filter/${TrafficMirrorFilterId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "traffic-mirror-filter-rule": { "key": "traffic-mirror-filter-rule", "arn": "arn:${Partition}:ec2:${Region}:${Account}:traffic-mirror-filter-rule/${TrafficMirrorFilterRuleId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "traffic-mirror-session": { "key": "traffic-mirror-session", "arn": "arn:${Partition}:ec2:${Region}:${Account}:traffic-mirror-session/${TrafficMirrorSessionId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "traffic-mirror-target": { "key": "traffic-mirror-target", "arn": "arn:${Partition}:ec2:${Region}:${Account}:traffic-mirror-target/${TrafficMirrorTargetId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "transit-gateway-attachment": { "key": "transit-gateway-attachment", "arn": "arn:${Partition}:ec2:${Region}:${Account}:transit-gateway-attachment/${TransitGatewayAttachmentId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:Region", "ec2:ResourceTag/${TagKey}", "ec2:transitGatewayAttachmentId" ] }, "transit-gateway-connect-peer": { "key": "transit-gateway-connect-peer", "arn": "arn:${Partition}:ec2:${Region}:${Account}:transit-gateway-connect-peer/${TransitGatewayConnectPeerId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}", "ec2:transitGatewayConnectPeerId" ] }, "transit-gateway": { "key": "transit-gateway", "arn": "arn:${Partition}:ec2:${Region}:${Account}:transit-gateway/${TransitGatewayId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:Region", "ec2:ResourceTag/${TagKey}", "ec2:transitGatewayId" ] }, "transit-gateway-multicast-domain": { "key": "transit-gateway-multicast-domain", "arn": "arn:${Partition}:ec2:${Region}:${Account}:transit-gateway-multicast-domain/${TransitGatewayMulticastDomainId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}", "ec2:transitGatewayMulticastDomainId" ] }, "transit-gateway-policy-table": { "key": "transit-gateway-policy-table", "arn": "arn:${Partition}:ec2:${Region}:${Account}:transit-gateway-policy-table/${TransitGatewayPolicyTableId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}", "ec2:transitGatewayPolicyTableId" ] }, "transit-gateway-route-table-announcement": { "key": "transit-gateway-route-table-announcement", "arn": "arn:${Partition}:ec2:${Region}:${Account}:transit-gateway-route-table-announcement/${TransitGatewayRouteTableAnnouncementId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}", "ec2:transitGatewayRouteTableAnnouncementId" ] }, "transit-gateway-route-table": { "key": "transit-gateway-route-table", "arn": "arn:${Partition}:ec2:${Region}:${Account}:transit-gateway-route-table/${TransitGatewayRouteTableId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:Region", "ec2:ResourceTag/${TagKey}", "ec2:transitGatewayRouteTableId" ] }, "verified-access-endpoint": { "key": "verified-access-endpoint", "arn": "arn:${Partition}:ec2:${Region}:${Account}:verified-access-endpoint/${VerifiedAccessEndpointId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Attribute/${AttributeName}", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "verified-access-endpoint-target": { "key": "verified-access-endpoint-target", "arn": "arn:${Partition}:ec2:${Region}:${Account}:verified-access-endpoint-target/${VerifiedAccessEndpointTargetId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "verified-access-group": { "key": "verified-access-group", "arn": "arn:${Partition}:ec2:${Region}:${Account}:verified-access-group/${VerifiedAccessGroupId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "verified-access-instance": { "key": "verified-access-instance", "arn": "arn:${Partition}:ec2:${Region}:${Account}:verified-access-instance/${VerifiedAccessInstanceId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "verified-access-policy": { "key": "verified-access-policy", "arn": "arn:${Partition}:ec2:${Region}:${Account}:verified-access-policy/${VerifiedAccessPolicyId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "verified-access-trust-provider": { "key": "verified-access-trust-provider", "arn": "arn:${Partition}:ec2:${Region}:${Account}:verified-access-trust-provider/${VerifiedAccessTrustProviderId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "volume": { "key": "volume", "arn": "arn:${Partition}:ec2:${Region}:${Account}:volume/${VolumeId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:AvailabilityZone", "ec2:Encrypted", "ec2:IsLaunchTemplateResource", "ec2:KmsKeyId", "ec2:LaunchTemplate", "ec2:ManagedResourceOperator", "ec2:ParentSnapshot", "ec2:Region", "ec2:ResourceTag/${TagKey}", "ec2:VolumeID", "ec2:VolumeIops", "ec2:VolumeSize", "ec2:VolumeThroughput", "ec2:VolumeType" ] }, "vpc-block-public-access-exclusion": { "key": "vpc-block-public-access-exclusion", "arn": "arn:${Partition}:ec2:${Region}:${Account}:vpc-block-public-access-exclusion/${VpcBlockPublicAccessExclusionId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "vpc-endpoint-connection": { "key": "vpc-endpoint-connection", "arn": "arn:${Partition}:ec2:${Region}:${Account}:vpc-endpoint-connection/${VpcEndpointConnectionId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "vpc-endpoint": { "key": "vpc-endpoint", "arn": "arn:${Partition}:ec2:${Region}:${Account}:vpc-endpoint/${VpcEndpointId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:Region", "ec2:ResourceTag/${TagKey}", "ec2:VpceServiceName", "ec2:VpceServiceOwner", "ec2:vpceMultiRegion", "ec2:vpceServiceRegion" ] }, "vpc-endpoint-service": { "key": "vpc-endpoint-service", "arn": "arn:${Partition}:ec2:${Region}:${Account}:vpc-endpoint-service/${VpcEndpointServiceId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:Region", "ec2:ResourceTag/${TagKey}", "ec2:VpceServicePrivateDnsName", "ec2:vpceMultiRegion", "ec2:vpceServiceRegion", "ec2:vpceSupportedRegion" ] }, "vpc-endpoint-service-permission": { "key": "vpc-endpoint-service-permission", "arn": "arn:${Partition}:ec2:${Region}:${Account}:vpc-endpoint-service-permission/${VpcEndpointServicePermissionId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "vpc-flow-log": { "key": "vpc-flow-log", "arn": "arn:${Partition}:ec2:${Region}:${Account}:vpc-flow-log/${VpcFlowLogId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] }, "vpc": { "key": "vpc", "arn": "arn:${Partition}:ec2:${Region}:${Account}:vpc/${VpcId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:Ipv4IpamPoolId", "ec2:Ipv6IpamPoolId", "ec2:Region", "ec2:ResourceTag/${TagKey}", "ec2:Tenancy", "ec2:VpcID" ] }, "vpc-peering-connection": { "key": "vpc-peering-connection", "arn": "arn:${Partition}:ec2:${Region}:${Account}:vpc-peering-connection/${VpcPeeringConnectionId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:AccepterVpc", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:Region", "ec2:RequesterVpc", "ec2:ResourceTag/${TagKey}", "ec2:VpcPeeringConnectionID" ] }, "vpn-connection-device-type": { "key": "vpn-connection-device-type", "arn": "arn:${Partition}:ec2:${Region}:${Account}:vpn-connection-device-type/${VpnConnectionDeviceTypeId}", "conditionKeys": [ "ec2:Region" ] }, "vpn-connection": { "key": "vpn-connection", "arn": "arn:${Partition}:ec2:${Region}:${Account}:vpn-connection/${VpnConnectionId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Attribute", "ec2:Attribute/${AttributeName}", "ec2:AuthenticationType", "ec2:DPDTimeoutSeconds", "ec2:GatewayType", "ec2:IKEVersions", "ec2:InsideTunnelCidr", "ec2:InsideTunnelIpv6Cidr", "ec2:Phase1DHGroup", "ec2:Phase1EncryptionAlgorithms", "ec2:Phase1IntegrityAlgorithms", "ec2:Phase1LifetimeSeconds", "ec2:Phase2DHGroup", "ec2:Phase2EncryptionAlgorithms", "ec2:Phase2IntegrityAlgorithms", "ec2:Phase2LifetimeSeconds", "ec2:Region", "ec2:RekeyFuzzPercentage", "ec2:RekeyMarginTimeSeconds", "ec2:ReplayWindowSizePackets", "ec2:ResourceTag/${TagKey}", "ec2:RoutingType" ] }, "vpn-gateway": { "key": "vpn-gateway", "arn": "arn:${Partition}:ec2:${Region}:${Account}:vpn-gateway/${VpnGatewayId}", "conditionKeys": [ "aws:RequestTag/${TagKey}", "aws:ResourceTag/${TagKey}", "aws:TagKeys", "ec2:Region", "ec2:ResourceTag/${TagKey}" ] } }