cdk-iam-floyd
Version:
AWS IAM policy statement generator with fluent interface for AWS CDK
611 lines • 246 kB
TypeScript
/** Provides names of all AWS managed policies. */
export declare class AwsManagedPolicy {
/** Allow Access Analyzer to analyze resource metadata */
static AccessAnalyzerServiceRolePolicy: string;
/** Provides full access to AWS services and resources. */
static AdministratorAccess: string;
/** Grants account administrative permissions while explicitly allowing direct access to resources needed by Amplify applications. */
static AdministratorAccessAmplify: string;
/** Grants account administrative permissions. Explicitly allows developers and administrators to gain direct access to resources they need to manage AWS Elastic Beanstalk applications */
static AdministratorAccessAWSElasticBeanstalk: string;
/** Provides ReadOnly permissions required by the Amazon AI Operations Assistant to do analysis on customer AWS resources during investigations. */
static AIOpsAssistantPolicy: string;
/** Grants full access to Amazon AI Operations service and its required permissions via AWS console. It also includes permissions to use identity-aware console sessions. */
static AIOpsConsoleAdminPolicy: string;
/** Grants access to the Amazon AI Operations APIs for creating, updating, and deleting investigations, investigation events, and investigation resources. It also includes ReadOnly access to all AI Operations APIs and to use identity-aware sessions. */
static AIOpsOperatorAccess: string;
/** Grants ReadOnly permissions to the Amazon AI Operations service and its required resources. */
static AIOpsReadOnlyAccess: string;
/** Provide device setup access to AlexaForBusiness services */
static AlexaForBusinessDeviceSetup: string;
/** Grants full access to AlexaForBusiness resources and access to related AWS Services */
static AlexaForBusinessFullAccess: string;
/** Provide gateway execution access to AlexaForBusiness services */
static AlexaForBusinessGatewayExecution: string;
/** Provide access to Lifesize AVS devices */
static AlexaForBusinessLifesizeDelegatedAccessPolicy: string;
/** This policy enables Alexa for Business to perform automated tasks scheduled by your network profiles. */
static AlexaForBusinessNetworkProfileServicePolicy: string;
/** Provide access to Poly AVS devices */
static AlexaForBusinessPolyDelegatedAccessPolicy: string;
/** Provide read only access to AlexaForBusiness services */
static AlexaForBusinessReadOnlyAccess: string;
/** Provides full access to create/edit/delete APIs in Amazon API Gateway via the AWS Management Console. */
static AmazonAPIGatewayAdministrator: string;
/** Provides full access to invoke APIs in Amazon API Gateway. */
static AmazonAPIGatewayInvokeFullAccess: string;
/** Allows API Gateway to push logs to user's account. */
static AmazonAPIGatewayPushToCloudWatchLogs: string;
/** Provides full access to Amazon AppFlow and access to AWS services supported as flow source or destination (S3 and Redshift). Also provides access to KMS for encryption */
static AmazonAppFlowFullAccess: string;
/** Provides read only access to Amazon Appflow flows */
static AmazonAppFlowReadOnlyAccess: string;
/** Provides full access to Amazon AppStream via the AWS Management Console. */
static AmazonAppStreamFullAccess: string;
/** Amazon AppStream 2.0 access to AWS Certificate Manager Private CA in customer accounts for certificate-based authentication */
static AmazonAppStreamPCAAccess: string;
/** Provides read only access to Amazon AppStream via the AWS Management Console. */
static AmazonAppStreamReadOnlyAccess: string;
/** Default policy for Amazon AppStream service role. */
static AmazonAppStreamServiceAccess: string;
/** Provide full access to Amazon Athena and scoped access to the dependencies needed to enable querying, writing results, and data management. */
static AmazonAthenaFullAccess: string;
/** Provides access to perform all operations Amazon Augmented AI resources, including FlowDefinitions, HumanTaskUis and HumanLoops. Does not allow access for creating FlowDefinitions against the public-crowd Workteam. */
static AmazonAugmentedAIFullAccess: string;
/** Provides access to perform all operations on HumanLoops. */
static AmazonAugmentedAIHumanLoopFullAccess: string;
/** Provides access to perform all operations Amazon Augmented AI resources, including FlowDefinitions, HumanTaskUis and HumanLoops. Also provides access to those operations of services that are integrated with Amazon Augmented AI. */
static AmazonAugmentedAIIntegratedAPIAccess: string;
/** Provides console full administrative access to Aurora DSQL */
static AmazonAuroraDSQLConsoleFullAccess: string;
/** Provides full administrative access to Aurora DSQL */
static AmazonAuroraDSQLFullAccess: string;
/** Provides read only access to Aurora DSQL */
static AmazonAuroraDSQLReadOnlyAccess: string;
/** Provides full access to Amazon Bedrock as well as limited access to related services that are required by it */
static AmazonBedrockFullAccess: string;
/** Provides read only access to Amazon Bedrock */
static AmazonBedrockReadOnly: string;
/** Defines the maximum permissions of IAM roles that Amazon Bedrock Studio creates for operating Amazon Bedrock Studio resources. */
static AmazonBedrockStudioPermissionsBoundary: string;
/** Provides full access to Amazon Braket via the AWS Management Console and SDK. Also provides access to related services (e.g., S3, logs). */
static AmazonBraketFullAccess: string;
/** Grants access to AWS Services and resources necessary for executing an Amazon Braket Job including S3, Cloudwatch, IAM and Braket */
static AmazonBraketJobsExecutionPolicy: string;
/** Allows Amazon Braket to create and manage AWS resources on your behalf */
static AmazonBraketServiceRolePolicy: string;
/** Provides full access to Amazon Chime Admin Console via the AWS Management Console. */
static AmazonChimeFullAccess: string;
/** Provides read only access to Amazon Chime Admin Console via the AWS Management Console. */
static AmazonChimeReadOnly: string;
/** Provides access to Amazon Chime SDK operations */
static AmazonChimeSDK: string;
/** Managed Policy For Amazon Chime SDK MediaPipelines Service Linked Role */
static AmazonChimeSDKMediaPipelinesServiceLinkedRolePolicy: string;
/** Allows Amazon Chime SDK Messaging to access AWS resources and enable messaging functionality */
static AmazonChimeSDKMessagingServiceRolePolicy: string;
/** Enables access to AWS Resources used or managed by Amazon Chime */
static AmazonChimeServiceRolePolicy: string;
/** Allows Amazon Chime to access Amazon Transcribe and Amazon Transcribe Medical on your behalf */
static AmazonChimeTranscriptionServiceLinkedRolePolicy: string;
/** Provides user management access to Amazon Chime Admin Console via the AWS Management Console. */
static AmazonChimeUserManagement: string;
/** Managed policy for Service Linked Role for Amazon Chime VoiceConnector */
static AmazonChimeVoiceConnectorServiceLinkedRolePolicy: string;
/** Provides full access to Amazon Cloud Directory Service. */
static AmazonCloudDirectoryFullAccess: string;
/** Provides read only access to Amazon Cloud Directory Service. */
static AmazonCloudDirectoryReadOnlyAccess: string;
/** Provides full only access to Amazon CloudWatch Evidently. Also provides access to related Amazon S3, Amazon SNS, Amazon CloudWatch, and other related services. */
static AmazonCloudWatchEvidentlyFullAccess: string;
/** Provides read only access to Amazon CloudWatch Evidently */
static AmazonCloudWatchEvidentlyReadOnlyAccess: string;
/** Allows CloudWatch Evidently Service to manage associated AWS Resources on behalf of the customer */
static AmazonCloudWatchEvidentlyServiceRolePolicy: string;
/** Grants full access permissions for the Amazon CloudWatch RUM service */
static AmazonCloudWatchRUMFullAccess: string;
/** Grants read only permissions for the Amazon CloudWatch RUM service */
static AmazonCloudWatchRUMReadOnlyAccess: string;
/** Grants permission to Amazon CloudWatch RUM Service to publish monitoring data to other relevant AWS services */
static AmazonCloudWatchRUMServiceRolePolicy: string;
/** Provides full access to Amazon CodeCatalyst */
static AmazonCodeCatalystFullAccess: string;
/** Provides read only access to Amazon CodeCatalyst */
static AmazonCodeCatalystReadOnlyAccess: string;
/** Allows Amazon CodeCatalyst to create, update, and resolve AWS Support cases on your behalf. */
static AmazonCodeCatalystSupportAccess: string;
/** Provides access required by Amazon CodeGuru Profiler agent. */
static AmazonCodeGuruProfilerAgentAccess: string;
/** Provides full access to Amazon CodeGuru Profiler. */
static AmazonCodeGuruProfilerFullAccess: string;
/** Provides read only access to Amazon CodeGuru Profiler. */
static AmazonCodeGuruProfilerReadOnlyAccess: string;
/** Grants full access to Amazon CodeGuru Reviewer and scoped access to required dependencies. */
static AmazonCodeGuruReviewerFullAccess: string;
/** Provides read only access to Amazon CodeGuru Reviewer. */
static AmazonCodeGuruReviewerReadOnlyAccess: string;
/** A service-linked role required for Amazon CodeGuru Reviewer to access resources on your behalf. */
static AmazonCodeGuruReviewerServiceRolePolicy: string;
/** Provides full access to Amazon CodeGuru Security. */
static AmazonCodeGuruSecurityFullAccess: string;
/** Provides access required for working with Amazon CodeGuru Security scans. */
static AmazonCodeGuruSecurityScanAccess: string;
/** Provides access to Amazon Cognito APIs to support developer authenticated identities from your authentication backend. */
static AmazonCognitoDeveloperAuthenticatedIdentities: string;
/** Allows Amazon Cognito User Pools service to use your SES identities for email sending */
static AmazonCognitoIdpEmailServiceRolePolicy: string;
/** Enables access to AWS Services and Resources used or managed by Amazon Cognito User Pools */
static AmazonCognitoIdpServiceRolePolicy: string;
/** Provides administrative access to existing Amazon Cognito resources. You will need AWS account admin privileges to create new Cognito resources. */
static AmazonCognitoPowerUser: string;
/** Provides read only access to Amazon Cognito resources. */
static AmazonCognitoReadOnly: string;
/** This policy defines the set of permissions allowed for unauthenticated identities for Cognito Identity Pools. This policy is not intended to be used as a stand alone permission policy. It is used as a guardrail against overly permissive policies attached for roles in an identity pool. Do not attach this policy to any roles, as Cognito Identity Service will automatically include it as a scoped down policy when creating credentials. The privileges to temporarily access other AWS resources through the enhanced flow will now be defined by the intersection of the role associated with the identity of the unauthenticated user provided by a service, and the privileges given in this managed policy that is owned by Cognito. */
static AmazonCognitoUnAuthedIdentitiesSessionPolicy: string;
/** This policy defines the set of permissions allowed for unauthenticated identities for Cognito Identity Pools. This does not need to be attached to your unauth role, as Cognito Identity Service will automatically include it as a scoped down policy when creating credentials. The privileges to temporarily access other AWS resources through the enhanced flow will now be defined by the intersection of the role associated with the identity of the unauthenticated user provided by a service, and the privileges given in this managed policy that is owned by Cognito. */
static AmazonCognitoUnauthenticatedIdentities: string;
/** The purpose of this policy is to grant permissions to AWS Connect users required to use Connect resources. This policy provides full access to AWS Connect resources via the Connect Console and public APIs */
static AmazonConnectFullAccess: string;
/** Policy for Amazon Connect Campaigns service linked role */
static AmazonConnectCampaignsServiceLinkedRolePolicy: string;
/** Grants permission to view the Amazon Connect instances in your AWS account. */
static AmazonConnectReadOnlyAccess: string;
/** Allows Amazon Connect to create and manage AWS resources on your behalf. */
static AmazonConnectServiceLinkedRolePolicy: string;
/** Allows Amazon Connect to synchronize AWS resources across regions on your behalf. */
static AmazonConnectSynchronizationServiceRolePolicy: string;
/** Provides full access to Amazon Connect Voice ID */
static AmazonConnectVoiceIDFullAccess: string;
/** Provides permissions to consume Amazon Bedrock models, including invoking Amazon Bedrock application inference profile created for particular Amazon DataZone domain. */
static AmazonDataZoneBedrockModelConsumptionPolicy: string;
/** Provides permissions to manage Amazon Bedrock model access, including creating, tagging and deleting application inference profiles. */
static AmazonDataZoneBedrockModelManagementPolicy: string;
/** Default policy for the Amazon DataZone's DomainExecutionRole service role. This role is used by Amazon DataZone to catalog, discover, govern, share, and analyze data in the Amazon DataZone domain. */
static AmazonDataZoneDomainExecutionRolePolicy: string;
/** Amazon DataZone creates IAM roles for Environments to perform data analytics actions, and uses this policy when creating these roles to define the boundary of their permissions. */
static AmazonDataZoneEnvironmentRolePermissionsBoundary: string;
/** Provides full access to Amazon DataZone via the AWS Management Console as well as limited access to related services that are required by it. */
static AmazonDataZoneFullAccess: string;
/** Provides full access to Amazon DataZone, but does not allow the management of domains, users, or associated accounts. */
static AmazonDataZoneFullUserAccess: string;
/** The policy grants permissions to allow Amazon DataZone to enable publishing and access grants to data. */
static AmazonDataZoneGlueManageAccessRolePolicy: string;
/** Amazon DataZone is a data management service that enables you to catalog, discover, govern, share, and analyze your data. With Amazon DataZone, you can share and access your data across accounts and supported regions. Amazon DataZone simplifies your experience across AWS services, including, but not limited to, Amazon Redshift, Amazon Athena, AWS Glue, and AWS Lake Formation. */
static AmazonDataZoneRedshiftGlueProvisioningPolicy: string;
/** This policy gives Amazon DataZone permissions to publish Amazon Redshift data to the catalog. It also gives Amazon DataZone permissions to grant access or revoke access to Amazon Redshift or Amazon Redshift Serverless published assets in the catalog. */
static AmazonDataZoneRedshiftManageAccessRolePolicy: string;
/** The AmazonDataZoneSageMakerEnvironmentRolePermissionsBoundary policy is the list of permissions that are permitted on an execution role created in a SageMaker environment provisioned by Amazon DataZone. */
static AmazonDataZoneSageMakerEnvironmentRolePermissionsBoundary: string;
/** The AmazonDataZoneSageMakerManageAccessRolePolicy policy grants Amazon DataZone the permissions required to grant user access to various resources in the SageMaker environment. */
static AmazonDataZoneSageMakerManageAccessRolePolicy: string;
/** The AmazonDataZoneSageMakerProvisioningRolePolicy policy grants Amazon DataZone the permissions required to interoperate with Amazon SageMaker. */
static AmazonDataZoneSageMakerProvisioningRolePolicy: string;
/** Provides full access to Amazon Detective service and scoped access to the console UI dependencies */
static AmazonDetectiveFullAccess: string;
/** Provides investigator access to Amazon Detective service and scoped access to the console UI dependencies. This policy grants permission to dive into Detective for investigation purposes and limited write access to Guardduty. */
static AmazonDetectiveInvestigatorAccess: string;
/** Provides member access to Amazon Detective service and scoped access to the console UI dependencies. */
static AmazonDetectiveMemberAccess: string;
/** Provides Organizations access to manage Delegated administrator for Amazon Detective and scoped access to the console UI dependencies. This also grants permission to create a service-linked role for Detective. */
static AmazonDetectiveOrganizationsAccess: string;
/** Allows Amazon Detective to make service calls on your behalf */
static AmazonDetectiveServiceLinkedRolePolicy: string;
/** The policy grants full-access to the DevOps Guru console. */
static AmazonDevOpsGuruConsoleFullAccess: string;
/** Provides full access to Amazon DevOps Guru. */
static AmazonDevOpsGuruFullAccess: string;
/** Provide access to enable and manage Amazon DevOps Guru within an organization. */
static AmazonDevOpsGuruOrganizationsAccess: string;
/** Provides read only access to Amazon DevOps Guru Console. */
static AmazonDevOpsGuruReadOnlyAccess: string;
/** A service-linked role required for Amazon DevOpsGuru to access your resources. */
static AmazonDevOpsGuruServiceRolePolicy: string;
/** Provides access to upload DMS replication logs to cloudwatch logs in customer account. */
static AmazonDMSCloudWatchLogsRole: string;
/** Provides access to manage S3 settings for Redshift endpoints for DMS. */
static AmazonDMSRedshiftS3Role: string;
/** Provides access to manage VPC settings for AWS managed customer configurations */
static AmazonDMSVPCManagementRole: string;
/** Allows Amazon DocumentDB-Elastic to manage AWS resources on your behalf. */
static AmazonDocDBElasticServiceRolePolicy: string;
/** Provides full access to manage Amazon DocumentDB with MongoDB compatibility using the AWS Management Console. Note this policy also grants full access to publish on all SNS topics within the account, permissions to create and edit Amazon EC2 instances and VPC configurations, permissions to view and list keys on Amazon KMS, and full access to Amazon RDS and Amazon Neptune. */
static AmazonDocDBConsoleFullAccess: string;
/** Provides full access to Amazon DocumentDB Elastic Clusters and other required permissions for its dependencies including EC2, KMS, SecretsManager, CloudWatch and IAM. */
static AmazonDocDBElasticFullAccess: string;
/** Provides read-only access to Amazon DocDB-Elastic and CloudWatch metrics. */
static AmazonDocDBElasticReadOnlyAccess: string;
/** Provides full access to Amazon DocumentDB with MongoDB compatibility. Note this policy also grants full access to publish on all SNS topics within the account and full access to Amazon RDS and Amazon Neptune. */
static AmazonDocDBFullAccess: string;
/** Provides read-only access to Amazon DocumentDB with MongoDB compatibility. Note that this policy also grants access to Amazon RDS and Amazon Neptune resources. */
static AmazonDocDBReadOnlyAccess: string;
/** Provides access to manage VPC settings for Amazon managed customer configurations */
static AmazonDRSVPCManagement: string;
/** Provides full access to Amazon DynamoDB via the AWS Management Console. */
static AmazonDynamoDBFullAccess: string;
/** Provides full access to Amazon DynamoDB */
static AmazonDynamoDBFullAccessV2: string;
/** This policy is on a deprecation path. See documentation for guidance: https://docs.aws.amazon.com/amazondynamodb/latest/developerguide/DynamoDBPipeline.html. Provides full access to Amazon DynamoDB including Export/Import using AWS Data Pipeline via the AWS Management Console. */
static AmazonDynamoDBFullAccesswithDataPipeline: string;
/** Provides read only access to Amazon DynamoDB via the AWS Management Console. */
static AmazonDynamoDBReadOnlyAccess: string;
/** IAM Policy that allows the CSI driver service account to make calls to related services such as EC2 on your behalf. */
static AmazonEBSCSIDriverPolicy: string;
/** Provides administrative access to Amazon ECR resources */
static AmazonEC2ContainerRegistryFullAccess: string;
/** Provides full access to Amazon EC2 Container Registry repositories, but does not allow repository deletion or policy changes. */
static AmazonEC2ContainerRegistryPowerUser: string;
/** Provides access to pull images from Amazon EC2 Container Registry repositories. */
static AmazonEC2ContainerRegistryPullOnly: string;
/** Provides read-only access to Amazon EC2 Container Registry repositories. */
static AmazonEC2ContainerRegistryReadOnly: string;
/** Policy to enable Task Autoscaling for Amazon EC2 Container Service */
static AmazonEC2ContainerServiceAutoscaleRole: string;
/** Policy to enable CloudWatch Events for EC2 Container Service */
static AmazonEC2ContainerServiceEventsRole: string;
/** Default policy for the Amazon EC2 Role for Amazon EC2 Container Service. */
static AmazonEC2ContainerServiceforEC2Role: string;
/** Default policy for Amazon ECS service role. */
static AmazonEC2ContainerServiceRole: string;
/** Provides full access to Amazon EC2 via the AWS Management Console. */
static AmazonEC2FullAccess: string;
/** Provides read only access to Amazon EC2 via the AWS Management Console. */
static AmazonEC2ReadOnlyAccess: string;
/** Provides EC2 access to S3 bucket to download revision. This role is needed by the CodeDeploy agent on EC2 instances. */
static AmazonEC2RoleforAWSCodeDeploy: string;
/** Provides EC2 limited access to S3 bucket to download revision. This role is needed by the CodeDeploy agent on EC2 instances. */
static AmazonEC2RoleforAWSCodeDeployLimited: string;
/** Default policy for the Amazon EC2 Role for Data Pipeline service role. */
static AmazonEC2RoleforDataPipelineRole: string;
/** This policy will soon be deprecated. Please use AmazonSSMManagedInstanceCore policy to enable AWS Systems Manager service core functionality on EC2 instances. For more information see https://docs.aws.amazon.com/systems-manager/latest/userguide/setup-instance-profile.html */
static AmazonEC2RoleforSSM: string;
/** Managed policy for the Amazon LaunchWizard service role for EC2 */
static AmazonEC2RolePolicyForLaunchWizard: string;
/** Policy to enable Autoscaling for Amazon EC2 Spot Fleet */
static AmazonEC2SpotFleetAutoscaleRole: string;
/** Allows EC2 Spot Fleet to request, terminate and tag Spot Instances on your behalf. */
static AmazonEC2SpotFleetTaggingRole: string;
/** Provides administrative access to Amazon ECS resources and enables ECS features through access to other AWS service resources, including VPCs, Auto Scaling groups, and CloudFormation stacks. */
static AmazonECSFullAccess: string;
/** Policy to enable Amazon ECS Compute to manage your EC2 instances and related resources as part of ECS managed instances */
static AmazonECSComputeServiceRolePolicy: string;
/** Provides administrative access to Private Certificate Authority, AWS Secrets Manager and other AWS Services required to manage ECS Service Connect TLS features on your behalf. */
static AmazonECSInfrastructureRolePolicyForServiceConnectTransportLayerSecurity: string;
/** Provides access to other AWS service resources required to manage volumes associated with ECS workloads on your behalf. */
static AmazonECSInfrastructureRolePolicyForVolumes: string;
/** Provides access to other AWS service resources required to manage VPC Lattice feature in ECS workloads on your behalf. */
static AmazonECSInfrastructureRolePolicyForVpcLattice: string;
/** Policy to enable Amazon ECS to manage your cluster. */
static AmazonECSServiceRolePolicy: string;
/** Provides access to other AWS service resources that are required to run Amazon ECS tasks */
static AmazonECSTaskExecutionRolePolicy: string;
/** Provides management access to EFS resources and read access to EC2 */
static AmazonEFSCSIDriverPolicy: string;
/** This policy provides the Amazon VPC CNI Plugin (amazon-vpc-cni-k8s) the permissions it requires to modify the IP address configuration on your EKS worker nodes. This permission set allows the CNI to list, describe, and modify Elastic Network Interfaces on your behalf. More information on the AWS VPC CNI Plugin is available here: https://github.com/aws/amazon-vpc-cni-k8s */
static AmazonEKSCNIPolicy: string;
/** Policy attached to the EKS Cluster Role that grants permissions to manage the cluster's block storage resources. */
static AmazonEKSBlockStoragePolicy: string;
/** This policy provides Kubernetes the permissions it requires to manage resources on your behalf. Kubernetes requires Ec2:CreateTags permissions to place identifying information on EC2 resources including but not limited to Instances, Security Groups, and Elastic Network Interfaces. */
static AmazonEKSClusterPolicy: string;
/** Policy attached to the EKS Cluster Role that grants permissions to manage the cluster's compute resources. */
static AmazonEKSComputePolicy: string;
/** This policy allows Amazon EKS to manage AWS resources for EKS connector */
static AmazonEKSConnectorServiceRolePolicy: string;
/** This policy enables the Amazon EKS Dashboard to access and display organization-wide information. The policy allows the EKS Dashboard service to gather information about your AWS Organizations structure and accounts. */
static AmazonEKSDashboardServiceRolePolicy: string;
/** Provides access to other AWS service resources that are required to run Amazon EKS pods on AWS Fargate */
static AmazonEKSFargatePodExecutionRolePolicy: string;
/** This policy grants necessary permissions to Amazon EKS to run fargate tasks */
static AmazonEKSForFargateServiceRolePolicy: string;
/** Policy attached to the EKS Cluster Role that grants permissions to manage the cluster's load balancing resources. */
static AmazonEKSLoadBalancingPolicy: string;
/** This policy provides permissions to EKS local cluster's control-plane instances running in your account to manage resources on your behalf. */
static AmazonEKSLocalOutpostClusterPolicy: string;
/** Allows Amazon EKS Local to call AWS services on your behalf. */
static AmazonEKSLocalOutpostServiceRolePolicy: string;
/** Policy attached to the EKS Cluster Role that grants permissions to manage the cluster's networking resources. */
static AmazonEKSNetworkingPolicy: string;
/** This policy allows Amazon Elastic Container Service for Kubernetes to create and manage the necessary resources to operate EKS Clusters. */
static AmazonEKSServicePolicy: string;
/** A Service-Linked Role required for Amazon EKS to call AWS services on your behalf. */
static AmazonEKSServiceRolePolicy: string;
/** Policy used by VPC Resource Controller to manage ENI and IPs for worker nodes. */
static AmazonEKSVPCResourceController: string;
/** This policy allows Amazon EKS worker nodes to connect to Amazon EKS Clusters. */
static AmazonEKSWorkerNodeMinimalPolicy: string;
/** This policy allows Amazon EKS worker nodes to connect to Amazon EKS Clusters. */
static AmazonEKSWorkerNodePolicy: string;
/** Provides full access to Amazon ElastiCache via the AWS Management Console. */
static AmazonElastiCacheFullAccess: string;
/** Provides read only access to Amazon ElastiCache via the AWS Management Console. */
static AmazonElastiCacheReadOnlyAccess: string;
/** Provides administrative access to Amazon ECR Public resources */
static AmazonElasticContainerRegistryPublicFullAccess: string;
/** Provides full access to Amazon ECR Public repositories, but does not allow repository deletion or policy changes. */
static AmazonElasticContainerRegistryPublicPowerUser: string;
/** Provides read-only access to Amazon ECR Public repositories. */
static AmazonElasticContainerRegistryPublicReadOnly: string;
/** Provides root client access to an Amazon EFS file system */
static AmazonElasticFileSystemClientFullAccess: string;
/** Provides read only client access to an Amazon EFS file system */
static AmazonElasticFileSystemClientReadOnlyAccess: string;
/** Provides read and write client access to an Amazon EFS file system */
static AmazonElasticFileSystemClientReadWriteAccess: string;
/** Provides full access to Amazon EFS via the AWS Management Console. */
static AmazonElasticFileSystemFullAccess: string;
/** Provides read only access to Amazon EFS via the AWS Management Console. */
static AmazonElasticFileSystemReadOnlyAccess: string;
/** Allows Amazon Elastic File System to manage AWS resources on your behalf */
static AmazonElasticFileSystemServiceRolePolicy: string;
/** Allows customers to use AWS Systems Manager to automatically manage Amazon EFS utilities (amazon-efs-utils) package on their EC2 instances, and use CloudWatchLog to get EFS file system mount success/failure notifications. */
static AmazonElasticFileSystemsUtils: string;
/** Default policy for the Amazon Elastic MapReduce Editors service role. */
static AmazonElasticMapReduceEditorsRole: string;
/** Amazon Elastic MapReduce for Auto Scaling. Role to allow Auto Scaling to add and remove instances from your EMR cluster. */
static AmazonElasticMapReduceforAutoScalingRole: string;
/** Default policy for the Amazon Elastic MapReduce for EC2 service role. */
static AmazonElasticMapReduceforEC2Role: string;
/** This policy is on a deprecation path. See documentation for guidance: https://docs.aws.amazon.com/emr/latest/ManagementGuide/emr-managed-iam-policies.html. Provides full access to Amazon Elastic MapReduce and underlying services that it requires such as EC2 and S3 */
static AmazonElasticMapReduceFullAccess: string;
/** Policy to allow EMR to create, describe and delete EC2 placement groups. */
static AmazonElasticMapReducePlacementGroupPolicy: string;
/** Provides read only access to Amazon Elastic MapReduce via the AWS Management Console. */
static AmazonElasticMapReduceReadOnlyAccess: string;
/** This policy is on a deprecation path. See documentation for guidance: https://docs.aws.amazon.com/emr/latest/ManagementGuide/emr-managed-iam-policies.html. Default policy for the Amazon Elastic MapReduce service role. */
static AmazonElasticMapReduceRole: string;
/** Allow Amazon Elasticsearch Service to access other AWS services such as EC2 Networking APIs on your behalf. */
static AmazonElasticsearchServiceRolePolicy: string;
/** Grants users full access to Elastic Transcoder and the access to associated services that is required for full Elastic Transcoder functionality. */
static AmazonElasticTranscoderFullAccess: string;
/** Grants users permission to change presets, submit jobs, and view Elastic Transcoder settings. This policy also grants some read-only access to some other services required to use the Elastic Transcode console, including S3, IAM, and SNS. */
static AmazonElasticTranscoderJobsSubmitter: string;
/** Grants users read-only access to Elastic Transcoder and list access to related services. */
static AmazonElasticTranscoderReadOnlyAccess: string;
/** Default policy for the Amazon Elastic Transcoder service role. */
static AmazonElasticTranscoderRole: string;
/** Allows the actions that EMR requires to terminate and delete AWS EC2 resources if the EMR Service role has lost that ability. */
static AmazonEMRCleanupPolicy: string;
/** Allows access to other AWS service resources that are required to run Amazon EMR */
static AmazonEMRContainersServiceRolePolicy: string;
/** Provides full access to Amazon EMR */
static AmazonEMRFullAccessPolicyV2: string;
/** Provides read only access to Amazon EMR and the associated CloudWatch Metrics. */
static AmazonEMRReadOnlyAccessPolicyV2: string;
/** Allows access to other AWS service resources that are required to run Amazon EMRServerless */
static AmazonEMRServerlessServiceRolePolicy: string;
/** This policy is used for the Amazon EMR Service Role and should NOT be used for any other IAM users or roles in your account. The policy grants permissions to create and manage resources associated with EMR and related services necessary for the operation of your EMR cluster. */
static AmazonEMRServicePolicyV2: string;
/** Provides limited access to the Amazon Cognito configuration service. */
static AmazonESCognitoAccess: string;
/** Provides full access to the Amazon ES configuration service. */
static AmazonESFullAccess: string;
/** Provides read-only access to the Amazon ES configuration service. */
static AmazonESReadOnlyAccess: string;
/** Allows EventBridge to access Secret Manager resources on your behalf. */
static AmazonEventBridgeApiDestinationsServiceRolePolicy: string;
/** Provides full access to Amazon EventBridge. */
static AmazonEventBridgeFullAccess: string;
/** Provides full access to Amazon EventBridge Pipes. */
static AmazonEventBridgePipesFullAccess: string;
/** Provides read-only and operator (ability to Stop and Start running Pipes) access to Amazon EventBridge Pipes. */
static AmazonEventBridgePipesOperatorAccess: string;
/** Provides read-only access to Amazon EventBridge Pipes. */
static AmazonEventBridgePipesReadOnlyAccess: string;
/** Provides read only access to Amazon EventBridge. */
static AmazonEventBridgeReadOnlyAccess: string;
/** The AmazonEventBridgeSchedulerFullAccess managed policy grants permissions to use all EventBridge Scheduler actions for schedules, and schedule groups. */
static AmazonEventBridgeSchedulerFullAccess: string;
/** The AmazonEventBridgeSchedulerReadOnlyAccess managed policy grants read-only permissions to view details about your schedules and schedule groups */
static AmazonEventBridgeSchedulerReadOnlyAccess: string;
/** Provides full access to Amazon EventBridge Schemas. */
static AmazonEventBridgeSchemasFullAccess: string;
/** Provides read only access to Amazon EventBridge Schemas. */
static AmazonEventBridgeSchemasReadOnlyAccess: string;
/** Grants permissions to Managed Rules created by Amazon EventBridge schemas. */
static AmazonEventBridgeSchemasServiceRolePolicy: string;
/** Grants permissions to EVS to manage resources on your behalf */
static AmazonEVSServiceRolePolicy: string;
/** Policy to enable AWS FIS to manage monitoring and resource selection for experiments. */
static AmazonFISServiceRolePolicy: string;
/** Gives access to all actions for Amazon Forecast */
static AmazonForecastFullAccess: string;
/** Gives access to all actions for Amazon Fraud Detector */
static AmazonFraudDetectorFullAccessPolicy: string;
/** Full Access Policy for Amazon FreeRTOS */
static AmazonFreeRTOSFullAccess: string;
/** Allows user to access Amazon FreeRTOS OTA Update */
static AmazonFreeRTOSOTAUpdate: string;
/** Provides full access to Amazon FSx and access to related AWS services via the AWS Management Console. */
static AmazonFSxConsoleFullAccess: string;
/** Provides read only access to Amazon FSx and access to related AWS services via the AWS Management Console. */
static AmazonFSxConsoleReadOnlyAccess: string;
/** Provides full access to Amazon FSx and access to related AWS services. */
static AmazonFSxFullAccess: string;
/** Provides read only access to Amazon FSx. */
static AmazonFSxReadOnlyAccess: string;
/** Allows Amazon FSx to manage AWS resources on your behalf */
static AmazonFSxServiceRolePolicy: string;
/** Provides full access to Amazon Glacier via the AWS Management Console. */
static AmazonGlacierFullAccess: string;
/** Provides read only access to Amazon Glacier via the AWS Management Console. */
static AmazonGlacierReadOnlyAccess: string;
/** This policy grants access to Amazon Athena and the dependencies needed to enable querying and writing results to s3 from the Amazon Athena plugin in Amazon Grafana. */
static AmazonGrafanaAthenaAccess: string;
/** This policy grants access to Amazon CloudWatch and the dependencies needed to use CloudWatch as a datasource within Amazon Managed Grafana. */
static AmazonGrafanaCloudWatchAccess: string;
/** This policy grants scoped access to Amazon Redshift and the dependencies needed to use the Amazon Redshift plugin in Amazon Grafana. */
static AmazonGrafanaRedshiftAccess: string;
/** Provides access to AWS Resources managed or used by Amazon Grafana. */
static AmazonGrafanaServiceLinkedRolePolicy: string;
/** Provides full access to use Amazon GuardDuty. */
static AmazonGuardDutyFullAccess: string;
/** Provides full access to use Amazon GuardDuty */
static AmazonGuardDutyFullAccessV2: string;
/** GuardDuty malware protection uses the service-linked role (SLR) named AWSServiceRoleForAmazonGuardDutyMalwareProtection. This service-linked role allows GuardDuty malware protection to perform agent-less scans to detect malware. It allows GuardDuty to create snapshots in your account, and share the snapshots with the GuardDuty service account to scan for malware. It evaluates these shared snapshots and includes the retrieved EC2 instance metadata in the GuardDuty Malware Protection findings. The AWSServiceRoleForAmazonGuardDutyMalwareProtection service-linked role trusts the malware-protection.guardduty.amazonaws.com service to assume the role. */
static AmazonGuardDutyMalwareProtectionServiceRolePolicy: string;
/** Provides read only access to Amazon GuardDuty resources */
static AmazonGuardDutyReadOnlyAccess: string;
/** Enable access to AWS Resources used or managed by Amazon Guard Duty */
static AmazonGuardDutyServiceRolePolicy: string;
/** Provides full access to Amazon HealthLake service. */
static AmazonHealthLakeFullAccess: string;
/** Provides read only access to Amazon HealthLake service. */
static AmazonHealthLakeReadOnlyAccess: string;
/** Provides full access to Honeycode via the AWS Management Console and the SDK. */
static AmazonHoneycodeFullAccess: string;
/** Provides read only access to Honeycode via the AWS Management Console and the SDK. */
static AmazonHoneycodeReadOnlyAccess: string;
/** A service-linked role required for Amazon Honeycode to access your resources. */
static AmazonHoneycodeServiceRolePolicy: string;
/** Provides full access to Honeycode Team Association via the AWS Management Console and the SDK. */
static AmazonHoneycodeTeamAssociationFullAccess: string;
/** Provides read only access to Honeycode Team Association via the AWS Management Console and the SDK. */
static AmazonHoneycodeTeamAssociationReadOnlyAccess: string;
/** Provides full access to Honeycode Workbook via the AWS Management Console and the SDK. */
static AmazonHoneycodeWorkbookFullAccess: string;
/** Provides read only access to Honeycode Workbook via the AWS Management Console and the SDK. */
static AmazonHoneycodeWorkbookReadOnlyAccess: string;
/** Grants Amazon Inspector access to AWS Services needed to perform agent-less security assessments */
static AmazonInspector2AgentlessServiceRolePolicy: string;
/** Provides full access to Amazon Inspector and access to other related services such as organizations. */
static AmazonInspector2FullAccess: string;
/** This is a managed policy that customer should attach to their roles to communicate with inspector service for CIS scans */
static AmazonInspector2ManagedCisPolicy: string;
/** Provides read only access to the Amazon inspector2 service and relevant support services */
static AmazonInspector2ReadOnlyAccess: string;
/** Grants Amazon Inspector access to AWS Services needed to perform security assessments */
static AmazonInspector2ServiceRolePolicy: string;
/** Provides full access to Amazon Inspector. */
static AmazonInspectorFullAccess: string;
/** Provides read only access to Amazon Inspector. */
static AmazonInspectorReadOnlyAccess: string;
/** Grants Amazon Inspector access to AWS Services needed to perform security assessments */
static AmazonInspectorServiceRolePolicy: string;
/** Provides full access to Amazon Kendra via the AWS Management Console. */
static AmazonKendraFullAccess: string;
/** Provides read only access to Amazon Kendra via the AWS Management Console. */
static AmazonKendraReadOnlyAccess: string;
/** Provide full access to Amazon Keyspaces */
static AmazonKeyspacesFullAccess: string;
/** Provide read only access to Amazon Keyspaces */
static AmazonKeyspacesReadOnlyAccess: string;
/** Provide read only access to Amazon Keyspaces and related AWS services. */
static AmazonKeyspacesReadOnlyAccessV2: string;
/** Provides full access to Amazon Kinesis Analytics via the AWS Management Console. */
static AmazonKinesisAnalyticsFullAccess: string;
/** Provides read-only access to Amazon Kinesis Analytics via the AWS Management Console. */
static AmazonKinesisAnalyticsReadOnly: string;
/** Provides full access to all Amazon Kinesis Firehose Delivery Streams. */
static AmazonKinesisFirehoseFullAccess: string;
/** Provides read only access to all Amazon Kinesis Firehose Delivery Streams. */
static AmazonKinesisFirehoseReadOnlyAccess: string;
/** Provides full access to all streams via the AWS Management Console. */
static AmazonKinesisFullAccess: string;
/** Provides read only access to all streams via the AWS Management Console. */
static AmazonKinesisReadOnlyAccess: string;
/** Provides full access to Amazon Kinesis Video Streams via the AWS Management Console. */
static AmazonKinesisVideoStreamsFullAccess: string;
/** Provides read only access to AWS Kinesis Video Streams via the AWS Management Console. */
static AmazonKinesisVideoStreamsReadOnlyAccess: string;
/** Full access to AWS Launch wizard and other required services. */
static AmazonLaunchWizardFullAccessV2: string;
/** This policy allows customers to call Lex runtime from channels */
static AmazonLexChannelsAccess: string;
/** Provides full access to Amazon Lex via the AWS Management Console. Also provides access to create Lex Service Linked Roles and grant Lex permissions to invoke a limited set of Lambda functions. */
static AmazonLexFullAccess: string;
/** Provides read-only access to Amazon Lex. */
static AmazonLexReadOnly: string;
/** Allows Amazon Lex to replicate Lex resources across regions on your behalf. */
static AmazonLexReplicationPolicy: string;
/** Provides access to Amazon Lex conversational APIs. */
static AmazonLexRunBotsOnly: string;
/** Provides Lex V2 bots access to call other AWS services on your behalf. */
static AmazonLexV2BotPolicy: string;
/** Provides full access to Amazon Lookout for Equipment operations */
static AmazonLookoutEquipmentFullAccess: string;
/** Provides read only access to Amazon Lookout for Equipments */
static AmazonLookoutEquipmentReadOnlyAccess: string;
/** Gives access to all actions for Amazon Lookout for Metrics */
static AmazonLookoutMetricsFullAccess: string;
/** Gives access to all read-only actions for Amazon Lookout for Metrics */
static AmazonLookoutMetricsReadOnlyAccess: string;
/** Provides full access to Amazon Lookout for Vision and scoped access to required service and console dependencies. */
static AmazonLookoutVisionConsoleFullAccess: string;
/** Provides read only access to Amazon Lookout for Vision and scoped access to required service and console dependencies. */
static AmazonLookoutVisionConsoleReadOnlyAccess: string;
/** Provides full access to Amazon Lookout for Vision and scoped access to required dependencies. */
static AmazonLookoutVisionFullAccess: string;
/** Provides read only access to Amazon Lookout for Vision and scoped access to required dependencies. */
static AmazonLookoutVisionReadOnlyAccess: string;
/** Grants users permission to request Amazon Machine Learning batch predictions. */
static AmazonMachineLearningBatchPredictionsAccess: string;
/** Provides create access for non-prediction Amazon Machine Learning resources. */
static AmazonMachineLearningCreateOnlyAccess: string;
/** Provides full access to Amazon Machine Learning resources. */
static AmazonMachineLearningFullAccess: string;
/** Grants users permission to create and delete the real-time endpoint for Amazon Machine Learning models. */
static AmazonMachineLearningManageRealTimeEndpointOnlyAccess: string;
/** Provides read only access to Amazon Machine Learning resources. */
static AmazonMachineLearningReadOnlyAccess: string;
/** Grants users permission to request Amazon Machine Learning real-time predictions. */
static AmazonMachineLearningRealTimePredictionOnlyAccess: string;
/** Allows Machine Learning to configure and use your Redshift Clusters and S3 Staging Locations for Redshift Data Source. */
static AmazonMachineLearningRoleforRedshiftDataSourceV3: string;
/** Provides full access to Amazon Macie. */
static AmazonMacieFullAccess: string;
/** Grants permission to create the service-linked role of Amazon Macie. */
static AmazonMacieHandshakeRole: string;
/** Provides readonly access to Amazon Macie. */
static AmazonMacieReadOnlyAccess: string;
/** Grants Macie read-only access to resource dependencies in your account in order to enable data analysis. */
static AmazonMacieServiceRole: string;
/** Service linked role for Amazon Macie */
static AmazonMacieServiceRolePolicy: string;
/** Provides full access to Amazon Managed Blockchain via the AWS Management Console */
static AmazonManagedBlockchainConsoleFullAccess: string;
/** Provides full access to Amazon Managed Blockchain. */
static AmazonManagedBlockchainFullAccess: string;
/** Provides read-only access to Amazon Managed Blockchain. */
static AmazonManagedBlockchainReadOnlyAccess: string;
/** Enables access to AWS Services and Resources used or managed by Amazon Managed Blockchain */
static AmazonManagedBlockchainServiceRolePolicy: string;
/** Provide full access to Amazon Managed Apache Cassandra Service */
static AmazonMCSFullAccess: string;
/** Provide read only access to Amazon Managed Apache Cassandra Service */
static AmazonMCSReadOnlyAccess: string;
/** Provides full access to all APIs in Amazon Mechanical Turk. */
static AmazonMechanicalTurkFullAccess: string;
/** Provides access to read only APIs in Amazon Mechanical Turk. */
static AmazonMechanicalTurkReadOnly: string;
/** Provides full access to Amazon MemoryDB via the AWS Management Console. */
static AmazonMemoryDBFullAccess: string;
/** Provides read only access to Amazon MemoryDB via the AWS Management Console. */
static AmazonMemoryDBReadOnlyAccess: string;
/** Provides read only access to all reports including financial data for all application resources. */
static AmazonMobileAnalyticsFinancialReportAccess: string;
/** Provides full access to all application resources. */
static AmazonMobileAnalyticsFullAccess: string;
/** Provides read only access to non financial reports for all application resources. */
static AmazonMobileAnalyticsNonFinancialReportAccess: string;
/** Provides write only access to put event data for all application resources. (Recommended for SDK integration) */
static AmazonMobileAnalyticsWriteOnlyAccess: string;
/** Provides full access to manage Amazon Monitron */
static AmazonMonitronFullAccess: string;
/** Provides full access to AmazonMQ via our API/SDK. */
static AmazonMQApiFullAccess: string;
/** Provides read only access to AmazonMQ via our API/SDK. */
static AmazonMQApiReadOnlyAccess: string;
/** Provides full access to AmazonMQ via the AWS Management Console. */
static AmazonMQFullAccess: string;
/** Provides read only access to AmazonMQ via the AWS Management Console. */
static AmazonMQReadOnlyAccess: string;
/** Service Linked Role Policy for AWS Amazon MQ */
static AmazonMQServiceRolePolicy: string;
/** Provide readonly access to Amazon MSK Connect */
static AmazonMSKConnectReadOnlyAccess: string;
/** Provide full access to Amazon MSK and other required permissions for its dependencies. */
static AmazonMSKFullAccess: string;
/** Provide readonly access to Amazon MSK */
static AmazonMSKReadOnlyAccess: string;
/** The Service Linked Role used by Amazon Managed Workflows for Apache Airflow. */
static AmazonMWAAServiceRolePolicy: string;
/** This policy grants access to resources needed by Nimble Studio Launch Profile workers. Attach this policy to EC2 instances created by Nimble Studio B