UNPKG

cdk-iam-floyd

Version:

AWS IAM policy statement generator with fluent interface for AWS CDK

598 lines (597 loc) 22 kB
import { AccessLevelList } from '../../shared/access-level'; import { PolicyStatement, Operator } from '../../shared'; import { aws_iam as iam } from "aws-cdk-lib"; /** * Statement provider for service [lookoutequipment](https://docs.aws.amazon.com/service-authorization/latest/reference/list_lookoutequipment.html). * * @param sid [SID](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_elements_sid.html) of the statement */ export declare class Lookoutequipment extends PolicyStatement { servicePrefix: string; /** * Grants permission to create a dataset * * Access Level: Write * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_CreateDataset.html */ toCreateDataset(): this; /** * Grants permission to create an inference scheduler for a trained model * * Access Level: Write * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_CreateInferenceScheduler.html */ toCreateInferenceScheduler(): this; /** * Grants permission to create a label * * Access Level: Write * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_CreateLabel.html */ toCreateLabel(): this; /** * Grants permission to create a label group * * Access Level: Write * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_CreateLabelGroup.html */ toCreateLabelGroup(): this; /** * Grants permission to create a model that is trained on a dataset * * Access Level: Write * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_CreateModel.html */ toCreateModel(): this; /** * Grants permission to create a retraining scheduler for a trained model * * Access Level: Write * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_CreateRetrainingScheduler.html */ toCreateRetrainingScheduler(): this; /** * Grants permission to delete a dataset * * Access Level: Write * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_DeleteDataset.html */ toDeleteDataset(): this; /** * Grants permission to delete an inference scheduler * * Access Level: Write * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_DeleteInferenceScheduler.html */ toDeleteInferenceScheduler(): this; /** * Grants permission to delete a label * * Access Level: Write * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_DeleteLabel.html */ toDeleteLabel(): this; /** * Grants permission to delete a label group * * Access Level: Write * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_DeleteLabelGroup.html */ toDeleteLabelGroup(): this; /** * Grants permission to delete a model * * Access Level: Write * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_DeleteModel.html */ toDeleteModel(): this; /** * Grants permission to delete a resource policy * * Access Level: Write * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_DeleteResourcePolicy.html */ toDeleteResourcePolicy(): this; /** * Grants permission to delete a retraining scheduler of a trained model * * Access Level: Write * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_DeleteRetrainingScheduler.html */ toDeleteRetrainingScheduler(): this; /** * Grants permission to describe a data ingestion job * * Access Level: Read * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_DescribeDataIngestionJob.html */ toDescribeDataIngestionJob(): this; /** * Grants permission to describe a dataset * * Access Level: Read * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_DescribeDataset.html */ toDescribeDataset(): this; /** * Grants permission to describe an inference scheduler * * Access Level: Read * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_DescribeInferenceScheduler.html */ toDescribeInferenceScheduler(): this; /** * Grants permission to describe a label group * * Access Level: Read * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_DescribeLabelGroup.html */ toDescribeLabelGroup(): this; /** * Grants permission to describe a model * * Access Level: Read * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_DescribeModel.html */ toDescribeModel(): this; /** * Grants permission to describe a model version * * Access Level: Read * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_DescribeModelVersion.html */ toDescribeModelVersion(): this; /** * Grants permission to describe a resource policy * * Access Level: Read * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_DescribeResourcePolicy.html */ toDescribeResourcePolicy(): this; /** * Grants permission to describe a retraining scheduler of a trained model * * Access Level: Read * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_DescribeRetrainingScheduler.html */ toDescribeRetrainingScheduler(): this; /** * Grants permission to describe a label * * Access Level: Read * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_DescribeLabel.html */ toDescribelabel(): this; /** * Grants permission to import a dataset * * Access Level: Write * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_ImportDataset.html */ toImportDataset(): this; /** * Grants permission to import a model version * * Access Level: Write * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_ImportModelVersion.html */ toImportModelVersion(): this; /** * Grants permission to list the data ingestion jobs in your account or for a particular dataset * * Access Level: List * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_ListDataIngestionJobs.html */ toListDataIngestionJobs(): this; /** * Grants permission to list the datasets in your account * * Access Level: List * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_ListDatasets.html */ toListDatasets(): this; /** * Grants permission to list the inference events for an inference scheduler * * Access Level: Read * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_ListInferenceEvents.html */ toListInferenceEvents(): this; /** * Grants permission to list the inference executions for an inference scheduler * * Access Level: Read * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_ListInferenceExecutions.html */ toListInferenceExecutions(): this; /** * Grants permission to list the inference schedulers in your account * * Access Level: List * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_ListInferenceSchedulers.html */ toListInferenceSchedulers(): this; /** * Grants permission to list the label groups in your account * * Access Level: List * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_ListLabelGroups.html */ toListLabelGroups(): this; /** * Grants permission to list the labels in your account * * Access Level: List * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_ListLabels.html */ toListLabels(): this; /** * Grants permission to list the model versions in your account * * Access Level: List * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_ListModelVersions.html */ toListModelVersions(): this; /** * Grants permission to list the models in your account * * Access Level: List * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_ListModels.html */ toListModels(): this; /** * Grants permission to list the retraining schedulers in your account * * Access Level: List * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_ListRetrainingSchedulers.html */ toListRetrainingSchedulers(): this; /** * Grants permission to list the sensor statistics for a particular dataset or an ingestion job * * Access Level: List * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_ListSensorStatistics.html */ toListSensorStatistics(): this; /** * Grants permission to list the tags for a resource * * Access Level: Read * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_ListTagsForResource.html */ toListTagsForResource(): this; /** * Grants permission to put a resource policy * * Access Level: Write * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_PutResourcePolicy.html */ toPutResourcePolicy(): this; /** * Grants permission to start a data ingestion job for a dataset * * Access Level: Write * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_StartDataIngestionJob.html */ toStartDataIngestionJob(): this; /** * Grants permission to start an inference scheduler * * Access Level: Write * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_StartInferenceScheduler.html */ toStartInferenceScheduler(): this; /** * Grants permission to start a retraining scheduler of a trained model * * Access Level: Write * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_StartRetrainingScheduler.html */ toStartRetrainingScheduler(): this; /** * Grants permission to stop an inference scheduler * * Access Level: Write * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_StopInferenceScheduler.html */ toStopInferenceScheduler(): this; /** * Grants permission to stop a retraining scheduler of a trained model * * Access Level: Write * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_StopRetrainingScheduler.html */ toStopRetrainingScheduler(): this; /** * Grants permission to tag a resource * * Access Level: Tagging, Write * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_TagResource.html */ toTagResource(): this; /** * Grants permission to untag a resource * * Access Level: Tagging, Write * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_UntagResource.html */ toUntagResource(): this; /** * Grants permission to set the active model version for a given machine learning model * * Access Level: Write * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_UpdateActiveModelVersion.html */ toUpdateActiveModelVersion(): this; /** * Grants permission to update an inference scheduler * * Access Level: Write * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_UpdateInferenceScheduler.html */ toUpdateInferenceScheduler(): this; /** * Grants permission to update a label group * * Access Level: Write * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_UpdateLabelGroup.html */ toUpdateLabelGroup(): this; /** * Grants permission to update a trained model * * Access Level: Write * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_UpdateModel.html */ toUpdateModel(): this; /** * Grants permission to update a retraining scheduler of a trained model * * Access Level: Write * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/API_UpdateRetrainingScheduler.html */ toUpdateRetrainingScheduler(): this; protected accessLevelList: AccessLevelList; /** * Adds a resource of type dataset to the statement * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/dataset.html * * @param datasetName - Identifier for the datasetName. * @param datasetId - Identifier for the datasetId. * @param account - Account of the resource; defaults to `*`, unless using the CDK, where the default is the current Stack's account. * @param region - Region of the resource; defaults to `*`, unless using the CDK, where the default is the current Stack's region. * @param partition - Partition of the AWS account [aws, aws-cn, aws-us-gov]; defaults to `aws`, unless using the CDK, where the default is the current Stack's partition. * * Possible conditions: * - .ifAwsResourceTag() */ onDataset(datasetName: string, datasetId: string, account?: string, region?: string, partition?: string): this; /** * Adds a resource of type inference-scheduler to the statement * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/inference-scheduler.html * * @param inferenceSchedulerName - Identifier for the inferenceSchedulerName. * @param inferenceSchedulerId - Identifier for the inferenceSchedulerId. * @param account - Account of the resource; defaults to `*`, unless using the CDK, where the default is the current Stack's account. * @param region - Region of the resource; defaults to `*`, unless using the CDK, where the default is the current Stack's region. * @param partition - Partition of the AWS account [aws, aws-cn, aws-us-gov]; defaults to `aws`, unless using the CDK, where the default is the current Stack's partition. * * Possible conditions: * - .ifAwsResourceTag() */ onInferenceScheduler(inferenceSchedulerName: string, inferenceSchedulerId: string, account?: string, region?: string, partition?: string): this; /** * Adds a resource of type label-group to the statement * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/label-group.html * * @param labelGroupName - Identifier for the labelGroupName. * @param labelGroupId - Identifier for the labelGroupId. * @param account - Account of the resource; defaults to `*`, unless using the CDK, where the default is the current Stack's account. * @param region - Region of the resource; defaults to `*`, unless using the CDK, where the default is the current Stack's region. * @param partition - Partition of the AWS account [aws, aws-cn, aws-us-gov]; defaults to `aws`, unless using the CDK, where the default is the current Stack's partition. * * Possible conditions: * - .ifAwsResourceTag() */ onLabelGroup(labelGroupName: string, labelGroupId: string, account?: string, region?: string, partition?: string): this; /** * Adds a resource of type model to the statement * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/model.html * * @param modelName - Identifier for the modelName. * @param modelId - Identifier for the modelId. * @param account - Account of the resource; defaults to `*`, unless using the CDK, where the default is the current Stack's account. * @param region - Region of the resource; defaults to `*`, unless using the CDK, where the default is the current Stack's region. * @param partition - Partition of the AWS account [aws, aws-cn, aws-us-gov]; defaults to `aws`, unless using the CDK, where the default is the current Stack's partition. * * Possible conditions: * - .ifAwsResourceTag() */ onModel(modelName: string, modelId: string, account?: string, region?: string, partition?: string): this; /** * Adds a resource of type model-version to the statement * * https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/model-version.html * * @param modelName - Identifier for the modelName. * @param modelId - Identifier for the modelId. * @param modelVersionNumber - Identifier for the modelVersionNumber. * @param account - Account of the resource; defaults to `*`, unless using the CDK, where the default is the current Stack's account. * @param region - Region of the resource; defaults to `*`, unless using the CDK, where the default is the current Stack's region. * @param partition - Partition of the AWS account [aws, aws-cn, aws-us-gov]; defaults to `aws`, unless using the CDK, where the default is the current Stack's partition. * * Possible conditions: * - .ifAwsResourceTag() */ onModelVersion(modelName: string, modelId: string, modelVersionNumber: string, account?: string, region?: string, partition?: string): this; /** * Filters access by the presence of tag key-value pairs in the request * * https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_condition-keys.html#condition-keys-requesttag * * Applies to actions: * - .toCreateDataset() * - .toCreateInferenceScheduler() * - .toCreateLabelGroup() * - .toCreateModel() * - .toImportDataset() * - .toImportModelVersion() * - .toTagResource() * * @param tagKey The tag key to check * @param value The value(s) to check * @param operator Works with [string operators](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_elements_condition_operators.html#Conditions_String). **Default:** `StringLike` */ ifAwsRequestTag(tagKey: string, value: string | string[], operator?: Operator | string): this; /** * Filters access by tag key-value pairs attached to the resource * * https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_condition-keys.html#condition-keys-resourcetag * * Applies to actions: * - .toCreateDataset() * - .toCreateInferenceScheduler() * - .toCreateLabel() * - .toCreateLabelGroup() * - .toCreateModel() * - .toCreateRetrainingScheduler() * - .toDeleteDataset() * - .toDeleteInferenceScheduler() * - .toDeleteLabel() * - .toDeleteLabelGroup() * - .toDeleteModel() * - .toDeleteResourcePolicy() * - .toDeleteRetrainingScheduler() * - .toDescribeDataset() * - .toDescribeInferenceScheduler() * - .toDescribeLabelGroup() * - .toDescribeModel() * - .toDescribeModelVersion() * - .toDescribeResourcePolicy() * - .toDescribeRetrainingScheduler() * - .toDescribelabel() * - .toImportDataset() * - .toImportModelVersion() * - .toListDataIngestionJobs() * - .toListInferenceEvents() * - .toListInferenceExecutions() * - .toListLabelGroups() * - .toListLabels() * - .toListModelVersions() * - .toListSensorStatistics() * - .toListTagsForResource() * - .toPutResourcePolicy() * - .toStartDataIngestionJob() * - .toStartInferenceScheduler() * - .toStartRetrainingScheduler() * - .toStopInferenceScheduler() * - .toStopRetrainingScheduler() * - .toTagResource() * - .toUntagResource() * - .toUpdateActiveModelVersion() * - .toUpdateInferenceScheduler() * - .toUpdateLabelGroup() * - .toUpdateModel() * - .toUpdateRetrainingScheduler() * * Applies to resource types: * - dataset * - inference-scheduler * - label-group * - model * - model-version * * @param tagKey The tag key to check * @param value The value(s) to check * @param operator Works with [string operators](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_elements_condition_operators.html#Conditions_String). **Default:** `StringLike` */ ifAwsResourceTag(tagKey: string, value: string | string[], operator?: Operator | string): this; /** * Filters access by the presence of tag keys in the request * * https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_condition-keys.html#condition-keys-tagkeys * * Applies to actions: * - .toCreateDataset() * - .toCreateInferenceScheduler() * - .toCreateLabelGroup() * - .toCreateModel() * - .toImportDataset() * - .toImportModelVersion() * - .toTagResource() * - .toUntagResource() * * @param value The value(s) to check * @param operator Works with [string operators](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_elements_condition_operators.html#Conditions_String). **Default:** `StringLike` */ ifAwsTagKeys(value: string | string[], operator?: Operator | string): this; /** * Filters access by the import strategy of underlying data * * https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_condition-keys.html#condition-keys-isimportingdata * * Applies to actions: * - .toImportModelVersion() * * @param value `true` or `false`. **Default:** `true` */ ifIsImportingData(value?: boolean): this; /** * Statement provider for service [lookoutequipment](https://docs.aws.amazon.com/service-authorization/latest/reference/list_lookoutequipment.html). * */ constructor(props?: iam.PolicyStatementProps); }