Resources created for AWS DevOps Agent activated from AWS Support
Activation from the Support Center Console creates the following resources in
us-east-1. Replace ACCOUNT_ID with your
12-digit AWS account ID. The role suffix is a
12-character identifier derived from the agent space.
AWS service |
Resource type |
Resource name |
Trust scope |
Permissions granted |
|---|---|---|---|---|
AWS DevOps Agent |
Agent space |
|
Not applicable |
Container for the account association, operator web app configuration, and data the agent generates while it operates. |
AWS Identity and Access Management (IAM) |
Role |
|
Trusted by |
Grants the agent the read-only investigation permissions
across AWS services that it needs to investigate resources in your
account. Permissions come from the AWS-managed
|
AWS Identity and Access Management (IAM) |
Role |
|
Trust policy scoped to a specific agent space, so only that agent space's operator web app can assume it. |
Grants the operator web app the permissions it needs for
chat, journal, recommendations, and Support integration. Permissions
come from the AWS-managed
|
AWS Identity and Access Management (IAM) |
Customer-managed policy |
|
Attached to the
|
Grants |
The Support Center Console activation doesn't create resources in any other AWS Region.