Terjemahan disediakan oleh mesin penerjemah. Jika konten terjemahan yang diberikan bertentangan dengan versi bahasa Inggris aslinya, utamakan versi bahasa Inggris.
AWS kebijakan yang dikelola untuk AWS Config
Kebijakan AWS terkelola adalah kebijakan mandiri yang dibuat dan dikelola oleh AWS. AWS kebijakan terkelola dirancang untuk memberikan izin untuk banyak kasus penggunaan umum sehingga Anda dapat mulai menetapkan izin kepada pengguna, grup, dan peran.
Perlu diingat bahwa kebijakan ter AWS kelola mungkin tidak memberikan izin hak istimewa terkecil untuk kasus penggunaan spesifik Anda karena kebijakan tersebut tersedia untuk digunakan semua AWS pelanggan. Kami menyarankan Anda untuk mengurangi izin lebih lanjut dengan menentukan kebijakan yang dikelola pelanggan yang khusus untuk kasus penggunaan Anda.
Anda tidak dapat mengubah izin yang ditentukan dalam kebijakan AWS terkelola. Jika AWS memperbarui izin yang ditentukan dalam kebijakan AWS terkelola, pembaruan akan memengaruhi semua identitas utama (pengguna, grup, dan peran) yang dilampirkan kebijakan tersebut. AWS kemungkinan besar akan memperbarui kebijakan ter AWS kelola ketika yang baru Layanan AWS diluncurkan atau operasi API baru tersedia untuk layanan yang ada.
Untuk informasi selengkapnya, lihat Kebijakan terkelola AWS dalam Panduan Pengguna IAM.
AWS kebijakan yang dikelola: AWSConfigServiceRolePolicy
AWS Config menggunakan peran terkait layanan yang dinamai AWSServiceRoleForConfig untuk memanggil AWS layanan lain atas nama Anda. Saat Anda menggunakan Konsol Manajemen AWS untuk mengatur AWS Config, SLR ini secara otomatis dibuat oleh AWS Config jika Anda memilih opsi untuk menggunakan AWS Config SLR alih-alih peran layanan AWS Identity and Access Management (IAM) Anda sendiri.
AWSServiceRoleForConfigSLR berisi kebijakan AWSConfigServiceRolePolicy terkelola. Kebijakan terkelola ini berisi izin baca saja dan tulis saja untuk AWS Config sumber daya dan izin baca-saja untuk sumber daya di layanan lain yang mendukung. AWS Config Kebijakan ini menyediakan akses komprehensif untuk memantau dan merekam perubahan konfigurasi di seluruh AWS infrastruktur Anda, termasuk izin untuk lebih dari 100 AWS layanan seperti komputasi, penyimpanan, jaringan, keamanan, analitik, dan layanan pembelajaran mesin.
Kebijakan ini mencakup izin untuk kategori layanan berikut:
-
access-analyzer- Memungkinkan kepala sekolah untuk menganalisis pola akses dan mengambil temuan keamanan. -
account— Memungkinkan kepala sekolah untuk mengambil informasi kontak akun. -
acmdanacm-pca- Memungkinkan kepala sekolah untuk mengelola SSL/TLS sertifikat dan otoritas sertifikat pribadi. -
airflow- Memungkinkan kepala sekolah untuk memantau lingkungan Apache Airflow yang dikelola. -
amplifydanamplifyuibuilder- Memungkinkan prinsipal untuk memantau aplikasi web dan komponen UI. -
aoss- Memungkinkan prinsipal untuk memantau koleksi OpenSearch Serverless dan konfigurasi keamanan. -
app-integrations- Memungkinkan prinsipal untuk memantau konfigurasi integrasi aplikasi. -
appconfig- Memungkinkan prinsipal untuk memantau penerapan konfigurasi aplikasi. -
appflow- Memungkinkan prinsipal untuk memantau konfigurasi aliran data antar aplikasi. -
application-autoscalingdanapplication-signals- Memungkinkan kepala sekolah untuk memantau kebijakan penskalaan otomatis dan metrik kinerja aplikasi. -
appmesh- Memungkinkan prinsipal untuk memantau konfigurasi mesh layanan. -
apprunner- Memungkinkan kepala sekolah untuk memantau aplikasi dan layanan web yang dikontainer. -
appstream- Memungkinkan kepala sekolah untuk memantau konfigurasi streaming aplikasi. -
appsync- Memungkinkan prinsipal untuk memantau konfigurasi GraphQL API. -
aps- Memungkinkan kepala sekolah untuk memantau konfigurasi pemantauan Prometheus. -
apptest- Memungkinkan prinsipal untuk memantau konfigurasi pengujian aplikasi. -
arc-zonal-shift- Memungkinkan kepala sekolah untuk memantau konfigurasi pergeseran zonal untuk ketersediaan. -
athena- Memungkinkan kepala sekolah untuk memantau konfigurasi mesin kueri dan katalog data. -
auditmanager- Memungkinkan kepala sekolah untuk memantau audit dan penilaian kepatuhan. -
autoscalingdanautoscaling-plans- Memungkinkan kepala sekolah untuk memantau grup penskalaan otomatis dan rencana penskalaan. -
b2bi- Memungkinkan kepala sekolah untuk memantau konfigurasi integrasi bisnis-ke-bisnis. -
backupdanbackup-gateway- Memungkinkan kepala sekolah untuk memantau kebijakan cadangan dan konfigurasi gateway. -
batch- Memungkinkan kepala sekolah untuk memantau lingkungan komputasi batch dan antrian pekerjaan. -
bcm-data-exports- Memungkinkan kepala sekolah untuk memantau ekspor data penagihan dan manajemen biaya. -
bedrockdanbedrock-agentcore- Memungkinkan kepala sekolah untuk memantau model dasar dan konfigurasi agen AI. -
billingconductor- Memungkinkan kepala sekolah untuk memantau konfigurasi grup penagihan. -
budgets- Memungkinkan kepala sekolah untuk memantau konfigurasi dan tindakan anggaran. -
cassandra- Memungkinkan kepala sekolah untuk menanyakan konfigurasi database Cassandra yang dikelola. -
ce- Memungkinkan prinsipal untuk memantau konfigurasi pelaporan biaya dan penggunaan. -
cleanroomsdancleanrooms-ml- Memungkinkan kepala sekolah untuk memantau kolaborasi data dan konfigurasi pembelajaran mesin. -
cloud9- Memungkinkan kepala sekolah untuk memantau konfigurasi lingkungan pengembangan cloud. -
cloudformation- Memungkinkan prinsipal untuk memantau infrastruktur sebagai konfigurasi tumpukan kode. -
cloudfront- Memungkinkan prinsipal untuk memantau konfigurasi jaringan pengiriman konten. -
cloudtrail- Memungkinkan prinsipal untuk memantau pencatatan API dan konfigurasi jejak audit. -
cloudwatch- Memungkinkan kepala sekolah untuk memantau metrik, alarm, dan konfigurasi dasbor. -
codeartifact- Memungkinkan kepala sekolah untuk memantau konfigurasi repositori paket perangkat lunak. -
codebuild- Memungkinkan kepala sekolah untuk memantau konfigurasi proyek pembangunan. -
codecommit- Memungkinkan prinsipal untuk memantau konfigurasi repositori kode sumber. -
codeconnections- Memungkinkan kepala sekolah untuk memantau koneksi sumber pihak ketiga. -
codedeploy- Memungkinkan prinsipal untuk memantau konfigurasi penerapan aplikasi. -
codeguru-profilerdancodeguru-reviewer- Memungkinkan kepala sekolah untuk memantau analisis kode dan konfigurasi profil. -
codepipeline- Memungkinkan prinsipal untuk memantau integrasi berkelanjutan dan konfigurasi pipa penyebaran. -
codestar-connections- Memungkinkan kepala sekolah untuk memantau koneksi alat pengembang. -
cognito-identitydancognito-idp- Memungkinkan prinsipal untuk memantau identitas dan konfigurasi kumpulan pengguna. -
comprehend- Memungkinkan kepala sekolah untuk memantau konfigurasi pemrosesan bahasa alami. -
config- Memungkinkan kepala sekolah untuk mengelola perekaman konfigurasi dan pemantauan kepatuhan. -
connect- Memungkinkan kepala sekolah untuk memantau konfigurasi pusat kontak.
Untuk informasi selengkapnya tentang jenis sumber daya yang didukung, lihat Jenis Sumber Daya yang Didukung untuk AWS Config danMenggunakan Service-Linked Peran untuk AWS Config.
Untuk melihat detail selengkapnya tentang kebijakan, termasuk versi terbaru dokumen kebijakan JSON, lihat AWSConfigServiceRolePolicy di Panduan Referensi AWS Kebijakan Terkelola.
Direkomendasikan: Gunakan Service-linked peran
Disarankan agar Anda menggunakan peran terkait layanan kecuali Anda memiliki kasus penggunaan tertentu. Peran terkait layanan menambahkan semua izin yang diperlukan AWS Config untuk berjalan seperti yang diharapkan. Beberapa fitur seperti perekam konfigurasi terkait layanan mengharuskan Anda menggunakan peran terkait layanan.
AWS kebijakan yang dikelola: AWS_ ConfigRole
Untuk merekam konfigurasi AWS sumber daya Anda, AWS Config memerlukan izin IAM untuk mendapatkan detail konfigurasi tentang sumber daya Anda. Jika Anda ingin membuat peran IAM untuk AWS Config, Anda dapat menggunakan kebijakan terkelola AWS_ConfigRole dan melampirkannya ke peran IAM Anda.
Kebijakan IAM ini diperbarui setiap kali AWS Config menambahkan dukungan untuk jenis AWS sumber daya. Ini berarti bahwa AWS Config akan terus memiliki izin yang diperlukan untuk merekam data konfigurasi jenis sumber daya yang didukung selama ConfigRole peran AWS_ memiliki kebijakan terkelola ini dilampirkan. Kebijakan ini menyediakan akses komprehensif untuk memantau dan merekam perubahan konfigurasi di seluruh AWS infrastruktur Anda, termasuk izin untuk lebih dari 100 AWS layanan seperti komputasi, penyimpanan, jaringan, keamanan, analitik, dan layanan pembelajaran mesin. Untuk informasi selengkapnya, lihat Jenis Sumber Daya yang Didukung untuk AWS Config dan Izin untuk Peran IAM yang Ditugaskan ke AWS Config.
Untuk melihat detail selengkapnya tentang kebijakan, termasuk versi terbaru dokumen kebijakan JSON, lihat AWS_ ConfigRole di Panduan Referensi Kebijakan Ter AWS kelola.
AWS kebijakan yang dikelola: AWSConfigUserAccess
Kebijakan IAM ini menyediakan akses untuk digunakan AWS Config, termasuk mencari berdasarkan tag pada sumber daya dan membaca semua tag. Ini tidak memberikan izin untuk mengkonfigurasi AWS Config, yang memerlukan hak administratif.
Lihat kebijakan: AWSConfigUserAccess.
AWS kebijakan yang dikelola: ConfigConformsServiceRolePolicy
Untuk menyebarkan dan mengelola paket kesesuaian, AWS Config memerlukan izin IAM dan izin tertentu dari layanan lain. AWS Ini memungkinkan Anda untuk menyebarkan dan mengelola paket kesesuaian dengan fungsionalitas penuh dan diperbarui setiap kali AWS Config menambahkan fungsionalitas baru untuk paket kesesuaian. Untuk informasi selengkapnya tentang paket kesesuaian, lihat paket kesesuaian.
Lihat kebijakan: ConfigConformsServiceRolePolicy.
AWS kebijakan yang dikelola: AWSConfigRulesExecutionRole
Untuk menerapkan A AWS turan Lambda Kustom, AWS Config memerlukan izin IAM dan izin tertentu dari layanan lain AWS . Ini memungkinkan AWS Lambda fungsi untuk mengakses AWS Config API dan snapshot konfigurasi yang dikirimkan secara ber AWS Config kala ke Amazon S3. Akses ini diperlukan oleh fungsi yang mengevaluasi perubahan konfigurasi untuk aturan Lambda K AWS ustom dan diperbarui setiap kali AWS Config menambahkan fungsionalitas baru. Untuk informasi selengkapnya tentang A AWS turan Lambda Kustom, lihat Membuat Aturan Lambda K AWS Config ustom. Untuk informasi selengkapnya tentang snapshot konfigurasi, lihat Kon sep | Cuplikan Konfigurasi. Untuk informasi selengkapnya tentang pengiriman snapshot konfigurasi, lihat M engelola Saluran Pengiriman.
Lihat kebijakan: AWSConfigRulesExecutionRole.
AWS kebijakan yang dikelola: AWSConfigMultiAccountSetupPolicy
Untuk menerapkan, memperbarui, dan menghapus AWS Config aturan dan paket kesesuaian secara terpusat di seluruh akun anggota dalam organisasi di AWS Organizations, AWS Config memerlukan izin IAM dan izin tertentu dari layanan lain. AWS Kebijakan terkelola ini diperbarui setiap kali AWS Config menambahkan fungsionalitas baru untuk penyiapan multi-akun. Untuk informasi selengkapnya, lihat M engel AWS Config ola Aturan di Semua Akun di Organisasi Anda dan M engelola Paket Kesesuaian di Semua Akun di Organisasi Anda.
Lihat kebijakan: AWSConfigMultiAccountSetupPolicy.
AWS kebijakan yang dikelola: AWSConfigRoleForOrganizations
Untuk mengiz AWS Config inkan memanggil AWS Organizations API read-only, AWS Config memerlukan izin IAM dan izin tertentu dari layanan lain. AWS Kebijakan terkelola ini diperbarui setiap kali AWS Config menambahkan fungsionalitas baru untuk penyiapan multi-akun. Untuk informasi selengkapnya, lihat M engel AWS Config ola Aturan di Semua Akun di Organisasi Anda dan M engelola Paket Kesesuaian di Semua Akun di Organisasi Anda.
Lihat kebijakan: AWSConfigRoleForOrganizations.
AWS kebijakan yang dikelola: AWSConfigRemediationServiceRolePolicy
AWS Config Untuk mengizinkan perbaikan sumber NON_COMPLIANT daya atas nama Anda, AWS Config
memerlukan izin IAM dan izin tertentu dari layanan lain AWS . Kebijakan terkelola ini diperbarui setiap kali AWS Config menambahkan fungsionalitas baru untuk remediasi. Untuk informasi selengkapnya tentang remediasi, lihat Memperbaiki Sumber Daya yang Tidak Sesuai dengan Aturan. AWS Config Untuk informasi lebih lanjut tentang kondisi yang memulai kemungkinan hasil AWS Config evaluasi, lihat Kon sep | A AWS Config turan.
Lihat kebijakan: AWSConfigRemediationServiceRolePolicy.
AWS Config update ke AWS kebijakan terkelola
Lihat detail tentang pembaruan kebijakan AWS terkelola AWS Config sejak layanan ini mulai melacak perubahan ini. Untuk peringatan otomatis tentang perubahan pada halaman ini, berlangganan umpan RSS di halaman AWS Config riwayat dokumen.
| Ubah | Deskripsi | Date |
|---|---|---|
|
AWSConfigServiceRolePolicy— Izin tambahan: access-analyzer:, access-analyzer:CheckNoPublicAccess, bedrock:, bedrock-agentcore:ValidatePolicy, bedrock-agentcore:ListEnforcedGuardrailsConfiguration, bedrock-agentcore:, bedrock-agentcore:GetPaymentManager, bedrock-agentcore:GetPolicyEngineSummary, bedrock-agentcore:, notifikasi:, notifikasi:, nova-act:GetPolicySummary, nova-act:, s3vector:ListPaymentManagers, s3vector:, sagemaker:, sagemaker:, sagemaker:ListPolicyEngineSummaries, sagemaker:, tukang sihir:ListPolicySummaries, pembuat saji:, ListNotificationConfigurations ListTagsForResource GetWorkflowDefinition ListWorkflowDefinitions GetIndex ListIndexes DescribeAlgorithm DescribeClusterSchedulerConfig DescribeFlowDefinition DescribeHumanTaskUi pembuat sagak:DescribeLabelingJob, pembuat sagak:, pembuat sag DescribeMlflowApp ak:, pembuat sagak:DescribeOptimizationJob, pembuat sagak:DescribeTrainingJob, pembuat sagak:, pembuat sagak:ListAlgorithms, pembuat sagak:ListClusterSchedulerConfigs, pembuat sagak:ListFlowDefinitions, pembuat sagak:, pembuat sag ListHumanTaskUis ak:, pembuat sagak:ListLabelingJobs. ListMlflowApps ListOptimizationJobs ListTrainingJobs |
Kebijakan ini sekarang mendukung izin tambahan untuk merekam perubahan konfigurasi di berbagai AWS layanan. |
Agustus 1, 2026 |
|
AWS_ConfigRole— Izin tambahan: access-analyzer:, access-analyzer:CheckNoPublicAccess, bedrock:, bedrock-agentcore:ValidatePolicy, bedrock-agentcore:ListEnforcedGuardrailsConfiguration, bedrock-agentcore:, bedrock-agentcore:GetPaymentManager, bedrock-agentcore:GetPolicyEngineSummary, bedrock-agentcore:, notifikasi:, notifikasi:, nova-act:GetPolicySummary, nova-act:, s3vector:ListPaymentManagers, s3vector:, sagemaker:, sagemaker:, sagemaker:ListPolicyEngineSummaries, sagemaker:, tukang sihir:ListPolicySummaries, pembuat saji:, ListNotificationConfigurations ListTagsForResource GetWorkflowDefinition ListWorkflowDefinitions GetIndex ListIndexes DescribeAlgorithm DescribeClusterSchedulerConfig DescribeFlowDefinition DescribeHumanTaskUi pembuat sagak:DescribeLabelingJob, pembuat sagak:, pembuat sag DescribeMlflowApp ak:, pembuat sagak:DescribeOptimizationJob, pembuat sagak:DescribeTrainingJob, pembuat sagak:, pembuat sagak:ListAlgorithms, pembuat sagak:ListClusterSchedulerConfigs, pembuat sagak:ListFlowDefinitions, pembuat sagak:, pembuat sag ListHumanTaskUis ak:, pembuat sagak:ListLabelingJobs. ListMlflowApps ListOptimizationJobs ListTrainingJobs |
Kebijakan ini sekarang mendukung izin tambahan untuk merekam perubahan konfigurasi di berbagai AWS layanan. |
Agustus 1, 2026 |
|
AWSConfigServiceRolePolicy— Izin tambahan: batuan dasar:, batuan dasar:GetAutomatedReasoningPolicy, batuan dasar:GetBlueprint, batuan dasar:GetFoundationModel, batuan dasar:, batuan dasar:GetPromptRouter, batuan dasar:ListAutomatedReasoningPolicies, bedrock-agentcore:ListBlueprints, bedrock-agentcore:ListFoundationModels, bedrock-agentcore:, bedrock-agentcore:GetApiKeyCredentialProvider, bedrock-agentcore:GetOauth2CredentialProvider, cloudtrail:, cloudwatch:, connect:, dynamodcore:GetPolicy, connect:, dynamodcore b:GetTokenVault, dinamodb:, dinamodb:, ListApiKeyCredentialProviders ListOauth2CredentialProviders ListPolicies GetTrail ListManagedInsightRules ListQueueEmailAddresses DescribeContributorInsights DescribeKinesisStreamingDestination GetResourcePolicy elasticloadbalancing:DescribeCapacityReservation, lambda:, lambda:, pengelola lisensi:GetFunctionRecursionConfig, pergeseran merah:, pergeseran merah:GetFunctionScalingConfig, s3:, s3:, s3express:ListTagsForResource, sagemaker:, sagemaker:DescribeClusterDbRevisions, sagemaker:, sagemaker:DescribeSnapshotCopyGrants, sagemaker:, sagemaker:GetBucketMetadataTableConfiguration, sagemaker:GetBucketOwnershipControls, sagemaker:, sagemaker:, sagemaker:GetMetricsConfiguration, sagemaker:, sagemaker:DescribeAction, sagemaker:, sagemaker:DescribeArtifact, sagemaker:, sagemaker:DescribeAutoMLJob, sagemaker:, sagemaker:, sagemaker:DescribeContext, sagemaker:, sagemaker:DescribeExperiment, sagemaker:, sagemaker:DescribeHub, sagemaker:, sagemaker:DescribeModelCardExportJob, sagemaker:, sagemaker:DescribeTrial, sagemaker:, sagemaker:, pembuat:DescribeTrialComponent, DescribeWorkforce ListActions ListArtifacts ListContexts ListExperiments ListHubs pembuat sagak:ListModelCardExportJobs, pembuat sagak:, pembuat sa ListMonitoringAlerts ji:, pembuat sagak:ListTrialComponents, pembuat sagak:ListTrials. ListWorkforces |
Kebijakan ini sekarang mendukung izin tambahan untuk merekam perubahan konfigurasi di berbagai AWS layanan. |
5 Mei 2026 |
|
AWS_ConfigRole— Izin tambahan: batuan dasar:, batuan dasar:GetAutomatedReasoningPolicy, batuan dasar:GetBlueprint, batuan dasar:GetFoundationModel, batuan dasar:, batuan dasar:GetPromptRouter, batuan dasar:ListAutomatedReasoningPolicies, bedrock-agentcore:ListBlueprints, bedrock-agentcore:ListFoundationModels, bedrock-agentcore:, bedrock-agentcore:GetApiKeyCredentialProvider, bedrock-agentcore:GetOauth2CredentialProvider, cloudtrail:, cloudwatch:, connect:, dynamodcore:GetPolicy, connect:, dynamodcore b:GetTokenVault, dinamodb:, dinamodb:, ListApiKeyCredentialProviders ListOauth2CredentialProviders ListPolicies GetTrail ListManagedInsightRules ListQueueEmailAddresses DescribeContributorInsights DescribeKinesisStreamingDestination GetResourcePolicy elasticloadbalancing:DescribeCapacityReservation, lambda:, lambda:, pengelola lisensi:GetFunctionRecursionConfig, pergeseran merah:, pergeseran merah:GetFunctionScalingConfig, s3:, s3:, s3express:ListTagsForResource, sagemaker:, sagemaker:DescribeClusterDbRevisions, sagemaker:, sagemaker:DescribeSnapshotCopyGrants, sagemaker:, sagemaker:GetBucketMetadataTableConfiguration, sagemaker:GetBucketOwnershipControls, sagemaker:, sagemaker:, sagemaker:GetMetricsConfiguration, sagemaker:, sagemaker:DescribeAction, sagemaker:, sagemaker:DescribeArtifact, sagemaker:, sagemaker:DescribeAutoMLJob, sagemaker:, sagemaker:, sagemaker:DescribeContext, sagemaker:, sagemaker:DescribeExperiment, sagemaker:, sagemaker:DescribeHub, sagemaker:, sagemaker:DescribeModelCardExportJob, sagemaker:, sagemaker:DescribeTrial, sagemaker:, sagemaker:, pembuat:DescribeTrialComponent, DescribeWorkforce ListActions ListArtifacts ListContexts ListExperiments ListHubs pembuat sagak:ListModelCardExportJobs, pembuat sagak:, pembuat sa ListMonitoringAlerts ji:, pembuat sagak:ListTrialComponents, pembuat sagak:ListTrials. ListWorkforces |
Kebijakan ini sekarang mendukung izin tambahan untuk merekam perubahan konfigurasi di berbagai AWS layanan. |
5 Mei 2026 |
|
AWSConfigServiceRolePolicy— Menambahkan izin: auditmanager:, auditmanager:GetAssessmentFramework, auditmanager:GetControl, auditmanager:, bcm-dashboards:ListAssessmentFrameworks, bcm-dasbor:ListControls, bcm-dasbor:, bedrock:GetDashboard, bedrock-agentcore:ListDashboards, bedrock-agentcore:, bedrock-agentcore:ListTagsForResource, bedrock-agentcore: GetEvaluationJobListEvaluationJobs, bedrock-agentcore:, bedrockagent-core:GetEvaluator, chime::, lonceng:GetOnlineEvaluationConfig, dms:, emr- GetPolicyEngine ListEvaluators ListOnlineEvaluationConfigs ListPolicyEngines DescribeAppInstance ListAppInstances ListTagsForResource ListInstanceProfiles wadah:DescribeManagedEndpoint, emr-kontainer:ListTagsForResource, gameliftstreams:, gameliftstreams:GetApplication, gameliftstreams:, gameliftstreams:GetStreamGroup, gameliftstreams:ListApplications, globalaccelerator:, lem:, lem:, lem:ListStreamGroups, lambda:, medialive:ListTagsForResource, medialive:DescribeAcceleratorAttributes, mediapackagev2:GetCatalog, mediapackagev2:GetSession, pos terdepan:ListSessions, pos terdepan:, qbusiness:ListCapacityProviders, pergeseran merah:DescribeNode, rtbfabric:ListNodes, rtbfabric: GetCatalogs GetChannelPolicy GetOriginEndpointPolicy GetSite ListSites GetPolicy DescribeDataShares GetInboundExternalLink GetLink, rtbfabric:, rtbfabric:, rtbfabric:GetOutboundExternalLink, rtbfabric:, rtbfabric:, rtbfabric:GetRequesterGateway, rtbfabric:, s3express:, s3express:GetResponderGateway, s3express:, s3express:, s3express:ListLinks, s3vektor:, s3vektor:, s3vektor:ListRequesterGateways, s3vektor:, sagemaker:, sagemaker:ListResponderGateways, sagemaker:, sagemaker:, sagemaker:, sagemaker:ListTagsForResource, sagemaker:, sagemaker:, sagemaker:, sagemaker:GetAccessPoint, sagemaker:, sagemaker:, sagemaker:GetAccessPointPolicy, sagemaker:, sagemaker:, sagemaker:, sagemaker:GetAccessPointScope, sagemaker:, sagemaker:, sagemaker:, sagemaker:ListAccessPointsForDirectoryBuckets, sagemaker:, sagemaker:, sagemaker:, sagemaker:ListTagsForResource, sagemaker:, sagemaker:, sagemaker pembuat:GetVectorBucket, pembuat sagak:, pembuat sagak:, katalog layanan:GetVectorBucketPolicy, ListTagsForResource ListVectorBuckets DescribeAutoMLJobV2 DescribeHyperParameterTuningJob DescribePartnerApp ListAutoMLJobs ListHyperParameterTuningJobs ListPartnerApps DescribeTagOption servicecatalog:ListTagOptions, ssm-kontak:, ssm-kontak:GetRotation, ssm-guiconnect:, sso:ListRotations, sso:, textract:, textract:GetConnectionRecordingPreferences, teks:, transfer:, transfer:GetPermissionsBoundaryForPermissionSet, transfer:ListCustomerManagedPolicyReferencesInPermissionSet, kebijaksanaan:getaiGuardrailGetAdapter, kebijaksanaan:List ListAdapters aiGuardrails. ListTagsForResource DescribeWebApp DescribeWebAppCustomization ListWebApps |
Kebijakan ini sekarang mendukung izin tambahan untuk merekam perubahan konfigurasi di berbagai AWS layanan. |
Maret 10, 2026 |
|
AWS_ConfigRole— Menambahkan izin: auditmanager:, auditmanager:GetAssessmentFramework, auditmanager:GetControl, auditmanager:, bcm-dashboards:ListAssessmentFrameworks, bcm-dasbor:ListControls, bcm-dasbor:, bedrock:GetDashboard, bedrock-agentcore:ListDashboards, bedrock-agentcore:, bedrock-agentcore:ListTagsForResource, bedrock-agentcore: GetEvaluationJobListEvaluationJobs, bedrock-agentcore:, bedrockagent-core:GetEvaluator, chime::, lonceng:GetOnlineEvaluationConfig, dms:, emr- GetPolicyEngine ListEvaluators ListOnlineEvaluationConfigs ListPolicyEngines DescribeAppInstance ListAppInstances ListTagsForResource ListInstanceProfiles wadah:DescribeManagedEndpoint, emr-kontainer:ListTagsForResource, gameliftstreams:, gameliftstreams:GetApplication, gameliftstreams:, gameliftstreams:GetStreamGroup, gameliftstreams:ListApplications, globalaccelerator:, lem:, lem:, lem:ListStreamGroups, lambda:, medialive:ListTagsForResource, medialive:DescribeAcceleratorAttributes, mediapackagev2:GetCatalog, mediapackagev2:GetSession, pos terdepan:ListSessions, pos terdepan:, qbusiness:ListCapacityProviders, pergeseran merah:DescribeNode, rtbfabric:ListNodes, rtbfabric: GetCatalogs GetChannelPolicy GetOriginEndpointPolicy GetSite ListSites GetPolicy DescribeDataShares GetInboundExternalLink GetLink, rtbfabric:, rtbfabric:, rtbfabric:GetOutboundExternalLink, rtbfabric:, rtbfabric:, rtbfabric:GetRequesterGateway, rtbfabric:, s3express:, s3express:GetResponderGateway, s3express:, s3express:, s3express:ListLinks, s3vektor:, s3vektor:, s3vektor:ListRequesterGateways, s3vektor:, sagemaker:, sagemaker:ListResponderGateways, sagemaker:, sagemaker:, sagemaker:, sagemaker:ListTagsForResource, sagemaker:, sagemaker:, sagemaker:, sagemaker:GetAccessPoint, sagemaker:, sagemaker:, sagemaker:GetAccessPointPolicy, sagemaker:, sagemaker:, sagemaker:, sagemaker:GetAccessPointScope, sagemaker:, sagemaker:, sagemaker:, sagemaker:ListAccessPointsForDirectoryBuckets, sagemaker:, sagemaker:, sagemaker:, sagemaker:ListTagsForResource, sagemaker:, sagemaker:, sagemaker pembuat:GetVectorBucket, pembuat sagak:, pembuat sagak:, katalog layanan:GetVectorBucketPolicy, ListTagsForResource ListVectorBuckets DescribeAutoMLJobV2 DescribeHyperParameterTuningJob DescribePartnerApp ListAutoMLJobs ListHyperParameterTuningJobs ListPartnerApps DescribeTagOption servicecatalog:ListTagOptions, ssm-kontak:, ssm-kontak:GetRotation, ssm-guiconnect:, sso:ListRotations, sso:, textract:, textract:GetConnectionRecordingPreferences, teks:, transfer:, transfer:GetPermissionsBoundaryForPermissionSet, transfer:ListCustomerManagedPolicyReferencesInPermissionSet, kebijaksanaan:getaiGuardrailGetAdapter, kebijaksanaan:List ListAdapters aiGuardrails. ListTagsForResource DescribeWebApp DescribeWebAppCustomization ListWebApps |
Kebijakan ini sekarang mendukung izin tambahan untuk merekam perubahan konfigurasi di berbagai AWS layanan. |
Maret 10, 2026 |
|
AWSConfigServiceRolePolicy- Menambahkan izin: application-autoscaling:DescribeScheduledActions, appsync:, cloudformation:, cloudformation:GetApiAssociation, cloudformation:DescribeStacks, cloudfront:, cloudfront:GetStackPolicy, cloudfront:GetTemplate, connect:, cur:GetKeyGroup, cur:, datazone:GetMonitoringSubscription, datazone:ListKeyGroups, datazone:ListEvaluationFormVersions, datazone:DescribeReportDefinitions, datazone:ListTagsForResource, datazone:GetDomainUnit, datazone:, datazone:GetEnvironmentAction, datazone:GetEnvironmentBlueprintConfiguration, datazone:, datazone one:GetEnvironmentProfile, data zone: GetGroupProfile GetSubscriptionTarget GetUserProfile ListDomainUnitsForParent ListEntityOwners ListEnvironmentActions ListEnvironmentBlueprintConfigurations, zona data:, zona data:, zona data:, zona data:ListEnvironmentProfiles, zona data:, zona data:, docdb-elastic:ListPolicyGrants, docdb-elastic:, docdb-elastic:, ec2:ListProjectMemberships, ec2:, ec2:, ec2:, fis:ListSubscriptionTargets, penipuan:, penipuan:, guardduty:SearchGroupProfiles, guardduty:, guardduty:, guardduty:SearchUserProfiles, guardduty:, guardduty:, guardduty:, guardduty:GetCluster, guardduty:, guardduty:, guardduty:, guardduty:ListClusters, guardduty:, guardduty:, guardduty:ListTagsForResource, guardduty:, guardduty:, guardduty:GetRouteServerAssociations, guardduty:, guardduty:GetRouteServerPropagations, guardduty:, guardduty:, guardduty:SearchTransitGatewayRoutes, guardduty: fleetwise:ListTagsForResource, iotfleetwise:, iotsitewise:GetListElements, iotsitewise:, GetListsMetadata GetThreatEntitySet GetTrustedEntitySet ListThreatEntitySets ListTrustedEntitySets GetCampaign ListCampaigns DescribeComputationModel DescribeDataset iotsitewise:ListComputationModels, iotsitewise:ListDatasets, iotwireless:, iotwireless:GetWirelessDeviceImportTask, kendra:, log:ListWirelessDeviceImportTasks, log:ListDataSources, log:, mediaconnect:GetIntegration, medialive:ListIntegrations, medialive:, medialive:ListRouterOutputs, medialive:DescribeMultiplex, medialive:, medialive:DescribeSdiSource, medialive:GetCloudWatchAlarmTemplate, medialive:GetCloudWatchAlarmTemplateGroup, medialive:GetEventBridgeRuleTemplate, medialive:, manajer jaringan:GetEventBridgeRuleTemplateGroup, manajer jaringan:ListCloudWatchAlarmTemplateGroups,:, manajer jaringan: DescribeQueryDefinitions ListCloudWatchAlarmTemplates ListEventBridgeRuleTemplateGroups ListEventBridgeRuleTemplates ListSdiSources ListSignalMaps GetConnectAttachment GetCoreNetwork GetCoreNetworkPolicy, networkmanager:, networkmanager:GetDirectConnectGatewayAttachment, networkmanager:GetSiteToSiteVpnAttachment, networkmanager:, notifikasi:ListAttachments, notifikasi:, pemberitahuan:ListCoreNetworks, pemberitahuan:, pemberitahuan:GetEventRule, refactor-space:ListEventRules, refactor-space:ListManagedNotificationChannelAssociations, refactor-space:ListNotificationHubs, resource-explorer-2:ListOrganizationalUnits, route53resolver:GetApplication, route53resolver:, securityhub:GetRoute, securityhub: V2, securityhub:ListRoutes, securityhub:, securityhub:GetDefaultView, securityhub:, GetOutpostResolver ListOutpostResolvers DescribeOrganizationConfiguration GetAggregator GetAutomationRuleV2 GetConfigurationPolicyAssociation securityhub:GetFindingAggregator, securityhub: ListAggregators V2, securityhub:, securityhub:, securityhub:ListAutomationRulesV2, sms-suara:, sms-suara:ListConfigurationPolicyAssociations, sms-suara:, sms-suara:ListFindingAggregators, sms-suara:DescribeConfigurationSets, sms-suara:, ruang kerja-web:DescribeKeywords, ruang kerja-web:DescribeProtectConfigurations, ruang kerja-web:, ruang kerja-web:GetProtectConfigurationCountryRuleSet. ListPoolOriginationIdentities ListTagsForResource GetTrustStore GetTrustStoreCertificate GetUserAccessLoggingSettings ListTagsForResource |
Kebijakan ini sekarang mendukung izin tambahan untuk merekam perubahan konfigurasi di berbagai AWS layanan. |
Februari 17, 2026 |
|
AWS_ConfigRole- Menambahkan izin: application-autoscaling:DescribeScheduledActions, appsync:, cloudformation:, cloudformation:GetApiAssociation, cloudformation:DescribeStacks, cloudfront:, cloudfront:GetStackPolicy, cloudfront:GetTemplate, connect:, cur:GetKeyGroup, cur:, datazone:GetMonitoringSubscription, datazone:ListKeyGroups, datazone:ListEvaluationFormVersions, datazone:DescribeReportDefinitions, datazone:ListTagsForResource, datazone:GetDomainUnit, datazone:, datazone:GetEnvironmentAction, datazone:GetEnvironmentBlueprintConfiguration, datazone:, datazone one:GetEnvironmentProfile, data zone: GetGroupProfile GetSubscriptionTarget GetUserProfile ListDomainUnitsForParent ListEntityOwners ListEnvironmentActions ListEnvironmentBlueprintConfigurations, zona data:, zona data:, zona data:, zona data:ListEnvironmentProfiles, zona data:, zona data:, docdb-elastic:ListPolicyGrants, docdb-elastic:, docdb-elastic:, ec2:ListProjectMemberships, ec2:, ec2:, ec2:, fis:ListSubscriptionTargets, penipuan:, penipuan:, guardduty:SearchGroupProfiles, guardduty:, guardduty:, guardduty:SearchUserProfiles, guardduty:, guardduty:, guardduty:, guardduty:GetCluster, guardduty:, guardduty:, guardduty:, guardduty:ListClusters, guardduty:, guardduty:, guardduty:ListTagsForResource, guardduty:, guardduty:, guardduty:GetRouteServerAssociations, guardduty:, guardduty:GetRouteServerPropagations, guardduty:, guardduty:, guardduty:SearchTransitGatewayRoutes, guardduty: fleetwise:ListTagsForResource, iotfleetwise:, iotsitewise:GetListElements, iotsitewise:, GetListsMetadata GetThreatEntitySet GetTrustedEntitySet ListThreatEntitySets ListTrustedEntitySets GetCampaign ListCampaigns DescribeComputationModel DescribeDataset iotsitewise:ListComputationModels, iotsitewise:ListDatasets, iotwireless:, iotwireless:GetWirelessDeviceImportTask, kendra:, log:ListWirelessDeviceImportTasks, log:ListDataSources, log:, mediaconnect:GetIntegration, medialive:ListIntegrations, medialive:, medialive:ListRouterOutputs, medialive:DescribeMultiplex, medialive:, medialive:DescribeSdiSource, medialive:GetCloudWatchAlarmTemplate, medialive:GetCloudWatchAlarmTemplateGroup, medialive:GetEventBridgeRuleTemplate, medialive:, manajer jaringan:GetEventBridgeRuleTemplateGroup, manajer jaringan:ListCloudWatchAlarmTemplateGroups,:, manajer jaringan: DescribeQueryDefinitions ListCloudWatchAlarmTemplates ListEventBridgeRuleTemplateGroups ListEventBridgeRuleTemplates ListSdiSources ListSignalMaps GetConnectAttachment GetCoreNetwork GetCoreNetworkPolicy, networkmanager:, networkmanager:GetDirectConnectGatewayAttachment, networkmanager:GetSiteToSiteVpnAttachment, networkmanager:, notifikasi:ListAttachments, notifikasi:, pemberitahuan:ListCoreNetworks, pemberitahuan:, pemberitahuan:GetEventRule, refactor-space:ListEventRules, refactor-space:ListManagedNotificationChannelAssociations, refactor-space:ListNotificationHubs, resource-explorer-2:ListOrganizationalUnits, route53resolver:GetApplication, route53resolver:, securityhub:GetRoute, securityhub: V2, securityhub:ListRoutes, securityhub:, securityhub:GetDefaultView, securityhub:, GetOutpostResolver ListOutpostResolvers DescribeOrganizationConfiguration GetAggregator GetAutomationRuleV2 GetConfigurationPolicyAssociation securityhub:GetFindingAggregator, securityhub: ListAggregators V2, securityhub:, securityhub:, securityhub:ListAutomationRulesV2, sms-suara:, sms-suara:ListConfigurationPolicyAssociations, sms-suara:, sms-suara:ListFindingAggregators, sms-suara:DescribeConfigurationSets, sms-suara:, ruang kerja-web:DescribeKeywords, ruang kerja-web:DescribeProtectConfigurations, ruang kerja-web:, ruang kerja-web:GetProtectConfigurationCountryRuleSet. ListPoolOriginationIdentities ListTagsForResource GetTrustStore GetTrustStoreCertificate GetUserAccessLoggingSettings ListTagsForResource |
Kebijakan ini sekarang mendukung izin tambahan untuk merekam perubahan konfigurasi di berbagai AWS layanan. |
Februari 17, 2026 |
|
AWSConfigServiceRolePolicyKebijakan terkelola yang diperbarui dengan izin komprehensif untuk perekaman konfigurasi AWS sumber daya di lebih dari 100 AWS layanan termasuk komputasi, penyimpanan, jaringan, keamanan, analitik, dan layanan pembelajaran mesin. |
Kebijakan ini sekarang menyediakan dokumentasi izin layanan yang disempurnakan dan mendukung pemantauan komprehensif di semua AWS layanan yang AWS Config mendukung perekaman konfigurasi. |
Januari 27, 2026 |
|
AWS_ConfigRoleKebijakan terkelola yang diperbarui dengan izin komprehensif untuk perekaman konfigurasi AWS sumber daya di lebih dari 100 AWS layanan termasuk komputasi, penyimpanan, jaringan, keamanan, analitik, dan layanan pembelajaran mesin. |
Kebijakan ini sekarang menyediakan dokumentasi izin layanan yang disempurnakan dan mendukung pemantauan komprehensif di semua AWS layanan yang AWS Config mendukung perekaman konfigurasi. |
Januari 27, 2026 |
|
AWS_ConfigRole— tambahkan “s3tables: ListTagsForResource “, “s3tables: “, “s3 GetTableBucketMetricsConfiguration tables:” GetTableBucketStorageClass |
Kebijakan ini sekarang mendukung izin tambahan untuk S3Tables.. |
Januari 09, 2026 |
|
AWSConfigServiceRolePolicy— tambahkan “s3tables: ListTagsForResource “, “s3tables: “, “s3 GetTableBucketMetricsConfiguration tables:” GetTableBucketStorageClass |
Kebijakan ini sekarang mendukung izin tambahan untuk S3Tables. |
Januari 09, 2026 |
|
AWS_ConfigRole— tambahkan “lightsail:GetActiveNames" “lightsail:GetOperations" “s3:” GetBucketAbac |
Kebijakan ini sekarang mendukung izin tambahan untuk Amazon Lightsail dan Amazon Simple Storage Service (Amazon S3). |
20 November 2025 |
|
AWSConfigServiceRolePolicy— tambahkan “lightsail:GetActiveNames" “lightsail:GetOperations" “s3:” GetBucketAbac |
Kebijakan ini sekarang mendukung izin tambahan untuk Amazon Lightsail dan Amazon Simple Storage Service (Amazon S3). |
20 November 2025 |
|
AWSConfigServiceRolePolicyKebijakan terkelola yang diperbarui dengan izin komprehensif untuk perekaman konfigurasi AWS sumber daya di lebih dari 100 AWS layanan termasuk komputasi, penyimpanan, jaringan, keamanan, analitik, dan layanan pembelajaran mesin. |
Kebijakan ini sekarang menyediakan dokumentasi izin layanan yang disempurnakan dan mendukung pemantauan komprehensif di semua AWS layanan yang AWS Config mendukung perekaman konfigurasi. |
November 11, 2025 |
|
AWS_ConfigRole— Kebijakan terkelola yang diperbarui dengan izin komprehensif untuk perekaman konfigurasi AWS sumber daya di beberapa layanan termasuk AWS Identity and Access Management, Amazon Elastic Compute Cloud, Amazon Simple Storage Service, AWS Lambda, Amazon Relational Database Service, dan banyak lainnya. |
Kebijakan ini sekarang mendukung izin tambahan untuk perekaman dan pemantauan konfigurasi AWS sumber daya yang komprehensif di semua AWS layanan yang didukung. |
November 10, 2025 |
|
AWS_ConfigRole— tambahkan “amplify:GetDomainAssociation" “amplify:ListDomainAssociations" “amplify:" “appsync:ListTagsForResource" “appsync:GetSourceApiAssociation" “bedrock:ListSourceApiAssociations" “bedrock:GetFlow" “batuan dasar:ListAgentCollaborators" “batuan dasar:ListFlows" “cloudTrail:GetResourcePolicy" “cloudformation:ListPrompts" “codeartefact:DescribePublisher" “codeartefact:DescribePackageGroup" “codepipeline:" “codepipeline:ListAllowedRepositoriesForGroup" “connect:" “connect:ListPackageGroups" “:ListActionTypes" “batas waktu:ListTagsForResource" “ec2:" “ec2:ListWebhooks" “ec DescribeTrafficDistributionGroup ListTrafficDistributionGroups ListFarms GetTransitGatewayRouteTablePropagations SearchLocalGatewayRoutes 2: SearchTransitGatewayMulticastGroups "“entityresolution:GetMatchingWorkflow" “entityresolution:" “iotsitewise:ListMatchingWorkflows" “iotsitewise:ListAssetModelCompositeModels" “iotsitewise:ListAssetModelProperties" “iotsitewise:" “ivs:ListAssetProperties" “lambda:" “lambda:ListAssociatedAssets" “lambda:" “pipa:ListPublicKeys" “quicksight:GetProvisionedConcurrencyConfig" “quicksight:GetRuntimeManagementConfig" “redshift-serverless:ListFunctionEventInvokeConfigs" “redshift-serverless:ListFunctionUrlConfigs" “redshift:DescribePipe" “rolesanywhere:ListPipes" “rolesanywhere:DescribeRefreshSchedule" “sagemaker:" “sagemaker:ListRefreshSchedules" “sagemaker: ListSnapshotCopyConfigurations GetResourcePolicy GetCrl ListCrls DescribeApp DescribeUserProfile ListAppssagemaker: "“sagemaker:ListModelPackages" “secretsmanager:ListUserProfiles" “securitylake:" “securitylake:GetResourcePolicy" “servicecatalog:ListSubscribers" “servicecatalog:" “servicecatalog:ListTagsForResource" “perisai:" “insiden ssm-:DescribeServiceAction" “ssm:" “ssm:ListApplications" “ssm:ListAssociatedResources" “ssm:" “ssm:ListProtectionGroups" “ssm:ListTagsForResource" “ssm:" “ssm:GetReplicationSet" “ssm:" “ssm:ListReplicationSets" “ssm:DescribeAssociation" “ssm:" “wafv2:DescribePatchBaselines" “bedrock-agentcore:GetDefaultPatchBaseline" “bedrock-agentcore:GetPatchBaseline" “batuan dasar GetResourcePolicies ListAssociations ListResourceDataSync ListLoggingConfigurations ListCodeInterpreters GetCodeInterpreter -agentcore: ListBrowsers "“bedrock-agentcore:" “bedrock-agentcore:GetBrowser" “bedrock-agentcore:" “bedrock-agentcore:ListAgentRuntimes" “bedrock-agentcore:” GetAgentRuntime ListAgentRuntimeEndpoints GetAgentRuntimeEndpoint |
Kebijakan ini sekarang mendukung izin tambahan untuk AWS Amplify, AWS AppSync, Amazon Bedrock,,, AWS CloudTrail CloudFormation AWS CodeArtifact, Connect Customer AWS CodePipeline,, Amazon EC2 AWS Deadline Cloud,,, Amazon IVS Resolusi Entitas AWS AWS IoT SiteWise,, Amazon Quick AWS Lambda, Amazon Redshift EventBridge, Amazon Redshift, Amazon Redshift Serverless,, Amazon, AWS Identity and Access Management Roles Anywhere, Amazon Security Lake SageMaker, AWS Secrets Manager, Amazon EC2 Systems Manager AWS Service Catalog AWS Shield, dan. AWS WAFV2 |
Oktober 1, 2025 |
|
AWSConfigServiceRolePolicy— tambahkan “amplify:GetDomainAssociation" “amplify:ListDomainAssociations" “amplify:" “appsync:ListTagsForResource" “appsync:GetSourceApiAssociation" “bedrock:ListSourceApiAssociations" “bedrock:GetFlow" “batuan dasar:ListAgentCollaborators" “batuan dasar:ListFlows" “cloudTrail:GetResourcePolicy" “cloudformation:ListPrompts" “codeartefact:DescribePublisher" “codeartefact:DescribePackageGroup" “codepipeline:" “codepipeline:ListAllowedRepositoriesForGroup" “connect:" “connect:ListPackageGroups" “:ListActionTypes" “batas waktu:ListTagsForResource" “ec2:" “ec2:ListWebhooks" “ec DescribeTrafficDistributionGroup ListTrafficDistributionGroups ListFarms GetTransitGatewayRouteTablePropagations SearchLocalGatewayRoutes 2: SearchTransitGatewayMulticastGroups "“entityresolution:GetMatchingWorkflow" “entityresolution:" “iotsitewise:ListMatchingWorkflows" “iotsitewise:ListAssetModelCompositeModels" “iotsitewise:ListAssetModelProperties" “iotsitewise:" “ivs:ListAssetProperties" “lambda:" “lambda:ListAssociatedAssets" “lambda:" “pipa:ListPublicKeys" “quicksight:GetProvisionedConcurrencyConfig" “quicksight:GetRuntimeManagementConfig" “redshift-serverless:ListFunctionEventInvokeConfigs" “redshift-serverless:ListFunctionUrlConfigs" “redshift:DescribePipe" “rolesanywhere:ListPipes" “rolesanywhere:DescribeRefreshSchedule" “sagemaker:" “sagemaker:ListRefreshSchedules" “sagemaker: ListSnapshotCopyConfigurations GetResourcePolicy GetCrl ListCrls DescribeApp DescribeUserProfile ListAppssagemaker: "“sagemaker:ListModelPackages" “secretsmanager:ListUserProfiles" “securitylake:" “securitylake:GetResourcePolicy" “servicecatalog:ListSubscribers" “servicecatalog:" “servicecatalog:ListTagsForResource" “perisai:" “insiden ssm-:DescribeServiceAction" “ssm:" “ssm:ListApplications" “ssm:ListAssociatedResources" “ssm:" “ssm:ListProtectionGroups" “ssm:ListTagsForResource" “ssm:" “ssm:GetReplicationSet" “ssm:" “ssm:ListReplicationSets" “ssm:DescribeAssociation" “ssm:" “wafv2:DescribePatchBaselines" “bedrock-agentcore:GetDefaultPatchBaseline" “bedrock-agentcore:GetPatchBaseline" “batuan dasar GetResourcePolicies ListAssociations ListResourceDataSync ListLoggingConfigurations ListCodeInterpreters GetCodeInterpreter -agentcore: ListBrowsers "“bedrock-agentcore:" “bedrock-agentcore:GetBrowser" “bedrock-agentcore:" “bedrock-agentcore:ListAgentRuntimes" “bedrock-agentcore:” GetAgentRuntime ListAgentRuntimeEndpoints GetAgentRuntimeEndpoint |
Kebijakan ini sekarang mendukung izin tambahan untuk AWS Amplify, AWS AppSync, Amazon Bedrock,,, AWS CloudTrail CloudFormation AWS CodeArtifact, Connect Customer AWS CodePipeline,, Amazon EC2 AWS Deadline Cloud,,, Amazon IVS Resolusi Entitas AWS AWS IoT SiteWise,, Amazon Quick AWS Lambda, Amazon Redshift EventBridge, Amazon Redshift, Amazon Redshift Serverless,, Amazon, AWS Identity and Access Management Roles Anywhere, Amazon Security Lake SageMaker, AWS Secrets Manager, Amazon EC2 Systems Manager AWS Service Catalog AWS Shield, dan. AWS WAFV2 |
Oktober 1, 2025 |
|
AWS_ConfigRole— Tambahkan “arc-zonal-shift: GetAutoshiftObserverNotificationStatus “, “bedrock: “, “cloudtrail: GetModelInvocationLoggingConfiguration “, “codeartefact: GetEventConfiguration “, “codeartefact: “, “deadline: DescribeDomain “, “tenggat waktu: GetDomainPermissionsPolicy “, “tenggat waktu: GetFleet “, “tenggat waktu: GetQueueFleetAssociation “, “tenggat waktu: ListFleets “, “dms: ListQueueFleetAssociations “, “dms: “, ListTagsForResource “glue: “, “kafkaconnect: DescribeDataMigrations “, “kafkaconnect: ListMigrationProjects “, “kafkaconnect: GetDataCatalogEncryptionSettings “, “kafkaconnect: DescribeCustomPlugin “, “kafkaconnect: DescribeWorkerConfiguration “, “lakeformation: “, “medialive: ListCustomPlugins “,” ListTagsForResource ListWorkerConfigurations DescribeLakeFormationIdentityCenterConfiguration DescribeMultiplexProgram medialive: ListMultiplexPrograms “, “mediapackagev2: “, “mediapackagev2: GetChannelGroup “, “rds: “, “rolesanywhere: “, “rolesanywhere: “, “rolesanywhere: ListChannelGroups “, “rolesanywhere: “, “rolesanywhere: “, “s3: DescribeEngineDefaultParameters “, “secretsmanager: “, “securitylake: GetProfile “, “securitylake: “, “securitylake: GetTrustAnchor “, “securitylake: “, “securitylake: ListProfiles “, “securitylake: “, “securitylake: ListTagsForResource “, “securitylake: “, “securitylake: ListTrustAnchors “, “securitylake: “, GetAccessGrant “securitylake: “, “securitylake: ListAccessGrants “, “securitylake: “, “securitylake: DescribeSecret “, ““, “securitylake: “, “servicecatalog: ListDataLakeExceptions “, “servicecatalog: “, “servicecatalog: ListDataLakes “, “servicecatalog: “, “ses: “ses: ListLogSources GetAttributeGroup ListAttributeGroups ListServiceActions ListServiceActionsForProvisioningArtifact GetTrafficPolicy ListTagsForResource“, “ses: ListTrafficPolicies “, “xray: GetGroup “, “xray: “, GetGroups “xray: “, GetSamplingRules “xray: “, “xray:ListResourcePolicies” ListTagsForResource |
Kebijakan ini sekarang mendukung izin tambahan untuk AWS ARC - Zonal Shift, Amazon Bedrock,,, AWS CloudTrail, AWS CodeArtifact AWS Deadline Cloud AWS Database Migration Service AWS Glue AWS Identity and Access Management, Amazon Managed Streaming untuk Apache Kafka,, Amazon CloudWatch Logs AWS Lake Formation,, AWS Elemental MediaLive AWS Elemental MediaPackage, Amazon Relational Database Service, Amazon Simple Storage Service,, Amazon Security Lake AWS Secrets Manager,, Amazon Simple Email Service AWS Service Catalog, dan. AWS X-Ray |
Juli 28, 2025 |
|
AWSConfigServiceRolePolicy— Tambah “arc-zonal-shift: “, “bedrock: GetAutoshiftObserverNotificationStatus “, “cloudtrail: “, “codeartefact: GetModelInvocationLoggingConfiguration “, “codeartefact: “, “tenggat waktu: GetEventConfiguration “, “tenggat waktu: “, “tenggat waktu: DescribeDomain “, “tenggat waktu: “, “tenggat waktu: GetDomainPermissionsPolicy “, “dms: “, “dms: GetFleet “, “glue: “, “iam: GetQueueFleetAssociation “, “kafkaconnect: ListFleets “, “kafkackaconnect: “, ListQueueFleetAssociations “kafkackaconnect: ListTagsForResource “, “kafkackaconnect: “, “kafkackaconnect: DescribeDataMigrations “, “kafkackaconnect: ListMigrationProjects “, “kafkackaconnect: “, GetDataCatalogEncryptionSettings “kafkackaconnect: “, “kafkackaconnect: ListPolicies “, “kafkackaconnect: “, “kafkackaconnect: DescribeCustomPlugin “, “, “kafkaconnect: DescribeWorkerConfiguration “, “kafkaconnect: “, “kafkaconnect: ListCustomPlugins “, “lakeformation: “, “log: “log: “, “medialive: ListTagsForResource ListWorkerConfigurations DescribeLakeFormationIdentityCenterConfiguration DescribeIndexPolicies ListTagsForResource DescribeMultiplexProgram“, “medialive: ListMultiplexPrograms “, “mediapackagev2: “, “mediapackagev2: GetChannelGroup “, “rds: ListChannelGroups “, “rolesanywhere: “, “rolesanywhere: DescribeEngineDefaultParameters “, “rolesanywhere: GetProfile “, “rolesanywhere: GetTrustAnchor “, “rolesanywhere: “, “s3: ListProfiles “, “secretsmanager: ListTagsForResource “, “securitylake: “, ListTrustAnchors “securitylake: “, GetAccessGrant “securitylake: “, ListAccessGrants “servicecatalog: “, “servicecatalog: DescribeSecret “, “servicecatalog: ListDataLakeExceptions “, “servicecatalog: “, “ses: ListDataLakes ListLogSources GetAttributeGroup ListAttributeGroups ListServiceActions ListServiceActionsForProvisioningArtifact GetTrafficPolicy “, “ses: “, “ses: ListTagsForResource “, “xray: ListTrafficPolicies “, “xray: “, “xray: GetGroup “, “xray: “, “xray: GetGroups “, “arn:aws:apigateway: GetSamplingRules ::/account”, ListResourcePolicies “arn:aws:apigateway: ::/usageplans”, ListTagsForResource “arn:aws:apigateway: :/usageplans/”. |
Kebijakan ini sekarang mendukung izin tambahan untuk AWS ARC - Zonal Shift, Amazon Bedrock,,,, AWS CloudTrail AWS CodeArtifact AWS Deadline Cloud AWS Database Migration Service AWS Glue, Amazon Managed Streaming untuk Apache Kafka AWS Identity and Access Management, Amazon CloudWatch Logs,, AWS Lake Formation, Amazon Relational Database Service AWS Elemental MediaLive AWS Elemental MediaPackage, Amazon Simple Storage Service, Amazon Security Lake,, Amazon Simple Email Service AWS Secrets Manager, AWS Service Catalog, Amazon Simple Email Service, AWS X-Ray, dan Amazon API Gateway. |
Juli 28, 2025 |
|
AWSConfigServiceRolePolicy— Tambahkan “backup-gateway: GetHypervisor “, “backup-gateway: “, ListHypervisors “bcm-data-ekspor: “, “bcm-data-ekspor: GetExport “, “bcm-data-ekspor: ListExports “, “bedrock: “, ListTagsForResource “batuan dasar: “, “batuan dasar: GetAgent “, “batuan dasar: GetAgentActionGroup “, “batuan dasar: GetAgentKnowledgeBase “, “batuan dasar: GetDataSource “, “batuan dasar: GetFlowAlias “, “batuan dasar: GetFlowVersion “, “batuan dasar: ListAgentActionGroups “, “pembentukan awan: “, ListAgentKnowledgeBases “pembentukan awan: “, ListDataSources “formasi awan: “, “formasi awan: ListFlowAliases ListFlowVersions BatchDescribeTypeConfigurations DescribeStackInstance DescribeStackSet ListStackInstances“, “cloudformation: “, ListStackSets “cloudfront: “, “cloudfront: GetPublicKey “, “cloudfront: “, GetRealtimeLogConfig “cloudfront: “, “entityresolution: ListPublicKeys “, “entityresolution: ListRealtimeLogConfigs “, “entityresolution: “, GetIdMappingWorkflow “entityresolution: “, “entityresolution: GetSchemaMapping “, “iotdeviceadvisor: ListIdMappingWorkflows “, “iotdeviceadvisor: ListSchemaMappings “, “lambda: “, “lambda: ListTagsForResource “, “lambda: “, “mediapackagev2: GetSuiteDefinition “, “mediapackagev2: ListSuiteDefinitions “, “manajer jaringan: “, “manajer jaringan: GetEventSourceMapping “, “konektor pca- ListEventSourceMappings GetChannel ListChannels GetTransitGatewayPeering ListPeerings iklan: GetDirectoryRegistration “, “pca-connector-ad: ListDirectoryRegistrations “, “pca-connector-ad: “, “rds: ListTagsForResource “, “rds: DescribeDBShardGroups “, “redshift: “, DescribeIntegrations “s3tables: “, DescribeIntegrations “s3tables: “, “s3tables: GetTableBucket “, “s3tables: GetTableBucketEncryption “, “ssm-quicksetup:” GetTableBucketMaintenanceConfiguration ListTableBuckets GetConfigurationManager ListConfigurationManagers |
Kebijakan ini sekarang mendukung izin tambahan untuk AWS Backup gateway, AWS Manajemen Penagihan dan Biaya, Amazon Bedrock,, Amazon AWS CloudFormation,, CloudFront,, Resolusi Entitas AWS, AWS IoT Core Device Advisor AWS Lambda AWS Network Manager AWS Private Certificate Authority, Amazon Relational Database Service, Amazon Redshift, Amazon S3 Tables,. Pengaturan Cepat AWS Systems Manager |
Juni 18, 2025 |
AWS_ConfigRole— Tambahkan “backup-gateway: GetHypervisor “, “backup-gateway: “, ListHypervisors “bcm-data-ekspor: “, “bcm-data-ekspor: GetExport “, “bcm-data-ekspor: ListExports “, “bedrock: “, ListTagsForResource “batuan dasar: “, “batuan dasar: GetAgent “, “batuan dasar: GetAgentActionGroup “, “batuan dasar: GetAgentKnowledgeBase “, “batuan dasar: GetDataSource “, “batuan dasar: GetFlowAlias “, “batuan dasar: GetFlowVersion “, “batuan dasar: ListAgentActionGroups “, “pembentukan awan: “, ListAgentKnowledgeBases “pembentukan awan: “, ListDataSources “formasi awan: “, “formasi awan: ListFlowAliases ListFlowVersions BatchDescribeTypeConfigurations DescribeStackInstance DescribeStackSet ListStackInstances“, “cloudformation: ListStackSets “, “cloudfront: “, “cloudfront: GetPublicKey “, “cloudfront: GetRealtimeLogConfig “, “cloudfront: “, ListPublicKeys “entityresolution: “, “entityresolution: ListRealtimeLogConfigs “, “entityresolution: GetIdMappingWorkflow “, “entityresolution: GetSchemaMapping “, “entityresolution: “, “iotdeviceadvisor: ListIdMappingWorkflows “, “iotdeviceadvisor: ListSchemaMappings “, “lambda: ListTagsForResource “, “lambda: “, “manajer jaringan: GetSuiteDefinition “, “manajer jaringan: “, “pca-connector-ad: ListSuiteDefinitions “, “pca-connector-ad: GetEventSourceMapping “, “pca- ListEventSourceMappings GetTransitGatewayPeering ListPeerings GetDirectoryRegistration ListDirectoryRegistrations connector-ad: ListTagsForResource “, “rds: “, “rds: DescribeDBShardGroups “, “redshift: DescribeIntegrations “, “s3tables: DescribeIntegrations “, “s3tables: “, “s3tables: GetTableBucket “, “s3tables: GetTableBucketEncryption “, “ssm-quicksetup: GetTableBucketMaintenanceConfiguration “, “ssm-quicksetup:” ListTableBuckets GetConfigurationManager ListConfigurationManagers |
Kebijakan ini sekarang mendukung izin tambahan untuk AWS Backup gateway, AWS Manajemen Penagihan dan Biaya, Amazon Bedrock,, Amazon AWS CloudFormation,, CloudFront,, Resolusi Entitas AWS, AWS IoT Core Device Advisor AWS Lambda AWS Network Manager AWS Private Certificate Authority, Amazon Relational Database Service, Amazon Redshift, Amazon S3 Tables,. Pengaturan Cepat AWS Systems Manager |
Juni 18, 2025 |
|
AWS_ConfigRole— Tambah "bedrock:GetGuardrail", "bedrock:GetInferenceProfile", "bedrock:GetKnowledgeBase", "bedrock:ListGuardrails", "bedrock:ListInferenceProfiles", "bedrock:ListKnowledgeBases", "bedrock:ListTagsForResource" |
Kebijakan ini sekarang mendukung izin tambahan untuk Amazon Bedrock. |
27 Mei 2025 |
|
AWSConfigServiceRolePolicy— Tambahkan "bedrock:GetGuardrail", "bedrock:GetInferenceProfile", "bedrock:GetKnowledgeBase", "bedrock:ListGuardrails", "bedrock:ListInferenceProfiles", "bedrock:ListKnowledgeBases", "bedrock:ListTagsForResource" |
Kebijakan ini sekarang mendukung izin tambahan untuk Amazon Bedrock. |
27 Mei 2025 |
|
AWS_ConfigRole— Tambahkan "b2bi:GetPartnership", "b2bi:GetProfile", "b2bi:ListPartnerships", "b2bi:ListProfiles", "bedrock:ListAgents", "cleanrooms:GetConfiguredTable", "cleanrooms:GetConfiguredTableAnalysisRule", "cleanrooms:GetMembership", "cleanrooms:GetPrivacyBudgetTemplate", "cleanrooms:ListConfiguredTables", "cleanrooms:ListMemberships", "cleanrooms:ListPrivacyBudgetTemplates", "codeconnections:GetConnection", "codeconnections:ListConnections", "codeconnections:ListTagsForResource", "directconnect:DescribeConnections", "dms:DescribeReplicationConfigs", "logs:DescribeAccountPolicies", "logs:DescribeResourcePolicies", "macie2:ListAutomatedDiscoveryAccounts", "managedblockchain:GetAccessor", "managedblockchain:ListAccessors", "qbusiness:GetApplication", "qbusiness:ListApplications", "qbusiness:ListTagsForResource", "route53profiles:GetProfile", "route53profiles:GetProfileAssociation", "route53profiles:ListProfileAssociations", "route53profiles:ListProfiles", "route53profiles:ListTagsForResource", "s3:GetAccessGrantsInstance", "s3:GetAccessGrantsLocation", "s3:ListAccessGrantsInstances", "s3:ListAccessGrantsLocations", "sagemaker:DescribeCluster", "sagemaker:DescribeMlflowTrackingServer", "sagemaker:DescribeStudioLifecycleConfig", "sagemaker:ListClusters", "sagemaker:ListMlflowTrackingServers", "sagemaker:ListStudioLifecycleConfigs", "securityhub:DescribeStandardsControls", "securityhub:GetEnabledStandards", "ssm-contacts:GetContact", "ssm-contacts:GetContactChannel", "ssm-contacts:ListContactChannels", "ssm-contacts:ListContacts", "ssm-incidents:GetResponsePlan", "ssm-incidents:ListResponsePlans", "ssm-incidents:ListTagsForResource", "ssm:DescribeInstanceInformation" |
Kebijakan ini sekarang mendukung izin tambahan untuk AWS B2B Pertukaran Data, Amazon Bedrock,, AWS Clean Rooms, AWS Database Migration Service (AWS DMS) AWS CodeConnections AWS Direct Connect, Amazon CloudWatch Logs, Amazon Macie, Amazon Managed Blockchain, Amazon Q Business, Profil Route 53, Amazon Simple Storage Service (Amazon S3), Amazon SageMaker AI,, dan AWS Security Hub CSPM, Kontak Manajer Insiden AWS Systems Manager, Manajer Insiden AWS Systems Manager dan. AWS Systems Manager |
08 April 2025 |
|
AWSConfigServiceRolePolicy— Tambahkan "b2bi:GetPartnership", "b2bi:GetProfile", "b2bi:ListPartnerships", "b2bi:ListProfiles", "bedrock:ListAgents", "cleanrooms:GetConfiguredTable", "cleanrooms:GetConfiguredTableAnalysisRule", "cleanrooms:GetMembership", "cleanrooms:GetPrivacyBudgetTemplate", "cleanrooms:ListConfiguredTables", "cleanrooms:ListMemberships", "cleanrooms:ListPrivacyBudgetTemplates", "codeconnections:GetConnection", "codeconnections:ListConnections", "codeconnections:ListTagsForResource", "directconnect:DescribeConnections", "dms:DescribeReplicationConfigs", "logs:DescribeAccountPolicies", "logs:DescribeResourcePolicies", "macie2:ListAutomatedDiscoveryAccounts", "managedblockchain:GetAccessor", "managedblockchain:ListAccessors", "qbusiness:GetApplication", "qbusiness:ListApplications", "qbusiness:ListTagsForResource", "route53profiles:GetProfile", "route53profiles:GetProfileAssociation", "route53profiles:ListProfileAssociations", "route53profiles:ListProfiles", "route53profiles:ListTagsForResource", "s3:GetAccessGrantsInstance", "s3:GetAccessGrantsLocation", "s3:ListAccessGrantsInstances", "s3:ListAccessGrantsLocations", "sagemaker:DescribeCluster", "sagemaker:DescribeMlflowTrackingServer", "sagemaker:DescribeStudioLifecycleConfig", "sagemaker:ListClusters", "sagemaker:ListMlflowTrackingServers", "sagemaker:ListStudioLifecycleConfigs", "securityhub:DescribeStandardsControls", "securityhub:GetEnabledStandards", "ssm-contacts:GetContact", "ssm-contacts:GetContactChannel", "ssm-contacts:ListContactChannels", "ssm-contacts:ListContacts", "ssm-incidents:GetResponsePlan", "ssm-incidents:ListResponsePlans", "ssm-incidents:ListTagsForResource", "ssm:DescribeInstanceInformation" |
Kebijakan ini sekarang mendukung izin tambahan untuk AWS B2B Pertukaran Data, Amazon Bedrock,, AWS Clean Rooms, AWS Database Migration Service (AWS DMS) AWS CodeConnections AWS Direct Connect, Amazon CloudWatch Logs, Amazon Macie, Amazon Managed Blockchain, Amazon Q Business, Profil Route 53, Amazon Simple Storage Service (Amazon S3), Amazon SageMaker AI,, dan AWS Security Hub CSPM, Kontak Manajer Insiden AWS Systems Manager, Manajer Insiden AWS Systems Manager
dan. AWS Systems Manager Kebijakan ini juga sekarang mendukung izin untuk mengakses semua nama domain Amazon API Gateway dengan menyertakan pola sumber daya " |
08 April 2025 |
|
AWS_ConfigRole— Tambahkan "ec2:GetAllowedImagesSettings" |
Kebijakan ini sekarang mendukung izin tambahan untuk Amazon Elastic Compute Cloud (Amazon EC2). |
Maret 4, 2025 |
|
AWSConfigServiceRolePolicy— Tambahkan "ec2:GetAllowedImagesSettings" |
Kebijakan ini sekarang mendukung izin tambahan untuk Amazon Elastic Compute Cloud (Amazon EC2). |
Maret 4, 2025 |
|
AWS_ConfigRole— Tambahkan "cleanrooms-ml:GetTrainingDataset", "cleanrooms-ml:ListTrainingDatasets", "comprehend:DescribeFlywheel", "comprehend:ListFlywheels", "comprehend:ListTagsForResource", "ec2:GetSnapshotBlockPublicAccessState", "omics:GetAnnotationStore", "omics:GetRunGroup", "omics:GetSequenceStore", "omics:GetVariantStore", "omics:ListAnnotationStores", "omics:ListRunGroups", "omics:ListSequenceStores", "omics:ListTagsForResource", "omics:ListVariantStores", "s3express:GetEncryptionConfiguration", "s3express:GetLifecycleConfiguration", "ses:GetDedicatedIpPool", "ses:GetDedicatedIps", and "ses:ListDedicatedIpPools" |
Kebijakan ini sekarang mendukung izin tambahan untuk AWS Clean Rooms, Amazon Comprecept, Amazon Elastic Compute Cloud (Amazon EC2), AWS HealthOmics, Amazon Simple Storage Service (Amazon S3), dan Amazon Simple Email Service (Amazon SES). |
Januari 16, 2025 |
|
AWSConfigServiceRolePolicy— Tambahkan "cleanrooms-ml:GetTrainingDataset", "cleanrooms-ml:ListTrainingDatasets", "comprehend:DescribeFlywheel", "comprehend:ListFlywheels", "comprehend:ListTagsForResource", "ec2:GetSnapshotBlockPublicAccessState", "omics:GetAnnotationStore", "omics:GetRunGroup", "omics:GetSequenceStore", "omics:GetVariantStore", "omics:ListAnnotationStores", "omics:ListRunGroups", "omics:ListSequenceStores", "omics:ListTagsForResource", "omics:ListVariantStores", "s3express:GetEncryptionConfiguration", "s3express:GetLifecycleConfiguration", "ses:GetDedicatedIpPool", "ses:GetDedicatedIps", and "ses:ListDedicatedIpPools" |
Kebijakan ini sekarang mendukung izin tambahan untuk AWS Clean Rooms, Amazon Comprecept, Amazon Elastic Compute Cloud (Amazon EC2), AWS HealthOmics, Amazon Simple Storage Service (Amazon S3), dan Amazon Simple Email Service (Amazon SES). |
Januari 16, 2025 |
|
AWSConfigServiceRolePolicy— Tambahkan "organizations:ListAWSServiceAccessForOrganization" |
Kebijakan ini sekarang mendukung izin tambahan untuk AWS Organizations. |
Desember 18, 2024 |
|
AWS_ConfigRole— Tambahkan "app-integrations:GetApplication", "app-integrations:ListApplications", "app-integrations:ListTagsForResource", "appconfig:GetExtension", "appconfig:ListExtensions", "cloudtrail:GetInsightSelectors", "connect:DescribeQueue", "connect:DescribeRoutingProfile", "connect:DescribeSecurityProfile", "connect:ListQueueQuickConnects", "connect:ListQueues", "connect:ListRoutingProfileQueues", "connect:ListRoutingProfiles", "connect:ListSecurityProfileApplications", "connect:ListSecurityProfilePermissions", "connect:ListSecurityProfiles", "datazone:GetDomain", "datazone:ListDomains", "devops-guru:ListNotificationChannels", "glue:GetRegistry", "glue:ListRegistries", "identitystore:DescribeGroup", "identitystore:DescribeGroupMembership" "identitystore:ListGroupMemberships", "identitystore:ListGroups", "iot:DescribeThingGroup", "iot:DescribeThingType", "iot:ListThingGroups", "iot:ListThingTypes", "iotfleetwise:GetDecoderManifest", "iotfleetwise:GetFleet", "iotfleetwise:GetModelManifest", "iotfleetwise:GetSignalCatalog", "iotfleetwise:GetVehicle", "iotfleetwise:ListDecoderManifestNetworkInterfaces", "iotfleetwise:ListDecoderManifests", "iotfleetwise:ListDecoderManifestSignals", "iotfleetwise:ListFleets", "iotfleetwise:ListModelManifestNodes", "iotfleetwise:ListModelManifests", "iotfleetwise:ListSignalCatalogNodes", "iotfleetwise:ListSignalCatalogs", "iotfleetwise:ListTagsForResource", "iotfleetwise:ListVehicles", "iotwireless:GetDestination", "iotwireless:GetDeviceProfile", "iotwireless:GetWirelessGateway", "iotwireless:ListDestinations", "iotwireless:ListDeviceProfiles", "iotwireless:ListWirelessGateways", "ivschat:GetLoggingConfiguration", "ivschat:GetRoom" "ivschat:ListLoggingConfigurations", "ivschat:ListRooms", "ivschat:ListTagsForResource", "logs:GetLogAnomalyDetector", "logs:ListLogAnomalyDetectors", "oam:GetSink" "oam:GetSinkPolicy", "oam:ListSinks", "payment-cryptography:GetAlias", "payment-cryptography:GetKey", "payment-cryptography:ListAliases", "payment-cryptography:ListKeys", "payment-cryptography:ListTagsForResource", "rds:DescribeDBProxyTargetGroups", "rds:DescribeDBProxyTargets", "rekognition:DescribeProjects", "s3:GetStorageLensGroup", "s3:ListStorageLensGroups", "s3:ListTagsForResource", "scheduler:GetScheduleGroup", "scheduler:ListScheduleGroups", "scheduler:ListTagsForResource", "ssm:GetServiceSetting", "vpc-lattice:GetAccessLogSubscription", "vpc-lattice:GetService", "vpc-lattice:GetServiceNetwork", "vpc-lattice:GetTargetGroup", "vpc-lattice:ListAccessLogSubscriptions", "vpc-lattice:ListServiceNetworks", "vpc-lattice:ListServices", "vpc-lattice:ListTagsForResource", "vpc-lattice:ListTargetGroups", and "vpc-lattice:ListTargets" |
Kebijakan ini sekarang mendukung izin tambahan untuk AWS AppConfig, AWS CloudTrail, Amazon Connect Customer, Amazon, Amazon DevOps Guru DataZone,, Identity Store AWS Glue,, AWS IoT AWS IoT FleetWise AWS IoT Wireless, Amazon Interactive Video Service (Amazon IVS), Amazon CloudWatch Logs, Amazon CloudWatch Observability Access Manager,, Amazon Relational Database Service (Amazon RDS) AWS Payment Cryptography, Amazon Rekognition, Amazon Simple Storage Service (Amazon S3), Amazon EventBridge Scheduler,, dan Amazon VPC Lattice. AWS Systems Manager |
7 November 2024 |
|
AWSConfigServiceRolePolicy— Tambahkan "app-integrations:GetApplication", "app-integrations:ListApplications", "app-integrations:ListTagsForResource", "appconfig:GetExtension", "appconfig:ListExtensions", "cloudtrail:GetInsightSelectors", "connect:DescribeQueue", "connect:DescribeRoutingProfile", "connect:DescribeSecurityProfile", "connect:ListQueueQuickConnects", "connect:ListQueues", "connect:ListRoutingProfileQueues", "connect:ListRoutingProfiles", "connect:ListSecurityProfileApplications", "connect:ListSecurityProfilePermissions", "connect:ListSecurityProfiles", "datazone:GetDomain", "datazone:ListDomains", "devops-guru:ListNotificationChannels", "glue:GetRegistry", "glue:ListRegistries", "identitystore:DescribeGroup", "identitystore:DescribeGroupMembership" "identitystore:ListGroupMemberships", "identitystore:ListGroups", "iot:DescribeThingGroup", "iot:DescribeThingType", "iot:ListThingGroups", "iot:ListThingTypes", "iotfleetwise:GetDecoderManifest", "iotfleetwise:GetFleet", "iotfleetwise:GetModelManifest", "iotfleetwise:GetSignalCatalog", "iotfleetwise:GetVehicle", "iotfleetwise:ListDecoderManifestNetworkInterfaces", "iotfleetwise:ListDecoderManifests", "iotfleetwise:ListDecoderManifestSignals", "iotfleetwise:ListFleets", "iotfleetwise:ListModelManifestNodes", "iotfleetwise:ListModelManifests", "iotfleetwise:ListSignalCatalogNodes", "iotfleetwise:ListSignalCatalogs", "iotfleetwise:ListTagsForResource", "iotfleetwise:ListVehicles", "iotwireless:GetDestination", "iotwireless:GetDeviceProfile", "iotwireless:GetWirelessGateway", "iotwireless:ListDestinations", "iotwireless:ListDeviceProfiles", "iotwireless:ListWirelessGateways", "ivschat:GetLoggingConfiguration", "ivschat:GetRoom" "ivschat:ListLoggingConfigurations", "ivschat:ListRooms", "ivschat:ListTagsForResource", "logs:GetLogAnomalyDetector", "logs:ListLogAnomalyDetectors", "oam:GetSink" "oam:GetSinkPolicy", "oam:ListSinks", "payment-cryptography:GetAlias", "payment-cryptography:GetKey", "payment-cryptography:ListAliases", "payment-cryptography:ListKeys", "payment-cryptography:ListTagsForResource", "rds:DescribeDBProxyTargetGroups", "rds:DescribeDBProxyTargets", "rekognition:DescribeProjects", "s3:GetStorageLensGroup", "s3:ListStorageLensGroups", "s3:ListTagsForResource", "scheduler:GetScheduleGroup", "scheduler:ListScheduleGroups", "scheduler:ListTagsForResource", "ssm:GetServiceSetting", "vpc-lattice:GetAccessLogSubscription", "vpc-lattice:GetService", "vpc-lattice:GetServiceNetwork", "vpc-lattice:GetTargetGroup", "vpc-lattice:ListAccessLogSubscriptions", "vpc-lattice:ListServiceNetworks", "vpc-lattice:ListServices", "vpc-lattice:ListTagsForResource", "vpc-lattice:ListTargetGroups", and "vpc-lattice:ListTargets" |
Kebijakan ini sekarang mendukung izin tambahan untuk AWS AppConfig, AWS CloudTrail, Amazon Connect Customer, Amazon, Amazon DevOps Guru DataZone,, Identity Store AWS Glue,, AWS IoT AWS IoT FleetWise AWS IoT Wireless, Amazon Interactive Video Service (Amazon IVS), Amazon CloudWatch Logs, Amazon CloudWatch Observability Access Manager,, Amazon Relational Database Service (Amazon RDS) AWS Payment Cryptography, Amazon Rekognition, Amazon Simple Storage Service (Amazon S3), Amazon EventBridge Scheduler,, dan Amazon VPC Lattice. AWS Systems Manager |
7 November 2024 |
|
AWS_ConfigRole— Tambahkan "aoss:BatchGetCollection," "aoss:BatchGetLifecyclePolicy," "aoss:BatchGetVpcEndpoint," "aoss:GetAccessPolicy," "aoss:GetSecurityConfig," "aoss:GetSecurityPolicy," "aoss:ListAccessPolicies," "aoss:ListCollections," "aoss:ListLifecyclePolicies," "aoss:ListSecurityConfigs," "aoss:ListSecurityPolicies," "aoss:ListVpcEndpoints," "appstream:DescribeAppBlockBuilders," "backup:GetRestoreTestingPlan," "backup:GetRestoreTestingSelection", "backup:ListRestoreTestingPlans," "backup:ListRestoreTestingSelections," "cloudTrail:GetChannel, "cloudTrail:ListChannels," "glue:GetTrigger," "glue:ListTriggers, "imagebuilder:GetLifecyclePolicy," "imagebuilder:ListLifecyclePolicies," "iot:DescribeBillingGroup," "iot:ListBillingGroups," "ivs:GetEncoderConfiguration," "ivs:GetPlaybackRestrictionPolicy," "ivs:GetStage," "ivs:GetStorageConfiguration," "ivs:ListEncoderConfigurations," "ivs:ListPlaybackRestrictionPolicies," "ivs:ListStages," "ivs:ListStorageConfigurations," "mediaconnect:DescribeBridge", "mediaconnect:DescribeGatewa," "mediaconnect:ListBridges," "mediaconnect:ListGateways", "mediatailor:DescribeChannel," "mediatailor:DescribeLiveSource," "mediatailor:DescribeSourceLocation," "mediatailor:DescribeVodSource", "mediatailor:ListChannels," "mediatailor:ListLiveSources", "mediatailor:ListSourceLocations," "mediatailor:ListVodSources," "omics:GetWorkflow," "omics:ListWorkflows," "scheduler:GetSchedule," and "scheduler:ListSchedules" |
Kebijakan ini sekarang mendukung izin tambahan untuk Amazon OpenSearch Service Severless, Amazon,, AppStream, AWS Backup AWS CloudTrail, EC2 Image Builder AWS Glue, AWS IoT, Amazon Interactive Video Service (Amazon IVS),,, AWS Elemental MediaConnect AWS Elemental MediaTailor AWS HealthOmics, dan Amazon Scheduler. EventBridge |
September 16, 2024 |
|
AWSConfigServiceRolePolicy— Tambahkan "aoss:BatchGetCollection," "aoss:BatchGetLifecyclePolicy," "aoss:BatchGetVpcEndpoint," "aoss:GetAccessPolicy," "aoss:GetSecurityConfig," "aoss:GetSecurityPolicy," "aoss:ListAccessPolicies," "aoss:ListCollections," "aoss:ListLifecyclePolicies," "aoss:ListSecurityConfigs," "aoss:ListSecurityPolicies," "aoss:ListVpcEndpoints," "appstream:DescribeAppBlockBuilders," "backup:GetRestoreTestingPlan," "backup:GetRestoreTestingSelection", "backup:ListRestoreTestingPlans," "backup:ListRestoreTestingSelections," "cloudTrail:GetChannel, "cloudTrail:ListChannels," "glue:GetTrigger," "glue:ListTriggers, "imagebuilder:GetLifecyclePolicy," "imagebuilder:ListLifecyclePolicies," "iot:DescribeBillingGroup," "iot:ListBillingGroups," "ivs:GetEncoderConfiguration," "ivs:GetPlaybackRestrictionPolicy," "ivs:GetStage," "ivs:GetStorageConfiguration," "ivs:ListEncoderConfigurations," "ivs:ListPlaybackRestrictionPolicies," "ivs:ListStages," "ivs:ListStorageConfigurations," "mediaconnect:DescribeBridge", "mediaconnect:DescribeGatewa," "mediaconnect:ListBridges," "mediaconnect:ListGateways", "mediatailor:DescribeChannel," "mediatailor:DescribeLiveSource," "mediatailor:DescribeSourceLocation," "mediatailor:DescribeVodSource", "mediatailor:ListChannels," "mediatailor:ListLiveSources", "mediatailor:ListSourceLocations," "mediatailor:ListVodSources," "omics:GetWorkflow," "omics:ListWorkflows," "scheduler:GetSchedule," and "scheduler:ListSchedules" |
Kebijakan ini sekarang mendukung izin tambahan untuk Amazon OpenSearch Service Severless, Amazon,, AppStream, AWS Backup AWS CloudTrail, EC2 Image Builder AWS Glue, AWS IoT, Amazon Interactive Video Service (Amazon IVS),,, AWS Elemental MediaConnect AWS Elemental MediaTailor AWS HealthOmics, dan Amazon Scheduler. EventBridge |
September 16, 2024 |
|
AWS_ConfigRole— Tambahkan "elasticfilesystem:DescribeTags," "redshift:DescribeTags," and "ssm-sap:ListTagsForResource" |
Kebijakan ini sekarang mendukung izin tambahan untuk Amazon Elastic File System (Amazon EFS), Amazon Redshift, dan Manajer Sistem AWS untuk SAP. |
Juni 17, 2024 |
|
AWSConfigServiceRolePolicy— Tambahkan "elasticfilesystem:DescribeTags," "redshift:DescribeTags," and "ssm-sap:ListTagsForResource" |
Kebijakan ini sekarang mendukung izin tambahan untuk Amazon Elastic File System (Amazon EFS), Amazon Redshift, dan Manajer Sistem AWS untuk SAP. |
Juni 17, 2024 |
| AWS_ConfigRole— Tambahkan "aps:DescribeAlertManagerDefinition," "cloudwatch:DescribeAlarmsForMetric," "cognito-identity:DescribeIdentityPool, "cognito-identity:GetPrincipalTagAttributeMap," "elasticache:DescribeCacheSecurityGroups," "elasticache:DescribeUserGroups," "elasticache:DescribeUsers," "elasticache:DescribeGlobalReplicationGroups," "fsx:DescribeDataRepositoryAssociations," "glue:GetDatabase," "glue:GetDatabases," "iam:ListUsers," "lambda:GetLayerVersion," "lambda:ListLayers," "lambda:ListLayerVersions," "ram:GetPermission," "ram:ListPermissionAssociations," "ram:ListPermissions," "ram:ListPermissionVersions," "redshift-serverless:GetNamespace," "redshift-serverless:GetWorkgroup," "redshift-serverless:ListNamespaces," "redshift-serverless:ListTagsForResource," "redshift-serverless:ListWorkgroups," "sagemaker:DescribeInferenceExperiment," "sagemaker:ListInferenceExperiments," and "sns:GetSMSSandboxAccountStatus" |
Kebijakan ini sekarang mendukung izin tambahan untuk Layanan Terkelola Amazon untuk Prometheus, Amazon, Amazon Cognito CloudWatch, Amazon, Amazon FSx ElastiCache,, AWS Identity and Access Management (IAM), AWS Glue,, Amazon Redshift Serverless AWS Lambda, Amazon SageMaker AI AWS RAM, dan Amazon Simple Notification Service (Amazon SNS). |
Februari 22, 2024 |
| AWSConfigServiceRolePolicy— Tambah "aps:DescribeAlertManagerDefinition," "cloudwatch:DescribeAlarmsForMetric," "cognito-identity:DescribeIdentityPool, "cognito-identity:GetPrincipalTagAttributeMap," "elasticache:DescribeCacheSecurityGroups," "elasticache:DescribeUserGroups," "elasticache:DescribeUsers," "elasticache:DescribeGlobalReplicationGroups," "fsx:DescribeDataRepositoryAssociations," "glue:GetDatabase," "glue:GetDatabases," "iam:ListUsers," "lambda:GetLayerVersion," "lambda:ListLayers," "lambda:ListLayerVersions," "ram:GetPermission," "ram:ListPermissionAssociations," "ram:ListPermissions," "ram:ListPermissionVersions," "redshift-serverless:GetNamespace," "redshift-serverless:GetWorkgroup," "redshift-serverless:ListNamespaces," "redshift-serverless:ListTagsForResource," "redshift-serverless:ListWorkgroups," "sagemaker:DescribeInferenceExperiment," "sagemaker:ListInferenceExperiments," and "sns:GetSMSSandboxAccountStatus" |
Kebijakan ini sekarang mendukung izin tambahan untuk Layanan Terkelola Amazon untuk Prometheus, Amazon, Amazon Cognito CloudWatch, Amazon, Amazon FSx ElastiCache,, AWS Identity and Access Management (IAM), AWS Glue,, Amazon Redshift Serverless AWS Lambda, Amazon SageMaker AI AWS RAM, dan Amazon Simple Notification Service (Amazon SNS). |
Februari 22, 2024 |
|
AWSConfigUserAccess— AWS Config mulai melacak perubahan untuk kebijakan terkel AWS ola ini |
Kebijakan ini menyediakan akses untuk digunakan AWS Config, termasuk mencari berdasarkan tag pada sumber daya dan membaca semua tag. Ini tidak memberikan izin untuk mengkonfigurasi AWS Config, yang memerlukan hak administratif. |
Februari 22, 2024 |
| AWS_ConfigRole— Tambah "appconfig:GetExtensionAssociation," "appconfig:ListExtensionAssociations," "aps:DescribeLoggingConfiguration," "dms:DescribeReplicationTaskAssessmentRuns," "iam:GetOpenIDConnectProvider," "iam:ListOpenIDConnectProviders," "kafka:DescribeVpcConnection," "kafka:GetClusterPolicy," "kafka:ListVpcConnections," "logs:DescribeMetricFilters," "organizations:ListDelegatedAdministrators," "s3:GetBucketPolicyStatus," "s3express:GetBucketPolicy," and "s3express:ListAllMyDirectoryBuckets" |
Kebijakan ini sekarang mendukung izin tambahan untuk AWS AppConfig, Amazon Managed Service untuk Prometheus, AWS Database Migration Service (AWS DMS), (AWS Identity and Access Management) IAM, Amazon Managed Streaming untuk Apache Kafka (Amazon MSK), Amazon CloudWatch Logs AWS Organizations, dan Amazon Simple Storage Service (Amazon S3). |
Desember 5, 2023 |
| AWSConfigServiceRolePolicy— Tambah "appconfig:GetExtensionAssociation," "appconfig:ListExtensionAssociations," "aps:DescribeLoggingConfiguration," "dms:DescribeReplicationTaskAssessmentRuns," "iam:GetOpenIDConnectProvider," "iam:ListOpenIDConnectProviders," "kafka:DescribeVpcConnection," "kafka:GetClusterPolicy," "kafka:ListVpcConnections," "logs:DescribeMetricFilters," "organizations:ListDelegatedAdministrators," "s3:GetBucketPolicyStatus," "s3express:GetBucketPolicy," and "s3express:ListAllMyDirectoryBuckets" |
Kebijakan ini sekarang mendukung izin tambahan untuk AWS AppConfig, Amazon Managed Service untuk Prometheus, AWS Database Migration Service (AWS DMS), (AWS Identity and Access Management) IAM, Amazon Managed Streaming untuk Apache Kafka (Amazon MSK), Amazon CloudWatch Logs AWS Organizations, dan Amazon Simple Storage Service (Amazon S3). |
5 Desember 2023 |
| AWS_ConfigRole— Tambah "backup:DescribeProtectedResource," "cognito-identity:GetIdentityPoolRoles," "cognito-identity:ListIdentityPools," "cognito-identity:ListTagsForResource," "cognito-idp:DescribeIdentityProvider," "cognito-idp:DescribeResourceServer," "cognito-idp:DescribeUserPool," "cognito-idp:DescribeUserPoolClient," "cognito-idp:DescribeUserPoolDomain," "cognito-idp:GetGroup," "cognito-idp:GetUserPoolMfaConfig," "cognito-idp:ListGroups," "cognito-idp:ListIdentityProviders," "cognito-idp:ListResourceServers," "cognito-idp:ListUserPoolClients," "cognito-idp:ListUserPools," "cognito-idp:ListTagsForResource," "connect:DescribeEvaluationForm," "connect:DescribeInstanceStorageConfig," "connect:DescribePrompt," "connect:DescribeRule," "connect:DescribeUser," "connect:GetTaskTemplate," "connect:ListApprovedOrigins," "connect:ListEvaluationForms," "connect:ListInstanceStorageConfigs," "connect:ListIntegrationAssociations," "connect:ListPrompts," "connect:ListRules," "connect:ListSecurityKeys," "connect:ListTagsForResource," "connect:ListTaskTemplates," "connect:ListUsers," "emr-containers:DescribeVirtualCluster," "emr-containers:ListVirtualClusters," "emr-serverless:GetApplication," "emr-serverless:ListApplications," "groundstation:GetDataflowEndpointGroup," "groundstation:ListDataflowEndpointGroups," "m2:GetEnvironment," "m2:ListEnvironments," "m2:ListTagsForResource," "memorydb:DescribeAcls," "memorydb:DescribeClusters," "memorydb:DescribeParameterGroups," "memorydb:DescribeParameters," "memorydb:DescribeSubnetGroups," "organizations:ListRoots," "quicksight:DescribeAccountSubscription," "quicksight:DescribeDataSetRefreshProperties," "rds:DescribeEngineDefaultClusterParameters," "redshift:DescribeEndpointAccess," "redshift:DescribeEndpointAuthorization," "route53:GetChange," "route53:ListCidrBlocks," "route53:ListCidrLocations," "serviceCatalog:DescribePortfolioShares," "transfer:DescribeProfile," and "transfer:ListProfiles" |
Kebijakan ini sekarang mendukung izin tambahan untuk Amazon Cognito, Amazon Connect Customer, Amazon EMR,, AWS Ground Station AWS Mainframe Modernization, Amazon MemoryDB,, Amazon Quick AWS Organizations, Amazon Relational Database Service (Amazon RDS), Amazon Redshift, Amazon Route 53,, dan. AWS Service Catalog AWS Transfer Family |
17 November 2023 |
| AWS_ConfigRole— Tambah "Sid": "AWSConfigServiceRolePolicyStatementID," "Sid": "AWSConfigSLRLogStatementID," "Sid": "AWSConfigSLRLogEventStatementID," and "Sid": "AWSConfigSLRApiGatewayStatementID" |
Kebijakan ini sekarang menambahkan pengidentifikasi keamanan (SID) untuk |
17 November 2023 |
| AWSConfigServiceRolePolicy— Tambah "backup:DescribeProtectedResource," "cognito-identity:GetIdentityPoolRoles," "cognito-identity:ListIdentityPools," "cognito-identity:ListTagsForResource," "cognito-idp:DescribeIdentityProvider," "cognito-idp:DescribeResourceServer," "cognito-idp:DescribeUserPool," "cognito-idp:DescribeUserPoolClient," "cognito-idp:DescribeUserPoolDomain," "cognito-idp:GetGroup," "cognito-idp:GetUserPoolMfaConfig," "cognito-idp:ListGroups," "cognito-idp:ListIdentityProviders," "cognito-idp:ListResourceServers," "cognito-idp:ListUserPoolClients," "cognito-idp:ListUserPools," "cognito-idp:ListTagsForResource," "connect:DescribeEvaluationForm," "connect:DescribeInstanceStorageConfig," "connect:DescribePrompt," "connect:DescribeRule," "connect:DescribeUser," "connect:GetTaskTemplate," "connect:ListApprovedOrigins," "connect:ListEvaluationForms," "connect:ListInstanceStorageConfigs," "connect:ListIntegrationAssociations," "connect:ListPrompts," "connect:ListRules," "connect:ListSecurityKeys," "connect:ListTagsForResource," "connect:ListTaskTemplates," "connect:ListUsers," "emr-containers:DescribeVirtualCluster," "emr-containers:ListVirtualClusters," "emr-serverless:GetApplication," "emr-serverless:ListApplications," "groundstation:GetDataflowEndpointGroup," "groundstation:ListDataflowEndpointGroups," "m2:GetEnvironment," "m2:ListEnvironments," "m2:ListTagsForResource," "memorydb:DescribeAcls," "memorydb:DescribeClusters," "memorydb:DescribeParameterGroups," "memorydb:DescribeParameters," "memorydb:DescribeSubnetGroups," "organizations:ListRoots," "quicksight:DescribeAccountSubscription," "quicksight:DescribeDataSetRefreshProperties," "rds:DescribeEngineDefaultClusterParameters," "redshift:DescribeEndpointAccess," "redshift:DescribeEndpointAuthorization," "route53:GetChange," "route53:ListCidrBlocks," "route53:ListCidrLocations," "serviceCatalog:DescribePortfolioShares," "transfer:DescribeProfile," and "transfer:ListProfiles" |
Kebijakan ini sekarang mendukung izin tambahan untuk Amazon Cognito, Amazon Connect Customer, Amazon EMR,, AWS Ground Station AWS Mainframe Modernization, Amazon MemoryDB,, Amazon Quick AWS Organizations, Amazon Relational Database Service (Amazon RDS), Amazon Redshift, Amazon Route 53,, dan. AWS Service Catalog AWS Transfer Family |
17 November 2023 |
| AWSConfigServiceRolePolicy— Tambah "Sid": "AWSConfigServiceRolePolicyStatementID," "Sid": "AWSConfigSLRLogStatementID," "Sid": "AWSConfigSLRLogEventStatementID," and "Sid": "AWSConfigSLRApiGatewayStatementID" |
Kebijakan ini sekarang menambahkan pengidentifikasi keamanan (SID) untuk |
17 November 2023 |
| AWS_ConfigRole— Tambah "acm-pca:GetCertificateAuthorityCertificate," "appmesh:DescribeMesh," "appmesh:ListGatewayRoutes," "connect:DescribeInstance," "connect:DescribeQuickConnect," "connect:ListQuickConnects," "ecs:DescribeCapacityProviders," "evidently:GetSegment," "evidently:ListSegments," "grafana:DescribeWorkspace," "grafana:DescribeWorkspaceAuthentication," "grafana:DescribeWorkspaceConfiguration," "grafana:DescribeWorkspaceConfiguration," "guardduty:GetMemberDetectors," "inspector2:BatchGetAccountStatus," "inspector2:GetDelegatedAdminAccount," "inspector2:ListMembers," "iot:DescribeCACertificate," "iot:ListCACertificates," "iot:ListTagsForResource," "iottwinmaker:GetSyncJob," "iottwinmaker:ListSyncJobs," "kafka:ListTagsForResource," "kafkaconnect:DescribeConnector," "kafkaconnect:ListConnectors," "lambda:GetCodeSigningConfig," "lambda:ListCodeSigningConfigs," "lambda:ListTags," "networkmanager:GetConnectPeer," "organizations:DescribeOrganization," "organizations:ListTargetsForPolicy," "sagemaker:DescribeDataQualityJob," "sagemaker:DescribeModelExplainabilityJob," "sagemaker:ListDataQualityJob," and "sagemaker:ExplainabilityJob" |
Kebijakan ini sekarang mendukung izin tambahan untuk AWS Private CA, Connect Customer AWS App Mesh, Amazon Elastic Container Service (Amazon ECS), Amazon E CloudWatch vidently, Amazon Managed Grafana, Amazon, Amazon Inspector GuardDuty,, AWS IoT AWS IoT TwinMaker, Amazon Managed Streaming untuk Apache Kafka (Amazon MSK),,, AWS Lambda AWS Network Manager, AWS Organizations dan Amazon AI. SageMaker |
4 Oktober 2023 |
| AWSConfigServiceRolePolicy— Tambah "acm-pca:GetCertificateAuthorityCertificate," "appmesh:DescribeMesh," "appmesh:ListGatewayRoutes," "connect:DescribeInstance," "connect:DescribeQuickConnect," "connect:ListQuickConnects," "ecs:DescribeCapacityProviders," "evidently:GetSegment," "evidently:ListSegments," "grafana:DescribeWorkspace," "grafana:DescribeWorkspaceAuthentication," "grafana:DescribeWorkspaceConfiguration," "grafana:DescribeWorkspaceConfiguration," "guardduty:GetMemberDetectors," "inspector2:BatchGetAccountStatus," "inspector2:GetDelegatedAdminAccount," "inspector2:ListMembers," "iot:DescribeCACertificate," "iot:ListCACertificates," "iot:ListTagsForResource," "iottwinmaker:GetSyncJob," "iottwinmaker:ListSyncJobs," "kafka:ListTagsForResource," "kafkaconnect:DescribeConnector," "kafkaconnect:ListConnectors," "lambda:GetCodeSigningConfig," "lambda:ListCodeSigningConfigs," "lambda:ListTags," "networkmanager:GetConnectPeer," "organizations:DescribeOrganization," "organizations:ListTargetsForPolicy," "sagemaker:DescribeDataQualityJob," "sagemaker:DescribeModelExplainabilityJob," "sagemaker:ListDataQualityJob," and "sagemaker:ExplainabilityJob" |
Kebijakan ini sekarang mendukung izin tambahan untuk AWS Private CA, Connect Customer AWS App Mesh, Amazon Elastic Container Service (Amazon ECS), Amazon E CloudWatch vidently, Amazon Managed Grafana, Amazon, Amazon Inspector GuardDuty,, AWS IoT AWS IoT TwinMaker, Amazon Managed Streaming untuk Apache Kafka (Amazon MSK),,, AWS Lambda AWS Network Manager, AWS Organizations dan Amazon AI. SageMaker |
4 Oktober 2023 |
| AWSConfigServiceRolePolicy— Hapus "ssm:GetParameter" |
Kebijakan ini sekarang menghapus izin untuk AWS Systems Manager (Manajer Sistem). |
September 6, 2023 |
| AWS_ConfigRole— Tambah "appmesh:DescribeGatewayRoute","appstream:DescribeStacks", "aps:ListTagsForResource", "cloudfront:GetFunction", "cloudfront:GetOriginAccessControl", "cloudfront:ListFunctions", "cloudfront:ListOriginAccessControls", "codeartifact:ListPackages", "codeartifact:ListPackageVersions", "codebuild:BatchGetReportGroups", "codebuild:ListReportGroups", "connect:ListInstanceAttributes", "connect:ListInstances", "glue:GetPartition", "glue:GetPartitions", "guardduty:GetAdministratorAccount", "iam:ListInstanceProfileTags", "inspector2:ListFilters", "iot:DescribeJobTemplate", "iot:DescribeProvisioningTemplate", "iot:ListJobTemplates", "iot:ListProvisioningTemplates", "iottwinmaker:GetComponentType", "iottwinmaker:ListComponentTypes", "iotwireless:GetFuotaTask", "iotwireless:GetMulticastGroup", "iotwireless:ListFuotaTasks", "iotwireless:ListMulticastGroups", "kafka:ListScramSecrets", "macie2:ListTagsForResource", "mediaconnect:ListTagsForResource", "networkmanager:GetConnectPeer", "networkmanager:ListConnectPeers", "organizations:DescribeEffectivePolicy", "organizations:DescribeResourcePolicy", "resource-explorer-2:GetIndex", "resource-explorer-2:ListIndexes", "resource-explorer-2:ListTagsForResource", "route53:ListCidrCollections", "s3:GetMultiRegionAccessPointPolicy", "s3:GetMultiRegionAccessPointPolicyStatus", and "sns:GetDataProtectionPolicy" |
Kebijakan ini sekarang mendukung izin tambahan untuk AWS App Mesh,, Amazon AWS CloudFormation, CloudFront AWS CodeArtifact AWS CodeBuild, Amazon Connect Customer,, Amazon AWS Glue, AWS Identity and Access Management (IAM) GuardDuty, Amazon Inspector,,, AWS IoT AWS IoT TwinMaker AWS IoT Wireless, Amazon Managed Streaming untuk Apache Kafka, Amazon Macie,,,, AWS Elemental MediaConnect AWS Network Manager, Amazon Route 53 AWS Organizations AWS Penjelajah Sumber Daya, Amazon Simple Storage Service (Amazon S3), dan Amazon Simple Notification Service (Amazon SNS). |
28 Juli 2023 |
| AWSConfigServiceRolePolicy— Tambah "appmesh:DescribeGatewayRoute", "appstream:DescribeStacks", "aps:ListTagsForResource", "cloudfront:GetFunction", "cloudfront:GetOriginAccessControl", "cloudfront:ListFunctions", "cloudfront:ListOriginAccessControls", "codeartifact:ListPackages", "codeartifact:ListPackageVersions", "codebuild:BatchGetReportGroups", "codebuild:ListReportGroups", "connect:ListInstanceAttributes", "connect:ListInstances", "glue:GetPartition", "glue:GetPartitions", "guardduty:GetAdministratorAccount", "iam:ListInstanceProfileTags", "inspector2:ListFilters", "iot:DescribeJobTemplate", "iot:DescribeProvisioningTemplate", "iot:ListJobTemplates", "iot:ListProvisioningTemplates", "iottwinmaker:GetComponentType", "iottwinmaker:ListComponentTypes", "iotwireless:GetFuotaTask", "iotwireless:GetMulticastGroup", "iotwireless:ListFuotaTasks", "iotwireless:ListMulticastGroups", "kafka:ListScramSecrets", "macie2:ListTagsForResource", "mediaconnect:ListTagsForResource", "networkmanager:GetConnectPeer", "networkmanager:ListConnectPeers", "organizations:DescribeEffectivePolicy", "organizations:DescribeResourcePolicy", "resource-explorer-2:GetIndex", "resource-explorer-2:ListIndexes", "resource-explorer-2:ListTagsForResource", "route53:ListCidrCollections", "s3:GetMultiRegionAccessPointPolicy", "s3:GetMultiRegionAccessPointPolicyStatus", "sns:GetDataProtectionPolicy", "ssm:DescribeParameters", "ssm:GetParameter", and "ssm:ListTagsForResource" |
Kebijakan ini sekarang mendukung izin tambahan untuk AWS App Mesh, WorkSpaces Aplikasi Amazon,, AWS CloudFormation, Amazon Connect Customer CloudFront AWS CodeArtifact AWS CodeBuild,, Amazon, AWS Identity and Access Management (IAM) AWS Glue GuardDuty, Amazon Inspector,,, AWS IoT AWS IoT TwinMaker AWS IoT Wireless, Amazon Managed Streaming untuk Apache Kafka, Amazon Macie,,,, Amazon Route 53 AWS Elemental MediaConnect AWS Network Manager AWS Organizations AWS Penjelajah Sumber Daya, Amazon Simple Storage Service (Amazon S3), Amazon Simple Notification Service (Amazon SNS), dan Amazon EC2 Systems Manager (SSM). |
28 Juli 2023 |
| AWS_ConfigRole— Tambah "amplify:GetBranch", "amplify:ListBranches", "app-integrations:GetEventIntegration", "app-integrations:ListEventIntegrationAssociations", "app-integrations:ListEventIntegrations", "appmesh:DescribeRoute", "appmesh:ListRoutes", "aps:ListRuleGroupsNamespaces", "athena:GetPreparedStatement", "athena:ListPreparedStatements", "batch:DescribeSchedulingPolicies", "batch:ListSchedulingPolicies", "cloudformation:ListTypes", "cloudtrail:ListTrails", "codeartifact:ListDomains", "codeguru-profiler:DescribeProfilingGroup", "codeguru-profiler:GetNotificationConfiguration", "codeguru-profiler:GetPolicy", "codeguru-profiler:ListProfilingGroups", "ds:DescribeDomainControllers", “dynamodb:DescribeTableReplicaAutoScaling" "dynamodb:DescribeTimeToLive", "ec2:DescribeTrafficMirrorFilters", "evidently:GetLaunch", "evidently:ListLaunches", "forecast:DescribeDatasetGroup", "forecast:ListDatasetGroups", "greengrass:DescribeComponent", "greengrass:GetComponent", "greengrass:ListComponents", "greengrass:ListComponentVersions", "groundstation:GetMissionProfile", "groundstation:ListMissionProfiles", "iam:ListGroups", "iam:ListRoles", "kafka:DescribeConfiguration", "kafka:DescribeConfigurationRevision", "kafka:ListConfigurations", "lightsail:GetRelationalDatabases" "logs:ListTagsLogGroup", "mediaconnect:DescribeFlow", "mediaconnect:ListFlows", "mediatailor:GetPlaybackConfiguration", "mediatailor:ListPlaybackConfigurations", "mobiletargeting:GetApplicationSettings", "mobiletargeting:GetEmailTemplate", "mobiletargeting:GetEventStream", "mobiletargeting:ListTemplates", "networkmanager:GetCustomerGatewayAssociations", "networkmanager:GetLinkAssociations", "organizations:DescribeAccount", "organizations:DescribeOrganizationalUnit", "organizations:ListAccounts", "organizations:ListAccountsForParent", "organizations:ListOrganizationalUnitsForParent", "organizations:ListTagsForResource", "personalize:DescribeDataset", "personalize:DescribeDatasetGroup", "personalize:DescribeSchema", "personalize:DescribeSolution", "personalize:ListDatasetGroups", "personalize:ListDatasetImportJobs", "personalize:ListDatasets", "personalize:ListSchemas", "personalize:ListSolutions", "personalize:ListTagsForResource", "quicksight:ListTemplates", "refactor-spaces:GetEnvironment", "refactor-spaces:GetService", "refactor-spaces:ListApplications", "refactor-spaces:ListEnvironments", "refactor-spaces:ListServices", "s3:GetAccessPointPolicyStatusForObjectLambda", "sagemaker:DescribeDeviceFleet", "sagemaker:DescribeFeatureGroup", "sagemaker:ListDeviceFleets", "sagemaker:ListFeatureGroups", "sagemaker:ListModels", and "transfer:ListTagsForResource" |
Kebijakan ini sekarang mendukung izin tambahan untuk AWS Amplify, Amazon Connect Customer, AWS App Mesh, Amazon Managed Service untuk Prometheus, Amazon Athena,,,, Amazon, AWS Batch, Amazon AWS CloudFormation, AWS CloudTrail AWS CodeArtifact, Amazon DynamoDB CodeGuru AWS Directory Service, Amazon Elastic Compute Cloud (Amazon EC2), Amazon E CloudWatch vidently,, Amazon Forecast,,, AWS Identity and Access Management (IAM) AWS Organizations AWS IoT Greengrass AWS Ground Station, Amazon Managed Streaming untuk Apache Kafka (Amazon MSK), Amazon Lightsail, Amazon Logs,, Amazon Cloud Pinpoint, Amazon Virtual Private ( CloudWatch AWS Elemental MediaConnect AWS Elemental MediaTailor Amazon VPC), Personalisasi Amazon, Amazon Cepat, AWS Migration Hub Refactor Spaces, Layanan Penyimpanan Sederhana Amazon (Amazon S3), Amazon SageMaker AI, AWS Transfer Family. |
13 Juni 2023 |
| AWSConfigServiceRolePolicy— Tambah "amplify:GetBranch", "amplify:ListBranches", "app-integrations:GetEventIntegration", "app-integrations:ListEventIntegrationAssociations", "app-integrations:ListEventIntegrations", "appmesh:DescribeRoute", "appmesh:ListRoutes", "aps:ListRuleGroupsNamespaces", "athena:GetPreparedStatement", "athena:ListPreparedStatements", "batch:DescribeSchedulingPolicies", "batch:ListSchedulingPolicies", "cloudformation:ListTypes", "cloudtrail:ListTrails", "codeartifact:ListDomains", "codeguru-profiler:DescribeProfilingGroup", "codeguru-profiler:GetNotificationConfiguration", "codeguru-profiler:GetPolicy", "codeguru-profiler:ListProfilingGroups", "ds:DescribeDomainControllers", "dynamodb:DescribeTableReplicaAutoScaling", "dynamodb:DescribeTimeToLive", "ec2:DescribeTrafficMirrorFilters", "evidently:GetLaunch", "evidently:ListLaunches", "forecast:DescribeDatasetGroup", "forecast:ListDatasetGroups", "greengrass:DescribeComponent", "greengrass:GetComponent", "greengrass:ListComponents", "greengrass:ListComponentVersions", "groundstation:GetMissionProfile", "groundstation:ListMissionProfiles", "iam:ListGroups", "iam:ListRoles", "kafka:DescribeConfiguration", "kafka:DescribeConfigurationRevision", "kafka:ListConfigurations", "lightsail:GetRelationalDatabases", "logs:ListTagsLogGroup", "mediaconnect:DescribeFlow", "mediaconnect:ListFlows", "mediatailor:GetPlaybackConfiguration", "mediatailor:ListPlaybackConfigurations", "mobiletargeting:GetApplicationSettings", "mobiletargeting:GetEmailTemplate", "mobiletargeting:GetEventStream", "mobiletargeting:ListTemplates", "networkmanager:GetCustomerGatewayAssociations", "networkmanager:GetLinkAssociations", "organizations:DescribeAccount", "organizations:DescribeOrganizationalUnit", "organizations:ListAccounts", "organizations:ListAccountsForParent", "organizations:ListOrganizationalUnitsForParent", "organizations:ListTagsForResource", "personalize:DescribeDataset", "personalize:DescribeDatasetGroup", "personalize:DescribeSchema", "personalize:DescribeSolution", "personalize:ListDatasetGroups", "personalize:ListDatasetImportJobs", "personalize:ListDatasets", "personalize:ListSchemas", "personalize:ListSolutions", "personalize:ListTagsForResource", "quicksight:ListTemplates", "refactor-spaces:GetEnvironment", "refactor-spaces:GetService", "refactor-spaces:ListApplications", "refactor-spaces:ListEnvironments", "refactor-spaces:ListServices", "s3:GetAccessPointPolicyStatusForObjectLambda", "sagemaker:DescribeDeviceFleet", "sagemaker:DescribeFeatureGroup", "sagemaker:ListDeviceFleets", "sagemaker:ListFeatureGroups", "sagemaker:ListModels", and "transfer:ListTagsForResource" |
Kebijakan ini sekarang mendukung izin tambahan untuk AWS Amplify, Amazon Connect Customer, AWS App Mesh, Amazon Managed Service untuk Prometheus, Amazon Athena,,,, Amazon, AWS Batch, Amazon AWS CloudFormation, AWS CloudTrail AWS CodeArtifact, Amazon DynamoDB CodeGuru AWS Directory Service, Amazon Elastic Compute Cloud (Amazon EC2), Amazon E CloudWatch vidently,, Amazon Forecast,,, AWS Identity and Access Management (IAM) AWS Organizations AWS IoT Greengrass AWS Ground Station, Amazon Managed Streaming untuk Apache Kafka (Amazon MSK), Amazon Lightsail, Amazon Logs,, Amazon Cloud Pinpoint, Amazon Virtual Private ( CloudWatch AWS Elemental MediaConnect AWS Elemental MediaTailor Amazon VPC), Personalisasi Amazon, Amazon Cepat, AWS Migration Hub Refactor Spaces, Layanan Penyimpanan Sederhana Amazon (Amazon S3), Amazon SageMaker AI, AWS Transfer Family. |
13 Juni 2023 |
| AWSConfigServiceRolePolicy— Tambah amplify:GetApp, amplify:ListApps, appmesh:DescribeVirtualGateway, appmesh:DescribeVirtualNode, appmesh:DescribeVirtualRouter, appmesh:DescribeVirtualService, appmesh:ListMeshes, appmesh:ListTagsForResource, appmesh:ListVirtualGateways, appmesh:ListVirtualNodes, appmesh:ListVirtualRouters, appmesh:ListVirtualServices, apprunner:DescribeVpcConnector, apprunner:ListVpcConnectors, cloudformation:ListTypes, cloudfront:ListResponseHeadersPolicies, codeartifact:ListRepositories, ds:DescribeEventTopics, ds:ListLogSubscriptions, GetInstanceTypesFromInstanceRequirement ec2:GetManagedPrefixListEntries, kendra:DescribeIndex, kendra:ListIndices, kendra:ListTagsForResource, logs:DescribeDestinations, logs:GetDataProtectionPolicy, macie2:DescribeOrganizationConfiguration, macie2:GetAutomatedDiscoveryConfiguration, macie2:GetClassificationExportConfiguration, macie2:GetCustomDataIdentifier, macie2:GetFindingsPublicationConfiguration, macie2:ListCustomDataIdentifiers, mobiletargeting:GetEmailChannel, refactor-spaces:GetEnvironment, refactor-spaces:ListEnvironments, resiliencehub:ListTagsForResource, route53:GetDNSSEC, sagemaker:DescribeDomain, sagemaker:DescribeModelBiasJobDefinition, sagemaker:DescribeModelQualityJobDefinition, sagemaker:DescribePipeline, sagemaker:DescribeProject, sagemaker:ListDomains, sagemaker:ListModelBiasJobDefinitions, sagemaker:ListModelQualityJobDefinitions, sagemaker:ListPipelines, sagemaker:ListProjects, transfer:DescribeAgreement, transfer:DescribeCertificate, transfer:ListAgreements, transfer:ListCertificates, and waf-regional:ListLoggingConfigurations |
Kebijakan ini sekarang mendukung izin tambahan untuk Alur Kerja Terkelola Amazon untuk AWS Amplify, AWS App Mesh, Amazon AWS App Runner, CloudFront AWS CodeArtifact, Amazon Elastic Compute Cloud, Amazon Kendra, Amazon Macie, Amazon Route 53, Amazon SageMaker AI,, Amazon Pinpoint, AWS Transfer Family, Resilience Hub, Amazon AWS Migration Hub, AWS Directory Service CloudWatch, AWS dan. AWS WAF |
13 April 2023 |
| AWS_ConfigRole— Tambah amplify:GetApp, amplify:ListApps, appmesh:DescribeVirtualGateway, appmesh:DescribeVirtualNode, appmesh:DescribeVirtualRouter, appmesh:DescribeVirtualService, appmesh:ListMeshes, appmesh:ListTagsForResource, appmesh:ListVirtualGateways, appmesh:ListVirtualNodes, appmesh:ListVirtualRouters, appmesh:ListVirtualServices, apprunner:DescribeVpcConnector, apprunner:ListVpcConnectors, cloudformation:ListTypes, cloudfront:ListResponseHeadersPolicies, codeartifact:ListRepositories, ds:DescribeEventTopics, ds:ListLogSubscriptions, ec2:GetInstanceTypesFromInstanceRequirement, ec2:GetManagedPrefixListEntries, kendra:DescribeIndex, kendra:ListIndices, kendra:ListTagsForResource, logs:DescribeDestinations, logs:GetDataProtectionPolicy, macie2:DescribeOrganizationConfiguration, macie2:GetAutomatedDiscoveryConfiguration, macie2:GetClassificationExportConfiguration, macie2:GetCustomDataIdentifier, macie2:GetFindingsPublicationConfiguration, macie2:ListCustomDataIdentifiers, mobiletargeting:GetEmailChannel, refactor-spaces:GetEnvironment, refactor-spaces:ListEnvironments, resiliencehub:ListTagsForResource, route53:GetDNSSEC, sagemaker:DescribeDomain, sagemaker:DescribeModelBiasJobDefinition, sagemaker:DescribeModelQualityJobDefinition, sagemaker:DescribePipeline, sagemaker:DescribeProject, sagemaker:ListDomains, sagemaker:ListModelBiasJobDefinitions, sagemaker:ListModelQualityJobDefinitions, sagemaker:ListPipelines, sagemaker:ListProjects, transfer:DescribeAgreement, transfer:DescribeCertificate, transfer:ListAgreements, transfer:ListCertificates, and waf-regional:ListLoggingConfigurations |
Kebijakan ini sekarang mendukung izin tambahan untuk Alur Kerja Terkelola Amazon untuk AWS Amplify, AWS App Mesh, Amazon AWS App Runner, CloudFront AWS CodeArtifact, Amazon Elastic Compute Cloud, Amazon Kendra, Amazon Macie, Amazon Route 53, Amazon SageMaker AI,, Amazon Pinpoint, AWS Transfer Family, Resilience Hub, Amazon AWS Migration Hub, AWS Directory Service CloudWatch, AWS dan. AWS WAF |
13 April 2023 |
| AWSConfigServiceRolePolicy— Tambah appflow:DescribeFlow, appflow:ListFlows, appflow:ListTagsForResource, apprunner:DescribeService, apprunner:ListServices, apprunner:ListTagsForResource, appstream:DescribeApplications, appstream:DescribeFleets, cloudfront:GetResponseHeadersPolicy, cloudwatch:ListTagsForResource, codeartifact:DescribeRepository, codeartifact:GetRepositoryPermissionsPolicy, codeartifact:ListTagsForResource, codecommit:GetRepository, codecommit:GetRepositoryTriggers, codecommit:ListRepositories, codecommit:ListTagsForResource, devicefarm:GetInstanceProfile, devicefarm:ListInstanceProfiles, devicefarm:ListProjects, evidently:GetProject, evidently:ListProjects, evidently:ListTagsForResource, forecast:DescribeDataset, forecast:ListDatasets, forecast:ListTagsForResource, groundstation:GetConfig, groundstation:ListConfigs, groundstation:ListTagsForResource, iam:GetInstanceProfile, iam:GetSAMLProvider, iam:GetServerCertificate, iam:ListAccessKeys, iam:ListGroups, iam:ListInstanceProfiles, iam:ListMFADevices, iam:ListMFADeviceTags, iam:ListRoles, iam:ListSAMLProviders, iot:DescribeFleetMetric, iot:ListFleetMetrics, memorydb:DescribeUsers, memorydb:ListTags, mobiletargeting:GetApp, mobiletargeting:GetCampaigns, networkmanager:GetDevices, networkmanager:GetLinks, networkmanager:GetSites, panorama:ListNodes, rds:DescribeDBProxyEndpoints, redshift:DescribeScheduledActions, sagemaker:DescribeAppImageConfig, sagemaker:DescribeImage, sagemaker:DescribeImageVersion, sagemaker:ListAppImageConfigs, sagemaker:ListImages, and sagemaker:ListImageVersions |
Kebijakan ini sekarang mendukung izin tambahan untuk Alur Kerja Terkelola Amazon untuk Amazon AppFlow, AWS App Runner, WorkSpaces Aplikasi Amazon, Amazon, CloudFront,, CloudWatch AWS CodeArtifact, Amazon CloudWatch Evidently AWS CodeCommit AWS Device Farm, Amazon Forecast,, AWS Identity and Access Management (IAM) AWS Ground Station,, Amazon MemoryDB AWS IoT, Amazon Pinpoint,,, Amazon Relational Database Service (Amazon RDS) AWS Network Manager AWS Panorama, Amazon Redshift, dan Amazon AI. SageMaker |
30 Maret 2023 |
| AWS_ConfigRole— Tambah appflow:DescribeFlow, appflow:ListFlows, appflow:ListTagsForResource, apprunner:DescribeService, apprunner:ListServices, apprunner:ListTagsForResource, appstream:DescribeApplications, appstream:DescribeFleets, cloudformation:ListTypes, cloudfront:GetResponseHeadersPolicy, cloudfront:ListDistributions, cloudwatch:ListTagsForResource, codeartifact:DescribeRepository, codeartifact:GetRepositoryPermissionsPolicy, codeartifact:ListTagsForResource, codecommit:GetRepository, codecommit:GetRepositoryTriggers, codecommit:ListRepositories, codecommit:ListTagsForResource, devicefarm:GetInstanceProfile, devicefarm:ListInstanceProfiles, devicefarm:ListProjects, ec2:DescribeTrafficMirrorFilters, evidently:GetProject, evidently:ListProjects, evidently:ListTagsForResource, forecast:DescribeDataset, forecast:ListDatasets, forecast:ListTagsForResource, groundstation:GetConfig, groundstation:ListConfigs, groundstation:ListTagsForResource, iam:GetInstanceProfile, iam:GetSAMLProvider, iam:GetServerCertificate, iam:ListAccessKeys, iam:ListGroups, iam:ListInstanceProfiles, iam:ListMFADevices, iam:ListMFADeviceTags, iam:ListRoles, iam:ListSAMLProviders, iot:DescribeFleetMetric, iot:ListFleetMetrics, memorydb:DescribeUsers, memorydb:ListTags, mobiletargeting:GetApp, mobiletargeting:GetCampaigns, networkmanager:GetDevices, networkmanager:GetLinks, networkmanager:GetSites, panorama:ListNodes, rds:DescribeDBProxyEndpoints, redshift:DescribeScheduledActions, sagemaker:DescribeAppImageConfig, sagemaker:DescribeImage, sagemaker:DescribeImageVersion, sagemaker:ListAppImageConfigs, sagemaker:ListImages, and sagemaker:ListImageVersions |
Kebijakan ini sekarang mendukung izin tambahan untuk Alur Kerja Terkelola Amazon untuk Amazon AppFlow, AWS App Runner, WorkSpaces Aplikasi Amazon,, Amazon AWS CloudFormation,, CloudFront, CloudWatch AWS CodeArtifact AWS CodeCommit AWS Device Farm, Amazon Elastic Compute Cloud (Amazon EC2), Amazon E CloudWatch vidently, Amazon Forecast,, AWS Identity and Access Management (IAM), AWS Ground Station, Amazon MemoryDB, Amazon Pinpoint AWS IoT,,, Amazon Relational Database Service (Amazon RDS) AWS Network Manager AWS Panorama, Amazon Redshift, dan Amazon AI. SageMaker |
30 Maret 2023 |
|
AWSConfigRulesExecutionRole— AWS Config mulai melacak perubahan untuk kebijakan terkel AWS ola ini |
Kebijakan ini memungkinkan AWS Lambda fungsi mengakses AWS Config API dan snapshot konfigurasi yang dikirimkan secara ber AWS Config kala ke Amazon S3. Akses ini diperlukan oleh fungsi yang mengevaluasi perubahan konfigurasi untuk aturan Lambda K AWS ustom. |
7 Maret 2023 |
|
AWSConfigRoleForOrganizations— AWS Config mulai melacak perubahan untuk kebijakan terkel AWS ola ini |
Kebijakan ini memungkinkan AWS Config untuk memanggil API read-only AWS Organizations . |
7 Maret 2023 |
|
AWSConfigRemediationServiceRolePolicy— AWS Config mulai melacak perubahan untuk kebijakan terkel AWS ola ini |
Kebijakan ini memungkinkan AWS Config untuk memperbaiki sumber |
7 Maret 2023 |
|
AWSConfigServiceRolePolicy— Tambah auditmanager:GetAccountStatus |
Kebijakan ini sekarang memberikan izin untuk mengembalikan status pendaftaran akun di AWS Audit Manager. |
3 Maret 2023 |
|
AWS_ConfigRole— Tambah auditmanager:GetAccountStatus |
Kebijakan ini sekarang memberikan izin untuk mengembalikan status pendaftaran akun di AWS Audit Manager. |
3 Maret 2023 |
|
AWSConfigMultiAccountSetupPolicy— AWS Config mulai melacak perubahan untuk kebijakan terkel AWS ola ini |
Kebijakan ini memungkinkan AWS Config untuk memanggil AWS layanan dan menyebarkan AWS Config sumber daya di seluruh organisasi dengan AWS Organizations. |
27 Februari 2023 |
|
AWSConfigServiceRolePolicy— Tambah airflow:ListTagsForResource, iot:ListCustomMetrics, iot:DescribeCustomMetric, appstream:DescribeDirectoryConfigs, appstream:ListTagsForResource, codeguru-reviewer:DescribeRepositoryAssociation, codeguru-reviewer:ListRepositoryAssociations, healthlake:ListFHIRDatastores, healthlake:DescribeFHIRDatastore, healthlake:ListTagsForResource, kinesisvideo:DescribeStream, kinesisvideo:ListStreams, kinesisvideo:ListTagsForStream, kinesisvideo:DescribeSignalingChannel, kinesisvideo:ListTagsForResource, kinesisvideo:ListSignalingChannels, route53-recovery-control-config:DescribeCluster, route53-recovery-control-config:DescribeRoutingControl, route53-recovery-control-config:DescribeSafetyRule, route53-recovery-control-config:ListClusters, route53-recovery-control-config:ListRoutingControls, route53-recovery-control-config:ListSafetyRules, devicefarm:GetTestGridProject, devicefarm:ListTestGridProjects, ec2:DescribeCapacityReservationFleets, ec2:DescribeIpamPools, ec2:DescribeIpams, ec2:GetInstanceTypesFromInstanceRequirement, mobiletargeting:GetApplicationSettings, mobiletargeting:ListTagsForResource, ecr:BatchGetRepositoryScanningConfiguration, iam:ListServerCertificates, guardduty:ListPublishingDestinations, guardduty:DescribePublishingDestination, logs:GetLogDelivery, and logs:ListLogDeliveries |
Kebijakan ini sekarang mendukung izin tambahan untuk Alur Kerja Terkelola Amazon untuk Apache Airflow AWS IoT,, WorkSpaces Aplikasi Amazon, Amazon CodeGuru Reviewer AWS HealthLake, Amazon Kinesis Video Streams, Amazon Application Recovery Controller (ARC) AWS Device Farm, Amazon Elastic Compute Cloud (Amazon EC2), Amazon Pinpoint, AWS Identity and Access Management (IAM), Amazon, dan Amazon Logs. GuardDuty CloudWatch |
1 Februari 2023 |
|
AWS_ConfigRole— Tambah airflow:ListTagsForResource, iot:ListCustomMetrics, iot:DescribeCustomMetric, appstream:DescribeDirectoryConfigs, appstream:ListTagsForResource, codeguru-reviewer:DescribeRepositoryAssociation, codeguru-reviewer:ListRepositoryAssociations, healthlake:ListFHIRDatastores, healthlake:DescribeFHIRDatastore, healthlake:ListTagsForResource, kinesisvideo:DescribeStream, kinesisvideo:ListStreams, kinesisvideo:ListTagsForStream, kinesisvideo:DescribeSignalingChannel, kinesisvideo:ListTagsForResource, kinesisvideo:ListSignalingChannels, route53-recovery-control-config:DescribeCluster, route53-recovery-control-config:DescribeRoutingControl, route53-recovery-control-config:DescribeSafetyRule, route53-recovery-control-config:ListClusters, route53-recovery-control-config:ListRoutingControls, route53-recovery-control-config:ListSafetyRules, devicefarm:GetTestGridProject, devicefarm:ListTestGridProjects, ec2:DescribeCapacityReservationFleets, ec2:DescribeIpamPools, ec2:DescribeIpams, ec2:GetInstanceTypesFromInstanceRequirement, mobiletargeting:GetApplicationSettings, mobiletargeting:ListTagsForResource, ecr:BatchGetRepositoryScanningConfiguration, iam:ListServerCertificates, guardduty:ListPublishingDestinations, guardduty:DescribePublishingDestination, logs:GetLogDelivery, and logs:ListLogDeliveries |
Kebijakan ini sekarang mendukung izin tambahan untuk Alur Kerja Terkelola Amazon untuk Apache Airflow AWS IoT,, WorkSpaces Aplikasi Amazon, Amazon CodeGuru Reviewer AWS HealthLake, Amazon Kinesis Video Streams, Amazon Application Recovery Controller (ARC) AWS Device Farm, Amazon Elastic Compute Cloud (Amazon EC2), Amazon Pinpoint, AWS Identity and Access Management (IAM), Amazon, dan Amazon Logs. GuardDuty CloudWatch |
1 Februari 2023 |
|
ConfigConformsServiceRolePolicy— Perbarui config:DescribeConfigRules |
Sebagai praktik terbaik keamanan, kebijakan ini sekarang menghapus izin tingkat sumber daya yang luas untuk. |
Januari 12, 2023 |
|
AWSConfigServiceRolePolicy— Tambah APS:DescribeRuleGroupsNamespace, APS:DescribeWorkspace, APS:ListWorkspaces, auditmanager:GetAssessment, auditmanager:ListAssessments, devicefarm:GetNetworkProfile, AWS Transfer Family devicefarm:GetProject, devicefarm:ListNetworkProfiles, devicefarm:ListTagsForResource, dms:DescribeEndpoints, ds:ListTagsForResource, ec2:DescribeTags, ec2:DescribeTrafficMirrorSessions, ec2:DescribeTrafficMirrorTargets, ec2:GetIpamPoolAllocations, ec2:GetIpamPoolCidrs, glue:GetMLTransform, glue:GetMLTransforms, glue:ListMLTransforms, iot:DescribeScheduledAudit, iot:ListScheduledAudits, ivs:GetChannel, lightsail:GetRelationalDatabases, mediapackage-vod:DescribePackagingConfiguration, mediapackage-vod:ListPackagingConfigurations, networkmanager:DescribeGlobalNetworks, networkmanager:GetTransitGatewayRegistrations, networkmanager:ListTagsForResource, quicksight:DescribeDashboard, quicksight:DescribeDashboardPermissions, quicksight:DescribeTemplate, quicksight:DescribeTemplatePermissions, quicksight:ListDashboards, quicksight:ListTemplates, ram:ListResources, route53-recovery-control-config:DescribeControlPanel, route53-recovery-control-config:ListControlPanels, route53-recovery-control-config:ListTagsForResource, route53resolver:GetResolverQueryLogConfigAssociation, route53resolver:ListResolverQueryLogConfigAssociations, s3:GetAccessPointForObjectLambda, s3:GetAccessPointPolicyForObjectLambda, s3:GetAccessPointPolicyStatusForObjectLambda, s3:GetMultiRegionAccessPoint, s3:ListAccessPointsForObjectLambda, s3:ListMultiRegionAccessPoints, timestream:DescribeEndpoints, transfer:DescribeConnector, transfer:ListConnectors, and transfer:ListTagsForResource |
Kebijakan ini sekarang mendukung izin tambahan untuk Layanan Terkelola Amazon untuk Prometheus,, AWS Audit Manager, AWS Database Migration Service (AWS DMS) AWS Device Farm, AWS Directory Service, Amazon Elastic Compute Cloud (Amazon EC2),,, Amazon Lightsail AWS Glue, AWS IoT, Amazon Quick, AWS Elemental MediaPackage AWS Network Manager, Amazon Application Recovery Controller (ARC) AWS Resource Access Manager, Amazon Simple Storage Service (Amazon S3), dan Amazon Timestream. |
Desember 15, 2022 |
|
AWS_ConfigRole— Tambah APS:DescribeRuleGroupsNamespace, APS:DescribeWorkspace, APS:ListWorkspaces, auditmanager:GetAssessment, auditmanager:ListAssessments, devicefarm:GetNetworkProfile, devicefarm:GetProject, devicefarm:ListNetworkProfiles, devicefarm:ListTagsForResource, dms:DescribeEndpoints, ds:ListTagsForResource, ec2:DescribeTags, ec2:DescribeTrafficMirrorSessions, ec2:DescribeTrafficMirrorTargets, ec2:GetIpamPoolAllocations, ec2:GetIpamPoolCidrs, glue:GetMLTransform, glue:GetMLTransforms, glue:ListMLTransforms, iot:DescribeScheduledAudit, iot:ListScheduledAudits, ivs:GetChannel, lightsail:GetRelationalDatabases, mediapackage-vod:DescribePackagingConfiguration, mediapackage-vod:ListPackagingConfigurations, networkmanager:DescribeGlobalNetworks, networkmanager:GetTransitGatewayRegistrations, networkmanager:ListTagsForResource, quicksight:DescribeDashboard, quicksight:DescribeDashboardPermissions, quicksight:DescribeTemplate, quicksight:DescribeTemplatePermissions, quicksight:ListDashboards, quicksight:ListTemplates, ram:ListResources, route53-recovery-control-config:DescribeControlPanel, route53-recovery-control-config:ListControlPanels, route53-recovery-control-config:ListTagsForResource, route53resolver:GetResolverQueryLogConfigAssociation, route53resolver:ListResolverQueryLogConfigAssociations, s3:GetAccessPointForObjectLambda, s3:GetAccessPointPolicyForObjectLambda, s3:GetAccessPointPolicyStatusForObjectLambda, s3:GetMultiRegionAccessPoint, s3:ListAccessPointsForObjectLambda, s3:ListMultiRegionAccessPoints, timestream:DescribeEndpoints, transfer:DescribeConnector, transfer:ListConnectors, and transfer:ListTagsForResource |
Kebijakan ini sekarang mendukung izin tambahan untuk Layanan Terkelola Amazon untuk Prometheus,, AWS Audit Manager, AWS Database Migration Service (AWS DMS) AWS Device Farm, AWS Directory Service, Amazon Elastic Compute Cloud (Amazon EC2),,, Amazon Lightsail AWS Glue, AWS IoT, Amazon Quick, AWS Elemental MediaPackage AWS Network Manager, Amazon Application Recovery Controller (ARC) AWS Resource Access Manager, Amazon Simple Storage Service (Amazon S3), dan Amazon Timestream. |
Desember 15, 2022 |
|
AWSConfigServiceRolePolicy— Tambah cloudformation:ListStackResources and cloudformation:ListStacks |
Kebijakan ini sekarang memberikan izin untuk mengembalikan deskripsi semua sumber daya dari AWS CloudFormation tumpukan tertentu dan mengembalikan informasi ringkasan untuk tumpukan yang statusnya cocok dengan yang ditentukanStackStatusFilter. |
7 November 2022 |
|
AWS_ConfigRole— Tambah cloudformation:ListStackResources and cloudformation:ListStacks |
Kebijakan ini sekarang memberikan izin untuk mengembalikan deskripsi semua sumber daya dari AWS CloudFormation tumpukan tertentu dan mengembalikan informasi ringkasan untuk tumpukan yang statusnya cocok dengan yang ditentukanStackStatusFilter. |
7 November 2022 |
|
AWSConfigServiceRolePolicy— Tambah acm-pca:GetCertificateAuthorityCsr, acm-pca:ListCertificateAuthorities, acm-pca:ListTags, airflow:GetEnvironment, airflow:ListEnvironments, amplifyuibuilder:ListThemes, appconfig:ListConfigurationProfiles, appconfig:ListDeployments, appconfig:ListDeploymentStrategies, appconfig:ListEnvironments, appconfig:ListHostedConfigurationVersions, cassandra:Select, cloudwatch:DescribeAnomalyDetectors, cloudwatch:GetDashboard, cloudwatch:ListDashboards, connect:DescribePhoneNumber, connect:ListPhoneNumbers, connect:ListPhoneNumbersV2, connect:SearchAvailablePhoneNumbers, databrew:DescribeDataset, databrew:DescribeJob, databrew:DescribeProject, databrew:DescribeRecipe, databrew:DescribeRuleset, databrew:DescribeSchedule, databrew:ListDatasets, databrew:ListJobs, databrew:ListProjects, databrew:ListRecipes, databrew:ListRecipeVersions, databrew:ListRulesets, databrew:ListSchedules, ec2:DescribeRouteTables, eks:DescribeAddon, eks:DescribeIdentityProviderConfig, eks:ListAddons, eks:ListIdentityProviderConfigs, events:DescribeConnection, events:ListApiDestinations, events:ListConnections, fis:GetExperimentTemplate, fis:ListExperimentTemplates, frauddetector:GetRules, fsx:DescribeBackups, fsx:DescribeSnapshots, fsx:DescribeStorageVirtualMachines, gamelift:DescribeMatchmakingRuleSets, gamelift:DescribeVpcPeeringConnections, geo:ListGeofenceCollections, geo:ListPlaceIndexes, geo:ListRouteCalculators, geo:ListTrackers, iot:DescribeAccountAuditConfiguration, iot:DescribeAuthorizer, iot:DescribeDomainConfiguration, iot:DescribeMitigationAction, iot:ListAuthorizers, iot:ListDomainConfigurations, iot:ListMitigationActions, iotsitewise:DescribeAssetModel, iotsitewise:DescribeDashboard, iotsitewise:DescribeGateway, iotsitewise:DescribePortal, iotsitewise:DescribeProject, iotsitewise:ListAssetModels, iotsitewise:ListDashboards, iotsitewise:ListGateways, iotsitewise:ListPortals, iotsitewise:ListProjectAssets, iotsitewise:ListProjects, iotsitewise:ListTagsForResource, iotwireless:GetServiceProfile, iotwireless:GetWirelessDevice, iotwireless:GetWirelessGatewayTaskDefinition, iotwireless:ListServiceProfiles, iotwireless:ListTagsForResource, iotwireless:ListWirelessDevices, iotwireless:ListWirelessGatewayTaskDefinitions, lex:DescribeBotVersion, lex:ListBotVersions, lightsail:GetContainerServices, lightsail:GetDistributions, lightsail:GetRelationalDatabase, lightsail:GetRelationalDatabaseParameters, mobiletargeting:GetApps, mobiletargeting:GetCampaign, mobiletargeting:GetSegment, mobiletargeting:GetSegments, opsworks:DescribeInstances, opsworks:DescribeTimeBasedAutoScaling, opsworks:DescribeVolumes, panorama:DescribeApplicationInstance, panorama:DescribeApplicationInstanceDetails, panorama:DescribePackage, panorama:DescribePackageVersion, panorama:ListApplicationInstances, panorama:ListPackages, quicksight:ListDataSources, ram:ListResourceSharePermissions, rds:DescribeDBProxies, rds:DescribeGlobalClusters, rekognition:ListStreamProcessors, resource-groups:GetGroup, resource-groups:GetGroupConfiguration, resource-groups:GetGroupQuery, resource-groups:GetTags, resource-groups:ListGroupResources, resource-groups:ListGroups, robomaker:ListRobotApplications, robomaker:ListSimulationApplications, route53resolver:GetResolverDnssecConfig, route53resolver:ListResolverDnssecConfigs, s3:ListStorageLensConfigurations, schemas:GetResourcePolicy, servicediscovery:ListInstances, sts:GetCallerIdentity, synthetics:GetGroup, synthetics:ListAssociatedGroups, synthetics:ListGroupResources, and synthetics:ListGroups |
Kebijakan ini sekarang mendukung izin tambahan untuk AWS Certificate Manager, Alur Kerja Terkelola Amazon untuk Apache Airflow, AWS Amplify AWS AppConfig, Amazon Keyspaces, Amazon, Connect Customer CloudWatch, AWS Glue DataBrew, Amazon Elastic Compute Cloud (Amazon EC2), Amazon Elastic Kubernetes Service (Amazon EKS), Amazon,, Amazon Fraud Detector EventBridge AWS Fault Injection Service, Amazon FSx, Amazon GameLift Servers, Amazon Location Service,, Amazon Lex, Amazon Lightsail AWS IoT, Amazon Pinpoint,,, Amazon Quick, Amazon Relational Database Service (Amazon) RDS) OpsWorks AWS Panorama AWS Resource Access Manager, Amazon Rekognition,, AWS RoboMaker AWS Resource Groups, Amazon Route 53, Layanan Penyimpanan Sederhana Amazon (Amazon S3), AWS Cloud Map, dan. AWS Security Token Service |
Oktober 19, 2022 |
|
AWS_ConfigRole— Tambah acm-pca:GetCertificateAuthorityCsr, acm-pca:ListCertificateAuthorities, acm-pca:ListTags, airflow:GetEnvironment, airflow:ListEnvironments, amplifyuibuilder:ListThemes, appconfig:ListConfigurationProfiles, appconfig:ListDeployments, appconfig:ListDeploymentStrategies, appconfig:ListEnvironments, appconfig:ListHostedConfigurationVersions, cassandra:Select, cloudwatch:DescribeAnomalyDetectors, cloudwatch:GetDashboard, cloudwatch:ListDashboards, connect:DescribePhoneNumber, connect:ListPhoneNumbers, connect:ListPhoneNumbersV2, connect:SearchAvailablePhoneNumbers, databrew:DescribeDataset, databrew:DescribeJob, databrew:DescribeProject, databrew:DescribeRecipe, databrew:DescribeRuleset, databrew:DescribeSchedule, databrew:ListDatasets, databrew:ListJobs, databrew:ListProjects, databrew:ListRecipes, databrew:ListRecipeVersions, databrew:ListRulesets, databrew:ListSchedules, ec2:DescribeRouteTables, eks:DescribeAddon, eks:DescribeIdentityProviderConfig, eks:ListAddons, eks:ListIdentityProviderConfigs, events:DescribeConnection, events:ListApiDestinations, events:ListConnections, fis:GetExperimentTemplate, fis:ListExperimentTemplates, frauddetector:GetRules, fsx:DescribeBackups, fsx:DescribeSnapshots, fsx:DescribeStorageVirtualMachines, gamelift:DescribeMatchmakingRuleSets, gamelift:DescribeVpcPeeringConnections, geo:ListGeofenceCollections, geo:ListPlaceIndexes, geo:ListRouteCalculators, geo:ListTrackers, iot:DescribeAccountAuditConfiguration, iot:DescribeAuthorizer, iot:DescribeDomainConfiguration, iot:DescribeMitigationAction, iot:ListAuthorizers, iot:ListDomainConfigurations, iot:ListMitigationActions, iotsitewise:DescribeAssetModel, iotsitewise:DescribeDashboard, iotsitewise:DescribeGateway, iotsitewise:DescribePortal, iotsitewise:DescribeProject, iotsitewise:ListAssetModels, iotsitewise:ListDashboards, iotsitewise:ListGateways, iotsitewise:ListPortals, iotsitewise:ListProjectAssets, iotsitewise:ListProjects, iotsitewise:ListTagsForResource, iotwireless:GetServiceProfile, iotwireless:GetWirelessDevice, iotwireless:GetWirelessGatewayTaskDefinition, iotwireless:ListServiceProfiles, iotwireless:ListTagsForResource, iotwireless:ListWirelessDevices, iotwireless:ListWirelessGatewayTaskDefinitions, lex:DescribeBotVersion, lex:ListBotVersions, lightsail:GetContainerServices, lightsail:GetDistributions, lightsail:GetRelationalDatabase, lightsail:GetRelationalDatabaseParameters, mobiletargeting:GetApps, mobiletargeting:GetCampaign, mobiletargeting:GetSegment, mobiletargeting:GetSegments, opsworks:DescribeInstances, opsworks:DescribeTimeBasedAutoScaling, opsworks:DescribeVolumes, panorama:DescribeApplicationInstance, panorama:DescribeApplicationInstanceDetails, panorama:DescribePackage, panorama:DescribePackageVersion, panorama:ListApplicationInstances, panorama:ListPackages, quicksight:ListDataSources, ram:ListResourceSharePermissions, rds:DescribeDBProxies, rds:DescribeGlobalClusters, rekognition:ListStreamProcessors, resource-groups:GetGroup, resource-groups:GetGroupConfiguration, resource-groups:GetGroupQuery, resource-groups:GetTags, resource-groups:ListGroupResources, resource-groups:ListGroups, robomaker:ListRobotApplications, robomaker:ListSimulationApplications, route53resolver:GetResolverDnssecConfig, route53resolver:ListResolverDnssecConfigs, s3:ListStorageLensConfigurations, schemas:GetResourcePolicy, servicediscovery:ListInstances, sts:GetCallerIdentity, synthetics:GetGroup, synthetics:ListAssociatedGroups, synthetics:ListGroupResources, and synthetics:ListGroups |
Kebijakan ini sekarang mendukung izin tambahan untuk AWS Certificate Manager, Alur Kerja Terkelola Amazon untuk Apache Airflow, AWS Amplify AWS AppConfig, Amazon Keyspaces, Amazon, Connect Customer CloudWatch, AWS Glue DataBrew, Amazon Elastic Compute Cloud (Amazon EC2), Amazon Elastic Kubernetes Service (Amazon EKS), Amazon,, Amazon Fraud Detector EventBridge AWS Fault Injection Service, Amazon FSx, Amazon GameLift Servers, Amazon Location Service,, Amazon Lex, Amazon Lightsail AWS IoT, Amazon Pinpoint,,, Amazon Quick, Amazon Relational Database Service (Amazon) RDS) OpsWorks AWS Panorama AWS Resource Access Manager, Amazon Rekognition,, AWS RoboMaker AWS Resource Groups, Amazon Route 53, Layanan Penyimpanan Sederhana Amazon (Amazon S3), AWS Cloud Map, dan. AWS Security Token Service |
Oktober 19, 2022 |
|
AWSConfigServiceRolePolicy— Tambah Glue::GetTable |
Kebijakan ini sekarang memberikan izin untuk mengambil definisi AWS Glue Tabel dalam Katalog Data untuk tabel tertentu. |
14 September 2022 |
|
AWS_ConfigRole— Tambah Glue::GetTable |
Kebijakan ini sekarang memberikan izin untuk mengambil definisi AWS Glue Tabel dalam Katalog Data untuk tabel tertentu. |
14 September 2022 |
|
AWSConfigServiceRolePolicy— Tambah appconfig:ListApplications, appflow:DescribeConnectorProfiles, appsync:GetApiCache, autoscaling-plans:DescribeScalingPlanResources, autoscaling-plans:DescribeScalingPlans, autoscaling-plans:GetScalingPlanResourceForecastData, autoscaling:DescribeWarmPool, backup:DescribeFramework, backup:DescribeReportPlan, backup:ListFrameworks, backup:ListReportPlans, budgets:DescribeBudgetAction, budgets:DescribeBudgetActionsForAccount, budgets:DescribeBudgetActionsForBudget, budgets:ViewBudget, ce:GetAnomalyMonitors, ce:GetAnomalySubscriptions, cloud9:DescribeEnvironmentMemberships, cloud9:DescribeEnvironments, cloud9:ListEnvironments, cloud9:ListTagsForResource, cloudwatch:GetMetricStream, cloudwatch:ListMetricStreams, datasync:DescribeLocationFsxWindows, devops-guru:GetResourceCollection, ds:DescribeDirectories, ec2:DescribeTrafficMirrorFilters, ec2:DescribeTrafficMirrorTargets, ec2:GetNetworkInsightsAccessScopeAnalysisFindings, ec2:GetNetworkInsightsAccessScopeContent, elasticmapreduce:DescribeStudio, elasticmapreduce:GetStudioSessionMapping, elasticmapreduce:ListStudios, elasticmapreduce:ListStudioSessionMappings, events:DescribeEndpoint, events:DescribeEventBus, events:DescribeRule, events:ListArchives, events:ListEndpoints, events:ListEventBuses, events:ListRules, events:ListTagsForResource, events:ListTargetsByRule, finspace:GetEnvironment, finspace:ListEnvironments, frauddetector:GetDetectors, frauddetector:GetDetectorVersion, frauddetector:GetEntityTypes, frauddetector:GetEventTypes, frauddetector:GetExternalModels, frauddetector:GetLabels, frauddetector:GetModels, frauddetector:GetOutcomes, frauddetector:GetVariables, frauddetector:ListTagsForResource, gamelift:DescribeAlias, gamelift:DescribeBuild, gamelift:DescribeFleetAttributes, gamelift:DescribeFleetCapacity, gamelift:DescribeFleetLocationAttributes, gamelift:DescribeFleetLocationCapacity, gamelift:DescribeFleetPortSettings, gamelift:DescribeGameServerGroup, gamelift:DescribeGameSessionQueues, gamelift:DescribeMatchmakingConfigurations, gamelift:DescribeMatchmakingRuleSets, gamelift:DescribeRuntimeConfiguration, gamelift:DescribeScript, gamelift:DescribeVpcPeeringAuthorizations, gamelift:ListAliases, gamelift:ListBuilds, gamelift:ListFleets, gamelift:ListGameServerGroups, gamelift:ListScripts, gamelift:ListTagsForResource, geo:ListMaps, glue:GetClassifier, glue:GetClassifiers, imagebuilder:GetContainerRecipe, imagebuilder:GetImage, imagebuilder:GetImagePipeline, imagebuilder:GetImageRecipe, imagebuilder:ListContainerRecipes, imagebuilder:ListImageBuildVersions, imagebuilder:ListImagePipelines, imagebuilder:ListImageRecipes, imagebuilder:ListImages, iot:DescribeCertificate, iot:DescribeDimension, iot:DescribeRoleAlias, iot:DescribeSecurityProfile, iot:GetPolicy, iot:GetTopicRule, iot:GetTopicRuleDestination, iot:ListCertificates, iot:ListDimensions, iot:ListPolicies, iot:ListRoleAliases, iot:ListSecurityProfiles, iot:ListSecurityProfilesForTarget, iot:ListTagsForResource, iot:ListTargetsForSecurityProfile, iot:ListTopicRuleDestinations, iot:ListTopicRules, iot:ListV2LoggingLevels, iot:ValidateSecurityProfileBehaviors, iotanalytics:DescribeChannel, iotanalytics:DescribeDataset, iotanalytics:DescribeDatastore, iotanalytics:DescribePipeline, iotanalytics:ListChannels, iotanalytics:ListDatasets, iotanalytics:ListDatastores, iotanalytics:ListPipelines, iotanalytics:ListTagsForResource, iotevents:DescribeAlarmModel, iotevents:DescribeDetectorModel, iotevents:DescribeInput, iotevents:ListAlarmModels, iotevents:ListDetectorModels, iotevents:ListInputs, iotevents:ListTagsForResource, iotsitewise:DescribeAccessPolicy, iotsitewise:DescribeAsset, iotsitewise:ListAccessPolicies, iotsitewise:ListAssets, iottwinmaker:GetEntity, iottwinmaker:GetScene, iottwinmaker:GetWorkspace, iottwinmaker:ListEntities, iottwinmaker:ListScenes, iottwinmaker:ListTagsForResource, iottwinmaker:ListWorkspaces, ivs:GetPlaybackKeyPair, ivs:GetRecordingConfiguration, ivs:GetStreamKey, ivs:ListChannels, ivs:ListPlaybackKeyPairs, ivs:ListRecordingConfigurations, ivs:ListStreamKeys, ivs:ListTagsForResource, kinesisanalytics:ListApplications, lakeformation:DescribeResource, lakeformation:GetDataLakeSettings, lakeformation:ListPermissions, lakeformation:ListResources, lex:DescribeBot, lex:DescribeBotAlias, lex:DescribeResourcePolicy, lex:ListBotAliases, lex:ListBotLocales, lex:ListBots, lex:ListTagsForResource, license-manager:GetGrant, license-manager:GetLicense, license-manager:ListDistributedGrants, license-manager:ListLicenses, license-manager:ListReceivedGrants, lightsail:GetAlarms, lightsail:GetBuckets, lightsail:GetCertificates, lightsail:GetDisk, lightsail:GetDisks, lightsail:GetInstance, lightsail:GetInstances, lightsail:GetKeyPair, lightsail:GetLoadBalancer, lightsail:GetLoadBalancers, lightsail:GetLoadBalancerTlsCertificates, lightsail:GetStaticIp, lightsail:GetStaticIps, lookoutequipment:DescribeInferenceScheduler, lookoutequipment:ListTagsForResource, lookoutmetrics:DescribeAlert, lookoutmetrics:DescribeAnomalyDetector, lookoutmetrics:ListAlerts, lookoutmetrics:ListAnomalyDetectors, lookoutmetrics:ListMetricSets, lookoutmetrics:ListTagsForResource, lookoutvision:DescribeProject, lookoutvision:ListProjects, managedblockchain:GetMember, managedblockchain:GetNetwork, managedblockchain:GetNode, managedblockchain:ListInvitations, managedblockchain:ListMembers, managedblockchain:ListNodes, mediapackage-vod:DescribePackagingGroup, mediapackage-vod:ListPackagingGroups, mediapackage-vod:ListTagsForResource, mobiletargeting:GetInAppTemplate, mobiletargeting:ListTemplates, mq:DescribeBroker, mq:ListBrokers, nimble:GetLaunchProfile, nimble:GetLaunchProfileDetails, nimble:GetStreamingImage, nimble:GetStudio, nimble:GetStudioComponent, nimble:ListLaunchProfiles, nimble:ListStreamingImages, nimble:ListStudioComponents, nimble:ListStudios, profile:GetDomain, profile:GetIntegration, profile:GetProfileObjectType, profile:ListDomains, profile:ListIntegrations, profile:ListProfileObjectTypes, profile:ListTagsForResource, quicksight:DescribeAnalysis, quicksight:DescribeAnalysisPermissions, quicksight:DescribeDataSet, quicksight:DescribeDataSetPermissions, quicksight:DescribeTheme, quicksight:DescribeThemePermissions, quicksight:ListAnalyses, quicksight:ListDataSets, quicksight:ListThemes, resiliencehub:DescribeApp, resiliencehub:DescribeAppVersionTemplate, resiliencehub:DescribeResiliencyPolicy, resiliencehub:ListApps, resiliencehub:ListAppVersionResourceMappings, resiliencehub:ListResiliencyPolicies, route53-recovery-readiness:GetCell, route53-recovery-readiness:GetReadinessCheck, route53-recovery-readiness:GetRecoveryGroup, route53-recovery-readiness:GetResourceSet, route53-recovery-readiness:ListCells, route53-recovery-readiness:ListReadinessChecks, route53-recovery-readiness:ListRecoveryGroups, route53-recovery-readiness:ListResourceSets, route53resolver:GetFirewallDomainList, route53resolver:GetFirewallRuleGroup, route53resolver:GetFirewallRuleGroupAssociation, route53resolver:GetResolverQueryLogConfig, route53resolver:ListFirewallDomainLists, route53resolver:ListFirewallDomains, route53resolver:ListFirewallRuleGroupAssociations, route53resolver:ListFirewallRuleGroups, route53resolver:ListFirewallRules, route53resolver:ListResolverQueryLogConfigs, rum:GetAppMonitor, rum:GetAppMonitorData, rum:ListAppMonitors, rum:ListTagsForResource, s3-outposts:GetAccessPoint, s3-outposts:GetAccessPointPolicy, s3-outposts:GetBucket, s3-outposts:GetBucketPolicy, s3-outposts:GetBucketTagging, s3-outposts:GetLifecycleConfiguration, s3-outposts:ListAccessPoints, s3-outposts:ListEndpoints, s3-outposts:ListRegionalBuckets, schemas:DescribeDiscoverer, schemas:DescribeRegistry, schemas:DescribeSchema, schemas:ListDiscoverers, schemas:ListRegistries, schemas:ListSchemas, sdb:GetAttributes, sdb:ListDomains, ses:ListEmailTemplates, ses:ListReceiptFilters, ses:ListReceiptRuleSets, ses:ListTemplates, signer:GetSigningProfile, signer:ListProfilePermissions, signer:ListSigningProfiles, synthetics:DescribeCanaries, synthetics:DescribeCanariesLastRun, synthetics:DescribeRuntimeVersions, synthetics:GetCanary, synthetics:GetCanaryRuns, synthetics:ListTagsForResource, timestream:DescribeDatabase, timestream:DescribeTable, timestream:ListDatabases, timestream:ListTables, timestream:ListTagsForResource, transfer:DescribeServer, transfer:DescribeUser, transfer:DescribeWorkflow, transfer:ListServers, transfer:ListUsers, transfer:ListWorkflows, voiceid:DescribeDomain, and voiceid:ListTagsForResource |
Kebijakan ini sekarang mendukung izin tambahan untuk Amazon AppFlow, Amazon, Amazon CloudWatch RUM CloudWatch, Amazon CloudWatch Synthetics, Profil Pelanggan Amazon Connect, ID Suara Pelanggan Amazon Connect, Amazon DevOps Guru, Amazon Elastic Compute Cloud (Amazon EC2), Amazon EC2 Auto Scaling, Amazon EMR, Amazon, Amazon EventBridge Schemas,, Amazon Fraud Detector EventBridge, Amazon GameLift Server Amazon FinSpace, Amazon Interactive Video Service (Amazon IVS), Amazon Managed Service untuk Apache Flink, EC2 Image Builder, Amazon Lex, Layar Cahaya Amazon, Layanan Lokasi Amazon, Amazon Lookout untuk Peralatan, Amazon Lookout untuk Metrik, Amazon Lookout untuk Visi, Amazon Managed Blockchain, Amazon MQ, Amazon Nimble StudioAmazon Pinpoint, Amazon Quick, Pengontrol Pemulihan Aplikasi Amazon (ARC), Amazon Route 53 Resolver, Layanan Penyimpanan Sederhana Amazon (Amazon S3), Amazon SimpleDB, Layanan Email Sederhana Amazon (Amazon SES), Amazon Timestream, AWS AppConfig, AWS AppSync, AWS Auto Scaling, AWS Backup, AWS Budgets,, AWS Cost Explorer, AWS Cloud9, AWS Directory Service AWS DataSync AWS Elemental MediaPackage AWS Glue AWS IoT AWS IoT Analytics AWS IoT Events AWS IoT SiteWise, AWS IoT TwinMaker, AWS Lake Formation, AWS License Manager, AWS Resilience Hub, AWS Signer, dan AWS Transfer Family. |
7 September 2022 |
|
AWS_ConfigRole— Tambah appconfig:ListApplications, appflow:DescribeConnectorProfiles, appsync:GetApiCache, autoscaling-plans:DescribeScalingPlanResources, autoscaling-plans:DescribeScalingPlans, autoscaling-plans:GetScalingPlanResourceForecastData, autoscaling:DescribeWarmPool, backup:DescribeFramework, backup:DescribeReportPlan, backup:ListFrameworks, backup:ListReportPlans, budgets:DescribeBudgetAction, budgets:DescribeBudgetActionsForAccount, budgets:DescribeBudgetActionsForBudget, budgets:ViewBudget, ce:GetAnomalyMonitors, ce:GetAnomalySubscriptions, cloud9:DescribeEnvironmentMemberships, cloud9:DescribeEnvironments, cloud9:ListEnvironments, cloud9:ListTagsForResource, cloudwatch:GetMetricStream, cloudwatch:ListMetricStreams, datasync:DescribeLocationFsxWindows, devops-guru:GetResourceCollection, ds:DescribeDirectories, ec2:DescribeTrafficMirrorTargets, ec2:GetNetworkInsightsAccessScopeAnalysisFindings, ec2:GetNetworkInsightsAccessScopeContent, elasticmapreduce:DescribeStudio, elasticmapreduce:GetStudioSessionMapping, elasticmapreduce:ListStudios, elasticmapreduce:ListStudioSessionMappings, events:DescribeEndpoint, events:DescribeEventBus, events:DescribeRule, events:ListArchives, events:ListEndpoints, events:ListEventBuses, events:ListRules, events:ListTagsForResource, events:ListTargetsByRule, finspace:GetEnvironment, finspace:ListEnvironments, frauddetector:GetDetectors, frauddetector:GetDetectorVersion, frauddetector:GetEntityTypes, frauddetector:GetEventTypes, frauddetector:GetExternalModels, frauddetector:GetLabels, frauddetector:GetModels, frauddetector:GetOutcomes, frauddetector:GetVariables, frauddetector:ListTagsForResource, gamelift:DescribeAlias, gamelift:DescribeBuild, gamelift:DescribeFleetAttributes, gamelift:DescribeFleetCapacity, gamelift:DescribeFleetLocationAttributes, gamelift:DescribeFleetLocationCapacity, gamelift:DescribeFleetPortSettings, gamelift:DescribeGameServerGroup, gamelift:DescribeGameSessionQueues, gamelift:DescribeMatchmakingConfigurations, gamelift:DescribeMatchmakingRuleSets, gamelift:DescribeRuntimeConfiguration, gamelift:DescribeScript, gamelift:DescribeVpcPeeringAuthorizations, gamelift:ListAliases, gamelift:ListBuilds, gamelift:ListFleets, gamelift:ListGameServerGroups, gamelift:ListScripts, gamelift:ListTagsForResource, geo:ListMaps, glue:GetClassifier, glue:GetClassifiers, imagebuilder:GetContainerRecipe, imagebuilder:GetImage, imagebuilder:GetImagePipeline, imagebuilder:GetImageRecipe, imagebuilder:ListContainerRecipes, imagebuilder:ListImageBuildVersions, imagebuilder:ListImagePipelines, imagebuilder:ListImageRecipes, imagebuilder:ListImages, iot:DescribeCertificate, iot:DescribeDimension, iot:DescribeRoleAlias, iot:DescribeSecurityProfile, iot:GetPolicy, iot:GetTopicRule, iot:GetTopicRuleDestination, iot:ListCertificates, iot:ListDimensions, iot:ListPolicies, iot:ListRoleAliases, iot:ListSecurityProfiles, iot:ListSecurityProfilesForTarget, iot:ListTagsForResource, iot:ListTargetsForSecurityProfile, iot:ListTopicRuleDestinations, iot:ListTopicRules, iot:ListV2LoggingLevels, iot:ValidateSecurityProfileBehaviors, iotanalytics:DescribeChannel, iotanalytics:DescribeDataset, iotanalytics:DescribeDatastore, iotanalytics:DescribePipeline, iotanalytics:ListChannels, iotanalytics:ListDatasets, iotanalytics:ListDatastores, iotanalytics:ListPipelines, iotanalytics:ListTagsForResource, iotevents:DescribeAlarmModel, iotevents:DescribeDetectorModel, iotevents:DescribeInput, iotevents:ListAlarmModels, iotevents:ListDetectorModels, iotevents:ListInputs, iotevents:ListTagsForResource, iotsitewise:DescribeAccessPolicy, iotsitewise:DescribeAsset, iotsitewise:ListAccessPolicies, iotsitewise:ListAssets, iottwinmaker:GetEntity, iottwinmaker:GetScene, iottwinmaker:GetWorkspace, iottwinmaker:ListEntities, iottwinmaker:ListScenes, iottwinmaker:ListTagsForResource, iottwinmaker:ListWorkspaces, ivs:GetPlaybackKeyPair, ivs:GetRecordingConfiguration, ivs:GetStreamKey, ivs:ListChannels, ivs:ListPlaybackKeyPairs, ivs:ListRecordingConfigurations, ivs:ListStreamKeys, ivs:ListTagsForResource, kinesisanalytics:ListApplications, lakeformation:DescribeResource, lakeformation:GetDataLakeSettings, lakeformation:ListPermissions, lakeformation:ListResources, lex:DescribeBot, lex:DescribeBotAlias, lex:DescribeResourcePolicy, lex:ListBotAliases, lex:ListBotLocales, lex:ListBots, lex:ListTagsForResource, license-manager:GetGrant, license-manager:GetLicense, license-manager:ListDistributedGrants, license-manager:ListLicenses, license-manager:ListReceivedGrants, lightsail:GetAlarms, lightsail:GetBuckets, lightsail:GetCertificates, lightsail:GetDisk, lightsail:GetDisks, lightsail:GetInstance, lightsail:GetInstances, lightsail:GetKeyPair, lightsail:GetLoadBalancer, lightsail:GetLoadBalancers, lightsail:GetLoadBalancerTlsCertificates, lightsail:GetStaticIp, lightsail:GetStaticIps, lookoutequipment:DescribeInferenceScheduler, lookoutequipment:ListTagsForResource, lookoutmetrics:DescribeAlert, lookoutmetrics:DescribeAnomalyDetector, lookoutmetrics:ListAlerts, lookoutmetrics:ListAnomalyDetectors, lookoutmetrics:ListMetricSets, lookoutmetrics:ListTagsForResource, lookoutvision:DescribeProject, lookoutvision:ListProjects, managedblockchain:GetMember, managedblockchain:GetNetwork, managedblockchain:GetNode, managedblockchain:ListInvitations, managedblockchain:ListMembers, managedblockchain:ListNodes, mediapackage-vod:DescribePackagingGroup, mediapackage-vod:ListPackagingGroups, mediapackage-vod:ListTagsForResource, mobiletargeting:GetInAppTemplate, mobiletargeting:ListTemplates, mq:DescribeBroker, mq:ListBrokers, nimble:GetLaunchProfile, nimble:GetLaunchProfileDetails, nimble:GetStreamingImage, nimble:GetStudio, nimble:GetStudioComponent, nimble:ListLaunchProfiles, nimble:ListStreamingImages, nimble:ListStudioComponents, nimble:ListStudios, profile:GetDomain, profile:GetIntegration, profile:GetProfileObjectType, profile:ListDomains, profile:ListIntegrations, profile:ListProfileObjectTypes, profile:ListTagsForResource, quicksight:DescribeAnalysis, quicksight:DescribeAnalysisPermissions, quicksight:DescribeDataSet, quicksight:DescribeDataSetPermissions, quicksight:DescribeTheme, quicksight:DescribeThemePermissions, quicksight:ListAnalyses, quicksight:ListDataSets, quicksight:ListThemes, resiliencehub:DescribeApp, resiliencehub:DescribeAppVersionTemplate, resiliencehub:DescribeResiliencyPolicy, resiliencehub:ListApps, resiliencehub:ListAppVersionResourceMappings, resiliencehub:ListResiliencyPolicies, route53-recovery-readiness:GetCell, route53-recovery-readiness:GetReadinessCheck, route53-recovery-readiness:GetRecoveryGroup, route53-recovery-readiness:GetResourceSet, route53-recovery-readiness:ListCells, route53-recovery-readiness:ListReadinessChecks, route53-recovery-readiness:ListRecoveryGroups, route53-recovery-readiness:ListResourceSets, route53resolver:GetFirewallDomainList, route53resolver:GetFirewallRuleGroup, route53resolver:GetFirewallRuleGroupAssociation, route53resolver:GetResolverQueryLogConfig, route53resolver:ListFirewallDomainLists, route53resolver:ListFirewallDomains, route53resolver:ListFirewallRuleGroupAssociations, route53resolver:ListFirewallRuleGroups, route53resolver:ListFirewallRules, route53resolver:ListResolverQueryLogConfigs, rum:GetAppMonitor, rum:GetAppMonitorData, rum:ListAppMonitors, rum:ListTagsForResource, s3-outposts:GetAccessPoint, s3-outposts:GetAccessPointPolicy, s3-outposts:GetBucket, s3-outposts:GetBucketPolicy, s3-outposts:GetBucketTagging, s3-outposts:GetLifecycleConfiguration, s3-outposts:ListAccessPoints, s3-outposts:ListEndpoints, s3-outposts:ListRegionalBuckets, schemas:DescribeDiscoverer, schemas:DescribeRegistry, schemas:DescribeSchema, schemas:ListDiscoverers, schemas:ListRegistries, schemas:ListSchemas, sdb:GetAttributes, sdb:ListDomains, ses:ListEmailTemplates, ses:ListReceiptFilters, ses:ListReceiptRuleSets, ses:ListTemplates, signer:GetSigningProfile, signer:ListProfilePermissions, signer:ListSigningProfiles, synthetics:DescribeCanaries, synthetics:DescribeCanariesLastRun, synthetics:DescribeRuntimeVersions, synthetics:GetCanary, synthetics:GetCanaryRuns, synthetics:ListTagsForResource, timestream:DescribeDatabase, timestream:DescribeTable, timestream:ListDatabases, timestream:ListTables, timestream:ListTagsForResource, transfer:DescribeServer, transfer:DescribeUser, transfer:DescribeWorkflow, transfer:ListServers, transfer:ListUsers, transfer:ListWorkflows, voiceid:DescribeDomain, and voiceid:ListTagsForResource |
Kebijakan ini sekarang mendukung izin tambahan untuk Amazon AppFlow, Amazon, Amazon CloudWatch RUM CloudWatch, Amazon CloudWatch Synthetics, Profil Pelanggan Amazon Connect, ID Suara Pelanggan Amazon Connect, Amazon DevOps Guru, Amazon Elastic Compute Cloud (Amazon EC2), Amazon EC2 Auto Scaling, Amazon EMR, Amazon, Amazon EventBridge Schemas,, Amazon Fraud Detector EventBridge, Amazon GameLift Server Amazon FinSpace, Amazon Interactive Video Service (Amazon IVS), Amazon Managed Service untuk Apache Flink, EC2 Image Builder, Amazon Lex, Layar Cahaya Amazon, Layanan Lokasi Amazon, Amazon Lookout untuk Peralatan, Amazon Lookout untuk Metrik, Amazon Lookout untuk Visi, Amazon Managed Blockchain, Amazon MQ, Amazon Nimble StudioAmazon Pinpoint, Amazon Quick, Pengontrol Pemulihan Aplikasi Amazon (ARC), Amazon Route 53 Resolver, Layanan Penyimpanan Sederhana Amazon (Amazon S3), Amazon SimpleDB, Layanan Email Sederhana Amazon (Amazon SES), Amazon Timestream, AWS AppConfig, AWS AppSync, AWS Auto Scaling, AWS Backup, AWS Budgets,, AWS Cost Explorer, AWS Cloud9, AWS Directory Service AWS DataSync AWS Elemental MediaPackage AWS Glue AWS IoT AWS IoT Analytics AWS IoT Events AWS IoT SiteWise, AWS IoT TwinMaker, AWS Lake Formation, AWS License Manager, AWS Resilience Hub, AWS Signer, dan AWS Transfer Family |
7 September 2022 |
| AWSConfigServiceRolePolicy— Tambah airflow:ListTagsForResource, iot:ListCustomMetrics, iot:DescribeCustomMetric, appstream:DescribeDirectoryConfigs, appstream:ListTagsForResource, codeguru-reviewer:DescribeRepositoryAssociation, codeguru-reviewer:ListRepositoryAssociations, healthlake:ListFHIRDatastores, healthlake:DescribeFHIRDatastore, healthlake:ListTagsForResource, kinesisvideo:DescribeStream, kinesisvideo:ListStreams, kinesisvideo:ListTagsForStream, kinesisvideo:DescribeSignalingChannel, kinesisvideo:ListTagsForResource, kinesisvideo:ListSignalingChannels, route53-recovery-control-config:DescribeCluster, route53-recovery-control-config:DescribeRoutingControl, route53-recovery-control-config:DescribeSafetyRule, route53-recovery-control-config:ListClusters, route53-recovery-control-config:ListRoutingControls, route53-recovery-control-config:ListSafetyRules, devicefarm:GetTestGridProject, devicefarm:ListTestGridProjects, ec2:DescribeCapacityReservationFleets, ec2:DescribeIpamPools, ec2:DescribeIpams, ec2:GetInstanceTypesFromInstanceRequirement, mobiletargeting:GetApplicationSettings, mobiletargeting:ListTagsForResource, ecr:BatchGetRepositoryScanningConfiguration, iam:ListServerCertificates, guardduty:ListPublishingDestinations, guardduty:DescribePublishingDestination, logs:GetLogDelivery, and logs:ListLogDeliveries | Kebijakan ini sekarang mendukung izin tambahan untuk Alur Kerja Terkelola Amazon untuk Apache Airflow AWS IoT,, WorkSpaces Aplikasi Amazon, Amazon CodeGuru Reviewer AWS HealthLake, Amazon Kinesis Video Streams, Amazon Application Recovery Controller (ARC) AWS Device Farm, Amazon Elastic Compute Cloud (Amazon EC2), Amazon Pinpoint, AWS Identity and Access Management (IAM), Amazon, dan Amazon Logs. GuardDuty CloudWatch | 1 Februari 2023 |
|
AWS_ConfigRole— Tambah airflow:ListTagsForResource, iot:ListCustomMetrics, iot:DescribeCustomMetric, appstream:DescribeDirectoryConfigs, appstream:ListTagsForResource, codeguru-reviewer:DescribeRepositoryAssociation, codeguru-reviewer:ListRepositoryAssociations, healthlake:ListFHIRDatastores, healthlake:DescribeFHIRDatastore, healthlake:ListTagsForResource, kinesisvideo:DescribeStream, kinesisvideo:ListStreams, kinesisvideo:ListTagsForStream, kinesisvideo:DescribeSignalingChannel, kinesisvideo:ListTagsForResource, kinesisvideo:ListSignalingChannels, route53-recovery-control-config:DescribeCluster, route53-recovery-control-config:DescribeRoutingControl, route53-recovery-control-config:DescribeSafetyRule, route53-recovery-control-config:ListClusters, route53-recovery-control-config:ListRoutingControls, route53-recovery-control-config:ListSafetyRules, devicefarm:GetTestGridProject, devicefarm:ListTestGridProjects, ec2:DescribeCapacityReservationFleets, ec2:DescribeIpamPools, ec2:DescribeIpams, ec2:GetInstanceTypesFromInstanceRequirement, mobiletargeting:GetApplicationSettings, mobiletargeting:ListTagsForResource, ecr:BatchGetRepositoryScanningConfiguration, iam:ListServerCertificates, guardduty:ListPublishingDestinations, guardduty:DescribePublishingDestination, logs:GetLogDelivery, and logs:ListLogDeliveries |
Kebijakan ini sekarang mendukung izin tambahan untuk Alur Kerja Terkelola Amazon untuk Apache Airflow AWS IoT,, WorkSpaces Aplikasi Amazon, Amazon CodeGuru Reviewer AWS HealthLake, Amazon Kinesis Video Streams, Amazon Application Recovery Controller (ARC) AWS Device Farm, Amazon Elastic Compute Cloud (Amazon EC2), Amazon Pinpoint, AWS Identity and Access Management (IAM), Amazon, dan Amazon Logs. GuardDuty CloudWatch |
1 Februari 2023 |
|
ConfigConformsServiceRolePolicy— Perbarui config:DescribeConfigRules |
Sebagai praktik terbaik keamanan, kebijakan ini sekarang menghapus izin tingkat sumber daya yang luas untuk. |
Januari 12, 2023 |
|
AWSConfigServiceRolePolicy— Tambah APS:DescribeRuleGroupsNamespace, APS:DescribeWorkspace, APS:ListWorkspaces, auditmanager:GetAssessment, auditmanager:ListAssessments, devicefarm:GetNetworkProfile, AWS Transfer Family devicefarm:GetProject, devicefarm:ListNetworkProfiles, devicefarm:ListTagsForResource, dms:DescribeEndpoints, ds:ListTagsForResource, ec2:DescribeTags, ec2:DescribeTrafficMirrorSessions, ec2:DescribeTrafficMirrorTargets, ec2:GetIpamPoolAllocations, ec2:GetIpamPoolCidrs, glue:GetMLTransform, glue:GetMLTransforms, glue:ListMLTransforms, iot:DescribeScheduledAudit, iot:ListScheduledAudits, ivs:GetChannel, lightsail:GetRelationalDatabases, mediapackage-vod:DescribePackagingConfiguration, mediapackage-vod:ListPackagingConfigurations, networkmanager:DescribeGlobalNetworks, networkmanager:GetTransitGatewayRegistrations, networkmanager:ListTagsForResource, quicksight:DescribeDashboard, quicksight:DescribeDashboardPermissions, quicksight:DescribeTemplate, quicksight:DescribeTemplatePermissions, quicksight:ListDashboards, quicksight:ListTemplates, ram:ListResources, route53-recovery-control-config:DescribeControlPanel, route53-recovery-control-config:ListControlPanels, route53-recovery-control-config:ListTagsForResource, route53resolver:GetResolverQueryLogConfigAssociation, route53resolver:ListResolverQueryLogConfigAssociations, s3:GetAccessPointForObjectLambda, s3:GetAccessPointPolicyForObjectLambda, s3:GetAccessPointPolicyStatusForObjectLambda, s3:GetMultiRegionAccessPoint, s3:ListAccessPointsForObjectLambda, s3:ListMultiRegionAccessPoints, timestream:DescribeEndpoints, transfer:DescribeConnector, transfer:ListConnectors, and transfer:ListTagsForResource |
Kebijakan ini sekarang mendukung izin tambahan untuk Layanan Terkelola Amazon untuk Prometheus,, AWS Audit Manager, AWS Database Migration Service (AWS DMS) AWS Device Farm, AWS Directory Service, Amazon Elastic Compute Cloud (Amazon EC2),,, Amazon Lightsail AWS Glue, AWS IoT, Amazon Quick, AWS Elemental MediaPackage AWS Network Manager, Amazon Application Recovery Controller (ARC) AWS Resource Access Manager, Amazon Simple Storage Service (Amazon S3), dan Amazon Timestream. |
Desember 15, 2022 |
|
AWS_ConfigRole— Tambah APS:DescribeRuleGroupsNamespace, APS:DescribeWorkspace, APS:ListWorkspaces, auditmanager:GetAssessment, auditmanager:ListAssessments, devicefarm:GetNetworkProfile, devicefarm:GetProject, devicefarm:ListNetworkProfiles, devicefarm:ListTagsForResource, dms:DescribeEndpoints, ds:ListTagsForResource, ec2:DescribeTags, ec2:DescribeTrafficMirrorSessions, ec2:DescribeTrafficMirrorTargets, ec2:GetIpamPoolAllocations, ec2:GetIpamPoolCidrs, glue:GetMLTransform, glue:GetMLTransforms, glue:ListMLTransforms, iot:DescribeScheduledAudit, iot:ListScheduledAudits, ivs:GetChannel, lightsail:GetRelationalDatabases, mediapackage-vod:DescribePackagingConfiguration, mediapackage-vod:ListPackagingConfigurations, networkmanager:DescribeGlobalNetworks, networkmanager:GetTransitGatewayRegistrations, networkmanager:ListTagsForResource, quicksight:DescribeDashboard, quicksight:DescribeDashboardPermissions, quicksight:DescribeTemplate, quicksight:DescribeTemplatePermissions, quicksight:ListDashboards, quicksight:ListTemplates, ram:ListResources, route53-recovery-control-config:DescribeControlPanel, route53-recovery-control-config:ListControlPanels, route53-recovery-control-config:ListTagsForResource, route53resolver:GetResolverQueryLogConfigAssociation, route53resolver:ListResolverQueryLogConfigAssociations, s3:GetAccessPointForObjectLambda, s3:GetAccessPointPolicyForObjectLambda, s3:GetAccessPointPolicyStatusForObjectLambda, s3:GetMultiRegionAccessPoint, s3:ListAccessPointsForObjectLambda, s3:ListMultiRegionAccessPoints, timestream:DescribeEndpoints, transfer:DescribeConnector, transfer:ListConnectors, and transfer:ListTagsForResource |
Kebijakan ini sekarang mendukung izin tambahan untuk Layanan Terkelola Amazon untuk Prometheus,, AWS Audit Manager, AWS Database Migration Service (AWS DMS) AWS Device Farm, AWS Directory Service, Amazon Elastic Compute Cloud (Amazon EC2),,, Amazon Lightsail AWS Glue, AWS IoT, Amazon Quick, AWS Elemental MediaPackage AWS Network Manager, Amazon Application Recovery Controller (ARC) AWS Resource Access Manager, Amazon Simple Storage Service (Amazon S3), dan Amazon Timestream. |
15 Desember 2022 |
|
AWSConfigServiceRolePolicy— Tambah cloudformation:ListStackResources and cloudformation:ListStacks |
Kebijakan ini sekarang memberikan izin untuk mengembalikan deskripsi semua sumber daya dari AWS CloudFormation tumpukan tertentu dan mengembalikan informasi ringkasan untuk tumpukan yang statusnya cocok dengan yang ditentukanStackStatusFilter. |
7 November 2022 |
|
AWS_ConfigRole— Tambah cloudformation:ListStackResources and cloudformation:ListStacks |
Kebijakan ini sekarang memberikan izin untuk mengembalikan deskripsi semua sumber daya dari AWS CloudFormation tumpukan tertentu dan mengembalikan informasi ringkasan untuk tumpukan yang statusnya cocok dengan yang ditentukanStackStatusFilter. |
7 November 2022 |
|
AWSConfigServiceRolePolicy— Tambah acm-pca:GetCertificateAuthorityCsr, acm-pca:ListCertificateAuthorities, acm-pca:ListTags, airflow:GetEnvironment, airflow:ListEnvironments, amplifyuibuilder:ListThemes, appconfig:ListConfigurationProfiles, appconfig:ListDeployments, appconfig:ListDeploymentStrategies, appconfig:ListEnvironments, appconfig:ListHostedConfigurationVersions, cassandra:Select, cloudwatch:DescribeAnomalyDetectors, cloudwatch:GetDashboard, cloudwatch:ListDashboards, connect:DescribePhoneNumber, connect:ListPhoneNumbers, connect:ListPhoneNumbersV2, connect:SearchAvailablePhoneNumbers, databrew:DescribeDataset, databrew:DescribeJob, databrew:DescribeProject, databrew:DescribeRecipe, databrew:DescribeRuleset, databrew:DescribeSchedule, databrew:ListDatasets, databrew:ListJobs, databrew:ListProjects, databrew:ListRecipes, databrew:ListRecipeVersions, databrew:ListRulesets, databrew:ListSchedules, ec2:DescribeRouteTables, eks:DescribeAddon, eks:DescribeIdentityProviderConfig, eks:ListAddons, eks:ListIdentityProviderConfigs, events:DescribeConnection, events:ListApiDestinations, events:ListConnections, fis:GetExperimentTemplate, fis:ListExperimentTemplates, frauddetector:GetRules, fsx:DescribeBackups, fsx:DescribeSnapshots, fsx:DescribeStorageVirtualMachines, gamelift:DescribeMatchmakingRuleSets, gamelift:DescribeVpcPeeringConnections, geo:ListGeofenceCollections, geo:ListPlaceIndexes, geo:ListRouteCalculators, geo:ListTrackers, iot:DescribeAccountAuditConfiguration, iot:DescribeAuthorizer, iot:DescribeDomainConfiguration, iot:DescribeMitigationAction, iot:ListAuthorizers, iot:ListDomainConfigurations, iot:ListMitigationActions, iotsitewise:DescribeAssetModel, iotsitewise:DescribeDashboard, iotsitewise:DescribeGateway, iotsitewise:DescribePortal, iotsitewise:DescribeProject, iotsitewise:ListAssetModels, iotsitewise:ListDashboards, iotsitewise:ListGateways, iotsitewise:ListPortals, iotsitewise:ListProjectAssets, iotsitewise:ListProjects, iotsitewise:ListTagsForResource, iotwireless:GetServiceProfile, iotwireless:GetWirelessDevice, iotwireless:GetWirelessGatewayTaskDefinition, iotwireless:ListServiceProfiles, iotwireless:ListTagsForResource, iotwireless:ListWirelessDevices, iotwireless:ListWirelessGatewayTaskDefinitions, lex:DescribeBotVersion, lex:ListBotVersions, lightsail:GetContainerServices, lightsail:GetDistributions, lightsail:GetRelationalDatabase, lightsail:GetRelationalDatabaseParameters, mobiletargeting:GetApps, mobiletargeting:GetCampaign, mobiletargeting:GetSegment, mobiletargeting:GetSegments, opsworks:DescribeInstances, opsworks:DescribeTimeBasedAutoScaling, opsworks:DescribeVolumes, panorama:DescribeApplicationInstance, panorama:DescribeApplicationInstanceDetails, panorama:DescribePackage, panorama:DescribePackageVersion, panorama:ListApplicationInstances, panorama:ListPackages, quicksight:ListDataSources, ram:ListResourceSharePermissions, rds:DescribeDBProxies, rds:DescribeGlobalClusters, rekognition:ListStreamProcessors, resource-groups:GetGroup, resource-groups:GetGroupConfiguration, resource-groups:GetGroupQuery, resource-groups:GetTags, resource-groups:ListGroupResources, resource-groups:ListGroups, robomaker:ListRobotApplications, robomaker:ListSimulationApplications, route53resolver:GetResolverDnssecConfig, route53resolver:ListResolverDnssecConfigs, s3:ListStorageLensConfigurations, schemas:GetResourcePolicy, servicediscovery:ListInstances, sts:GetCallerIdentity, synthetics:GetGroup, synthetics:ListAssociatedGroups, synthetics:ListGroupResources, and synthetics:ListGroups |
Kebijakan ini sekarang mendukung izin tambahan untuk AWS Certificate Manager, Alur Kerja Terkelola Amazon untuk Apache Airflow, AWS Amplify AWS AppConfig, Amazon Keyspaces, Amazon, Connect Customer CloudWatch, AWS Glue DataBrew, Amazon Elastic Compute Cloud (Amazon EC2), Amazon Elastic Kubernetes Service (Amazon EKS), Amazon,, Amazon Fraud Detector EventBridge AWS Fault Injection Service, Amazon FSx, Amazon GameLift Servers, Amazon Location Service,, Amazon Lex, Amazon Lightsail AWS IoT, Amazon Pinpoint,,, Amazon Quick, Amazon Relational Database Service (Amazon) RDS) OpsWorks AWS Panorama AWS Resource Access Manager, Amazon Rekognition,, AWS RoboMaker AWS Resource Groups, Amazon Route 53, Layanan Penyimpanan Sederhana Amazon (Amazon S3), AWS Cloud Map, dan. AWS Security Token Service |
Oktober 19, 2022 |
|
AWS_ConfigRole— Tambah acm-pca:GetCertificateAuthorityCsr, acm-pca:ListCertificateAuthorities, acm-pca:ListTags, airflow:GetEnvironment, airflow:ListEnvironments, amplifyuibuilder:ListThemes, appconfig:ListConfigurationProfiles, appconfig:ListDeployments, appconfig:ListDeploymentStrategies, appconfig:ListEnvironments, appconfig:ListHostedConfigurationVersions, cassandra:Select, cloudwatch:DescribeAnomalyDetectors, cloudwatch:GetDashboard, cloudwatch:ListDashboards, connect:DescribePhoneNumber, connect:ListPhoneNumbers, connect:ListPhoneNumbersV2, connect:SearchAvailablePhoneNumbers, databrew:DescribeDataset, databrew:DescribeJob, databrew:DescribeProject, databrew:DescribeRecipe, databrew:DescribeRuleset, databrew:DescribeSchedule, databrew:ListDatasets, databrew:ListJobs, databrew:ListProjects, databrew:ListRecipes, databrew:ListRecipeVersions, databrew:ListRulesets, databrew:ListSchedules, ec2:DescribeRouteTables, eks:DescribeAddon, eks:DescribeIdentityProviderConfig, eks:ListAddons, eks:ListIdentityProviderConfigs, events:DescribeConnection, events:ListApiDestinations, events:ListConnections, fis:GetExperimentTemplate, fis:ListExperimentTemplates, frauddetector:GetRules, fsx:DescribeBackups, fsx:DescribeSnapshots, fsx:DescribeStorageVirtualMachines, gamelift:DescribeMatchmakingRuleSets, gamelift:DescribeVpcPeeringConnections, geo:ListGeofenceCollections, geo:ListPlaceIndexes, geo:ListRouteCalculators, geo:ListTrackers, iot:DescribeAccountAuditConfiguration, iot:DescribeAuthorizer, iot:DescribeDomainConfiguration, iot:DescribeMitigationAction, iot:ListAuthorizers, iot:ListDomainConfigurations, iot:ListMitigationActions, iotsitewise:DescribeAssetModel, iotsitewise:DescribeDashboard, iotsitewise:DescribeGateway, iotsitewise:DescribePortal, iotsitewise:DescribeProject, iotsitewise:ListAssetModels, iotsitewise:ListDashboards, iotsitewise:ListGateways, iotsitewise:ListPortals, iotsitewise:ListProjectAssets, iotsitewise:ListProjects, iotsitewise:ListTagsForResource, iotwireless:GetServiceProfile, iotwireless:GetWirelessDevice, iotwireless:GetWirelessGatewayTaskDefinition, iotwireless:ListServiceProfiles, iotwireless:ListTagsForResource, iotwireless:ListWirelessDevices, iotwireless:ListWirelessGatewayTaskDefinitions, lex:DescribeBotVersion, lex:ListBotVersions, lightsail:GetContainerServices, lightsail:GetDistributions, lightsail:GetRelationalDatabase, lightsail:GetRelationalDatabaseParameters, mobiletargeting:GetApps, mobiletargeting:GetCampaign, mobiletargeting:GetSegment, mobiletargeting:GetSegments, opsworks:DescribeInstances, opsworks:DescribeTimeBasedAutoScaling, opsworks:DescribeVolumes, panorama:DescribeApplicationInstance, panorama:DescribeApplicationInstanceDetails, panorama:DescribePackage, panorama:DescribePackageVersion, panorama:ListApplicationInstances, panorama:ListPackages, quicksight:ListDataSources, ram:ListResourceSharePermissions, rds:DescribeDBProxies, rds:DescribeGlobalClusters, rekognition:ListStreamProcessors, resource-groups:GetGroup, resource-groups:GetGroupConfiguration, resource-groups:GetGroupQuery, resource-groups:GetTags, resource-groups:ListGroupResources, resource-groups:ListGroups, robomaker:ListRobotApplications, robomaker:ListSimulationApplications, route53resolver:GetResolverDnssecConfig, route53resolver:ListResolverDnssecConfigs, s3:ListStorageLensConfigurations, schemas:GetResourcePolicy, servicediscovery:ListInstances, sts:GetCallerIdentity, synthetics:GetGroup, synthetics:ListAssociatedGroups, synthetics:ListGroupResources, and synthetics:ListGroups |
Kebijakan ini sekarang mendukung izin tambahan untuk AWS Certificate Manager, Alur Kerja Terkelola Amazon untuk Apache Airflow, AWS Amplify AWS AppConfig, Amazon Keyspaces, Amazon, Connect Customer CloudWatch, AWS Glue DataBrew, Amazon Elastic Compute Cloud (Amazon EC2), Amazon Elastic Kubernetes Service (Amazon EKS), Amazon,, Amazon Fraud Detector EventBridge AWS Fault Injection Service, Amazon FSx, Amazon GameLift Servers, Amazon Location Service,, Amazon Lex, Amazon Lightsail AWS IoT, Amazon Pinpoint,,, Amazon Quick, Amazon Relational Database Service (Amazon) RDS) OpsWorks AWS Panorama AWS Resource Access Manager, Amazon Rekognition,, AWS RoboMaker AWS Resource Groups, Amazon Route 53, Layanan Penyimpanan Sederhana Amazon (Amazon S3), AWS Cloud Map, dan. AWS Security Token Service |
Oktober 19, 2022 |
|
AWSConfigServiceRolePolicy— Tambah Glue::GetTable |
Kebijakan ini sekarang memberikan izin untuk mengambil definisi AWS Glue Tabel dalam Katalog Data untuk tabel tertentu. |
14 September 2022 |
|
AWS_ConfigRole— Tambah Glue::GetTable |
Kebijakan ini sekarang memberikan izin untuk mengambil definisi AWS Glue Tabel dalam Katalog Data untuk tabel tertentu. |
14 September 2022 |
|
AWSConfigServiceRolePolicy— Tambah appconfig:ListApplications, appflow:DescribeConnectorProfiles, appsync:GetApiCache, autoscaling-plans:DescribeScalingPlanResources, autoscaling-plans:DescribeScalingPlans, autoscaling-plans:GetScalingPlanResourceForecastData, autoscaling:DescribeWarmPool, backup:DescribeFramework, backup:DescribeReportPlan, backup:ListFrameworks, backup:ListReportPlans, budgets:DescribeBudgetAction, budgets:DescribeBudgetActionsForAccount, budgets:DescribeBudgetActionsForBudget, budgets:ViewBudget, ce:GetAnomalyMonitors, ce:GetAnomalySubscriptions, cloud9:DescribeEnvironmentMemberships, cloud9:DescribeEnvironments, cloud9:ListEnvironments, cloud9:ListTagsForResource, cloudwatch:GetMetricStream, cloudwatch:ListMetricStreams, datasync:DescribeLocationFsxWindows, devops-guru:GetResourceCollection, ds:DescribeDirectories, ec2:DescribeTrafficMirrorFilters, ec2:DescribeTrafficMirrorTargets, ec2:GetNetworkInsightsAccessScopeAnalysisFindings, ec2:GetNetworkInsightsAccessScopeContent, elasticmapreduce:DescribeStudio, elasticmapreduce:GetStudioSessionMapping, elasticmapreduce:ListStudios, elasticmapreduce:ListStudioSessionMappings, events:DescribeEndpoint, events:DescribeEventBus, events:DescribeRule, events:ListArchives, events:ListEndpoints, events:ListEventBuses, events:ListRules, events:ListTagsForResource, events:ListTargetsByRule, finspace:GetEnvironment, finspace:ListEnvironments, frauddetector:GetDetectors, frauddetector:GetDetectorVersion, frauddetector:GetEntityTypes, frauddetector:GetEventTypes, frauddetector:GetExternalModels, frauddetector:GetLabels, frauddetector:GetModels, frauddetector:GetOutcomes, frauddetector:GetVariables, frauddetector:ListTagsForResource, gamelift:DescribeAlias, gamelift:DescribeBuild, gamelift:DescribeFleetAttributes, gamelift:DescribeFleetCapacity, gamelift:DescribeFleetLocationAttributes, gamelift:DescribeFleetLocationCapacity, gamelift:DescribeFleetPortSettings, gamelift:DescribeGameServerGroup, gamelift:DescribeGameSessionQueues, gamelift:DescribeMatchmakingConfigurations, gamelift:DescribeMatchmakingRuleSets, gamelift:DescribeRuntimeConfiguration, gamelift:DescribeScript, gamelift:DescribeVpcPeeringAuthorizations, gamelift:ListAliases, gamelift:ListBuilds, gamelift:ListFleets, gamelift:ListGameServerGroups, gamelift:ListScripts, gamelift:ListTagsForResource, geo:ListMaps, glue:GetClassifier, glue:GetClassifiers, imagebuilder:GetContainerRecipe, imagebuilder:GetImage, imagebuilder:GetImagePipeline, imagebuilder:GetImageRecipe, imagebuilder:ListContainerRecipes, imagebuilder:ListImageBuildVersions, imagebuilder:ListImagePipelines, imagebuilder:ListImageRecipes, imagebuilder:ListImages, iot:DescribeCertificate, iot:DescribeDimension, iot:DescribeRoleAlias, iot:DescribeSecurityProfile, iot:GetPolicy, iot:GetTopicRule, iot:GetTopicRuleDestination, iot:ListCertificates, iot:ListDimensions, iot:ListPolicies, iot:ListRoleAliases, iot:ListSecurityProfiles, iot:ListSecurityProfilesForTarget, iot:ListTagsForResource, iot:ListTargetsForSecurityProfile, iot:ListTopicRuleDestinations, iot:ListTopicRules, iot:ListV2LoggingLevels, iot:ValidateSecurityProfileBehaviors, iotanalytics:DescribeChannel, iotanalytics:DescribeDataset, iotanalytics:DescribeDatastore, iotanalytics:DescribePipeline, iotanalytics:ListChannels, iotanalytics:ListDatasets, iotanalytics:ListDatastores, iotanalytics:ListPipelines, iotanalytics:ListTagsForResource, iotevents:DescribeAlarmModel, iotevents:DescribeDetectorModel, iotevents:DescribeInput, iotevents:ListAlarmModels, iotevents:ListDetectorModels, iotevents:ListInputs, iotevents:ListTagsForResource, iotsitewise:DescribeAccessPolicy, iotsitewise:DescribeAsset, iotsitewise:ListAccessPolicies, iotsitewise:ListAssets, iottwinmaker:GetEntity, iottwinmaker:GetScene, iottwinmaker:GetWorkspace, iottwinmaker:ListEntities, iottwinmaker:ListScenes, iottwinmaker:ListTagsForResource, iottwinmaker:ListWorkspaces, ivs:GetPlaybackKeyPair, ivs:GetRecordingConfiguration, ivs:GetStreamKey, ivs:ListChannels, ivs:ListPlaybackKeyPairs, ivs:ListRecordingConfigurations, ivs:ListStreamKeys, ivs:ListTagsForResource, kinesisanalytics:ListApplications, lakeformation:DescribeResource, lakeformation:GetDataLakeSettings, lakeformation:ListPermissions, lakeformation:ListResources, lex:DescribeBot, lex:DescribeBotAlias, lex:DescribeResourcePolicy, lex:ListBotAliases, lex:ListBotLocales, lex:ListBots, lex:ListTagsForResource, license-manager:GetGrant, license-manager:GetLicense, license-manager:ListDistributedGrants, license-manager:ListLicenses, license-manager:ListReceivedGrants, lightsail:GetAlarms, lightsail:GetBuckets, lightsail:GetCertificates, lightsail:GetDisk, lightsail:GetDisks, lightsail:GetInstance, lightsail:GetInstances, lightsail:GetKeyPair, lightsail:GetLoadBalancer, lightsail:GetLoadBalancers, lightsail:GetLoadBalancerTlsCertificates, lightsail:GetStaticIp, lightsail:GetStaticIps, lookoutequipment:DescribeInferenceScheduler, lookoutequipment:ListTagsForResource, lookoutmetrics:DescribeAlert, lookoutmetrics:DescribeAnomalyDetector, lookoutmetrics:ListAlerts, lookoutmetrics:ListAnomalyDetectors, lookoutmetrics:ListMetricSets, lookoutmetrics:ListTagsForResource, lookoutvision:DescribeProject, lookoutvision:ListProjects, managedblockchain:GetMember, managedblockchain:GetNetwork, managedblockchain:GetNode, managedblockchain:ListInvitations, managedblockchain:ListMembers, managedblockchain:ListNodes, mediapackage-vod:DescribePackagingGroup, mediapackage-vod:ListPackagingGroups, mediapackage-vod:ListTagsForResource, mobiletargeting:GetInAppTemplate, mobiletargeting:ListTemplates, mq:DescribeBroker, mq:ListBrokers, nimble:GetLaunchProfile, nimble:GetLaunchProfileDetails, nimble:GetStreamingImage, nimble:GetStudio, nimble:GetStudioComponent, nimble:ListLaunchProfiles, nimble:ListStreamingImages, nimble:ListStudioComponents, nimble:ListStudios, profile:GetDomain, profile:GetIntegration, profile:GetProfileObjectType, profile:ListDomains, profile:ListIntegrations, profile:ListProfileObjectTypes, profile:ListTagsForResource, quicksight:DescribeAnalysis, quicksight:DescribeAnalysisPermissions, quicksight:DescribeDataSet, quicksight:DescribeDataSetPermissions, quicksight:DescribeTheme, quicksight:DescribeThemePermissions, quicksight:ListAnalyses, quicksight:ListDataSets, quicksight:ListThemes, resiliencehub:DescribeApp, resiliencehub:DescribeAppVersionTemplate, resiliencehub:DescribeResiliencyPolicy, resiliencehub:ListApps, resiliencehub:ListAppVersionResourceMappings, resiliencehub:ListResiliencyPolicies, route53-recovery-readiness:GetCell, route53-recovery-readiness:GetReadinessCheck, route53-recovery-readiness:GetRecoveryGroup, route53-recovery-readiness:GetResourceSet, route53-recovery-readiness:ListCells, route53-recovery-readiness:ListReadinessChecks, route53-recovery-readiness:ListRecoveryGroups, route53-recovery-readiness:ListResourceSets, route53resolver:GetFirewallDomainList, route53resolver:GetFirewallRuleGroup, route53resolver:GetFirewallRuleGroupAssociation, route53resolver:GetResolverQueryLogConfig, route53resolver:ListFirewallDomainLists, route53resolver:ListFirewallDomains, route53resolver:ListFirewallRuleGroupAssociations, route53resolver:ListFirewallRuleGroups, route53resolver:ListFirewallRules, route53resolver:ListResolverQueryLogConfigs, rum:GetAppMonitor, rum:GetAppMonitorData, rum:ListAppMonitors, rum:ListTagsForResource, s3-outposts:GetAccessPoint, s3-outposts:GetAccessPointPolicy, s3-outposts:GetBucket, s3-outposts:GetBucketPolicy, s3-outposts:GetBucketTagging, s3-outposts:GetLifecycleConfiguration, s3-outposts:ListAccessPoints, s3-outposts:ListEndpoints, s3-outposts:ListRegionalBuckets, schemas:DescribeDiscoverer, schemas:DescribeRegistry, schemas:DescribeSchema, schemas:ListDiscoverers, schemas:ListRegistries, schemas:ListSchemas, sdb:GetAttributes, sdb:ListDomains, ses:ListEmailTemplates, ses:ListReceiptFilters, ses:ListReceiptRuleSets, ses:ListTemplates, signer:GetSigningProfile, signer:ListProfilePermissions, signer:ListSigningProfiles, synthetics:DescribeCanaries, synthetics:DescribeCanariesLastRun, synthetics:DescribeRuntimeVersions, synthetics:GetCanary, synthetics:GetCanaryRuns, synthetics:ListTagsForResource, timestream:DescribeDatabase, timestream:DescribeTable, timestream:ListDatabases, timestream:ListTables, timestream:ListTagsForResource, transfer:DescribeServer, transfer:DescribeUser, transfer:DescribeWorkflow, transfer:ListServers, transfer:ListUsers, transfer:ListWorkflows, voiceid:DescribeDomain, and voiceid:ListTagsForResource |
Kebijakan ini sekarang mendukung izin tambahan untuk Amazon AppFlow, Amazon, Amazon CloudWatch RUM CloudWatch, Amazon CloudWatch Synthetics, Profil Pelanggan Amazon Connect, ID Suara Pelanggan Amazon Connect, Amazon DevOps Guru, Amazon Elastic Compute Cloud (Amazon EC2), Amazon EC2 Auto Scaling, Amazon EMR, Amazon, Amazon EventBridge Schemas,, Amazon Fraud Detector EventBridge, Amazon GameLift Server Amazon FinSpace, Amazon Interactive Video Service (Amazon IVS), Amazon Managed Service untuk Apache Flink, EC2 Image Builder, Amazon Lex, Layar Cahaya Amazon, Layanan Lokasi Amazon, Amazon Lookout untuk Peralatan, Amazon Lookout untuk Metrik, Amazon Lookout untuk Visi, Amazon Managed Blockchain, Amazon MQ, Amazon Nimble StudioAmazon Pinpoint, Amazon Quick, Pengontrol Pemulihan Aplikasi Amazon (ARC), Amazon Route 53 Resolver, Layanan Penyimpanan Sederhana Amazon (Amazon S3), Amazon SimpleDB, Layanan Email Sederhana Amazon (Amazon SES), Amazon Timestream, AWS AppConfig, AWS AppSync, AWS Auto Scaling, AWS Backup, AWS Budgets,, AWS Cost Explorer, AWS Cloud9, AWS Directory Service AWS DataSync AWS Elemental MediaPackage AWS Glue AWS IoT AWS IoT Analytics AWS IoT Events AWS IoT SiteWise, AWS IoT TwinMaker, AWS Lake Formation, AWS License Manager, AWS Resilience Hub, AWS Signer, dan AWS Transfer Family. |
7 September 2022 |
|
AWS_ConfigRole— Tambah appconfig:ListApplications, appflow:DescribeConnectorProfiles, appsync:GetApiCache, autoscaling-plans:DescribeScalingPlanResources, autoscaling-plans:DescribeScalingPlans, autoscaling-plans:GetScalingPlanResourceForecastData, autoscaling:DescribeWarmPool, backup:DescribeFramework, backup:DescribeReportPlan, backup:ListFrameworks, backup:ListReportPlans, budgets:DescribeBudgetAction, budgets:DescribeBudgetActionsForAccount, budgets:DescribeBudgetActionsForBudget, budgets:ViewBudget, ce:GetAnomalyMonitors, ce:GetAnomalySubscriptions, cloud9:DescribeEnvironmentMemberships, cloud9:DescribeEnvironments, cloud9:ListEnvironments, cloud9:ListTagsForResource, cloudwatch:GetMetricStream, cloudwatch:ListMetricStreams, datasync:DescribeLocationFsxWindows, devops-guru:GetResourceCollection, ds:DescribeDirectories, ec2:DescribeTrafficMirrorTargets, ec2:GetNetworkInsightsAccessScopeAnalysisFindings, ec2:GetNetworkInsightsAccessScopeContent, elasticmapreduce:DescribeStudio, elasticmapreduce:GetStudioSessionMapping, elasticmapreduce:ListStudios, elasticmapreduce:ListStudioSessionMappings, events:DescribeEndpoint, events:DescribeEventBus, events:DescribeRule, events:ListArchives, events:ListEndpoints, events:ListEventBuses, events:ListRules, events:ListTagsForResource, events:ListTargetsByRule, finspace:GetEnvironment, finspace:ListEnvironments, frauddetector:GetDetectors, frauddetector:GetDetectorVersion, frauddetector:GetEntityTypes, frauddetector:GetEventTypes, frauddetector:GetExternalModels, frauddetector:GetLabels, frauddetector:GetModels, frauddetector:GetOutcomes, frauddetector:GetVariables, frauddetector:ListTagsForResource, gamelift:DescribeAlias, gamelift:DescribeBuild, gamelift:DescribeFleetAttributes, gamelift:DescribeFleetCapacity, gamelift:DescribeFleetLocationAttributes, gamelift:DescribeFleetLocationCapacity, gamelift:DescribeFleetPortSettings, gamelift:DescribeGameServerGroup, gamelift:DescribeGameSessionQueues, gamelift:DescribeMatchmakingConfigurations, gamelift:DescribeMatchmakingRuleSets, gamelift:DescribeRuntimeConfiguration, gamelift:DescribeScript, gamelift:DescribeVpcPeeringAuthorizations, gamelift:ListAliases, gamelift:ListBuilds, gamelift:ListFleets, gamelift:ListGameServerGroups, gamelift:ListScripts, gamelift:ListTagsForResource, geo:ListMaps, glue:GetClassifier, glue:GetClassifiers, imagebuilder:GetContainerRecipe, imagebuilder:GetImage, imagebuilder:GetImagePipeline, imagebuilder:GetImageRecipe, imagebuilder:ListContainerRecipes, imagebuilder:ListImageBuildVersions, imagebuilder:ListImagePipelines, imagebuilder:ListImageRecipes, imagebuilder:ListImages, iot:DescribeCertificate, iot:DescribeDimension, iot:DescribeRoleAlias, iot:DescribeSecurityProfile, iot:GetPolicy, iot:GetTopicRule, iot:GetTopicRuleDestination, iot:ListCertificates, iot:ListDimensions, iot:ListPolicies, iot:ListRoleAliases, iot:ListSecurityProfiles, iot:ListSecurityProfilesForTarget, iot:ListTagsForResource, iot:ListTargetsForSecurityProfile, iot:ListTopicRuleDestinations, iot:ListTopicRules, iot:ListV2LoggingLevels, iot:ValidateSecurityProfileBehaviors, iotanalytics:DescribeChannel, iotanalytics:DescribeDataset, iotanalytics:DescribeDatastore, iotanalytics:DescribePipeline, iotanalytics:ListChannels, iotanalytics:ListDatasets, iotanalytics:ListDatastores, iotanalytics:ListPipelines, iotanalytics:ListTagsForResource, iotevents:DescribeAlarmModel, iotevents:DescribeDetectorModel, iotevents:DescribeInput, iotevents:ListAlarmModels, iotevents:ListDetectorModels, iotevents:ListInputs, iotevents:ListTagsForResource, iotsitewise:DescribeAccessPolicy, iotsitewise:DescribeAsset, iotsitewise:ListAccessPolicies, iotsitewise:ListAssets, iottwinmaker:GetEntity, iottwinmaker:GetScene, iottwinmaker:GetWorkspace, iottwinmaker:ListEntities, iottwinmaker:ListScenes, iottwinmaker:ListTagsForResource, iottwinmaker:ListWorkspaces, ivs:GetPlaybackKeyPair, ivs:GetRecordingConfiguration, ivs:GetStreamKey, ivs:ListChannels, ivs:ListPlaybackKeyPairs, ivs:ListRecordingConfigurations, ivs:ListStreamKeys, ivs:ListTagsForResource, kinesisanalytics:ListApplications, lakeformation:DescribeResource, lakeformation:GetDataLakeSettings, lakeformation:ListPermissions, lakeformation:ListResources, lex:DescribeBot, lex:DescribeBotAlias, lex:DescribeResourcePolicy, lex:ListBotAliases, lex:ListBotLocales, lex:ListBots, lex:ListTagsForResource, license-manager:GetGrant, license-manager:GetLicense, license-manager:ListDistributedGrants, license-manager:ListLicenses, license-manager:ListReceivedGrants, lightsail:GetAlarms, lightsail:GetBuckets, lightsail:GetCertificates, lightsail:GetDisk, lightsail:GetDisks, lightsail:GetInstance, lightsail:GetInstances, lightsail:GetKeyPair, lightsail:GetLoadBalancer, lightsail:GetLoadBalancers, lightsail:GetLoadBalancerTlsCertificates, lightsail:GetStaticIp, lightsail:GetStaticIps, lookoutequipment:DescribeInferenceScheduler, lookoutequipment:ListTagsForResource, lookoutmetrics:DescribeAlert, lookoutmetrics:DescribeAnomalyDetector, lookoutmetrics:ListAlerts, lookoutmetrics:ListAnomalyDetectors, lookoutmetrics:ListMetricSets, lookoutmetrics:ListTagsForResource, lookoutvision:DescribeProject, lookoutvision:ListProjects, managedblockchain:GetMember, managedblockchain:GetNetwork, managedblockchain:GetNode, managedblockchain:ListInvitations, managedblockchain:ListMembers, managedblockchain:ListNodes, mediapackage-vod:DescribePackagingGroup, mediapackage-vod:ListPackagingGroups, mediapackage-vod:ListTagsForResource, mobiletargeting:GetInAppTemplate, mobiletargeting:ListTemplates, mq:DescribeBroker, mq:ListBrokers, nimble:GetLaunchProfile, nimble:GetLaunchProfileDetails, nimble:GetStreamingImage, nimble:GetStudio, nimble:GetStudioComponent, nimble:ListLaunchProfiles, nimble:ListStreamingImages, nimble:ListStudioComponents, nimble:ListStudios, profile:GetDomain, profile:GetIntegration, profile:GetProfileObjectType, profile:ListDomains, profile:ListIntegrations, profile:ListProfileObjectTypes, profile:ListTagsForResource, quicksight:DescribeAnalysis, quicksight:DescribeAnalysisPermissions, quicksight:DescribeDataSet, quicksight:DescribeDataSetPermissions, quicksight:DescribeTheme, quicksight:DescribeThemePermissions, quicksight:ListAnalyses, quicksight:ListDataSets, quicksight:ListThemes, resiliencehub:DescribeApp, resiliencehub:DescribeAppVersionTemplate, resiliencehub:DescribeResiliencyPolicy, resiliencehub:ListApps, resiliencehub:ListAppVersionResourceMappings, resiliencehub:ListResiliencyPolicies, route53-recovery-readiness:GetCell, route53-recovery-readiness:GetReadinessCheck, route53-recovery-readiness:GetRecoveryGroup, route53-recovery-readiness:GetResourceSet, route53-recovery-readiness:ListCells, route53-recovery-readiness:ListReadinessChecks, route53-recovery-readiness:ListRecoveryGroups, route53-recovery-readiness:ListResourceSets, route53resolver:GetFirewallDomainList, route53resolver:GetFirewallRuleGroup, route53resolver:GetFirewallRuleGroupAssociation, route53resolver:GetResolverQueryLogConfig, route53resolver:ListFirewallDomainLists, route53resolver:ListFirewallDomains, route53resolver:ListFirewallRuleGroupAssociations, route53resolver:ListFirewallRuleGroups, route53resolver:ListFirewallRules, route53resolver:ListResolverQueryLogConfigs, rum:GetAppMonitor, rum:GetAppMonitorData, rum:ListAppMonitors, rum:ListTagsForResource, s3-outposts:GetAccessPoint, s3-outposts:GetAccessPointPolicy, s3-outposts:GetBucket, s3-outposts:GetBucketPolicy, s3-outposts:GetBucketTagging, s3-outposts:GetLifecycleConfiguration, s3-outposts:ListAccessPoints, s3-outposts:ListEndpoints, s3-outposts:ListRegionalBuckets, schemas:DescribeDiscoverer, schemas:DescribeRegistry, schemas:DescribeSchema, schemas:ListDiscoverers, schemas:ListRegistries, schemas:ListSchemas, sdb:GetAttributes, sdb:ListDomains, ses:ListEmailTemplates, ses:ListReceiptFilters, ses:ListReceiptRuleSets, ses:ListTemplates, signer:GetSigningProfile, signer:ListProfilePermissions, signer:ListSigningProfiles, synthetics:DescribeCanaries, synthetics:DescribeCanariesLastRun, synthetics:DescribeRuntimeVersions, synthetics:GetCanary, synthetics:GetCanaryRuns, synthetics:ListTagsForResource, timestream:DescribeDatabase, timestream:DescribeTable, timestream:ListDatabases, timestream:ListTables, timestream:ListTagsForResource, transfer:DescribeServer, transfer:DescribeUser, transfer:DescribeWorkflow, transfer:ListServers, transfer:ListUsers, transfer:ListWorkflows, voiceid:DescribeDomain, and voiceid:ListTagsForResource |
Kebijakan ini sekarang mendukung izin tambahan untuk Amazon AppFlow, Amazon, Amazon CloudWatch RUM CloudWatch, Amazon CloudWatch Synthetics, Profil Pelanggan Amazon Connect, ID Suara Pelanggan Amazon Connect, Amazon DevOps Guru, Amazon Elastic Compute Cloud (Amazon EC2), Amazon EC2 Auto Scaling, Amazon EMR, Amazon, Amazon EventBridge Schemas,, Amazon Fraud Detector EventBridge, Amazon GameLift Server Amazon FinSpace, Amazon Interactive Video Service (Amazon IVS), Amazon Managed Service untuk Apache Flink, EC2 Image Builder, Amazon Lex, Layar Cahaya Amazon, Layanan Lokasi Amazon, Amazon Lookout untuk Peralatan, Amazon Lookout untuk Metrik, Amazon Lookout untuk Visi, Amazon Managed Blockchain, Amazon MQ, Amazon Nimble StudioAmazon Pinpoint, Amazon Quick, Pengontrol Pemulihan Aplikasi Amazon (ARC), Amazon Route 53 Resolver, Layanan Penyimpanan Sederhana Amazon (Amazon S3), Amazon SimpleDB, Layanan Email Sederhana Amazon (Amazon SES), Amazon Timestream, AWS AppConfig, AWS AppSync, AWS Auto Scaling, AWS Backup, AWS Budgets,, AWS Cost Explorer, AWS Cloud9, AWS Directory Service AWS DataSync AWS Elemental MediaPackage AWS Glue AWS IoT AWS IoT Analytics AWS IoT Events AWS IoT SiteWise, AWS IoT TwinMaker, AWS Lake Formation, AWS License Manager, AWS Resilience Hub, AWS Signer, dan AWS Transfer Family |
7 September 2022 |
|
AWSConfigServiceRolePolicy— Tambah datasync:ListAgents, datasync:ListLocations, datasync:ListTasks, servicediscovery:ListNamespaces, servicediscovery:ListServices, and ses:ListContactLists |
Kebijakan ini sekarang memberikan izin untuk mengembalikan daftar AWS DataSync agen, lokasi DataSync sumber dan tujuan, serta DataSync tugas dalam daftar informasi ringkasan tentang ruang nama dan layanan yang terkait dengan satu atau beberapa ruang nama tertentu dalam Akun AWS; dan daftar semua daftar kontak Amazon Simple Email Service (Amazon SES) yang tersedia di. Akun AWS AWS Cloud Map Akun AWS |
22 Agustus 2022 |
|
AWS_ConfigRole— Tambah datasync:ListAgents, datasync:ListLocations, datasync:ListTasks, servicediscovery:ListNamespaces, servicediscovery:ListServices, and ses:ListContactLists |
Kebijakan ini sekarang memberikan izin untuk mengembalikan daftar AWS DataSync agen, lokasi DataSync sumber dan tujuan, serta DataSync tugas dalam daftar informasi ringkasan tentang ruang nama dan layanan yang terkait dengan satu atau beberapa ruang nama tertentu dalam Akun AWS; dan daftar semua daftar kontak Amazon Simple Email Service (Amazon SES) yang tersedia di. Akun AWS AWS Cloud Map Akun AWS |
22 Agustus 2022 |
|
ConfigConformsServiceRolePolicy— Tambah cloudwatch:PutMetricData |
Kebijakan ini sekarang memberikan izin untuk mempublikasikan titik data metrik ke Amazon CloudWatch. |
25 Juli 2022 |
|
AWSConfigServiceRolePolicy— Tambah amplifyuibuilder:ExportThemes, amplifyuibuilder:GetTheme, appconfig:GetApplication, appconfig:GetApplication, appconfig:GetConfigurationProfile, appconfig:GetConfigurationProfile, appconfig:GetDeployment, appconfig:GetDeploymentStrategy, appconfig:GetEnvironment, appconfig:GetHostedConfigurationVersion, appconfig:ListTagsForResource, appsync:GetGraphqlApi, appsync:ListGraphqlApis, billingconductor: ListPricingRulesAssociatedToPricingPlan, billingconductor:ListAccountAssociations, billingconductor:ListBillingGroups, billingconductor:ListCustomLineItems, billingconductor:ListPricingPlans, billingconductor:ListPricingRules, billingconductor:ListTagsForResource, datasync:DescribeAgent, datasync:DescribeLocationEfs, datasync:DescribeLocationFsxLustre, datasync:DescribeLocationHdfs, datasync:DescribeLocationNfs, datasync:DescribeLocationObjectStorage, datasync:DescribeLocationS3, datasync:DescribeLocationSmb, datasync:DescribeTask, datasync:ListTagsForResource, ecr:DescribePullThroughCacheRules, ecr:DescribeRegistry, ecr:GetRegistryPolicy, elasticache:DescribeCacheParameters, elasticloadbalancing:DescribeListenerCertificates, elasticloadbalancing:DescribeTargetGroupAttributes, elasticloadbalancing:DescribeTargetGroups, elasticloadbalancing:DescribeTargetHealth, events:DescribeApiDestination, events:DescribeArchive, fms:GetNotificationChannel, fms:GetPolicy, fms:ListPolicies, fms:ListTagsForResource, fsx:DescribeVolumes, geo:DescribeGeofenceCollection, geo:DescribeMap, geo:DescribePlaceIndex, geo:DescribeRouteCalculator, geo:DescribeTracker, geo:ListTrackerConsumers, glue:BatchGetJobs, glue:BatchGetWorkflows, glue:GetCrawler, glue:GetCrawlers, glue:GetJob, glue:GetJobs, glue:GetWorkflow, imagebuilder: GetComponent, imagebuilder: ListComponentBuildVersions, imagebuilder: ListComponents, imagebuilder:GetDistributionConfiguration, imagebuilder:GetInfrastructureConfiguration, imagebuilder:ListDistributionConfigurations, imagebuilder:ListInfrastructureConfigurations, kafka:DescribeClusterV2, kafka:ListClustersV2, kinesisanalytics:DescribeApplication, kinesisanalytics:ListTagsForResource, quicksight:DescribeDataSource, quicksight:DescribeDataSourcePermissions, quicksight:ListTagsForResource, rekognition:DescribeStreamProcessor, rekognition:ListTagsForResource, robomaker:DescribeRobotApplication, robomaker:DescribeSimulationApplication, s3:GetStorageLensConfiguration, s3:GetStorageLensConfigurationTagging, servicediscovery:GetInstance, servicediscovery:GetNamespace, servicediscovery:GetService, servicediscovery:ListTagsForResource, ses:DescribeReceiptRule, ses:DescribeReceiptRuleSet, ses:GetContactList, ses:GetEmailTemplate, ses:GetTemplate, and sso:GetInlinePolicyForPermissionSet |
Kebijakan ini sekarang mendukung izin tambahan untuk Amazon Elastic Container Service (Amazon ECS), Amazon, Amazon FSx ElastiCache EventBridge, Amazon Managed Service untuk Apache Flink, Layanan Lokasi Amazon, Streaming Terkelola Amazon untuk Apache Kafka, Amazon Quick, Amazon Rekognition,, Layanan Penyimpanan Sederhana Amazon (Amazon S3) AWS RoboMaker, Amazon Simple Email Service (Amazon SES),,,,, AWS Amplify, (Pusat Identitas IAM) AWS AppConfig AWS AppSync AWS Billing Conductor AWS DataSync AWS Firewall Manager, Pembuat Gambar EC2 AWS Glue, AWS IAM Identity Center Elastic dan Menyeimbangkan. |
15 Juli 2022 |
|
AWS_ConfigRole— Tambah amplifyuibuilder:ExportThemes, amplifyuibuilder:GetTheme, appconfig:GetApplication, appconfig:GetApplication, appconfig:GetConfigurationProfile, appconfig:GetConfigurationProfile, appconfig:GetDeployment, appconfig:GetDeploymentStrategy, appconfig:GetEnvironment, appconfig:GetHostedConfigurationVersion, appconfig:ListTagsForResource, appsync:GetGraphqlApi, appsync:ListGraphqlApis, billingconductor: ListPricingRulesAssociatedToPricingPlan, billingconductor:ListAccountAssociations, billingconductor:ListBillingGroups, billingconductor:ListCustomLineItems, billingconductor:ListPricingPlans, billingconductor:ListPricingRules, billingconductor:ListTagsForResource, datasync:DescribeAgent, datasync:DescribeLocationEfs, datasync:DescribeLocationFsxLustre, datasync:DescribeLocationHdfs, datasync:DescribeLocationNfs, datasync:DescribeLocationObjectStorage, datasync:DescribeLocationS3, datasync:DescribeLocationSmb, datasync:DescribeTask, datasync:ListTagsForResource, ecr:DescribePullThroughCacheRules, ecr:DescribeRegistry, ecr:GetRegistryPolicy, elasticache:DescribeCacheParameters, elasticloadbalancing:DescribeListenerCertificates, elasticloadbalancing:DescribeTargetGroupAttributes, elasticloadbalancing:DescribeTargetGroups, elasticloadbalancing:DescribeTargetHealth, events:DescribeApiDestination, events:DescribeArchive, fms:GetNotificationChannel, fms:GetPolicy, fms:ListPolicies, fms:ListTagsForResource, fsx:DescribeVolumes, geo:DescribeGeofenceCollection, geo:DescribeMap, geo:DescribePlaceIndex, geo:DescribeRouteCalculator, geo:DescribeTracker, geo:ListTrackerConsumers, glue:BatchGetJobs, glue:BatchGetWorkflows, glue:GetCrawler, glue:GetCrawlers, glue:GetJob, glue:GetJobs, glue:GetWorkflow, imagebuilder: GetComponent, imagebuilder: ListComponentBuildVersions, imagebuilder: ListComponents, imagebuilder:GetDistributionConfiguration, imagebuilder:GetInfrastructureConfiguration, imagebuilder:ListDistributionConfigurations, imagebuilder:ListInfrastructureConfigurations, kafka:DescribeClusterV2, kafka:ListClustersV2, kinesisanalytics:DescribeApplication, kinesisanalytics:ListTagsForResource, quicksight:DescribeDataSource, quicksight:DescribeDataSourcePermissions, quicksight:ListTagsForResource, rekognition:DescribeStreamProcessor, rekognition:ListTagsForResource, robomaker:DescribeRobotApplication, robomaker:DescribeSimulationApplication, s3:GetStorageLensConfiguration, s3:GetStorageLensConfigurationTagging, servicediscovery:GetInstance, servicediscovery:GetNamespace, servicediscovery:GetService, servicediscovery:ListTagsForResource, ses:DescribeReceiptRule, ses:DescribeReceiptRuleSet, ses:GetContactList, ses:GetEmailTemplate, ses:GetTemplate, and sso:GetInlinePolicyForPermissionSet |
Kebijakan ini sekarang mendukung izin tambahan untuk Amazon Elastic Container Service (Amazon ECS), Amazon, Amazon FSx ElastiCache EventBridge, Amazon Managed Service untuk Apache Flink, Layanan Lokasi Amazon, Streaming Terkelola Amazon untuk Apache Kafka, Amazon Quick, Amazon Rekognition,, Layanan Penyimpanan Sederhana Amazon (Amazon S3) AWS RoboMaker, Amazon Simple Email Service (Amazon SES),,,,, AWS Amplify, (Pusat Identitas IAM) AWS AppConfig AWS AppSync AWS Billing Conductor AWS DataSync AWS Firewall Manager, Pembuat Gambar EC2 AWS Glue, AWS IAM Identity Center Elastic dan Menyeimbangkan. |
15 Juli 2022 |
|
AWSConfigServiceRolePolicy— Tambah athena:GetDataCatalog, athena:ListDataCatalogs, athena:ListTagsForResource, detective:ListGraphs, detective:ListTagsForResource, glue:BatchGetDevEndpoints, glue:GetDevEndpoint, glue:GetDevEndpoints, glue:GetSecurityConfiguration, glue:GetSecurityConfigurations, glue:GetTags glue:GetWorkGroup, glue:ListCrawlers, glue:ListDevEndpoints, glue:ListJobs, glue:ListMembers, glue:ListWorkflows, glue:ListWorkGroups, guardduty:GetFilter, guardduty:GetIPSet, guardduty:GetThreatIntelSet, guardduty:GetMembers, guardduty:ListFilters, guardduty:ListIPSets, guardduty:ListTagsForResource, guardduty:ListThreatIntelSets, macie:GetMacieSession, ram:GetResourceShareAssociations, ram:GetResourceShares, ses:GetConfigurationSet, ses:GetConfigurationSetEventDestinations, ses:ListConfigurationSets, sso:DescribeInstanceAccessControlAttributeConfiguration, sso:DescribePermissionSet, sso:ListManagedPoliciesInPermissionSet, sso:ListPermissionSets, and sso:ListTagsForResource |
Kebijakan ini sekarang memberikan izin untuk mendapatkan katalog data Amazon Athena tertentu, mencantumkan katalog data Athena dalam Akun AWS, dan daftar tag yang terkait dengan kelompok kerja Athena atau sumber daya katalog data; untuk mendapatkan daftar grafik perilaku Amazon Detective dan tag daftar untuk grafik perilaku Detektif; mendapatkan daftar metadata sumber daya untuk daftar nama titik akhir AWS Glue pengembangan tertentu, dapatkan informasi tentang titik akhir AWS Glue pengembangan tertentu, dapatkan semua titik akhir AWS Glue
pengembangan dalam, ambil keamanan yang Akun AWS ditentukan AWS Glue konfigurasi, dapatkan semua konfigurasi AWS Glue keamanan, dapatkan daftar tag yang terkait dengan AWS Glue sumber daya, dapatkan informasi tentang AWS Glue kelompok kerja dengan nama yang ditentukan, ambil nama semua sumber daya AWS Glue crawler dalam AWS
akun, dapatkan nama semua AWS Glue |
31 Mei 2022 |
|
AWS_ConfigRole— Tambah athena:GetDataCatalog, athena:ListDataCatalogs, athena:ListTagsForResource, detective:ListGraphs, detective:ListTagsForResource, glue:BatchGetDevEndpoints, glue:GetDevEndpoint, glue:GetDevEndpoints, glue:GetSecurityConfiguration, glue:GetSecurityConfigurations, glue:GetTags glue:GetWorkGroup, glue:ListCrawlers, glue:ListDevEndpoints, glue:ListJobs, glue:ListMembers, glue:ListWorkflows, glue:ListWorkGroups, guardduty:GetFilter, guardduty:GetIPSet, guardduty:GetThreatIntelSet, guardduty:GetMembers, guardduty:ListFilters, guardduty:ListIPSets, guardduty:ListTagsForResource, guardduty:ListThreatIntelSets, macie:GetMacieSession, ram:GetResourceShareAssociations, ram:GetResourceShares, ses:GetConfigurationSet, ses:GetConfigurationSetEventDestinations, ses:ListConfigurationSets, sso:DescribeInstanceAccessControlAttributeConfiguration, sso:DescribePermissionSet, sso:ListManagedPoliciesInPermissionSet, sso:ListPermissionSets, and sso:ListTagsForResource |
Kebijakan ini sekarang memberikan izin untuk mendapatkan katalog data Amazon Athena tertentu, mencantumkan katalog data Athena dalam Akun AWS, dan daftar tag yang terkait dengan kelompok kerja Athena atau sumber daya katalog data; untuk mendapatkan daftar grafik perilaku Amazon Detective dan tag daftar untuk grafik perilaku Detektif; mendapatkan daftar metadata sumber daya untuk daftar nama titik akhir AWS Glue pengembangan tertentu, dapatkan informasi tentang titik akhir AWS Glue pengembangan tertentu, dapatkan semua titik akhir AWS Glue
pengembangan dalam, ambil keamanan yang Akun AWS ditentukan AWS Glue konfigurasi, dapatkan semua konfigurasi AWS Glue keamanan, dapatkan daftar tag yang terkait dengan AWS Glue sumber daya, dapatkan informasi tentang AWS Glue kelompok kerja dengan nama yang ditentukan, ambil nama semua sumber daya AWS Glue crawler dalam AWS
akun, dapatkan nama semua AWS Glue |
31 Mei 2022 |
|
AWSConfigServiceRolePolicy— Tambah cloudformation:GetResource, cloudformation:ListResources, cloudtrail:GetEventDataStore, cloudtrail:ListEventDataStores, dax:DescribeParameterGroups, dax:DescribeParameters, dax:DescribeSubnetGroups, DMS:DescribeReplicationTasks, and organizations:ListPolicies |
Kebijakan ini sekarang memberikan izin untuk mendapatkan informasi tentang semua atau penyimpanan data AWS CloudTrail peristiwa tertentu (EDS), mendapatkan informasi tentang semua atau AWS CloudFormation sumber daya tertentu, mendapatkan daftar grup parameter atau grup subnet DynamoDB Accelerator (DAX), mendapatkan informasi tentang tugas replikasi AWS Database Migration Service (AWS DMS) untuk akun Anda di wilayah yang diakses saat ini, dan mendapatkan daftar semua kebijakan dalam AWS Organizations jenis tertentu. |
7 April 2022 |
|
AWS_ConfigRole— Tambahkan cloudformation:GetResource, cloudformation:ListResources, cloudtrail:GetEventDataStore, cloudtrail:ListEventDataStores, dax:DescribeParameterGroups, dax:DescribeParameters, dax:DescribeSubnetGroups, DMS:DescribeReplicationTasks, and organizations:ListPolicies |
Kebijakan ini sekarang memberikan izin untuk mendapatkan informasi tentang semua atau penyimpanan data AWS CloudTrail peristiwa tertentu (EDS), mendapatkan informasi tentang semua atau AWS CloudFormation sumber daya tertentu, mendapatkan daftar grup parameter atau grup subnet DynamoDB Accelerator (DAX), mendapatkan informasi tentang tugas replikasi AWS Database Migration Service (AWS DMS) untuk akun Anda di wilayah yang diakses saat ini, dan mendapatkan daftar semua kebijakan dalam AWS Organizations jenis tertentu. |
7 April 2022 |
|
AWSConfigServiceRolePolicy— Tambahkan backup-gateway:ListTagsForResource, backup-gateway:ListVirtualMachines, batch:DescribeComputeEnvironments, batch:DescribeJobQueues, batch:ListTagsForResource, dax:ListTags, dms:DescribeCertificates, dynamodb:DescribeGlobalTable, dynamodb:DescribeGlobalTableSettings, ec2:DescribeClientVpnAuthorizationRules, ec2:DescribeClientVpnEndpoints, ec2:DescribeDhcpOptions, ec2:DescribeFleets, ec2:DescribeNetworkAcls, ec2:DescribePlacementGroups, ec2:DescribeSpotFleetRequests, ec2:DescribeVolumeAttribute, ec2:DescribeVolumes, eks:DescribeFargateProfile, eks:ListFargateProfiles, eks:ListTagsForResource, fsx:ListTagsForResource, guardduty:ListOrganizationAdminAccounts, kms:ListAliases, opsworks:DescribeLayers, opsworks:DescribeStacks, opsworks:ListTags, rds:DescribeDBClusterParameterGroups, rds:DescribeDBClusterParameters, states:DescribeActivity, states:ListActivities, wafv2:GetRuleGroup, wafv2:ListRuleGroups, wafv2:ListTagsForResource, workspaces:DescribeConnectionAliases, workspaces:DescribeTags, and workspaces:DescribeWorkspaces |
Kebijakan ini sekarang mendukung izin tambahan untuk AWS Backup, AWS Batch, DynamoDB Accelerator,, Amazon DynamoDB AWS Database Migration Service, Amazon Elastic Compute Cloud (Amazon EC2), Amazon Elastic Kubernetes Service, Amazon FSx, Amazon,,, Amazon Relational Database Service, V2 GuardDuty AWS Key Management Service AWS OpsWorks, dan Amazon. AWS WAF WorkSpaces |
Maret 14, 2022 |
|
AWS_ConfigRole— Tambahkan backup-gateway:ListTagsForResource, backup-gateway:ListVirtualMachines, batch:DescribeComputeEnvironments, batch:DescribeJobQueues, batch:ListTagsForResource, dax:ListTags, dms:DescribeCertificates, dynamodb:DescribeGlobalTable, dynamodb:DescribeGlobalTableSettings, ec2:DescribeClientVpnAuthorizationRules, ec2:DescribeClientVpnEndpoints, ec2:DescribeDhcpOptions, ec2:DescribeFleets, ec2:DescribeNetworkAcls, ec2:DescribePlacementGroups, ec2:DescribeSpotFleetRequests, ec2:DescribeVolumeAttribute, ec2:DescribeVolumes, eks:DescribeFargateProfile, eks:ListFargateProfiles, eks:ListTagsForResource, fsx:ListTagsForResource, guardduty:ListOrganizationAdminAccounts, kms:ListAliases, opsworks:DescribeLayers, opsworks:DescribeStacks, opsworks:ListTags, rds:DescribeDBClusterParameterGroups, rds:DescribeDBClusterParameters, states:DescribeActivity, states:ListActivities, wafv2:GetRuleGroup, wafv2:ListRuleGroups, wafv2:ListTagsForResource, workspaces:DescribeConnectionAliases, workspaces:DescribeTags, and workspaces:DescribeWorkspaces |
Kebijakan ini sekarang mendukung izin tambahan untuk AWS Backup, AWS Batch, DynamoDB Accelerator,, Amazon DynamoDB AWS Database Migration Service, Amazon Elastic Compute Cloud (Amazon EC2), Amazon Elastic Kubernetes Service, Amazon FSx, Amazon,,, Amazon Relational Database Service, V2 GuardDuty AWS Key Management Service AWS OpsWorks, dan Amazon. AWS WAF WorkSpaces |
Maret 14, 2022 |
|
AWSConfigServiceRolePolicy— Tambahkan elasticbeanstalk:DescribeEnvironments, elasticbeanstalk:DescribeConfigurationSettings, account:GetAlternateContact, organizations:DescribePolicy, organizations:ListParents, organizations:ListPoliciesForTarget, es:GetCompatibleElasticsearchVersions, rds:DescribeOptionGroups, rds:DescribeOptionGroups, es:GetCompatibleVersions, codedeploy:GetDeploymentConfig, ecr-public:GetRepositoryPolicy, access-analyzer:GetArchiveRule, and ecs:ListTaskDefinitionFamilies |
Kebijakan ini sekarang memberikan izin untuk mendapatkan detail tentang lingkungan Elastic Beanstalk dan deskripsi pengaturan untuk kumpulan konfigurasi Elastic Beanstalk yang ditentukan, mendapatkan peta OpenSearch atau versi Elasticsearch, menjelaskan grup opsi Amazon RDS yang tersedia untuk database, dan mendapatkan informasi tentang konfigurasi penerapan. CodeDeploy Kebijakan ini juga sekarang memberikan izin untuk mengambil kontak alternatif tertentu yang dilampirkan pada sebuah Akun AWS, mengambil informasi tentang AWS Organizations kebijakan, mengambil kebijakan repositori Amazon ECR, mengambil informasi tentang AWS Config aturan yang diarsipkan, mengambil daftar keluarga definisi tugas Amazon ECS, mencantumkan root atau unit organisasi induk (OU) dari OU anak atau akun tertentu, dan mencantumkan kebijakan yang dilampirkan ke root target, unit organisasi, atau akun yang ditentukan. |
Februari 10, 2022 |
|
AWS_ConfigRole— Tambahkan elasticbeanstalk:DescribeEnvironments, elasticbeanstalk:DescribeConfigurationSettings, account:GetAlternateContact, organizations:DescribePolicy, organizations:ListParents, organizations:ListPoliciesForTarget, es:GetCompatibleElasticsearchVersions, rds:DescribeOptionGroups, rds:DescribeOptionGroups, es:GetCompatibleVersions, codedeploy:GetDeploymentConfig, ecr-public:GetRepositoryPolicy, access-analyzer:GetArchiveRule, and ecs:ListTaskDefinitionFamilies |
Kebijakan ini sekarang memberikan izin untuk mendapatkan detail tentang lingkungan Elastic Beanstalk dan deskripsi pengaturan untuk kumpulan konfigurasi Elastic Beanstalk yang ditentukan, mendapatkan peta OpenSearch atau versi Elasticsearch, menjelaskan grup opsi Amazon RDS yang tersedia untuk database, dan mendapatkan informasi tentang konfigurasi penerapan. CodeDeploy Kebijakan ini juga sekarang memberikan izin untuk mengambil kontak alternatif tertentu yang dilampirkan pada sebuah Akun AWS, mengambil informasi tentang AWS Organizations kebijakan, mengambil kebijakan repositori Amazon ECR, mengambil informasi tentang AWS Config aturan yang diarsipkan, mengambil daftar keluarga definisi tugas Amazon ECS, mencantumkan root atau unit organisasi induk (OU) dari OU anak atau akun tertentu, dan mencantumkan kebijakan yang dilampirkan ke root target, unit organisasi, atau akun yang ditentukan. |
Februari 10, 2022 |
|
AWSConfigServiceRolePolicy— Tambahkan logs:CreateLogStream, logs:CreateLogGroup, and logs:PutLogEvent |
Kebijakan ini sekarang memberikan izin untuk membuat grup dan aliran CloudWatch log Amazon serta menulis log ke aliran log yang dibuat. |
Desember 15, 2021 |
|
AWS_ConfigRole— Tambahkan logs:CreateLogStream, logs:CreateLogGroup, and logs:PutLogEvent |
Kebijakan ini sekarang memberikan izin untuk membuat grup dan aliran CloudWatch log Amazon serta menulis log ke aliran log yang dibuat. |
Desember 15, 2021 |
|
AWSConfigServiceRolePolicy— Tambah es:DescribeDomain, es:DescribeDomains, rds:DescribeDBParameters, and, elasticache:DescribeSnapshots |
Kebijakan ini sekarang memberikan izin untuk mendapatkan detail tentang OpenSearch Layanan Amazon (OpenSearch Layanan) domain/domains dan untuk mendapatkan daftar parameter terperinci untuk grup parameter DB Layanan Database Relasional Amazon (Amazon RDS) tertentu. Kebijakan ini juga memberikan izin untuk mendapatkan detail tentang ElastiCache snapshot Amazon. |
8 September 2021 |
|
AWS_ConfigRole— Tambah es:DescribeDomain, es:DescribeDomains, rds:DescribeDBParameters, and, elasticache:DescribeSnapshots |
Kebijakan ini sekarang memberikan izin untuk mendapatkan detail tentang OpenSearch Layanan Amazon (OpenSearch Layanan) domain/domains dan untuk mendapatkan daftar parameter terperinci untuk grup parameter DB Layanan Database Relasional Amazon (Amazon RDS) tertentu. Kebijakan ini juga memberikan izin untuk mendapatkan detail tentang ElastiCache snapshot Amazon. |
8 September 2021 |
|
AWSConfigServiceRolePolicy— Tambahlogs:ListTagsLogGroup, states:ListTagsForResource, states:ListStateMachines, states:DescribeStateMachine, dan izin tambahan untuk jenis AWS sumber daya |
Kebijakan ini sekarang memberikan izin untuk mencantumkan tag untuk grup log, tag daftar untuk mesin status, dan daftar semua mesin status. Kebijakan ini sekarang memberikan izin untuk mendapatkan detail tentang mesin status. Kebijakan ini juga sekarang mendukung izin tambahan untuk Amazon EC2 Systems Manager (SSM), Amazon Elastic Container Registry, Amazon FSx, Amazon Data Firehose, Amazon Managed Streaming untuk Apache Kafka (Amazon MSK), Amazon Relational Database Service (Amazon RDS), Amazon Route 53, Amazon SageMaker AI, Amazon Simple Notification Service,, dan. AWS Database Migration Service AWS Global Accelerator AWS Storage Gateway |
28 Juli 2021 |
|
AWS_ConfigRole— Tambahkan logs:ListTagsLogGroup, states:ListTagsForResource, states:ListStateMachines, states:DescribeStateMachine, dan izin tambahan untuk jenis AWS sumber daya |
Kebijakan ini sekarang memberikan izin untuk mencantumkan tag untuk grup log, tag daftar untuk mesin status, dan daftar semua mesin status. Kebijakan ini sekarang memberikan izin untuk mendapatkan detail tentang mesin status. Kebijakan ini juga sekarang mendukung izin tambahan untuk Amazon EC2 Systems Manager (SSM), Amazon Elastic Container Registry, Amazon FSx, Amazon Data Firehose, Amazon Managed Streaming untuk Apache Kafka (Amazon MSK), Amazon Relational Database Service (Amazon RDS), Amazon Route 53, Amazon SageMaker AI, Amazon Simple Notification Service,, dan. AWS Database Migration Service AWS Global Accelerator AWS Storage Gateway |
28 Juli 2021 |
|
AWSConfigServiceRolePolicy— Tambah ssm:DescribeDocumentPermission dan izin tambahan untuk jenis AWS sumber daya |
Kebijakan ini sekarang memberikan izin untuk melihat izin AWS Systems Manager dokumen dan informasi tentang Penganalisis Akses IAM. Kebijakan ini sekarang mendukung jenis AWS sumber daya tambahan untuk Amazon Kinesis, Amazon ElastiCache, Amazon EMR,, Amazon Route 53 AWS Network Firewall, dan Amazon Relational Database Service (Amazon RDS). Perubahan izin ini memungkinkan AWS Config untuk memanggil API read-only yang diperlukan untuk mendukung jenis sumber daya ini. Kebijakan ini juga sekarang mendukung pemfilteran fungsi Lambda @Edge untuk aturan terkelola lambda- AWS Config inside-vpc. |
8 Juni 2021 |
|
AWS_ConfigRole— Tambah ssm:DescribeDocumentPermission dan izin tambahan untuk jenis AWS sumber daya |
Kebijakan ini sekarang memberikan izin untuk melihat izin AWS Systems Manager dokumen dan informasi tentang Penganalisis Akses IAM. Kebijakan ini sekarang mendukung jenis AWS sumber daya tambahan untuk Amazon Kinesis, Amazon ElastiCache, Amazon EMR,, Amazon Route 53 AWS Network Firewall, dan Amazon Relational Database Service (Amazon RDS). Perubahan izin ini memungkinkan AWS Config untuk memanggil API read-only yang diperlukan untuk mendukung jenis sumber daya ini. Kebijakan ini juga sekarang mendukung pemfilteran fungsi Lambda @Edge untuk aturan terkelola lambda- AWS Config inside-vpc. |
8 Juni 2021 |
|
AWSConfigServiceRolePolicy— Tambahkan apigateway:GET izin untuk membuat panggilan GET read-only ke API Gateway dan s3:GetAccessPointPolicy izin serta s3:GetAccessPointPolicyStatus izin untuk memanggil API read-only Amazon S3 |
Kebijakan ini sekarang memberikan izin yang memungkinkan AWS Config untuk membuat panggilan GET read-only ke API Gateway untuk mendukung A AWS Config turan untuk API Gateway. Kebijakan ini juga menambahkan izin yang memungkinkan AWS Config untuk memanggil API read-only Amazon Simple Storage Service (Amazon S3), yang diperlukan untuk mendukung jenis sumber daya baru |
10 Mei 2021 |
|
AWS_ ConfigRole — Tambahkan apigateway:GET izin untuk membuat panggilan GET read-only ke API Gateway dan s3:GetAccessPointPolicy s3:GetAccessPointPolicyStatus izin serta izin untuk memanggil API read-only Amazon S3 |
Kebijakan ini sekarang memberikan izin yang memungkinkan AWS Config untuk membuat panggilan GET read-only ke API Gateway untuk mendukung Gateway API. AWS Config Kebijakan ini juga menambahkan izin yang memungkinkan AWS Config untuk memanggil API read-only Amazon Simple Storage Service (Amazon S3), yang diperlukan untuk mendukung jenis sumber daya baru |
10 Mei 2021 |
|
AWSConfigServiceRolePolicy— Tambahkan ssm:ListDocuments izin dan izin tambahan untuk jenis AWS sumber daya |
Kebijakan ini sekarang memberikan izin untuk melihat informasi tentang dokumen AWS Systems Manager tertentu. Kebijakan ini juga sekarang mendukung jenis AWS sumber daya tambahan untuk AWS Backup, Amazon Elastic File System, Amazon ElastiCache, Amazon Simple Storage Service (Amazon S3), Amazon Elastic Compute Cloud (Amazon EC2), Amazon Kinesis, Amazon SageMaker AI AWS Database Migration Service, dan Amazon Route 53. Perubahan izin ini memungkinkan AWS Config untuk memanggil API read-only yang diperlukan untuk mendukung jenis sumber daya ini. |
1 April 2021 |
|
AWS_ConfigRole— Tambahkan ssm:ListDocuments izin dan izin tambahan untuk jenis AWS sumber daya |
Kebijakan ini sekarang memberikan izin untuk melihat informasi tentang dokumen AWS Systems Manager tertentu. Kebijakan ini juga sekarang mendukung jenis AWS sumber daya tambahan untuk AWS Backup, Amazon Elastic File System, Amazon ElastiCache, Amazon Simple Storage Service (Amazon S3), Amazon Elastic Compute Cloud (Amazon EC2), Amazon Kinesis, Amazon SageMaker AI AWS Database Migration Service, dan Amazon Route 53. Perubahan izin ini memungkinkan AWS Config untuk memanggil API read-only yang diperlukan untuk mendukung jenis sumber daya ini. |
1 April 2021 |
|
|
|
1 April 2021 |
|
AWS Config mulai melacak perubahan |
AWS Config mulai melacak perubahan untuk kebijakan yang AWS dikelolanya. |
1 April 2021 |