View a markdown version of this page

AWS kebijakan yang dikelola untuk AWS Config - AWS Config

Terjemahan disediakan oleh mesin penerjemah. Jika konten terjemahan yang diberikan bertentangan dengan versi bahasa Inggris aslinya, utamakan versi bahasa Inggris.

AWS kebijakan yang dikelola untuk AWS Config

Kebijakan AWS terkelola adalah kebijakan mandiri yang dibuat dan dikelola oleh AWS. AWS kebijakan terkelola dirancang untuk memberikan izin untuk banyak kasus penggunaan umum sehingga Anda dapat mulai menetapkan izin kepada pengguna, grup, dan peran.

Perlu diingat bahwa kebijakan ter AWS kelola mungkin tidak memberikan izin hak istimewa terkecil untuk kasus penggunaan spesifik Anda karena kebijakan tersebut tersedia untuk digunakan semua AWS pelanggan. Kami menyarankan Anda untuk mengurangi izin lebih lanjut dengan menentukan kebijakan yang dikelola pelanggan yang khusus untuk kasus penggunaan Anda.

Anda tidak dapat mengubah izin yang ditentukan dalam kebijakan AWS terkelola. Jika AWS memperbarui izin yang ditentukan dalam kebijakan AWS terkelola, pembaruan akan memengaruhi semua identitas utama (pengguna, grup, dan peran) yang dilampirkan kebijakan tersebut. AWS kemungkinan besar akan memperbarui kebijakan ter AWS kelola ketika yang baru Layanan AWS diluncurkan atau operasi API baru tersedia untuk layanan yang ada.

Untuk informasi selengkapnya, lihat Kebijakan terkelola AWS dalam Panduan Pengguna IAM.

AWS kebijakan yang dikelola: AWSConfigServiceRolePolicy

AWS Config menggunakan peran terkait layanan yang dinamai AWSServiceRoleForConfig untuk memanggil AWS layanan lain atas nama Anda. Saat Anda menggunakan Konsol Manajemen AWS untuk mengatur AWS Config, SLR ini secara otomatis dibuat oleh AWS Config jika Anda memilih opsi untuk menggunakan AWS Config SLR alih-alih peran layanan AWS Identity and Access Management (IAM) Anda sendiri.

AWSServiceRoleForConfigSLR berisi kebijakan AWSConfigServiceRolePolicy terkelola. Kebijakan terkelola ini berisi izin baca saja dan tulis saja untuk AWS Config sumber daya dan izin baca-saja untuk sumber daya di layanan lain yang mendukung. AWS Config Kebijakan ini menyediakan akses komprehensif untuk memantau dan merekam perubahan konfigurasi di seluruh AWS infrastruktur Anda, termasuk izin untuk lebih dari 100 AWS layanan seperti komputasi, penyimpanan, jaringan, keamanan, analitik, dan layanan pembelajaran mesin.

Kebijakan ini mencakup izin untuk kategori layanan berikut:

  • access-analyzer- Memungkinkan kepala sekolah untuk menganalisis pola akses dan mengambil temuan keamanan.

  • account— Memungkinkan kepala sekolah untuk mengambil informasi kontak akun.

  • acmdan acm-pca - Memungkinkan kepala sekolah untuk mengelola SSL/TLS sertifikat dan otoritas sertifikat pribadi.

  • airflow- Memungkinkan kepala sekolah untuk memantau lingkungan Apache Airflow yang dikelola.

  • amplifydan amplifyuibuilder - Memungkinkan prinsipal untuk memantau aplikasi web dan komponen UI.

  • aoss- Memungkinkan prinsipal untuk memantau koleksi OpenSearch Serverless dan konfigurasi keamanan.

  • app-integrations- Memungkinkan prinsipal untuk memantau konfigurasi integrasi aplikasi.

  • appconfig- Memungkinkan prinsipal untuk memantau penerapan konfigurasi aplikasi.

  • appflow- Memungkinkan prinsipal untuk memantau konfigurasi aliran data antar aplikasi.

  • application-autoscalingdan application-signals - Memungkinkan kepala sekolah untuk memantau kebijakan penskalaan otomatis dan metrik kinerja aplikasi.

  • appmesh- Memungkinkan prinsipal untuk memantau konfigurasi mesh layanan.

  • apprunner- Memungkinkan kepala sekolah untuk memantau aplikasi dan layanan web yang dikontainer.

  • appstream- Memungkinkan kepala sekolah untuk memantau konfigurasi streaming aplikasi.

  • appsync- Memungkinkan prinsipal untuk memantau konfigurasi GraphQL API.

  • aps- Memungkinkan kepala sekolah untuk memantau konfigurasi pemantauan Prometheus.

  • apptest- Memungkinkan prinsipal untuk memantau konfigurasi pengujian aplikasi.

  • arc-zonal-shift- Memungkinkan kepala sekolah untuk memantau konfigurasi pergeseran zonal untuk ketersediaan.

  • athena- Memungkinkan kepala sekolah untuk memantau konfigurasi mesin kueri dan katalog data.

  • auditmanager- Memungkinkan kepala sekolah untuk memantau audit dan penilaian kepatuhan.

  • autoscalingdan autoscaling-plans - Memungkinkan kepala sekolah untuk memantau grup penskalaan otomatis dan rencana penskalaan.

  • b2bi- Memungkinkan kepala sekolah untuk memantau konfigurasi integrasi bisnis-ke-bisnis.

  • backupdan backup-gateway - Memungkinkan kepala sekolah untuk memantau kebijakan cadangan dan konfigurasi gateway.

  • batch- Memungkinkan kepala sekolah untuk memantau lingkungan komputasi batch dan antrian pekerjaan.

  • bcm-data-exports- Memungkinkan kepala sekolah untuk memantau ekspor data penagihan dan manajemen biaya.

  • bedrockdan bedrock-agentcore - Memungkinkan kepala sekolah untuk memantau model dasar dan konfigurasi agen AI.

  • billingconductor- Memungkinkan kepala sekolah untuk memantau konfigurasi grup penagihan.

  • budgets- Memungkinkan kepala sekolah untuk memantau konfigurasi dan tindakan anggaran.

  • cassandra- Memungkinkan kepala sekolah untuk menanyakan konfigurasi database Cassandra yang dikelola.

  • ce- Memungkinkan prinsipal untuk memantau konfigurasi pelaporan biaya dan penggunaan.

  • cleanroomsdan cleanrooms-ml - Memungkinkan kepala sekolah untuk memantau kolaborasi data dan konfigurasi pembelajaran mesin.

  • cloud9- Memungkinkan kepala sekolah untuk memantau konfigurasi lingkungan pengembangan cloud.

  • cloudformation- Memungkinkan prinsipal untuk memantau infrastruktur sebagai konfigurasi tumpukan kode.

  • cloudfront- Memungkinkan prinsipal untuk memantau konfigurasi jaringan pengiriman konten.

  • cloudtrail- Memungkinkan prinsipal untuk memantau pencatatan API dan konfigurasi jejak audit.

  • cloudwatch- Memungkinkan kepala sekolah untuk memantau metrik, alarm, dan konfigurasi dasbor.

  • codeartifact- Memungkinkan kepala sekolah untuk memantau konfigurasi repositori paket perangkat lunak.

  • codebuild- Memungkinkan kepala sekolah untuk memantau konfigurasi proyek pembangunan.

  • codecommit- Memungkinkan prinsipal untuk memantau konfigurasi repositori kode sumber.

  • codeconnections- Memungkinkan kepala sekolah untuk memantau koneksi sumber pihak ketiga.

  • codedeploy- Memungkinkan prinsipal untuk memantau konfigurasi penerapan aplikasi.

  • codeguru-profilerdan codeguru-reviewer - Memungkinkan kepala sekolah untuk memantau analisis kode dan konfigurasi profil.

  • codepipeline- Memungkinkan prinsipal untuk memantau integrasi berkelanjutan dan konfigurasi pipa penyebaran.

  • codestar-connections- Memungkinkan kepala sekolah untuk memantau koneksi alat pengembang.

  • cognito-identitydan cognito-idp - Memungkinkan prinsipal untuk memantau identitas dan konfigurasi kumpulan pengguna.

  • comprehend- Memungkinkan kepala sekolah untuk memantau konfigurasi pemrosesan bahasa alami.

  • config- Memungkinkan kepala sekolah untuk mengelola perekaman konfigurasi dan pemantauan kepatuhan.

  • connect- Memungkinkan kepala sekolah untuk memantau konfigurasi pusat kontak.

Untuk informasi selengkapnya tentang jenis sumber daya yang didukung, lihat Jenis Sumber Daya yang Didukung untuk AWS Config danMenggunakan Service-Linked Peran untuk AWS Config.

Untuk melihat detail selengkapnya tentang kebijakan, termasuk versi terbaru dokumen kebijakan JSON, lihat AWSConfigServiceRolePolicy di Panduan Referensi AWS Kebijakan Terkelola.

Direkomendasikan: Gunakan Service-linked peran

Disarankan agar Anda menggunakan peran terkait layanan kecuali Anda memiliki kasus penggunaan tertentu. Peran terkait layanan menambahkan semua izin yang diperlukan AWS Config untuk berjalan seperti yang diharapkan. Beberapa fitur seperti perekam konfigurasi terkait layanan mengharuskan Anda menggunakan peran terkait layanan.

AWS kebijakan yang dikelola: AWS_ ConfigRole

Untuk merekam konfigurasi AWS sumber daya Anda, AWS Config memerlukan izin IAM untuk mendapatkan detail konfigurasi tentang sumber daya Anda. Jika Anda ingin membuat peran IAM untuk AWS Config, Anda dapat menggunakan kebijakan terkelola AWS_ConfigRole dan melampirkannya ke peran IAM Anda.

Kebijakan IAM ini diperbarui setiap kali AWS Config menambahkan dukungan untuk jenis AWS sumber daya. Ini berarti bahwa AWS Config akan terus memiliki izin yang diperlukan untuk merekam data konfigurasi jenis sumber daya yang didukung selama ConfigRole peran AWS_ memiliki kebijakan terkelola ini dilampirkan. Kebijakan ini menyediakan akses komprehensif untuk memantau dan merekam perubahan konfigurasi di seluruh AWS infrastruktur Anda, termasuk izin untuk lebih dari 100 AWS layanan seperti komputasi, penyimpanan, jaringan, keamanan, analitik, dan layanan pembelajaran mesin. Untuk informasi selengkapnya, lihat Jenis Sumber Daya yang Didukung untuk AWS Config dan Izin untuk Peran IAM yang Ditugaskan ke AWS Config.

Untuk melihat detail selengkapnya tentang kebijakan, termasuk versi terbaru dokumen kebijakan JSON, lihat AWS_ ConfigRole di Panduan Referensi Kebijakan Ter AWS kelola.

AWS kebijakan yang dikelola: AWSConfigUserAccess

Kebijakan IAM ini menyediakan akses untuk digunakan AWS Config, termasuk mencari berdasarkan tag pada sumber daya dan membaca semua tag. Ini tidak memberikan izin untuk mengkonfigurasi AWS Config, yang memerlukan hak administratif.

Lihat kebijakan: AWSConfigUserAccess.

AWS kebijakan yang dikelola: ConfigConformsServiceRolePolicy

Untuk menyebarkan dan mengelola paket kesesuaian, AWS Config memerlukan izin IAM dan izin tertentu dari layanan lain. AWS Ini memungkinkan Anda untuk menyebarkan dan mengelola paket kesesuaian dengan fungsionalitas penuh dan diperbarui setiap kali AWS Config menambahkan fungsionalitas baru untuk paket kesesuaian. Untuk informasi selengkapnya tentang paket kesesuaian, lihat paket kesesuaian.

Lihat kebijakan: ConfigConformsServiceRolePolicy.

AWS kebijakan yang dikelola: AWSConfigRulesExecutionRole

Untuk menerapkan A AWS turan Lambda Kustom, AWS Config memerlukan izin IAM dan izin tertentu dari layanan lain AWS . Ini memungkinkan AWS Lambda fungsi untuk mengakses AWS Config API dan snapshot konfigurasi yang dikirimkan secara ber AWS Config kala ke Amazon S3. Akses ini diperlukan oleh fungsi yang mengevaluasi perubahan konfigurasi untuk aturan Lambda K AWS ustom dan diperbarui setiap kali AWS Config menambahkan fungsionalitas baru. Untuk informasi selengkapnya tentang A AWS turan Lambda Kustom, lihat Membuat Aturan Lambda K AWS Config ustom. Untuk informasi selengkapnya tentang snapshot konfigurasi, lihat Kon sep | Cuplikan Konfigurasi. Untuk informasi selengkapnya tentang pengiriman snapshot konfigurasi, lihat M engelola Saluran Pengiriman.

Lihat kebijakan: AWSConfigRulesExecutionRole.

AWS kebijakan yang dikelola: AWSConfigMultiAccountSetupPolicy

Untuk menerapkan, memperbarui, dan menghapus AWS Config aturan dan paket kesesuaian secara terpusat di seluruh akun anggota dalam organisasi di AWS Organizations, AWS Config memerlukan izin IAM dan izin tertentu dari layanan lain. AWS Kebijakan terkelola ini diperbarui setiap kali AWS Config menambahkan fungsionalitas baru untuk penyiapan multi-akun. Untuk informasi selengkapnya, lihat M engel AWS Config ola Aturan di Semua Akun di Organisasi Anda dan M engelola Paket Kesesuaian di Semua Akun di Organisasi Anda.

Lihat kebijakan: AWSConfigMultiAccountSetupPolicy.

AWS kebijakan yang dikelola: AWSConfigRoleForOrganizations

Untuk mengiz AWS Config inkan memanggil AWS Organizations API read-only, AWS Config memerlukan izin IAM dan izin tertentu dari layanan lain. AWS Kebijakan terkelola ini diperbarui setiap kali AWS Config menambahkan fungsionalitas baru untuk penyiapan multi-akun. Untuk informasi selengkapnya, lihat M engel AWS Config ola Aturan di Semua Akun di Organisasi Anda dan M engelola Paket Kesesuaian di Semua Akun di Organisasi Anda.

Lihat kebijakan: AWSConfigRoleForOrganizations.

AWS kebijakan yang dikelola: AWSConfigRemediationServiceRolePolicy

AWS Config Untuk mengizinkan perbaikan sumber NON_COMPLIANT daya atas nama Anda, AWS Config memerlukan izin IAM dan izin tertentu dari layanan lain AWS . Kebijakan terkelola ini diperbarui setiap kali AWS Config menambahkan fungsionalitas baru untuk remediasi. Untuk informasi selengkapnya tentang remediasi, lihat Memperbaiki Sumber Daya yang Tidak Sesuai dengan Aturan. AWS Config Untuk informasi lebih lanjut tentang kondisi yang memulai kemungkinan hasil AWS Config evaluasi, lihat Kon sep | A AWS Config turan.

Lihat kebijakan: AWSConfigRemediationServiceRolePolicy.

AWS Config update ke AWS kebijakan terkelola

Lihat detail tentang pembaruan kebijakan AWS terkelola AWS Config sejak layanan ini mulai melacak perubahan ini. Untuk peringatan otomatis tentang perubahan pada halaman ini, berlangganan umpan RSS di halaman AWS Config riwayat dokumen.

Ubah Deskripsi Date

AWSConfigServiceRolePolicy— Izin tambahan: access-analyzer:, access-analyzer:CheckNoPublicAccess, bedrock:, bedrock-agentcore:ValidatePolicy, bedrock-agentcore:ListEnforcedGuardrailsConfiguration, bedrock-agentcore:, bedrock-agentcore:GetPaymentManager, bedrock-agentcore:GetPolicyEngineSummary, bedrock-agentcore:, notifikasi:, notifikasi:, nova-act:GetPolicySummary, nova-act:, s3vector:ListPaymentManagers, s3vector:, sagemaker:, sagemaker:, sagemaker:ListPolicyEngineSummaries, sagemaker:, tukang sihir:ListPolicySummaries, pembuat saji:, ListNotificationConfigurations ListTagsForResource GetWorkflowDefinition ListWorkflowDefinitions GetIndex ListIndexes DescribeAlgorithm DescribeClusterSchedulerConfig DescribeFlowDefinition DescribeHumanTaskUi pembuat sagak:DescribeLabelingJob, pembuat sagak:, pembuat sag DescribeMlflowApp ak:, pembuat sagak:DescribeOptimizationJob, pembuat sagak:DescribeTrainingJob, pembuat sagak:, pembuat sagak:ListAlgorithms, pembuat sagak:ListClusterSchedulerConfigs, pembuat sagak:ListFlowDefinitions, pembuat sagak:, pembuat sag ListHumanTaskUis ak:, pembuat sagak:ListLabelingJobs. ListMlflowApps ListOptimizationJobs ListTrainingJobs

Kebijakan ini sekarang mendukung izin tambahan untuk merekam perubahan konfigurasi di berbagai AWS layanan.

Agustus 1, 2026

AWS_ConfigRole— Izin tambahan: access-analyzer:, access-analyzer:CheckNoPublicAccess, bedrock:, bedrock-agentcore:ValidatePolicy, bedrock-agentcore:ListEnforcedGuardrailsConfiguration, bedrock-agentcore:, bedrock-agentcore:GetPaymentManager, bedrock-agentcore:GetPolicyEngineSummary, bedrock-agentcore:, notifikasi:, notifikasi:, nova-act:GetPolicySummary, nova-act:, s3vector:ListPaymentManagers, s3vector:, sagemaker:, sagemaker:, sagemaker:ListPolicyEngineSummaries, sagemaker:, tukang sihir:ListPolicySummaries, pembuat saji:, ListNotificationConfigurations ListTagsForResource GetWorkflowDefinition ListWorkflowDefinitions GetIndex ListIndexes DescribeAlgorithm DescribeClusterSchedulerConfig DescribeFlowDefinition DescribeHumanTaskUi pembuat sagak:DescribeLabelingJob, pembuat sagak:, pembuat sag DescribeMlflowApp ak:, pembuat sagak:DescribeOptimizationJob, pembuat sagak:DescribeTrainingJob, pembuat sagak:, pembuat sagak:ListAlgorithms, pembuat sagak:ListClusterSchedulerConfigs, pembuat sagak:ListFlowDefinitions, pembuat sagak:, pembuat sag ListHumanTaskUis ak:, pembuat sagak:ListLabelingJobs. ListMlflowApps ListOptimizationJobs ListTrainingJobs

Kebijakan ini sekarang mendukung izin tambahan untuk merekam perubahan konfigurasi di berbagai AWS layanan.

Agustus 1, 2026

AWSConfigServiceRolePolicy— Izin tambahan: batuan dasar:, batuan dasar:GetAutomatedReasoningPolicy, batuan dasar:GetBlueprint, batuan dasar:GetFoundationModel, batuan dasar:, batuan dasar:GetPromptRouter, batuan dasar:ListAutomatedReasoningPolicies, bedrock-agentcore:ListBlueprints, bedrock-agentcore:ListFoundationModels, bedrock-agentcore:, bedrock-agentcore:GetApiKeyCredentialProvider, bedrock-agentcore:GetOauth2CredentialProvider, cloudtrail:, cloudwatch:, connect:, dynamodcore:GetPolicy, connect:, dynamodcore b:GetTokenVault, dinamodb:, dinamodb:, ListApiKeyCredentialProviders ListOauth2CredentialProviders ListPolicies GetTrail ListManagedInsightRules ListQueueEmailAddresses DescribeContributorInsights DescribeKinesisStreamingDestination GetResourcePolicy elasticloadbalancing:DescribeCapacityReservation, lambda:, lambda:, pengelola lisensi:GetFunctionRecursionConfig, pergeseran merah:, pergeseran merah:GetFunctionScalingConfig, s3:, s3:, s3express:ListTagsForResource, sagemaker:, sagemaker:DescribeClusterDbRevisions, sagemaker:, sagemaker:DescribeSnapshotCopyGrants, sagemaker:, sagemaker:GetBucketMetadataTableConfiguration, sagemaker:GetBucketOwnershipControls, sagemaker:, sagemaker:, sagemaker:GetMetricsConfiguration, sagemaker:, sagemaker:DescribeAction, sagemaker:, sagemaker:DescribeArtifact, sagemaker:, sagemaker:DescribeAutoMLJob, sagemaker:, sagemaker:, sagemaker:DescribeContext, sagemaker:, sagemaker:DescribeExperiment, sagemaker:, sagemaker:DescribeHub, sagemaker:, sagemaker:DescribeModelCardExportJob, sagemaker:, sagemaker:DescribeTrial, sagemaker:, sagemaker:, pembuat:DescribeTrialComponent, DescribeWorkforce ListActions ListArtifacts ListContexts ListExperiments ListHubs pembuat sagak:ListModelCardExportJobs, pembuat sagak:, pembuat sa ListMonitoringAlerts ji:, pembuat sagak:ListTrialComponents, pembuat sagak:ListTrials. ListWorkforces

Kebijakan ini sekarang mendukung izin tambahan untuk merekam perubahan konfigurasi di berbagai AWS layanan.

5 Mei 2026

AWS_ConfigRole— Izin tambahan: batuan dasar:, batuan dasar:GetAutomatedReasoningPolicy, batuan dasar:GetBlueprint, batuan dasar:GetFoundationModel, batuan dasar:, batuan dasar:GetPromptRouter, batuan dasar:ListAutomatedReasoningPolicies, bedrock-agentcore:ListBlueprints, bedrock-agentcore:ListFoundationModels, bedrock-agentcore:, bedrock-agentcore:GetApiKeyCredentialProvider, bedrock-agentcore:GetOauth2CredentialProvider, cloudtrail:, cloudwatch:, connect:, dynamodcore:GetPolicy, connect:, dynamodcore b:GetTokenVault, dinamodb:, dinamodb:, ListApiKeyCredentialProviders ListOauth2CredentialProviders ListPolicies GetTrail ListManagedInsightRules ListQueueEmailAddresses DescribeContributorInsights DescribeKinesisStreamingDestination GetResourcePolicy elasticloadbalancing:DescribeCapacityReservation, lambda:, lambda:, pengelola lisensi:GetFunctionRecursionConfig, pergeseran merah:, pergeseran merah:GetFunctionScalingConfig, s3:, s3:, s3express:ListTagsForResource, sagemaker:, sagemaker:DescribeClusterDbRevisions, sagemaker:, sagemaker:DescribeSnapshotCopyGrants, sagemaker:, sagemaker:GetBucketMetadataTableConfiguration, sagemaker:GetBucketOwnershipControls, sagemaker:, sagemaker:, sagemaker:GetMetricsConfiguration, sagemaker:, sagemaker:DescribeAction, sagemaker:, sagemaker:DescribeArtifact, sagemaker:, sagemaker:DescribeAutoMLJob, sagemaker:, sagemaker:, sagemaker:DescribeContext, sagemaker:, sagemaker:DescribeExperiment, sagemaker:, sagemaker:DescribeHub, sagemaker:, sagemaker:DescribeModelCardExportJob, sagemaker:, sagemaker:DescribeTrial, sagemaker:, sagemaker:, pembuat:DescribeTrialComponent, DescribeWorkforce ListActions ListArtifacts ListContexts ListExperiments ListHubs pembuat sagak:ListModelCardExportJobs, pembuat sagak:, pembuat sa ListMonitoringAlerts ji:, pembuat sagak:ListTrialComponents, pembuat sagak:ListTrials. ListWorkforces

Kebijakan ini sekarang mendukung izin tambahan untuk merekam perubahan konfigurasi di berbagai AWS layanan.

5 Mei 2026

AWSConfigServiceRolePolicy— Menambahkan izin: auditmanager:, auditmanager:GetAssessmentFramework, auditmanager:GetControl, auditmanager:, bcm-dashboards:ListAssessmentFrameworks, bcm-dasbor:ListControls, bcm-dasbor:, bedrock:GetDashboard, bedrock-agentcore:ListDashboards, bedrock-agentcore:, bedrock-agentcore:ListTagsForResource, bedrock-agentcore: GetEvaluationJobListEvaluationJobs, bedrock-agentcore:, bedrockagent-core:GetEvaluator, chime::, lonceng:GetOnlineEvaluationConfig, dms:, emr- GetPolicyEngine ListEvaluators ListOnlineEvaluationConfigs ListPolicyEngines DescribeAppInstance ListAppInstances ListTagsForResource ListInstanceProfiles wadah:DescribeManagedEndpoint, emr-kontainer:ListTagsForResource, gameliftstreams:, gameliftstreams:GetApplication, gameliftstreams:, gameliftstreams:GetStreamGroup, gameliftstreams:ListApplications, globalaccelerator:, lem:, lem:, lem:ListStreamGroups, lambda:, medialive:ListTagsForResource, medialive:DescribeAcceleratorAttributes, mediapackagev2:GetCatalog, mediapackagev2:GetSession, pos terdepan:ListSessions, pos terdepan:, qbusiness:ListCapacityProviders, pergeseran merah:DescribeNode, rtbfabric:ListNodes, rtbfabric: GetCatalogs GetChannelPolicy GetOriginEndpointPolicy GetSite ListSites GetPolicy DescribeDataShares GetInboundExternalLink GetLink, rtbfabric:, rtbfabric:, rtbfabric:GetOutboundExternalLink, rtbfabric:, rtbfabric:, rtbfabric:GetRequesterGateway, rtbfabric:, s3express:, s3express:GetResponderGateway, s3express:, s3express:, s3express:ListLinks, s3vektor:, s3vektor:, s3vektor:ListRequesterGateways, s3vektor:, sagemaker:, sagemaker:ListResponderGateways, sagemaker:, sagemaker:, sagemaker:, sagemaker:ListTagsForResource, sagemaker:, sagemaker:, sagemaker:, sagemaker:GetAccessPoint, sagemaker:, sagemaker:, sagemaker:GetAccessPointPolicy, sagemaker:, sagemaker:, sagemaker:, sagemaker:GetAccessPointScope, sagemaker:, sagemaker:, sagemaker:, sagemaker:ListAccessPointsForDirectoryBuckets, sagemaker:, sagemaker:, sagemaker:, sagemaker:ListTagsForResource, sagemaker:, sagemaker:, sagemaker pembuat:GetVectorBucket, pembuat sagak:, pembuat sagak:, katalog layanan:GetVectorBucketPolicy, ListTagsForResource ListVectorBuckets DescribeAutoMLJobV2 DescribeHyperParameterTuningJob DescribePartnerApp ListAutoMLJobs ListHyperParameterTuningJobs ListPartnerApps DescribeTagOption servicecatalog:ListTagOptions, ssm-kontak:, ssm-kontak:GetRotation, ssm-guiconnect:, sso:ListRotations, sso:, textract:, textract:GetConnectionRecordingPreferences, teks:, transfer:, transfer:GetPermissionsBoundaryForPermissionSet, transfer:ListCustomerManagedPolicyReferencesInPermissionSet, kebijaksanaan:getaiGuardrailGetAdapter, kebijaksanaan:List ListAdapters aiGuardrails. ListTagsForResource DescribeWebApp DescribeWebAppCustomization ListWebApps

Kebijakan ini sekarang mendukung izin tambahan untuk merekam perubahan konfigurasi di berbagai AWS layanan.

Maret 10, 2026

AWS_ConfigRole— Menambahkan izin: auditmanager:, auditmanager:GetAssessmentFramework, auditmanager:GetControl, auditmanager:, bcm-dashboards:ListAssessmentFrameworks, bcm-dasbor:ListControls, bcm-dasbor:, bedrock:GetDashboard, bedrock-agentcore:ListDashboards, bedrock-agentcore:, bedrock-agentcore:ListTagsForResource, bedrock-agentcore: GetEvaluationJobListEvaluationJobs, bedrock-agentcore:, bedrockagent-core:GetEvaluator, chime::, lonceng:GetOnlineEvaluationConfig, dms:, emr- GetPolicyEngine ListEvaluators ListOnlineEvaluationConfigs ListPolicyEngines DescribeAppInstance ListAppInstances ListTagsForResource ListInstanceProfiles wadah:DescribeManagedEndpoint, emr-kontainer:ListTagsForResource, gameliftstreams:, gameliftstreams:GetApplication, gameliftstreams:, gameliftstreams:GetStreamGroup, gameliftstreams:ListApplications, globalaccelerator:, lem:, lem:, lem:ListStreamGroups, lambda:, medialive:ListTagsForResource, medialive:DescribeAcceleratorAttributes, mediapackagev2:GetCatalog, mediapackagev2:GetSession, pos terdepan:ListSessions, pos terdepan:, qbusiness:ListCapacityProviders, pergeseran merah:DescribeNode, rtbfabric:ListNodes, rtbfabric: GetCatalogs GetChannelPolicy GetOriginEndpointPolicy GetSite ListSites GetPolicy DescribeDataShares GetInboundExternalLink GetLink, rtbfabric:, rtbfabric:, rtbfabric:GetOutboundExternalLink, rtbfabric:, rtbfabric:, rtbfabric:GetRequesterGateway, rtbfabric:, s3express:, s3express:GetResponderGateway, s3express:, s3express:, s3express:ListLinks, s3vektor:, s3vektor:, s3vektor:ListRequesterGateways, s3vektor:, sagemaker:, sagemaker:ListResponderGateways, sagemaker:, sagemaker:, sagemaker:, sagemaker:ListTagsForResource, sagemaker:, sagemaker:, sagemaker:, sagemaker:GetAccessPoint, sagemaker:, sagemaker:, sagemaker:GetAccessPointPolicy, sagemaker:, sagemaker:, sagemaker:, sagemaker:GetAccessPointScope, sagemaker:, sagemaker:, sagemaker:, sagemaker:ListAccessPointsForDirectoryBuckets, sagemaker:, sagemaker:, sagemaker:, sagemaker:ListTagsForResource, sagemaker:, sagemaker:, sagemaker pembuat:GetVectorBucket, pembuat sagak:, pembuat sagak:, katalog layanan:GetVectorBucketPolicy, ListTagsForResource ListVectorBuckets DescribeAutoMLJobV2 DescribeHyperParameterTuningJob DescribePartnerApp ListAutoMLJobs ListHyperParameterTuningJobs ListPartnerApps DescribeTagOption servicecatalog:ListTagOptions, ssm-kontak:, ssm-kontak:GetRotation, ssm-guiconnect:, sso:ListRotations, sso:, textract:, textract:GetConnectionRecordingPreferences, teks:, transfer:, transfer:GetPermissionsBoundaryForPermissionSet, transfer:ListCustomerManagedPolicyReferencesInPermissionSet, kebijaksanaan:getaiGuardrailGetAdapter, kebijaksanaan:List ListAdapters aiGuardrails. ListTagsForResource DescribeWebApp DescribeWebAppCustomization ListWebApps

Kebijakan ini sekarang mendukung izin tambahan untuk merekam perubahan konfigurasi di berbagai AWS layanan.

Maret 10, 2026

AWSConfigServiceRolePolicy- Menambahkan izin: application-autoscaling:DescribeScheduledActions, appsync:, cloudformation:, cloudformation:GetApiAssociation, cloudformation:DescribeStacks, cloudfront:, cloudfront:GetStackPolicy, cloudfront:GetTemplate, connect:, cur:GetKeyGroup, cur:, datazone:GetMonitoringSubscription, datazone:ListKeyGroups, datazone:ListEvaluationFormVersions, datazone:DescribeReportDefinitions, datazone:ListTagsForResource, datazone:GetDomainUnit, datazone:, datazone:GetEnvironmentAction, datazone:GetEnvironmentBlueprintConfiguration, datazone:, datazone one:GetEnvironmentProfile, data zone: GetGroupProfile GetSubscriptionTarget GetUserProfile ListDomainUnitsForParent ListEntityOwners ListEnvironmentActions ListEnvironmentBlueprintConfigurations, zona data:, zona data:, zona data:, zona data:ListEnvironmentProfiles, zona data:, zona data:, docdb-elastic:ListPolicyGrants, docdb-elastic:, docdb-elastic:, ec2:ListProjectMemberships, ec2:, ec2:, ec2:, fis:ListSubscriptionTargets, penipuan:, penipuan:, guardduty:SearchGroupProfiles, guardduty:, guardduty:, guardduty:SearchUserProfiles, guardduty:, guardduty:, guardduty:, guardduty:GetCluster, guardduty:, guardduty:, guardduty:, guardduty:ListClusters, guardduty:, guardduty:, guardduty:ListTagsForResource, guardduty:, guardduty:, guardduty:GetRouteServerAssociations, guardduty:, guardduty:GetRouteServerPropagations, guardduty:, guardduty:, guardduty:SearchTransitGatewayRoutes, guardduty: fleetwise:ListTagsForResource, iotfleetwise:, iotsitewise:GetListElements, iotsitewise:, GetListsMetadata GetThreatEntitySet GetTrustedEntitySet ListThreatEntitySets ListTrustedEntitySets GetCampaign ListCampaigns DescribeComputationModel DescribeDataset iotsitewise:ListComputationModels, iotsitewise:ListDatasets, iotwireless:, iotwireless:GetWirelessDeviceImportTask, kendra:, log:ListWirelessDeviceImportTasks, log:ListDataSources, log:, mediaconnect:GetIntegration, medialive:ListIntegrations, medialive:, medialive:ListRouterOutputs, medialive:DescribeMultiplex, medialive:, medialive:DescribeSdiSource, medialive:GetCloudWatchAlarmTemplate, medialive:GetCloudWatchAlarmTemplateGroup, medialive:GetEventBridgeRuleTemplate, medialive:, manajer jaringan:GetEventBridgeRuleTemplateGroup, manajer jaringan:ListCloudWatchAlarmTemplateGroups,:, manajer jaringan: DescribeQueryDefinitions ListCloudWatchAlarmTemplates ListEventBridgeRuleTemplateGroups ListEventBridgeRuleTemplates ListSdiSources ListSignalMaps GetConnectAttachment GetCoreNetwork GetCoreNetworkPolicy, networkmanager:, networkmanager:GetDirectConnectGatewayAttachment, networkmanager:GetSiteToSiteVpnAttachment, networkmanager:, notifikasi:ListAttachments, notifikasi:, pemberitahuan:ListCoreNetworks, pemberitahuan:, pemberitahuan:GetEventRule, refactor-space:ListEventRules, refactor-space:ListManagedNotificationChannelAssociations, refactor-space:ListNotificationHubs, resource-explorer-2:ListOrganizationalUnits, route53resolver:GetApplication, route53resolver:, securityhub:GetRoute, securityhub: V2, securityhub:ListRoutes, securityhub:, securityhub:GetDefaultView, securityhub:, GetOutpostResolver ListOutpostResolvers DescribeOrganizationConfiguration GetAggregator GetAutomationRuleV2 GetConfigurationPolicyAssociation securityhub:GetFindingAggregator, securityhub: ListAggregators V2, securityhub:, securityhub:, securityhub:ListAutomationRulesV2, sms-suara:, sms-suara:ListConfigurationPolicyAssociations, sms-suara:, sms-suara:ListFindingAggregators, sms-suara:DescribeConfigurationSets, sms-suara:, ruang kerja-web:DescribeKeywords, ruang kerja-web:DescribeProtectConfigurations, ruang kerja-web:, ruang kerja-web:GetProtectConfigurationCountryRuleSet. ListPoolOriginationIdentities ListTagsForResource GetTrustStore GetTrustStoreCertificate GetUserAccessLoggingSettings ListTagsForResource

Kebijakan ini sekarang mendukung izin tambahan untuk merekam perubahan konfigurasi di berbagai AWS layanan.

Februari 17, 2026

AWS_ConfigRole- Menambahkan izin: application-autoscaling:DescribeScheduledActions, appsync:, cloudformation:, cloudformation:GetApiAssociation, cloudformation:DescribeStacks, cloudfront:, cloudfront:GetStackPolicy, cloudfront:GetTemplate, connect:, cur:GetKeyGroup, cur:, datazone:GetMonitoringSubscription, datazone:ListKeyGroups, datazone:ListEvaluationFormVersions, datazone:DescribeReportDefinitions, datazone:ListTagsForResource, datazone:GetDomainUnit, datazone:, datazone:GetEnvironmentAction, datazone:GetEnvironmentBlueprintConfiguration, datazone:, datazone one:GetEnvironmentProfile, data zone: GetGroupProfile GetSubscriptionTarget GetUserProfile ListDomainUnitsForParent ListEntityOwners ListEnvironmentActions ListEnvironmentBlueprintConfigurations, zona data:, zona data:, zona data:, zona data:ListEnvironmentProfiles, zona data:, zona data:, docdb-elastic:ListPolicyGrants, docdb-elastic:, docdb-elastic:, ec2:ListProjectMemberships, ec2:, ec2:, ec2:, fis:ListSubscriptionTargets, penipuan:, penipuan:, guardduty:SearchGroupProfiles, guardduty:, guardduty:, guardduty:SearchUserProfiles, guardduty:, guardduty:, guardduty:, guardduty:GetCluster, guardduty:, guardduty:, guardduty:, guardduty:ListClusters, guardduty:, guardduty:, guardduty:ListTagsForResource, guardduty:, guardduty:, guardduty:GetRouteServerAssociations, guardduty:, guardduty:GetRouteServerPropagations, guardduty:, guardduty:, guardduty:SearchTransitGatewayRoutes, guardduty: fleetwise:ListTagsForResource, iotfleetwise:, iotsitewise:GetListElements, iotsitewise:, GetListsMetadata GetThreatEntitySet GetTrustedEntitySet ListThreatEntitySets ListTrustedEntitySets GetCampaign ListCampaigns DescribeComputationModel DescribeDataset iotsitewise:ListComputationModels, iotsitewise:ListDatasets, iotwireless:, iotwireless:GetWirelessDeviceImportTask, kendra:, log:ListWirelessDeviceImportTasks, log:ListDataSources, log:, mediaconnect:GetIntegration, medialive:ListIntegrations, medialive:, medialive:ListRouterOutputs, medialive:DescribeMultiplex, medialive:, medialive:DescribeSdiSource, medialive:GetCloudWatchAlarmTemplate, medialive:GetCloudWatchAlarmTemplateGroup, medialive:GetEventBridgeRuleTemplate, medialive:, manajer jaringan:GetEventBridgeRuleTemplateGroup, manajer jaringan:ListCloudWatchAlarmTemplateGroups,:, manajer jaringan: DescribeQueryDefinitions ListCloudWatchAlarmTemplates ListEventBridgeRuleTemplateGroups ListEventBridgeRuleTemplates ListSdiSources ListSignalMaps GetConnectAttachment GetCoreNetwork GetCoreNetworkPolicy, networkmanager:, networkmanager:GetDirectConnectGatewayAttachment, networkmanager:GetSiteToSiteVpnAttachment, networkmanager:, notifikasi:ListAttachments, notifikasi:, pemberitahuan:ListCoreNetworks, pemberitahuan:, pemberitahuan:GetEventRule, refactor-space:ListEventRules, refactor-space:ListManagedNotificationChannelAssociations, refactor-space:ListNotificationHubs, resource-explorer-2:ListOrganizationalUnits, route53resolver:GetApplication, route53resolver:, securityhub:GetRoute, securityhub: V2, securityhub:ListRoutes, securityhub:, securityhub:GetDefaultView, securityhub:, GetOutpostResolver ListOutpostResolvers DescribeOrganizationConfiguration GetAggregator GetAutomationRuleV2 GetConfigurationPolicyAssociation securityhub:GetFindingAggregator, securityhub: ListAggregators V2, securityhub:, securityhub:, securityhub:ListAutomationRulesV2, sms-suara:, sms-suara:ListConfigurationPolicyAssociations, sms-suara:, sms-suara:ListFindingAggregators, sms-suara:DescribeConfigurationSets, sms-suara:, ruang kerja-web:DescribeKeywords, ruang kerja-web:DescribeProtectConfigurations, ruang kerja-web:, ruang kerja-web:GetProtectConfigurationCountryRuleSet. ListPoolOriginationIdentities ListTagsForResource GetTrustStore GetTrustStoreCertificate GetUserAccessLoggingSettings ListTagsForResource

Kebijakan ini sekarang mendukung izin tambahan untuk merekam perubahan konfigurasi di berbagai AWS layanan.

Februari 17, 2026

AWSConfigServiceRolePolicyKebijakan terkelola yang diperbarui dengan izin komprehensif untuk perekaman konfigurasi AWS sumber daya di lebih dari 100 AWS layanan termasuk komputasi, penyimpanan, jaringan, keamanan, analitik, dan layanan pembelajaran mesin.

Kebijakan ini sekarang menyediakan dokumentasi izin layanan yang disempurnakan dan mendukung pemantauan komprehensif di semua AWS layanan yang AWS Config mendukung perekaman konfigurasi.

Januari 27, 2026

AWS_ConfigRoleKebijakan terkelola yang diperbarui dengan izin komprehensif untuk perekaman konfigurasi AWS sumber daya di lebih dari 100 AWS layanan termasuk komputasi, penyimpanan, jaringan, keamanan, analitik, dan layanan pembelajaran mesin.

Kebijakan ini sekarang menyediakan dokumentasi izin layanan yang disempurnakan dan mendukung pemantauan komprehensif di semua AWS layanan yang AWS Config mendukung perekaman konfigurasi.

Januari 27, 2026

AWS_ConfigRole— tambahkan “s3tables: ListTagsForResource “, “s3tables: “, “s3 GetTableBucketMetricsConfiguration tables:” GetTableBucketStorageClass

Kebijakan ini sekarang mendukung izin tambahan untuk S3Tables..

Januari 09, 2026

AWSConfigServiceRolePolicy— tambahkan “s3tables: ListTagsForResource “, “s3tables: “, “s3 GetTableBucketMetricsConfiguration tables:” GetTableBucketStorageClass

Kebijakan ini sekarang mendukung izin tambahan untuk S3Tables.

Januari 09, 2026

AWS_ConfigRole— tambahkan “lightsail:GetActiveNames" “lightsail:GetOperations" “s3:” GetBucketAbac

Kebijakan ini sekarang mendukung izin tambahan untuk Amazon Lightsail dan Amazon Simple Storage Service (Amazon S3).

20 November 2025

AWSConfigServiceRolePolicy— tambahkan “lightsail:GetActiveNames" “lightsail:GetOperations" “s3:” GetBucketAbac

Kebijakan ini sekarang mendukung izin tambahan untuk Amazon Lightsail dan Amazon Simple Storage Service (Amazon S3).

20 November 2025

AWSConfigServiceRolePolicyKebijakan terkelola yang diperbarui dengan izin komprehensif untuk perekaman konfigurasi AWS sumber daya di lebih dari 100 AWS layanan termasuk komputasi, penyimpanan, jaringan, keamanan, analitik, dan layanan pembelajaran mesin.

Kebijakan ini sekarang menyediakan dokumentasi izin layanan yang disempurnakan dan mendukung pemantauan komprehensif di semua AWS layanan yang AWS Config mendukung perekaman konfigurasi.

November 11, 2025

AWS_ConfigRole— Kebijakan terkelola yang diperbarui dengan izin komprehensif untuk perekaman konfigurasi AWS sumber daya di beberapa layanan termasuk AWS Identity and Access Management, Amazon Elastic Compute Cloud, Amazon Simple Storage Service, AWS Lambda, Amazon Relational Database Service, dan banyak lainnya.

Kebijakan ini sekarang mendukung izin tambahan untuk perekaman dan pemantauan konfigurasi AWS sumber daya yang komprehensif di semua AWS layanan yang didukung.

November 10, 2025

AWS_ConfigRole— tambahkan “amplify:GetDomainAssociation" “amplify:ListDomainAssociations" “amplify:" “appsync:ListTagsForResource" “appsync:GetSourceApiAssociation" “bedrock:ListSourceApiAssociations" “bedrock:GetFlow" “batuan dasar:ListAgentCollaborators" “batuan dasar:ListFlows" “cloudTrail:GetResourcePolicy" “cloudformation:ListPrompts" “codeartefact:DescribePublisher" “codeartefact:DescribePackageGroup" “codepipeline:" “codepipeline:ListAllowedRepositoriesForGroup" “connect:" “connect:ListPackageGroups" “:ListActionTypes" “batas waktu:ListTagsForResource" “ec2:" “ec2:ListWebhooks" “ec DescribeTrafficDistributionGroup ListTrafficDistributionGroups ListFarms GetTransitGatewayRouteTablePropagations SearchLocalGatewayRoutes 2: SearchTransitGatewayMulticastGroups "“entityresolution:GetMatchingWorkflow" “entityresolution:" “iotsitewise:ListMatchingWorkflows" “iotsitewise:ListAssetModelCompositeModels" “iotsitewise:ListAssetModelProperties" “iotsitewise:" “ivs:ListAssetProperties" “lambda:" “lambda:ListAssociatedAssets" “lambda:" “pipa:ListPublicKeys" “quicksight:GetProvisionedConcurrencyConfig" “quicksight:GetRuntimeManagementConfig" “redshift-serverless:ListFunctionEventInvokeConfigs" “redshift-serverless:ListFunctionUrlConfigs" “redshift:DescribePipe" “rolesanywhere:ListPipes" “rolesanywhere:DescribeRefreshSchedule" “sagemaker:" “sagemaker:ListRefreshSchedules" “sagemaker: ListSnapshotCopyConfigurations GetResourcePolicy GetCrl ListCrls DescribeApp DescribeUserProfile ListAppssagemaker: "“sagemaker:ListModelPackages" “secretsmanager:ListUserProfiles" “securitylake:" “securitylake:GetResourcePolicy" “servicecatalog:ListSubscribers" “servicecatalog:" “servicecatalog:ListTagsForResource" “perisai:" “insiden ssm-:DescribeServiceAction" “ssm:" “ssm:ListApplications" “ssm:ListAssociatedResources" “ssm:" “ssm:ListProtectionGroups" “ssm:ListTagsForResource" “ssm:" “ssm:GetReplicationSet" “ssm:" “ssm:ListReplicationSets" “ssm:DescribeAssociation" “ssm:" “wafv2:DescribePatchBaselines" “bedrock-agentcore:GetDefaultPatchBaseline" “bedrock-agentcore:GetPatchBaseline" “batuan dasar GetResourcePolicies ListAssociations ListResourceDataSync ListLoggingConfigurations ListCodeInterpreters GetCodeInterpreter -agentcore: ListBrowsers "“bedrock-agentcore:" “bedrock-agentcore:GetBrowser" “bedrock-agentcore:" “bedrock-agentcore:ListAgentRuntimes" “bedrock-agentcore:” GetAgentRuntime ListAgentRuntimeEndpoints GetAgentRuntimeEndpoint

Kebijakan ini sekarang mendukung izin tambahan untuk AWS Amplify, AWS AppSync, Amazon Bedrock,,, AWS CloudTrail CloudFormation AWS CodeArtifact, Connect Customer AWS CodePipeline,, Amazon EC2 AWS Deadline Cloud,,, Amazon IVS Resolusi Entitas AWS AWS IoT SiteWise,, Amazon Quick AWS Lambda, Amazon Redshift EventBridge, Amazon Redshift, Amazon Redshift Serverless,, Amazon, AWS Identity and Access Management Roles Anywhere, Amazon Security Lake SageMaker, AWS Secrets Manager, Amazon EC2 Systems Manager AWS Service Catalog AWS Shield, dan. AWS WAFV2

Oktober 1, 2025

AWSConfigServiceRolePolicy— tambahkan “amplify:GetDomainAssociation" “amplify:ListDomainAssociations" “amplify:" “appsync:ListTagsForResource" “appsync:GetSourceApiAssociation" “bedrock:ListSourceApiAssociations" “bedrock:GetFlow" “batuan dasar:ListAgentCollaborators" “batuan dasar:ListFlows" “cloudTrail:GetResourcePolicy" “cloudformation:ListPrompts" “codeartefact:DescribePublisher" “codeartefact:DescribePackageGroup" “codepipeline:" “codepipeline:ListAllowedRepositoriesForGroup" “connect:" “connect:ListPackageGroups" “:ListActionTypes" “batas waktu:ListTagsForResource" “ec2:" “ec2:ListWebhooks" “ec DescribeTrafficDistributionGroup ListTrafficDistributionGroups ListFarms GetTransitGatewayRouteTablePropagations SearchLocalGatewayRoutes 2: SearchTransitGatewayMulticastGroups "“entityresolution:GetMatchingWorkflow" “entityresolution:" “iotsitewise:ListMatchingWorkflows" “iotsitewise:ListAssetModelCompositeModels" “iotsitewise:ListAssetModelProperties" “iotsitewise:" “ivs:ListAssetProperties" “lambda:" “lambda:ListAssociatedAssets" “lambda:" “pipa:ListPublicKeys" “quicksight:GetProvisionedConcurrencyConfig" “quicksight:GetRuntimeManagementConfig" “redshift-serverless:ListFunctionEventInvokeConfigs" “redshift-serverless:ListFunctionUrlConfigs" “redshift:DescribePipe" “rolesanywhere:ListPipes" “rolesanywhere:DescribeRefreshSchedule" “sagemaker:" “sagemaker:ListRefreshSchedules" “sagemaker: ListSnapshotCopyConfigurations GetResourcePolicy GetCrl ListCrls DescribeApp DescribeUserProfile ListAppssagemaker: "“sagemaker:ListModelPackages" “secretsmanager:ListUserProfiles" “securitylake:" “securitylake:GetResourcePolicy" “servicecatalog:ListSubscribers" “servicecatalog:" “servicecatalog:ListTagsForResource" “perisai:" “insiden ssm-:DescribeServiceAction" “ssm:" “ssm:ListApplications" “ssm:ListAssociatedResources" “ssm:" “ssm:ListProtectionGroups" “ssm:ListTagsForResource" “ssm:" “ssm:GetReplicationSet" “ssm:" “ssm:ListReplicationSets" “ssm:DescribeAssociation" “ssm:" “wafv2:DescribePatchBaselines" “bedrock-agentcore:GetDefaultPatchBaseline" “bedrock-agentcore:GetPatchBaseline" “batuan dasar GetResourcePolicies ListAssociations ListResourceDataSync ListLoggingConfigurations ListCodeInterpreters GetCodeInterpreter -agentcore: ListBrowsers "“bedrock-agentcore:" “bedrock-agentcore:GetBrowser" “bedrock-agentcore:" “bedrock-agentcore:ListAgentRuntimes" “bedrock-agentcore:” GetAgentRuntime ListAgentRuntimeEndpoints GetAgentRuntimeEndpoint

Kebijakan ini sekarang mendukung izin tambahan untuk AWS Amplify, AWS AppSync, Amazon Bedrock,,, AWS CloudTrail CloudFormation AWS CodeArtifact, Connect Customer AWS CodePipeline,, Amazon EC2 AWS Deadline Cloud,,, Amazon IVS Resolusi Entitas AWS AWS IoT SiteWise,, Amazon Quick AWS Lambda, Amazon Redshift EventBridge, Amazon Redshift, Amazon Redshift Serverless,, Amazon, AWS Identity and Access Management Roles Anywhere, Amazon Security Lake SageMaker, AWS Secrets Manager, Amazon EC2 Systems Manager AWS Service Catalog AWS Shield, dan. AWS WAFV2

Oktober 1, 2025

AWS_ConfigRole— Tambahkan “arc-zonal-shift: GetAutoshiftObserverNotificationStatus “, “bedrock: “, “cloudtrail: GetModelInvocationLoggingConfiguration “, “codeartefact: GetEventConfiguration “, “codeartefact: “, “deadline: DescribeDomain “, “tenggat waktu: GetDomainPermissionsPolicy “, “tenggat waktu: GetFleet “, “tenggat waktu: GetQueueFleetAssociation “, “tenggat waktu: ListFleets “, “dms: ListQueueFleetAssociations “, “dms: “, ListTagsForResource “glue: “, “kafkaconnect: DescribeDataMigrations “, “kafkaconnect: ListMigrationProjects “, “kafkaconnect: GetDataCatalogEncryptionSettings “, “kafkaconnect: DescribeCustomPlugin “, “kafkaconnect: DescribeWorkerConfiguration “, “lakeformation: “, “medialive: ListCustomPlugins “,” ListTagsForResource ListWorkerConfigurations DescribeLakeFormationIdentityCenterConfiguration DescribeMultiplexProgram medialive: ListMultiplexPrograms “, “mediapackagev2: “, “mediapackagev2: GetChannelGroup “, “rds: “, “rolesanywhere: “, “rolesanywhere: “, “rolesanywhere: ListChannelGroups “, “rolesanywhere: “, “rolesanywhere: “, “s3: DescribeEngineDefaultParameters “, “secretsmanager: “, “securitylake: GetProfile “, “securitylake: “, “securitylake: GetTrustAnchor “, “securitylake: “, “securitylake: ListProfiles “, “securitylake: “, “securitylake: ListTagsForResource “, “securitylake: “, “securitylake: ListTrustAnchors “, “securitylake: “, GetAccessGrant “securitylake: “, “securitylake: ListAccessGrants “, “securitylake: “, “securitylake: DescribeSecret “, ““, “securitylake: “, “servicecatalog: ListDataLakeExceptions “, “servicecatalog: “, “servicecatalog: ListDataLakes “, “servicecatalog: “, “ses: “ses: ListLogSources GetAttributeGroup ListAttributeGroups ListServiceActions ListServiceActionsForProvisioningArtifact GetTrafficPolicy ListTagsForResource“, “ses: ListTrafficPolicies “, “xray: GetGroup “, “xray: “, GetGroups “xray: “, GetSamplingRules “xray: “, “xray:ListResourcePolicies” ListTagsForResource

Kebijakan ini sekarang mendukung izin tambahan untuk AWS ARC - Zonal Shift, Amazon Bedrock,,, AWS CloudTrail, AWS CodeArtifact AWS Deadline Cloud AWS Database Migration Service AWS Glue AWS Identity and Access Management, Amazon Managed Streaming untuk Apache Kafka,, Amazon CloudWatch Logs AWS Lake Formation,, AWS Elemental MediaLive AWS Elemental MediaPackage, Amazon Relational Database Service, Amazon Simple Storage Service,, Amazon Security Lake AWS Secrets Manager,, Amazon Simple Email Service AWS Service Catalog, dan. AWS X-Ray

Juli 28, 2025

AWSConfigServiceRolePolicy— Tambah

“arc-zonal-shift: “, “bedrock: GetAutoshiftObserverNotificationStatus “, “cloudtrail: “, “codeartefact: GetModelInvocationLoggingConfiguration “, “codeartefact: “, “tenggat waktu: GetEventConfiguration “, “tenggat waktu: “, “tenggat waktu: DescribeDomain “, “tenggat waktu: “, “tenggat waktu: GetDomainPermissionsPolicy “, “dms: “, “dms: GetFleet “, “glue: “, “iam: GetQueueFleetAssociation “, “kafkaconnect: ListFleets “, “kafkackaconnect: “, ListQueueFleetAssociations “kafkackaconnect: ListTagsForResource “, “kafkackaconnect: “, “kafkackaconnect: DescribeDataMigrations “, “kafkackaconnect: ListMigrationProjects “, “kafkackaconnect: “, GetDataCatalogEncryptionSettings “kafkackaconnect: “, “kafkackaconnect: ListPolicies “, “kafkackaconnect: “, “kafkackaconnect: DescribeCustomPlugin “, “, “kafkaconnect: DescribeWorkerConfiguration “, “kafkaconnect: “, “kafkaconnect: ListCustomPlugins “, “lakeformation: “, “log: “log: “, “medialive: ListTagsForResource ListWorkerConfigurations DescribeLakeFormationIdentityCenterConfiguration DescribeIndexPolicies ListTagsForResource DescribeMultiplexProgram“, “medialive: ListMultiplexPrograms “, “mediapackagev2: “, “mediapackagev2: GetChannelGroup “, “rds: ListChannelGroups “, “rolesanywhere: “, “rolesanywhere: DescribeEngineDefaultParameters “, “rolesanywhere: GetProfile “, “rolesanywhere: GetTrustAnchor “, “rolesanywhere: “, “s3: ListProfiles “, “secretsmanager: ListTagsForResource “, “securitylake: “, ListTrustAnchors “securitylake: “, GetAccessGrant “securitylake: “, ListAccessGrants “servicecatalog: “, “servicecatalog: DescribeSecret “, “servicecatalog: ListDataLakeExceptions “, “servicecatalog: “, “ses: ListDataLakes ListLogSources GetAttributeGroup ListAttributeGroups ListServiceActions ListServiceActionsForProvisioningArtifact GetTrafficPolicy “, “ses: “, “ses: ListTagsForResource “, “xray: ListTrafficPolicies “, “xray: “, “xray: GetGroup “, “xray: “, “xray: GetGroups “, “arn:aws:apigateway: GetSamplingRules ::/account”, ListResourcePolicies “arn:aws:apigateway: ::/usageplans”, ListTagsForResource “arn:aws:apigateway: :/usageplans/”.

Kebijakan ini sekarang mendukung izin tambahan untuk AWS ARC - Zonal Shift, Amazon Bedrock,,,, AWS CloudTrail AWS CodeArtifact AWS Deadline Cloud AWS Database Migration Service AWS Glue, Amazon Managed Streaming untuk Apache Kafka AWS Identity and Access Management, Amazon CloudWatch Logs,, AWS Lake Formation, Amazon Relational Database Service AWS Elemental MediaLive AWS Elemental MediaPackage, Amazon Simple Storage Service, Amazon Security Lake,, Amazon Simple Email Service AWS Secrets Manager, AWS Service Catalog, Amazon Simple Email Service, AWS X-Ray, dan Amazon API Gateway.

Juli 28, 2025

AWSConfigServiceRolePolicy— Tambahkan “backup-gateway: GetHypervisor “, “backup-gateway: “, ListHypervisors “bcm-data-ekspor: “, “bcm-data-ekspor: GetExport “, “bcm-data-ekspor: ListExports “, “bedrock: “, ListTagsForResource “batuan dasar: “, “batuan dasar: GetAgent “, “batuan dasar: GetAgentActionGroup “, “batuan dasar: GetAgentKnowledgeBase “, “batuan dasar: GetDataSource “, “batuan dasar: GetFlowAlias “, “batuan dasar: GetFlowVersion “, “batuan dasar: ListAgentActionGroups “, “pembentukan awan: “, ListAgentKnowledgeBases “pembentukan awan: “, ListDataSources “formasi awan: “, “formasi awan: ListFlowAliases ListFlowVersions BatchDescribeTypeConfigurations DescribeStackInstance DescribeStackSet ListStackInstances“, “cloudformation: “, ListStackSets “cloudfront: “, “cloudfront: GetPublicKey “, “cloudfront: “, GetRealtimeLogConfig “cloudfront: “, “entityresolution: ListPublicKeys “, “entityresolution: ListRealtimeLogConfigs “, “entityresolution: “, GetIdMappingWorkflow “entityresolution: “, “entityresolution: GetSchemaMapping “, “iotdeviceadvisor: ListIdMappingWorkflows “, “iotdeviceadvisor: ListSchemaMappings “, “lambda: “, “lambda: ListTagsForResource “, “lambda: “, “mediapackagev2: GetSuiteDefinition “, “mediapackagev2: ListSuiteDefinitions “, “manajer jaringan: “, “manajer jaringan: GetEventSourceMapping “, “konektor pca- ListEventSourceMappings GetChannel ListChannels GetTransitGatewayPeering ListPeerings iklan: GetDirectoryRegistration “, “pca-connector-ad: ListDirectoryRegistrations “, “pca-connector-ad: “, “rds: ListTagsForResource “, “rds: DescribeDBShardGroups “, “redshift: “, DescribeIntegrations “s3tables: “, DescribeIntegrations “s3tables: “, “s3tables: GetTableBucket “, “s3tables: GetTableBucketEncryption “, “ssm-quicksetup:” GetTableBucketMaintenanceConfiguration ListTableBuckets GetConfigurationManager ListConfigurationManagers

Kebijakan ini sekarang mendukung izin tambahan untuk AWS Backup gateway, AWS Manajemen Penagihan dan Biaya, Amazon Bedrock,, Amazon AWS CloudFormation,, CloudFront,, Resolusi Entitas AWS, AWS IoT Core Device Advisor AWS Lambda AWS Network Manager AWS Private Certificate Authority, Amazon Relational Database Service, Amazon Redshift, Amazon S3 Tables,. Pengaturan Cepat AWS Systems Manager

Juni 18, 2025

AWS_ConfigRole— Tambahkan “backup-gateway: GetHypervisor “, “backup-gateway: “, ListHypervisors “bcm-data-ekspor: “, “bcm-data-ekspor: GetExport “, “bcm-data-ekspor: ListExports “, “bedrock: “, ListTagsForResource “batuan dasar: “, “batuan dasar: GetAgent “, “batuan dasar: GetAgentActionGroup “, “batuan dasar: GetAgentKnowledgeBase “, “batuan dasar: GetDataSource “, “batuan dasar: GetFlowAlias “, “batuan dasar: GetFlowVersion “, “batuan dasar: ListAgentActionGroups “, “pembentukan awan: “, ListAgentKnowledgeBases “pembentukan awan: “, ListDataSources “formasi awan: “, “formasi awan: ListFlowAliases ListFlowVersions BatchDescribeTypeConfigurations DescribeStackInstance DescribeStackSet ListStackInstances“, “cloudformation: ListStackSets “, “cloudfront: “, “cloudfront: GetPublicKey “, “cloudfront: GetRealtimeLogConfig “, “cloudfront: “, ListPublicKeys “entityresolution: “, “entityresolution: ListRealtimeLogConfigs “, “entityresolution: GetIdMappingWorkflow “, “entityresolution: GetSchemaMapping “, “entityresolution: “, “iotdeviceadvisor: ListIdMappingWorkflows “, “iotdeviceadvisor: ListSchemaMappings “, “lambda: ListTagsForResource “, “lambda: “, “manajer jaringan: GetSuiteDefinition “, “manajer jaringan: “, “pca-connector-ad: ListSuiteDefinitions “, “pca-connector-ad: GetEventSourceMapping “, “pca- ListEventSourceMappings GetTransitGatewayPeering ListPeerings GetDirectoryRegistration ListDirectoryRegistrations connector-ad: ListTagsForResource “, “rds: “, “rds: DescribeDBShardGroups “, “redshift: DescribeIntegrations “, “s3tables: DescribeIntegrations “, “s3tables: “, “s3tables: GetTableBucket “, “s3tables: GetTableBucketEncryption “, “ssm-quicksetup: GetTableBucketMaintenanceConfiguration “, “ssm-quicksetup:” ListTableBuckets GetConfigurationManager ListConfigurationManagers

Kebijakan ini sekarang mendukung izin tambahan untuk AWS Backup gateway, AWS Manajemen Penagihan dan Biaya, Amazon Bedrock,, Amazon AWS CloudFormation,, CloudFront,, Resolusi Entitas AWS, AWS IoT Core Device Advisor AWS Lambda AWS Network Manager AWS Private Certificate Authority, Amazon Relational Database Service, Amazon Redshift, Amazon S3 Tables,. Pengaturan Cepat AWS Systems Manager

Juni 18, 2025

AWS_ConfigRole— Tambah "bedrock:GetGuardrail", "bedrock:GetInferenceProfile", "bedrock:GetKnowledgeBase", "bedrock:ListGuardrails", "bedrock:ListInferenceProfiles", "bedrock:ListKnowledgeBases", "bedrock:ListTagsForResource"

Kebijakan ini sekarang mendukung izin tambahan untuk Amazon Bedrock.

27 Mei 2025

AWSConfigServiceRolePolicy— Tambahkan "bedrock:GetGuardrail", "bedrock:GetInferenceProfile", "bedrock:GetKnowledgeBase", "bedrock:ListGuardrails", "bedrock:ListInferenceProfiles", "bedrock:ListKnowledgeBases", "bedrock:ListTagsForResource"

Kebijakan ini sekarang mendukung izin tambahan untuk Amazon Bedrock.

27 Mei 2025

AWS_ConfigRole— Tambahkan "b2bi:GetPartnership", "b2bi:GetProfile", "b2bi:ListPartnerships", "b2bi:ListProfiles", "bedrock:ListAgents", "cleanrooms:GetConfiguredTable", "cleanrooms:GetConfiguredTableAnalysisRule", "cleanrooms:GetMembership", "cleanrooms:GetPrivacyBudgetTemplate", "cleanrooms:ListConfiguredTables", "cleanrooms:ListMemberships", "cleanrooms:ListPrivacyBudgetTemplates", "codeconnections:GetConnection", "codeconnections:ListConnections", "codeconnections:ListTagsForResource", "directconnect:DescribeConnections", "dms:DescribeReplicationConfigs", "logs:DescribeAccountPolicies", "logs:DescribeResourcePolicies", "macie2:ListAutomatedDiscoveryAccounts", "managedblockchain:GetAccessor", "managedblockchain:ListAccessors", "qbusiness:GetApplication", "qbusiness:ListApplications", "qbusiness:ListTagsForResource", "route53profiles:GetProfile", "route53profiles:GetProfileAssociation", "route53profiles:ListProfileAssociations", "route53profiles:ListProfiles", "route53profiles:ListTagsForResource", "s3:GetAccessGrantsInstance", "s3:GetAccessGrantsLocation", "s3:ListAccessGrantsInstances", "s3:ListAccessGrantsLocations", "sagemaker:DescribeCluster", "sagemaker:DescribeMlflowTrackingServer", "sagemaker:DescribeStudioLifecycleConfig", "sagemaker:ListClusters", "sagemaker:ListMlflowTrackingServers", "sagemaker:ListStudioLifecycleConfigs", "securityhub:DescribeStandardsControls", "securityhub:GetEnabledStandards", "ssm-contacts:GetContact", "ssm-contacts:GetContactChannel", "ssm-contacts:ListContactChannels", "ssm-contacts:ListContacts", "ssm-incidents:GetResponsePlan", "ssm-incidents:ListResponsePlans", "ssm-incidents:ListTagsForResource", "ssm:DescribeInstanceInformation"

Kebijakan ini sekarang mendukung izin tambahan untuk AWS B2B Pertukaran Data, Amazon Bedrock,, AWS Clean Rooms, AWS Database Migration Service (AWS DMS) AWS CodeConnections AWS Direct Connect, Amazon CloudWatch Logs, Amazon Macie, Amazon Managed Blockchain, Amazon Q Business, Profil Route 53, Amazon Simple Storage Service (Amazon S3), Amazon SageMaker AI,, dan AWS Security Hub CSPM, Kontak Manajer Insiden AWS Systems Manager, Manajer Insiden AWS Systems Manager dan. AWS Systems Manager

08 April 2025

AWSConfigServiceRolePolicy— Tambahkan "b2bi:GetPartnership", "b2bi:GetProfile", "b2bi:ListPartnerships", "b2bi:ListProfiles", "bedrock:ListAgents", "cleanrooms:GetConfiguredTable", "cleanrooms:GetConfiguredTableAnalysisRule", "cleanrooms:GetMembership", "cleanrooms:GetPrivacyBudgetTemplate", "cleanrooms:ListConfiguredTables", "cleanrooms:ListMemberships", "cleanrooms:ListPrivacyBudgetTemplates", "codeconnections:GetConnection", "codeconnections:ListConnections", "codeconnections:ListTagsForResource", "directconnect:DescribeConnections", "dms:DescribeReplicationConfigs", "logs:DescribeAccountPolicies", "logs:DescribeResourcePolicies", "macie2:ListAutomatedDiscoveryAccounts", "managedblockchain:GetAccessor", "managedblockchain:ListAccessors", "qbusiness:GetApplication", "qbusiness:ListApplications", "qbusiness:ListTagsForResource", "route53profiles:GetProfile", "route53profiles:GetProfileAssociation", "route53profiles:ListProfileAssociations", "route53profiles:ListProfiles", "route53profiles:ListTagsForResource", "s3:GetAccessGrantsInstance", "s3:GetAccessGrantsLocation", "s3:ListAccessGrantsInstances", "s3:ListAccessGrantsLocations", "sagemaker:DescribeCluster", "sagemaker:DescribeMlflowTrackingServer", "sagemaker:DescribeStudioLifecycleConfig", "sagemaker:ListClusters", "sagemaker:ListMlflowTrackingServers", "sagemaker:ListStudioLifecycleConfigs", "securityhub:DescribeStandardsControls", "securityhub:GetEnabledStandards", "ssm-contacts:GetContact", "ssm-contacts:GetContactChannel", "ssm-contacts:ListContactChannels", "ssm-contacts:ListContacts", "ssm-incidents:GetResponsePlan", "ssm-incidents:ListResponsePlans", "ssm-incidents:ListTagsForResource", "ssm:DescribeInstanceInformation"

Kebijakan ini sekarang mendukung izin tambahan untuk AWS B2B Pertukaran Data, Amazon Bedrock,, AWS Clean Rooms, AWS Database Migration Service (AWS DMS) AWS CodeConnections AWS Direct Connect, Amazon CloudWatch Logs, Amazon Macie, Amazon Managed Blockchain, Amazon Q Business, Profil Route 53, Amazon Simple Storage Service (Amazon S3), Amazon SageMaker AI,, dan AWS Security Hub CSPM, Kontak Manajer Insiden AWS Systems Manager, Manajer Insiden AWS Systems Manager dan. AWS Systems Manager Kebijakan ini juga sekarang mendukung izin untuk mengakses semua nama domain Amazon API Gateway dengan menyertakan pola sumber daya "arn:aws:apigateway:::/domainnames/”.

08 April 2025

AWS_ConfigRole— Tambahkan "ec2:GetAllowedImagesSettings"

Kebijakan ini sekarang mendukung izin tambahan untuk Amazon Elastic Compute Cloud (Amazon EC2).

Maret 4, 2025

AWSConfigServiceRolePolicy— Tambahkan "ec2:GetAllowedImagesSettings"

Kebijakan ini sekarang mendukung izin tambahan untuk Amazon Elastic Compute Cloud (Amazon EC2).

Maret 4, 2025

AWS_ConfigRole— Tambahkan "cleanrooms-ml:GetTrainingDataset", "cleanrooms-ml:ListTrainingDatasets", "comprehend:DescribeFlywheel", "comprehend:ListFlywheels", "comprehend:ListTagsForResource", "ec2:GetSnapshotBlockPublicAccessState", "omics:GetAnnotationStore", "omics:GetRunGroup", "omics:GetSequenceStore", "omics:GetVariantStore", "omics:ListAnnotationStores", "omics:ListRunGroups", "omics:ListSequenceStores", "omics:ListTagsForResource", "omics:ListVariantStores", "s3express:GetEncryptionConfiguration", "s3express:GetLifecycleConfiguration", "ses:GetDedicatedIpPool", "ses:GetDedicatedIps", and "ses:ListDedicatedIpPools"

Kebijakan ini sekarang mendukung izin tambahan untuk AWS Clean Rooms, Amazon Comprecept, Amazon Elastic Compute Cloud (Amazon EC2), AWS HealthOmics, Amazon Simple Storage Service (Amazon S3), dan Amazon Simple Email Service (Amazon SES).

Januari 16, 2025

AWSConfigServiceRolePolicy— Tambahkan "cleanrooms-ml:GetTrainingDataset", "cleanrooms-ml:ListTrainingDatasets", "comprehend:DescribeFlywheel", "comprehend:ListFlywheels", "comprehend:ListTagsForResource", "ec2:GetSnapshotBlockPublicAccessState", "omics:GetAnnotationStore", "omics:GetRunGroup", "omics:GetSequenceStore", "omics:GetVariantStore", "omics:ListAnnotationStores", "omics:ListRunGroups", "omics:ListSequenceStores", "omics:ListTagsForResource", "omics:ListVariantStores", "s3express:GetEncryptionConfiguration", "s3express:GetLifecycleConfiguration", "ses:GetDedicatedIpPool", "ses:GetDedicatedIps", and "ses:ListDedicatedIpPools"

Kebijakan ini sekarang mendukung izin tambahan untuk AWS Clean Rooms, Amazon Comprecept, Amazon Elastic Compute Cloud (Amazon EC2), AWS HealthOmics, Amazon Simple Storage Service (Amazon S3), dan Amazon Simple Email Service (Amazon SES).

Januari 16, 2025

AWSConfigServiceRolePolicy— Tambahkan "organizations:ListAWSServiceAccessForOrganization"

Kebijakan ini sekarang mendukung izin tambahan untuk AWS Organizations.

Desember 18, 2024

AWS_ConfigRole— Tambahkan "app-integrations:GetApplication", "app-integrations:ListApplications", "app-integrations:ListTagsForResource", "appconfig:GetExtension", "appconfig:ListExtensions", "cloudtrail:GetInsightSelectors", "connect:DescribeQueue", "connect:DescribeRoutingProfile", "connect:DescribeSecurityProfile", "connect:ListQueueQuickConnects", "connect:ListQueues", "connect:ListRoutingProfileQueues", "connect:ListRoutingProfiles", "connect:ListSecurityProfileApplications", "connect:ListSecurityProfilePermissions", "connect:ListSecurityProfiles", "datazone:GetDomain", "datazone:ListDomains", "devops-guru:ListNotificationChannels", "glue:GetRegistry", "glue:ListRegistries", "identitystore:DescribeGroup", "identitystore:DescribeGroupMembership" "identitystore:ListGroupMemberships", "identitystore:ListGroups", "iot:DescribeThingGroup", "iot:DescribeThingType", "iot:ListThingGroups", "iot:ListThingTypes", "iotfleetwise:GetDecoderManifest", "iotfleetwise:GetFleet", "iotfleetwise:GetModelManifest", "iotfleetwise:GetSignalCatalog", "iotfleetwise:GetVehicle", "iotfleetwise:ListDecoderManifestNetworkInterfaces", "iotfleetwise:ListDecoderManifests", "iotfleetwise:ListDecoderManifestSignals", "iotfleetwise:ListFleets", "iotfleetwise:ListModelManifestNodes", "iotfleetwise:ListModelManifests", "iotfleetwise:ListSignalCatalogNodes", "iotfleetwise:ListSignalCatalogs", "iotfleetwise:ListTagsForResource", "iotfleetwise:ListVehicles", "iotwireless:GetDestination", "iotwireless:GetDeviceProfile", "iotwireless:GetWirelessGateway", "iotwireless:ListDestinations", "iotwireless:ListDeviceProfiles", "iotwireless:ListWirelessGateways", "ivschat:GetLoggingConfiguration", "ivschat:GetRoom" "ivschat:ListLoggingConfigurations", "ivschat:ListRooms", "ivschat:ListTagsForResource", "logs:GetLogAnomalyDetector", "logs:ListLogAnomalyDetectors", "oam:GetSink" "oam:GetSinkPolicy", "oam:ListSinks", "payment-cryptography:GetAlias", "payment-cryptography:GetKey", "payment-cryptography:ListAliases", "payment-cryptography:ListKeys", "payment-cryptography:ListTagsForResource", "rds:DescribeDBProxyTargetGroups", "rds:DescribeDBProxyTargets", "rekognition:DescribeProjects", "s3:GetStorageLensGroup", "s3:ListStorageLensGroups", "s3:ListTagsForResource", "scheduler:GetScheduleGroup", "scheduler:ListScheduleGroups", "scheduler:ListTagsForResource", "ssm:GetServiceSetting", "vpc-lattice:GetAccessLogSubscription", "vpc-lattice:GetService", "vpc-lattice:GetServiceNetwork", "vpc-lattice:GetTargetGroup", "vpc-lattice:ListAccessLogSubscriptions", "vpc-lattice:ListServiceNetworks", "vpc-lattice:ListServices", "vpc-lattice:ListTagsForResource", "vpc-lattice:ListTargetGroups", and "vpc-lattice:ListTargets"

Kebijakan ini sekarang mendukung izin tambahan untuk AWS AppConfig, AWS CloudTrail, Amazon Connect Customer, Amazon, Amazon DevOps Guru DataZone,, Identity Store AWS Glue,, AWS IoT AWS IoT FleetWise AWS IoT Wireless, Amazon Interactive Video Service (Amazon IVS), Amazon CloudWatch Logs, Amazon CloudWatch Observability Access Manager,, Amazon Relational Database Service (Amazon RDS) AWS Payment Cryptography, Amazon Rekognition, Amazon Simple Storage Service (Amazon S3), Amazon EventBridge Scheduler,, dan Amazon VPC Lattice. AWS Systems Manager

7 November 2024

AWSConfigServiceRolePolicy— Tambahkan "app-integrations:GetApplication", "app-integrations:ListApplications", "app-integrations:ListTagsForResource", "appconfig:GetExtension", "appconfig:ListExtensions", "cloudtrail:GetInsightSelectors", "connect:DescribeQueue", "connect:DescribeRoutingProfile", "connect:DescribeSecurityProfile", "connect:ListQueueQuickConnects", "connect:ListQueues", "connect:ListRoutingProfileQueues", "connect:ListRoutingProfiles", "connect:ListSecurityProfileApplications", "connect:ListSecurityProfilePermissions", "connect:ListSecurityProfiles", "datazone:GetDomain", "datazone:ListDomains", "devops-guru:ListNotificationChannels", "glue:GetRegistry", "glue:ListRegistries", "identitystore:DescribeGroup", "identitystore:DescribeGroupMembership" "identitystore:ListGroupMemberships", "identitystore:ListGroups", "iot:DescribeThingGroup", "iot:DescribeThingType", "iot:ListThingGroups", "iot:ListThingTypes", "iotfleetwise:GetDecoderManifest", "iotfleetwise:GetFleet", "iotfleetwise:GetModelManifest", "iotfleetwise:GetSignalCatalog", "iotfleetwise:GetVehicle", "iotfleetwise:ListDecoderManifestNetworkInterfaces", "iotfleetwise:ListDecoderManifests", "iotfleetwise:ListDecoderManifestSignals", "iotfleetwise:ListFleets", "iotfleetwise:ListModelManifestNodes", "iotfleetwise:ListModelManifests", "iotfleetwise:ListSignalCatalogNodes", "iotfleetwise:ListSignalCatalogs", "iotfleetwise:ListTagsForResource", "iotfleetwise:ListVehicles", "iotwireless:GetDestination", "iotwireless:GetDeviceProfile", "iotwireless:GetWirelessGateway", "iotwireless:ListDestinations", "iotwireless:ListDeviceProfiles", "iotwireless:ListWirelessGateways", "ivschat:GetLoggingConfiguration", "ivschat:GetRoom" "ivschat:ListLoggingConfigurations", "ivschat:ListRooms", "ivschat:ListTagsForResource", "logs:GetLogAnomalyDetector", "logs:ListLogAnomalyDetectors", "oam:GetSink" "oam:GetSinkPolicy", "oam:ListSinks", "payment-cryptography:GetAlias", "payment-cryptography:GetKey", "payment-cryptography:ListAliases", "payment-cryptography:ListKeys", "payment-cryptography:ListTagsForResource", "rds:DescribeDBProxyTargetGroups", "rds:DescribeDBProxyTargets", "rekognition:DescribeProjects", "s3:GetStorageLensGroup", "s3:ListStorageLensGroups", "s3:ListTagsForResource", "scheduler:GetScheduleGroup", "scheduler:ListScheduleGroups", "scheduler:ListTagsForResource", "ssm:GetServiceSetting", "vpc-lattice:GetAccessLogSubscription", "vpc-lattice:GetService", "vpc-lattice:GetServiceNetwork", "vpc-lattice:GetTargetGroup", "vpc-lattice:ListAccessLogSubscriptions", "vpc-lattice:ListServiceNetworks", "vpc-lattice:ListServices", "vpc-lattice:ListTagsForResource", "vpc-lattice:ListTargetGroups", and "vpc-lattice:ListTargets"

Kebijakan ini sekarang mendukung izin tambahan untuk AWS AppConfig, AWS CloudTrail, Amazon Connect Customer, Amazon, Amazon DevOps Guru DataZone,, Identity Store AWS Glue,, AWS IoT AWS IoT FleetWise AWS IoT Wireless, Amazon Interactive Video Service (Amazon IVS), Amazon CloudWatch Logs, Amazon CloudWatch Observability Access Manager,, Amazon Relational Database Service (Amazon RDS) AWS Payment Cryptography, Amazon Rekognition, Amazon Simple Storage Service (Amazon S3), Amazon EventBridge Scheduler,, dan Amazon VPC Lattice. AWS Systems Manager

7 November 2024

AWS_ConfigRole— Tambahkan "aoss:BatchGetCollection," "aoss:BatchGetLifecyclePolicy," "aoss:BatchGetVpcEndpoint," "aoss:GetAccessPolicy," "aoss:GetSecurityConfig," "aoss:GetSecurityPolicy," "aoss:ListAccessPolicies," "aoss:ListCollections," "aoss:ListLifecyclePolicies," "aoss:ListSecurityConfigs," "aoss:ListSecurityPolicies," "aoss:ListVpcEndpoints," "appstream:DescribeAppBlockBuilders," "backup:GetRestoreTestingPlan," "backup:GetRestoreTestingSelection", "backup:ListRestoreTestingPlans," "backup:ListRestoreTestingSelections," "cloudTrail:GetChannel, "cloudTrail:ListChannels," "glue:GetTrigger," "glue:ListTriggers, "imagebuilder:GetLifecyclePolicy," "imagebuilder:ListLifecyclePolicies," "iot:DescribeBillingGroup," "iot:ListBillingGroups," "ivs:GetEncoderConfiguration," "ivs:GetPlaybackRestrictionPolicy," "ivs:GetStage," "ivs:GetStorageConfiguration," "ivs:ListEncoderConfigurations," "ivs:ListPlaybackRestrictionPolicies," "ivs:ListStages," "ivs:ListStorageConfigurations," "mediaconnect:DescribeBridge", "mediaconnect:DescribeGatewa," "mediaconnect:ListBridges," "mediaconnect:ListGateways", "mediatailor:DescribeChannel," "mediatailor:DescribeLiveSource," "mediatailor:DescribeSourceLocation," "mediatailor:DescribeVodSource", "mediatailor:ListChannels," "mediatailor:ListLiveSources", "mediatailor:ListSourceLocations," "mediatailor:ListVodSources," "omics:GetWorkflow," "omics:ListWorkflows," "scheduler:GetSchedule," and "scheduler:ListSchedules"

Kebijakan ini sekarang mendukung izin tambahan untuk Amazon OpenSearch Service Severless, Amazon,, AppStream, AWS Backup AWS CloudTrail, EC2 Image Builder AWS Glue, AWS IoT, Amazon Interactive Video Service (Amazon IVS),,, AWS Elemental MediaConnect AWS Elemental MediaTailor AWS HealthOmics, dan Amazon Scheduler. EventBridge

September 16, 2024

AWSConfigServiceRolePolicy— Tambahkan "aoss:BatchGetCollection," "aoss:BatchGetLifecyclePolicy," "aoss:BatchGetVpcEndpoint," "aoss:GetAccessPolicy," "aoss:GetSecurityConfig," "aoss:GetSecurityPolicy," "aoss:ListAccessPolicies," "aoss:ListCollections," "aoss:ListLifecyclePolicies," "aoss:ListSecurityConfigs," "aoss:ListSecurityPolicies," "aoss:ListVpcEndpoints," "appstream:DescribeAppBlockBuilders," "backup:GetRestoreTestingPlan," "backup:GetRestoreTestingSelection", "backup:ListRestoreTestingPlans," "backup:ListRestoreTestingSelections," "cloudTrail:GetChannel, "cloudTrail:ListChannels," "glue:GetTrigger," "glue:ListTriggers, "imagebuilder:GetLifecyclePolicy," "imagebuilder:ListLifecyclePolicies," "iot:DescribeBillingGroup," "iot:ListBillingGroups," "ivs:GetEncoderConfiguration," "ivs:GetPlaybackRestrictionPolicy," "ivs:GetStage," "ivs:GetStorageConfiguration," "ivs:ListEncoderConfigurations," "ivs:ListPlaybackRestrictionPolicies," "ivs:ListStages," "ivs:ListStorageConfigurations," "mediaconnect:DescribeBridge", "mediaconnect:DescribeGatewa," "mediaconnect:ListBridges," "mediaconnect:ListGateways", "mediatailor:DescribeChannel," "mediatailor:DescribeLiveSource," "mediatailor:DescribeSourceLocation," "mediatailor:DescribeVodSource", "mediatailor:ListChannels," "mediatailor:ListLiveSources", "mediatailor:ListSourceLocations," "mediatailor:ListVodSources," "omics:GetWorkflow," "omics:ListWorkflows," "scheduler:GetSchedule," and "scheduler:ListSchedules"

Kebijakan ini sekarang mendukung izin tambahan untuk Amazon OpenSearch Service Severless, Amazon,, AppStream, AWS Backup AWS CloudTrail, EC2 Image Builder AWS Glue, AWS IoT, Amazon Interactive Video Service (Amazon IVS),,, AWS Elemental MediaConnect AWS Elemental MediaTailor AWS HealthOmics, dan Amazon Scheduler. EventBridge

September 16, 2024

AWS_ConfigRole— Tambahkan "elasticfilesystem:DescribeTags," "redshift:DescribeTags," and "ssm-sap:ListTagsForResource"

Kebijakan ini sekarang mendukung izin tambahan untuk Amazon Elastic File System (Amazon EFS), Amazon Redshift, dan Manajer Sistem AWS untuk SAP.

Juni 17, 2024

AWSConfigServiceRolePolicy— Tambahkan "elasticfilesystem:DescribeTags," "redshift:DescribeTags," and "ssm-sap:ListTagsForResource"

Kebijakan ini sekarang mendukung izin tambahan untuk Amazon Elastic File System (Amazon EFS), Amazon Redshift, dan Manajer Sistem AWS untuk SAP.

Juni 17, 2024
AWS_ConfigRole— Tambahkan "aps:DescribeAlertManagerDefinition," "cloudwatch:DescribeAlarmsForMetric," "cognito-identity:DescribeIdentityPool, "cognito-identity:GetPrincipalTagAttributeMap," "elasticache:DescribeCacheSecurityGroups," "elasticache:DescribeUserGroups," "elasticache:DescribeUsers," "elasticache:DescribeGlobalReplicationGroups," "fsx:DescribeDataRepositoryAssociations," "glue:GetDatabase," "glue:GetDatabases," "iam:ListUsers," "lambda:GetLayerVersion," "lambda:ListLayers," "lambda:ListLayerVersions," "ram:GetPermission," "ram:ListPermissionAssociations," "ram:ListPermissions," "ram:ListPermissionVersions," "redshift-serverless:GetNamespace," "redshift-serverless:GetWorkgroup," "redshift-serverless:ListNamespaces," "redshift-serverless:ListTagsForResource," "redshift-serverless:ListWorkgroups," "sagemaker:DescribeInferenceExperiment," "sagemaker:ListInferenceExperiments," and "sns:GetSMSSandboxAccountStatus"

Kebijakan ini sekarang mendukung izin tambahan untuk Layanan Terkelola Amazon untuk Prometheus, Amazon, Amazon Cognito CloudWatch, Amazon, Amazon FSx ElastiCache,, AWS Identity and Access Management (IAM), AWS Glue,, Amazon Redshift Serverless AWS Lambda, Amazon SageMaker AI AWS RAM, dan Amazon Simple Notification Service (Amazon SNS).

Februari 22, 2024
AWSConfigServiceRolePolicy— Tambah "aps:DescribeAlertManagerDefinition," "cloudwatch:DescribeAlarmsForMetric," "cognito-identity:DescribeIdentityPool, "cognito-identity:GetPrincipalTagAttributeMap," "elasticache:DescribeCacheSecurityGroups," "elasticache:DescribeUserGroups," "elasticache:DescribeUsers," "elasticache:DescribeGlobalReplicationGroups," "fsx:DescribeDataRepositoryAssociations," "glue:GetDatabase," "glue:GetDatabases," "iam:ListUsers," "lambda:GetLayerVersion," "lambda:ListLayers," "lambda:ListLayerVersions," "ram:GetPermission," "ram:ListPermissionAssociations," "ram:ListPermissions," "ram:ListPermissionVersions," "redshift-serverless:GetNamespace," "redshift-serverless:GetWorkgroup," "redshift-serverless:ListNamespaces," "redshift-serverless:ListTagsForResource," "redshift-serverless:ListWorkgroups," "sagemaker:DescribeInferenceExperiment," "sagemaker:ListInferenceExperiments," and "sns:GetSMSSandboxAccountStatus"

Kebijakan ini sekarang mendukung izin tambahan untuk Layanan Terkelola Amazon untuk Prometheus, Amazon, Amazon Cognito CloudWatch, Amazon, Amazon FSx ElastiCache,, AWS Identity and Access Management (IAM), AWS Glue,, Amazon Redshift Serverless AWS Lambda, Amazon SageMaker AI AWS RAM, dan Amazon Simple Notification Service (Amazon SNS).

Februari 22, 2024

AWSConfigUserAccess— AWS Config mulai melacak perubahan untuk kebijakan terkel AWS ola ini

Kebijakan ini menyediakan akses untuk digunakan AWS Config, termasuk mencari berdasarkan tag pada sumber daya dan membaca semua tag. Ini tidak memberikan izin untuk mengkonfigurasi AWS Config, yang memerlukan hak administratif.

Februari 22, 2024
AWS_ConfigRole— Tambah "appconfig:GetExtensionAssociation," "appconfig:ListExtensionAssociations," "aps:DescribeLoggingConfiguration," "dms:DescribeReplicationTaskAssessmentRuns," "iam:GetOpenIDConnectProvider," "iam:ListOpenIDConnectProviders," "kafka:DescribeVpcConnection," "kafka:GetClusterPolicy," "kafka:ListVpcConnections," "logs:DescribeMetricFilters," "organizations:ListDelegatedAdministrators," "s3:GetBucketPolicyStatus," "s3express:GetBucketPolicy," and "s3express:ListAllMyDirectoryBuckets"

Kebijakan ini sekarang mendukung izin tambahan untuk AWS AppConfig, Amazon Managed Service untuk Prometheus, AWS Database Migration Service (AWS DMS), (AWS Identity and Access Management) IAM, Amazon Managed Streaming untuk Apache Kafka (Amazon MSK), Amazon CloudWatch Logs AWS Organizations, dan Amazon Simple Storage Service (Amazon S3).

Desember 5, 2023
AWSConfigServiceRolePolicy— Tambah "appconfig:GetExtensionAssociation," "appconfig:ListExtensionAssociations," "aps:DescribeLoggingConfiguration," "dms:DescribeReplicationTaskAssessmentRuns," "iam:GetOpenIDConnectProvider," "iam:ListOpenIDConnectProviders," "kafka:DescribeVpcConnection," "kafka:GetClusterPolicy," "kafka:ListVpcConnections," "logs:DescribeMetricFilters," "organizations:ListDelegatedAdministrators," "s3:GetBucketPolicyStatus," "s3express:GetBucketPolicy," and "s3express:ListAllMyDirectoryBuckets"

Kebijakan ini sekarang mendukung izin tambahan untuk AWS AppConfig, Amazon Managed Service untuk Prometheus, AWS Database Migration Service (AWS DMS), (AWS Identity and Access Management) IAM, Amazon Managed Streaming untuk Apache Kafka (Amazon MSK), Amazon CloudWatch Logs AWS Organizations, dan Amazon Simple Storage Service (Amazon S3).

5 Desember 2023
AWS_ConfigRole— Tambah "backup:DescribeProtectedResource," "cognito-identity:GetIdentityPoolRoles," "cognito-identity:ListIdentityPools," "cognito-identity:ListTagsForResource," "cognito-idp:DescribeIdentityProvider," "cognito-idp:DescribeResourceServer," "cognito-idp:DescribeUserPool," "cognito-idp:DescribeUserPoolClient," "cognito-idp:DescribeUserPoolDomain," "cognito-idp:GetGroup," "cognito-idp:GetUserPoolMfaConfig," "cognito-idp:ListGroups," "cognito-idp:ListIdentityProviders," "cognito-idp:ListResourceServers," "cognito-idp:ListUserPoolClients," "cognito-idp:ListUserPools," "cognito-idp:ListTagsForResource," "connect:DescribeEvaluationForm," "connect:DescribeInstanceStorageConfig," "connect:DescribePrompt," "connect:DescribeRule," "connect:DescribeUser," "connect:GetTaskTemplate," "connect:ListApprovedOrigins," "connect:ListEvaluationForms," "connect:ListInstanceStorageConfigs," "connect:ListIntegrationAssociations," "connect:ListPrompts," "connect:ListRules," "connect:ListSecurityKeys," "connect:ListTagsForResource," "connect:ListTaskTemplates," "connect:ListUsers," "emr-containers:DescribeVirtualCluster," "emr-containers:ListVirtualClusters," "emr-serverless:GetApplication," "emr-serverless:ListApplications," "groundstation:GetDataflowEndpointGroup," "groundstation:ListDataflowEndpointGroups," "m2:GetEnvironment," "m2:ListEnvironments," "m2:ListTagsForResource," "memorydb:DescribeAcls," "memorydb:DescribeClusters," "memorydb:DescribeParameterGroups," "memorydb:DescribeParameters," "memorydb:DescribeSubnetGroups," "organizations:ListRoots," "quicksight:DescribeAccountSubscription," "quicksight:DescribeDataSetRefreshProperties," "rds:DescribeEngineDefaultClusterParameters," "redshift:DescribeEndpointAccess," "redshift:DescribeEndpointAuthorization," "route53:GetChange," "route53:ListCidrBlocks," "route53:ListCidrLocations," "serviceCatalog:DescribePortfolioShares," "transfer:DescribeProfile," and "transfer:ListProfiles"

Kebijakan ini sekarang mendukung izin tambahan untuk Amazon Cognito, Amazon Connect Customer, Amazon EMR,, AWS Ground Station AWS Mainframe Modernization, Amazon MemoryDB,, Amazon Quick AWS Organizations, Amazon Relational Database Service (Amazon RDS), Amazon Redshift, Amazon Route 53,, dan. AWS Service Catalog AWS Transfer Family

17 November 2023
AWS_ConfigRole— Tambah "Sid": "AWSConfigServiceRolePolicyStatementID," "Sid": "AWSConfigSLRLogStatementID," "Sid": "AWSConfigSLRLogEventStatementID," and "Sid": "AWSConfigSLRApiGatewayStatementID"

Kebijakan ini sekarang menambahkan pengidentifikasi keamanan (SID) untuk AWSConfigServiceRolePolicyStatementIDAWSConfigSLRLogStatementID,,AWSConfigSLRLogEventStatementID, danAWSConfigSLRApiGatewayStatementID.

17 November 2023
AWSConfigServiceRolePolicy— Tambah "backup:DescribeProtectedResource," "cognito-identity:GetIdentityPoolRoles," "cognito-identity:ListIdentityPools," "cognito-identity:ListTagsForResource," "cognito-idp:DescribeIdentityProvider," "cognito-idp:DescribeResourceServer," "cognito-idp:DescribeUserPool," "cognito-idp:DescribeUserPoolClient," "cognito-idp:DescribeUserPoolDomain," "cognito-idp:GetGroup," "cognito-idp:GetUserPoolMfaConfig," "cognito-idp:ListGroups," "cognito-idp:ListIdentityProviders," "cognito-idp:ListResourceServers," "cognito-idp:ListUserPoolClients," "cognito-idp:ListUserPools," "cognito-idp:ListTagsForResource," "connect:DescribeEvaluationForm," "connect:DescribeInstanceStorageConfig," "connect:DescribePrompt," "connect:DescribeRule," "connect:DescribeUser," "connect:GetTaskTemplate," "connect:ListApprovedOrigins," "connect:ListEvaluationForms," "connect:ListInstanceStorageConfigs," "connect:ListIntegrationAssociations," "connect:ListPrompts," "connect:ListRules," "connect:ListSecurityKeys," "connect:ListTagsForResource," "connect:ListTaskTemplates," "connect:ListUsers," "emr-containers:DescribeVirtualCluster," "emr-containers:ListVirtualClusters," "emr-serverless:GetApplication," "emr-serverless:ListApplications," "groundstation:GetDataflowEndpointGroup," "groundstation:ListDataflowEndpointGroups," "m2:GetEnvironment," "m2:ListEnvironments," "m2:ListTagsForResource," "memorydb:DescribeAcls," "memorydb:DescribeClusters," "memorydb:DescribeParameterGroups," "memorydb:DescribeParameters," "memorydb:DescribeSubnetGroups," "organizations:ListRoots," "quicksight:DescribeAccountSubscription," "quicksight:DescribeDataSetRefreshProperties," "rds:DescribeEngineDefaultClusterParameters," "redshift:DescribeEndpointAccess," "redshift:DescribeEndpointAuthorization," "route53:GetChange," "route53:ListCidrBlocks," "route53:ListCidrLocations," "serviceCatalog:DescribePortfolioShares," "transfer:DescribeProfile," and "transfer:ListProfiles"

Kebijakan ini sekarang mendukung izin tambahan untuk Amazon Cognito, Amazon Connect Customer, Amazon EMR,, AWS Ground Station AWS Mainframe Modernization, Amazon MemoryDB,, Amazon Quick AWS Organizations, Amazon Relational Database Service (Amazon RDS), Amazon Redshift, Amazon Route 53,, dan. AWS Service Catalog AWS Transfer Family

17 November 2023
AWSConfigServiceRolePolicy— Tambah "Sid": "AWSConfigServiceRolePolicyStatementID," "Sid": "AWSConfigSLRLogStatementID," "Sid": "AWSConfigSLRLogEventStatementID," and "Sid": "AWSConfigSLRApiGatewayStatementID"

Kebijakan ini sekarang menambahkan pengidentifikasi keamanan (SID) untuk AWSConfigServiceRolePolicyStatementIDAWSConfigSLRLogStatementID,,AWSConfigSLRLogEventStatementID, danAWSConfigSLRApiGatewayStatementID.

17 November 2023
AWS_ConfigRole— Tambah "acm-pca:GetCertificateAuthorityCertificate," "appmesh:DescribeMesh," "appmesh:ListGatewayRoutes," "connect:DescribeInstance," "connect:DescribeQuickConnect," "connect:ListQuickConnects," "ecs:DescribeCapacityProviders," "evidently:GetSegment," "evidently:ListSegments," "grafana:DescribeWorkspace," "grafana:DescribeWorkspaceAuthentication," "grafana:DescribeWorkspaceConfiguration," "grafana:DescribeWorkspaceConfiguration," "guardduty:GetMemberDetectors," "inspector2:BatchGetAccountStatus," "inspector2:GetDelegatedAdminAccount," "inspector2:ListMembers," "iot:DescribeCACertificate," "iot:ListCACertificates," "iot:ListTagsForResource," "iottwinmaker:GetSyncJob," "iottwinmaker:ListSyncJobs," "kafka:ListTagsForResource," "kafkaconnect:DescribeConnector," "kafkaconnect:ListConnectors," "lambda:GetCodeSigningConfig," "lambda:ListCodeSigningConfigs," "lambda:ListTags," "networkmanager:GetConnectPeer," "organizations:DescribeOrganization," "organizations:ListTargetsForPolicy," "sagemaker:DescribeDataQualityJob," "sagemaker:DescribeModelExplainabilityJob," "sagemaker:ListDataQualityJob," and "sagemaker:ExplainabilityJob"

Kebijakan ini sekarang mendukung izin tambahan untuk AWS Private CA, Connect Customer AWS App Mesh, Amazon Elastic Container Service (Amazon ECS), Amazon E CloudWatch vidently, Amazon Managed Grafana, Amazon, Amazon Inspector GuardDuty,, AWS IoT AWS IoT TwinMaker, Amazon Managed Streaming untuk Apache Kafka (Amazon MSK),,, AWS Lambda AWS Network Manager, AWS Organizations dan Amazon AI. SageMaker

4 Oktober 2023
AWSConfigServiceRolePolicy— Tambah "acm-pca:GetCertificateAuthorityCertificate," "appmesh:DescribeMesh," "appmesh:ListGatewayRoutes," "connect:DescribeInstance," "connect:DescribeQuickConnect," "connect:ListQuickConnects," "ecs:DescribeCapacityProviders," "evidently:GetSegment," "evidently:ListSegments," "grafana:DescribeWorkspace," "grafana:DescribeWorkspaceAuthentication," "grafana:DescribeWorkspaceConfiguration," "grafana:DescribeWorkspaceConfiguration," "guardduty:GetMemberDetectors," "inspector2:BatchGetAccountStatus," "inspector2:GetDelegatedAdminAccount," "inspector2:ListMembers," "iot:DescribeCACertificate," "iot:ListCACertificates," "iot:ListTagsForResource," "iottwinmaker:GetSyncJob," "iottwinmaker:ListSyncJobs," "kafka:ListTagsForResource," "kafkaconnect:DescribeConnector," "kafkaconnect:ListConnectors," "lambda:GetCodeSigningConfig," "lambda:ListCodeSigningConfigs," "lambda:ListTags," "networkmanager:GetConnectPeer," "organizations:DescribeOrganization," "organizations:ListTargetsForPolicy," "sagemaker:DescribeDataQualityJob," "sagemaker:DescribeModelExplainabilityJob," "sagemaker:ListDataQualityJob," and "sagemaker:ExplainabilityJob"

Kebijakan ini sekarang mendukung izin tambahan untuk AWS Private CA, Connect Customer AWS App Mesh, Amazon Elastic Container Service (Amazon ECS), Amazon E CloudWatch vidently, Amazon Managed Grafana, Amazon, Amazon Inspector GuardDuty,, AWS IoT AWS IoT TwinMaker, Amazon Managed Streaming untuk Apache Kafka (Amazon MSK),,, AWS Lambda AWS Network Manager, AWS Organizations dan Amazon AI. SageMaker

4 Oktober 2023
AWSConfigServiceRolePolicy— Hapus "ssm:GetParameter"

Kebijakan ini sekarang menghapus izin untuk AWS Systems Manager (Manajer Sistem).

September 6, 2023
AWS_ConfigRole— Tambah "appmesh:DescribeGatewayRoute","appstream:DescribeStacks", "aps:ListTagsForResource", "cloudfront:GetFunction", "cloudfront:GetOriginAccessControl", "cloudfront:ListFunctions", "cloudfront:ListOriginAccessControls", "codeartifact:ListPackages", "codeartifact:ListPackageVersions", "codebuild:BatchGetReportGroups", "codebuild:ListReportGroups", "connect:ListInstanceAttributes", "connect:ListInstances", "glue:GetPartition", "glue:GetPartitions", "guardduty:GetAdministratorAccount", "iam:ListInstanceProfileTags", "inspector2:ListFilters", "iot:DescribeJobTemplate", "iot:DescribeProvisioningTemplate", "iot:ListJobTemplates", "iot:ListProvisioningTemplates", "iottwinmaker:GetComponentType", "iottwinmaker:ListComponentTypes", "iotwireless:GetFuotaTask", "iotwireless:GetMulticastGroup", "iotwireless:ListFuotaTasks", "iotwireless:ListMulticastGroups", "kafka:ListScramSecrets", "macie2:ListTagsForResource", "mediaconnect:ListTagsForResource", "networkmanager:GetConnectPeer", "networkmanager:ListConnectPeers", "organizations:DescribeEffectivePolicy", "organizations:DescribeResourcePolicy", "resource-explorer-2:GetIndex", "resource-explorer-2:ListIndexes", "resource-explorer-2:ListTagsForResource", "route53:ListCidrCollections", "s3:GetMultiRegionAccessPointPolicy", "s3:GetMultiRegionAccessPointPolicyStatus", and "sns:GetDataProtectionPolicy"

Kebijakan ini sekarang mendukung izin tambahan untuk AWS App Mesh,, Amazon AWS CloudFormation, CloudFront AWS CodeArtifact AWS CodeBuild, Amazon Connect Customer,, Amazon AWS Glue, AWS Identity and Access Management (IAM) GuardDuty, Amazon Inspector,,, AWS IoT AWS IoT TwinMaker AWS IoT Wireless, Amazon Managed Streaming untuk Apache Kafka, Amazon Macie,,,, AWS Elemental MediaConnect AWS Network Manager, Amazon Route 53 AWS Organizations AWS Penjelajah Sumber Daya, Amazon Simple Storage Service (Amazon S3), dan Amazon Simple Notification Service (Amazon SNS).

28 Juli 2023
AWSConfigServiceRolePolicy— Tambah "appmesh:DescribeGatewayRoute", "appstream:DescribeStacks", "aps:ListTagsForResource", "cloudfront:GetFunction", "cloudfront:GetOriginAccessControl", "cloudfront:ListFunctions", "cloudfront:ListOriginAccessControls", "codeartifact:ListPackages", "codeartifact:ListPackageVersions", "codebuild:BatchGetReportGroups", "codebuild:ListReportGroups", "connect:ListInstanceAttributes", "connect:ListInstances", "glue:GetPartition", "glue:GetPartitions", "guardduty:GetAdministratorAccount", "iam:ListInstanceProfileTags", "inspector2:ListFilters", "iot:DescribeJobTemplate", "iot:DescribeProvisioningTemplate", "iot:ListJobTemplates", "iot:ListProvisioningTemplates", "iottwinmaker:GetComponentType", "iottwinmaker:ListComponentTypes", "iotwireless:GetFuotaTask", "iotwireless:GetMulticastGroup", "iotwireless:ListFuotaTasks", "iotwireless:ListMulticastGroups", "kafka:ListScramSecrets", "macie2:ListTagsForResource", "mediaconnect:ListTagsForResource", "networkmanager:GetConnectPeer", "networkmanager:ListConnectPeers", "organizations:DescribeEffectivePolicy", "organizations:DescribeResourcePolicy", "resource-explorer-2:GetIndex", "resource-explorer-2:ListIndexes", "resource-explorer-2:ListTagsForResource", "route53:ListCidrCollections", "s3:GetMultiRegionAccessPointPolicy", "s3:GetMultiRegionAccessPointPolicyStatus", "sns:GetDataProtectionPolicy", "ssm:DescribeParameters", "ssm:GetParameter", and "ssm:ListTagsForResource"

Kebijakan ini sekarang mendukung izin tambahan untuk AWS App Mesh, WorkSpaces Aplikasi Amazon,, AWS CloudFormation, Amazon Connect Customer CloudFront AWS CodeArtifact AWS CodeBuild,, Amazon, AWS Identity and Access Management (IAM) AWS Glue GuardDuty, Amazon Inspector,,, AWS IoT AWS IoT TwinMaker AWS IoT Wireless, Amazon Managed Streaming untuk Apache Kafka, Amazon Macie,,,, Amazon Route 53 AWS Elemental MediaConnect AWS Network Manager AWS Organizations AWS Penjelajah Sumber Daya, Amazon Simple Storage Service (Amazon S3), Amazon Simple Notification Service (Amazon SNS), dan Amazon EC2 Systems Manager (SSM).

28 Juli 2023
AWS_ConfigRole— Tambah "amplify:GetBranch", "amplify:ListBranches", "app-integrations:GetEventIntegration", "app-integrations:ListEventIntegrationAssociations", "app-integrations:ListEventIntegrations", "appmesh:DescribeRoute", "appmesh:ListRoutes", "aps:ListRuleGroupsNamespaces", "athena:GetPreparedStatement", "athena:ListPreparedStatements", "batch:DescribeSchedulingPolicies", "batch:ListSchedulingPolicies", "cloudformation:ListTypes", "cloudtrail:ListTrails", "codeartifact:ListDomains", "codeguru-profiler:DescribeProfilingGroup", "codeguru-profiler:GetNotificationConfiguration", "codeguru-profiler:GetPolicy", "codeguru-profiler:ListProfilingGroups", "ds:DescribeDomainControllers", “dynamodb:DescribeTableReplicaAutoScaling" "dynamodb:DescribeTimeToLive", "ec2:DescribeTrafficMirrorFilters", "evidently:GetLaunch", "evidently:ListLaunches", "forecast:DescribeDatasetGroup", "forecast:ListDatasetGroups", "greengrass:DescribeComponent", "greengrass:GetComponent", "greengrass:ListComponents", "greengrass:ListComponentVersions", "groundstation:GetMissionProfile", "groundstation:ListMissionProfiles", "iam:ListGroups", "iam:ListRoles", "kafka:DescribeConfiguration", "kafka:DescribeConfigurationRevision", "kafka:ListConfigurations", "lightsail:GetRelationalDatabases" "logs:ListTagsLogGroup", "mediaconnect:DescribeFlow", "mediaconnect:ListFlows", "mediatailor:GetPlaybackConfiguration", "mediatailor:ListPlaybackConfigurations", "mobiletargeting:GetApplicationSettings", "mobiletargeting:GetEmailTemplate", "mobiletargeting:GetEventStream", "mobiletargeting:ListTemplates", "networkmanager:GetCustomerGatewayAssociations", "networkmanager:GetLinkAssociations", "organizations:DescribeAccount", "organizations:DescribeOrganizationalUnit", "organizations:ListAccounts", "organizations:ListAccountsForParent", "organizations:ListOrganizationalUnitsForParent", "organizations:ListTagsForResource", "personalize:DescribeDataset", "personalize:DescribeDatasetGroup", "personalize:DescribeSchema", "personalize:DescribeSolution", "personalize:ListDatasetGroups", "personalize:ListDatasetImportJobs", "personalize:ListDatasets", "personalize:ListSchemas", "personalize:ListSolutions", "personalize:ListTagsForResource", "quicksight:ListTemplates", "refactor-spaces:GetEnvironment", "refactor-spaces:GetService", "refactor-spaces:ListApplications", "refactor-spaces:ListEnvironments", "refactor-spaces:ListServices", "s3:GetAccessPointPolicyStatusForObjectLambda", "sagemaker:DescribeDeviceFleet", "sagemaker:DescribeFeatureGroup", "sagemaker:ListDeviceFleets", "sagemaker:ListFeatureGroups", "sagemaker:ListModels", and "transfer:ListTagsForResource"

Kebijakan ini sekarang mendukung izin tambahan untuk AWS Amplify, Amazon Connect Customer, AWS App Mesh, Amazon Managed Service untuk Prometheus, Amazon Athena,,,, Amazon, AWS Batch, Amazon AWS CloudFormation, AWS CloudTrail AWS CodeArtifact, Amazon DynamoDB CodeGuru AWS Directory Service, Amazon Elastic Compute Cloud (Amazon EC2), Amazon E CloudWatch vidently,, Amazon Forecast,,, AWS Identity and Access Management (IAM) AWS Organizations AWS IoT Greengrass AWS Ground Station, Amazon Managed Streaming untuk Apache Kafka (Amazon MSK), Amazon Lightsail, Amazon Logs,, Amazon Cloud Pinpoint, Amazon Virtual Private ( CloudWatch AWS Elemental MediaConnect AWS Elemental MediaTailor Amazon VPC), Personalisasi Amazon, Amazon Cepat, AWS Migration Hub Refactor Spaces, Layanan Penyimpanan Sederhana Amazon (Amazon S3), Amazon SageMaker AI, AWS Transfer Family.

13 Juni 2023
AWSConfigServiceRolePolicy— Tambah "amplify:GetBranch", "amplify:ListBranches", "app-integrations:GetEventIntegration", "app-integrations:ListEventIntegrationAssociations", "app-integrations:ListEventIntegrations", "appmesh:DescribeRoute", "appmesh:ListRoutes", "aps:ListRuleGroupsNamespaces", "athena:GetPreparedStatement", "athena:ListPreparedStatements", "batch:DescribeSchedulingPolicies", "batch:ListSchedulingPolicies", "cloudformation:ListTypes", "cloudtrail:ListTrails", "codeartifact:ListDomains", "codeguru-profiler:DescribeProfilingGroup", "codeguru-profiler:GetNotificationConfiguration", "codeguru-profiler:GetPolicy", "codeguru-profiler:ListProfilingGroups", "ds:DescribeDomainControllers", "dynamodb:DescribeTableReplicaAutoScaling", "dynamodb:DescribeTimeToLive", "ec2:DescribeTrafficMirrorFilters", "evidently:GetLaunch", "evidently:ListLaunches", "forecast:DescribeDatasetGroup", "forecast:ListDatasetGroups", "greengrass:DescribeComponent", "greengrass:GetComponent", "greengrass:ListComponents", "greengrass:ListComponentVersions", "groundstation:GetMissionProfile", "groundstation:ListMissionProfiles", "iam:ListGroups", "iam:ListRoles", "kafka:DescribeConfiguration", "kafka:DescribeConfigurationRevision", "kafka:ListConfigurations", "lightsail:GetRelationalDatabases", "logs:ListTagsLogGroup", "mediaconnect:DescribeFlow", "mediaconnect:ListFlows", "mediatailor:GetPlaybackConfiguration", "mediatailor:ListPlaybackConfigurations", "mobiletargeting:GetApplicationSettings", "mobiletargeting:GetEmailTemplate", "mobiletargeting:GetEventStream", "mobiletargeting:ListTemplates", "networkmanager:GetCustomerGatewayAssociations", "networkmanager:GetLinkAssociations", "organizations:DescribeAccount", "organizations:DescribeOrganizationalUnit", "organizations:ListAccounts", "organizations:ListAccountsForParent", "organizations:ListOrganizationalUnitsForParent", "organizations:ListTagsForResource", "personalize:DescribeDataset", "personalize:DescribeDatasetGroup", "personalize:DescribeSchema", "personalize:DescribeSolution", "personalize:ListDatasetGroups", "personalize:ListDatasetImportJobs", "personalize:ListDatasets", "personalize:ListSchemas", "personalize:ListSolutions", "personalize:ListTagsForResource", "quicksight:ListTemplates", "refactor-spaces:GetEnvironment", "refactor-spaces:GetService", "refactor-spaces:ListApplications", "refactor-spaces:ListEnvironments", "refactor-spaces:ListServices", "s3:GetAccessPointPolicyStatusForObjectLambda", "sagemaker:DescribeDeviceFleet", "sagemaker:DescribeFeatureGroup", "sagemaker:ListDeviceFleets", "sagemaker:ListFeatureGroups", "sagemaker:ListModels", and "transfer:ListTagsForResource"

Kebijakan ini sekarang mendukung izin tambahan untuk AWS Amplify, Amazon Connect Customer, AWS App Mesh, Amazon Managed Service untuk Prometheus, Amazon Athena,,,, Amazon, AWS Batch, Amazon AWS CloudFormation, AWS CloudTrail AWS CodeArtifact, Amazon DynamoDB CodeGuru AWS Directory Service, Amazon Elastic Compute Cloud (Amazon EC2), Amazon E CloudWatch vidently,, Amazon Forecast,,, AWS Identity and Access Management (IAM) AWS Organizations AWS IoT Greengrass AWS Ground Station, Amazon Managed Streaming untuk Apache Kafka (Amazon MSK), Amazon Lightsail, Amazon Logs,, Amazon Cloud Pinpoint, Amazon Virtual Private ( CloudWatch AWS Elemental MediaConnect AWS Elemental MediaTailor Amazon VPC), Personalisasi Amazon, Amazon Cepat, AWS Migration Hub Refactor Spaces, Layanan Penyimpanan Sederhana Amazon (Amazon S3), Amazon SageMaker AI, AWS Transfer Family.

13 Juni 2023
AWSConfigServiceRolePolicy— Tambah amplify:GetApp, amplify:ListApps, appmesh:DescribeVirtualGateway, appmesh:DescribeVirtualNode, appmesh:DescribeVirtualRouter, appmesh:DescribeVirtualService, appmesh:ListMeshes, appmesh:ListTagsForResource, appmesh:ListVirtualGateways, appmesh:ListVirtualNodes, appmesh:ListVirtualRouters, appmesh:ListVirtualServices, apprunner:DescribeVpcConnector, apprunner:ListVpcConnectors, cloudformation:ListTypes, cloudfront:ListResponseHeadersPolicies, codeartifact:ListRepositories, ds:DescribeEventTopics, ds:ListLogSubscriptions, GetInstanceTypesFromInstanceRequirement ec2:GetManagedPrefixListEntries, kendra:DescribeIndex, kendra:ListIndices, kendra:ListTagsForResource, logs:DescribeDestinations, logs:GetDataProtectionPolicy, macie2:DescribeOrganizationConfiguration, macie2:GetAutomatedDiscoveryConfiguration, macie2:GetClassificationExportConfiguration, macie2:GetCustomDataIdentifier, macie2:GetFindingsPublicationConfiguration, macie2:ListCustomDataIdentifiers, mobiletargeting:GetEmailChannel, refactor-spaces:GetEnvironment, refactor-spaces:ListEnvironments, resiliencehub:ListTagsForResource, route53:GetDNSSEC, sagemaker:DescribeDomain, sagemaker:DescribeModelBiasJobDefinition, sagemaker:DescribeModelQualityJobDefinition, sagemaker:DescribePipeline, sagemaker:DescribeProject, sagemaker:ListDomains, sagemaker:ListModelBiasJobDefinitions, sagemaker:ListModelQualityJobDefinitions, sagemaker:ListPipelines, sagemaker:ListProjects, transfer:DescribeAgreement, transfer:DescribeCertificate, transfer:ListAgreements, transfer:ListCertificates, and waf-regional:ListLoggingConfigurations

Kebijakan ini sekarang mendukung izin tambahan untuk Alur Kerja Terkelola Amazon untuk AWS Amplify, AWS App Mesh, Amazon AWS App Runner, CloudFront AWS CodeArtifact, Amazon Elastic Compute Cloud, Amazon Kendra, Amazon Macie, Amazon Route 53, Amazon SageMaker AI,, Amazon Pinpoint, AWS Transfer Family, Resilience Hub, Amazon AWS Migration Hub, AWS Directory Service CloudWatch, AWS dan. AWS WAF

13 April 2023
AWS_ConfigRole— Tambah amplify:GetApp, amplify:ListApps, appmesh:DescribeVirtualGateway, appmesh:DescribeVirtualNode, appmesh:DescribeVirtualRouter, appmesh:DescribeVirtualService, appmesh:ListMeshes, appmesh:ListTagsForResource, appmesh:ListVirtualGateways, appmesh:ListVirtualNodes, appmesh:ListVirtualRouters, appmesh:ListVirtualServices, apprunner:DescribeVpcConnector, apprunner:ListVpcConnectors, cloudformation:ListTypes, cloudfront:ListResponseHeadersPolicies, codeartifact:ListRepositories, ds:DescribeEventTopics, ds:ListLogSubscriptions, ec2:GetInstanceTypesFromInstanceRequirement, ec2:GetManagedPrefixListEntries, kendra:DescribeIndex, kendra:ListIndices, kendra:ListTagsForResource, logs:DescribeDestinations, logs:GetDataProtectionPolicy, macie2:DescribeOrganizationConfiguration, macie2:GetAutomatedDiscoveryConfiguration, macie2:GetClassificationExportConfiguration, macie2:GetCustomDataIdentifier, macie2:GetFindingsPublicationConfiguration, macie2:ListCustomDataIdentifiers, mobiletargeting:GetEmailChannel, refactor-spaces:GetEnvironment, refactor-spaces:ListEnvironments, resiliencehub:ListTagsForResource, route53:GetDNSSEC, sagemaker:DescribeDomain, sagemaker:DescribeModelBiasJobDefinition, sagemaker:DescribeModelQualityJobDefinition, sagemaker:DescribePipeline, sagemaker:DescribeProject, sagemaker:ListDomains, sagemaker:ListModelBiasJobDefinitions, sagemaker:ListModelQualityJobDefinitions, sagemaker:ListPipelines, sagemaker:ListProjects, transfer:DescribeAgreement, transfer:DescribeCertificate, transfer:ListAgreements, transfer:ListCertificates, and waf-regional:ListLoggingConfigurations

Kebijakan ini sekarang mendukung izin tambahan untuk Alur Kerja Terkelola Amazon untuk AWS Amplify, AWS App Mesh, Amazon AWS App Runner, CloudFront AWS CodeArtifact, Amazon Elastic Compute Cloud, Amazon Kendra, Amazon Macie, Amazon Route 53, Amazon SageMaker AI,, Amazon Pinpoint, AWS Transfer Family, Resilience Hub, Amazon AWS Migration Hub, AWS Directory Service CloudWatch, AWS dan. AWS WAF

13 April 2023
AWSConfigServiceRolePolicy— Tambah appflow:DescribeFlow, appflow:ListFlows, appflow:ListTagsForResource, apprunner:DescribeService, apprunner:ListServices, apprunner:ListTagsForResource, appstream:DescribeApplications, appstream:DescribeFleets, cloudfront:GetResponseHeadersPolicy, cloudwatch:ListTagsForResource, codeartifact:DescribeRepository, codeartifact:GetRepositoryPermissionsPolicy, codeartifact:ListTagsForResource, codecommit:GetRepository, codecommit:GetRepositoryTriggers, codecommit:ListRepositories, codecommit:ListTagsForResource, devicefarm:GetInstanceProfile, devicefarm:ListInstanceProfiles, devicefarm:ListProjects, evidently:GetProject, evidently:ListProjects, evidently:ListTagsForResource, forecast:DescribeDataset, forecast:ListDatasets, forecast:ListTagsForResource, groundstation:GetConfig, groundstation:ListConfigs, groundstation:ListTagsForResource, iam:GetInstanceProfile, iam:GetSAMLProvider, iam:GetServerCertificate, iam:ListAccessKeys, iam:ListGroups, iam:ListInstanceProfiles, iam:ListMFADevices, iam:ListMFADeviceTags, iam:ListRoles, iam:ListSAMLProviders, iot:DescribeFleetMetric, iot:ListFleetMetrics, memorydb:DescribeUsers, memorydb:ListTags, mobiletargeting:GetApp, mobiletargeting:GetCampaigns, networkmanager:GetDevices, networkmanager:GetLinks, networkmanager:GetSites, panorama:ListNodes, rds:DescribeDBProxyEndpoints, redshift:DescribeScheduledActions, sagemaker:DescribeAppImageConfig, sagemaker:DescribeImage, sagemaker:DescribeImageVersion, sagemaker:ListAppImageConfigs, sagemaker:ListImages, and sagemaker:ListImageVersions

Kebijakan ini sekarang mendukung izin tambahan untuk Alur Kerja Terkelola Amazon untuk Amazon AppFlow, AWS App Runner, WorkSpaces Aplikasi Amazon, Amazon, CloudFront,, CloudWatch AWS CodeArtifact, Amazon CloudWatch Evidently AWS CodeCommit AWS Device Farm, Amazon Forecast,, AWS Identity and Access Management (IAM) AWS Ground Station,, Amazon MemoryDB AWS IoT, Amazon Pinpoint,,, Amazon Relational Database Service (Amazon RDS) AWS Network Manager AWS Panorama, Amazon Redshift, dan Amazon AI. SageMaker

30 Maret 2023
AWS_ConfigRole— Tambah appflow:DescribeFlow, appflow:ListFlows, appflow:ListTagsForResource, apprunner:DescribeService, apprunner:ListServices, apprunner:ListTagsForResource, appstream:DescribeApplications, appstream:DescribeFleets, cloudformation:ListTypes, cloudfront:GetResponseHeadersPolicy, cloudfront:ListDistributions, cloudwatch:ListTagsForResource, codeartifact:DescribeRepository, codeartifact:GetRepositoryPermissionsPolicy, codeartifact:ListTagsForResource, codecommit:GetRepository, codecommit:GetRepositoryTriggers, codecommit:ListRepositories, codecommit:ListTagsForResource, devicefarm:GetInstanceProfile, devicefarm:ListInstanceProfiles, devicefarm:ListProjects, ec2:DescribeTrafficMirrorFilters, evidently:GetProject, evidently:ListProjects, evidently:ListTagsForResource, forecast:DescribeDataset, forecast:ListDatasets, forecast:ListTagsForResource, groundstation:GetConfig, groundstation:ListConfigs, groundstation:ListTagsForResource, iam:GetInstanceProfile, iam:GetSAMLProvider, iam:GetServerCertificate, iam:ListAccessKeys, iam:ListGroups, iam:ListInstanceProfiles, iam:ListMFADevices, iam:ListMFADeviceTags, iam:ListRoles, iam:ListSAMLProviders, iot:DescribeFleetMetric, iot:ListFleetMetrics, memorydb:DescribeUsers, memorydb:ListTags, mobiletargeting:GetApp, mobiletargeting:GetCampaigns, networkmanager:GetDevices, networkmanager:GetLinks, networkmanager:GetSites, panorama:ListNodes, rds:DescribeDBProxyEndpoints, redshift:DescribeScheduledActions, sagemaker:DescribeAppImageConfig, sagemaker:DescribeImage, sagemaker:DescribeImageVersion, sagemaker:ListAppImageConfigs, sagemaker:ListImages, and sagemaker:ListImageVersions

Kebijakan ini sekarang mendukung izin tambahan untuk Alur Kerja Terkelola Amazon untuk Amazon AppFlow, AWS App Runner, WorkSpaces Aplikasi Amazon,, Amazon AWS CloudFormation,, CloudFront, CloudWatch AWS CodeArtifact AWS CodeCommit AWS Device Farm, Amazon Elastic Compute Cloud (Amazon EC2), Amazon E CloudWatch vidently, Amazon Forecast,, AWS Identity and Access Management (IAM), AWS Ground Station, Amazon MemoryDB, Amazon Pinpoint AWS IoT,,, Amazon Relational Database Service (Amazon RDS) AWS Network Manager AWS Panorama, Amazon Redshift, dan Amazon AI. SageMaker

30 Maret 2023

AWSConfigRulesExecutionRole— AWS Config mulai melacak perubahan untuk kebijakan terkel AWS ola ini

Kebijakan ini memungkinkan AWS Lambda fungsi mengakses AWS Config API dan snapshot konfigurasi yang dikirimkan secara ber AWS Config kala ke Amazon S3. Akses ini diperlukan oleh fungsi yang mengevaluasi perubahan konfigurasi untuk aturan Lambda K AWS ustom.

7 Maret 2023

AWSConfigRoleForOrganizations— AWS Config mulai melacak perubahan untuk kebijakan terkel AWS ola ini

Kebijakan ini memungkinkan AWS Config untuk memanggil API read-only AWS Organizations .

7 Maret 2023

AWSConfigRemediationServiceRolePolicy— AWS Config mulai melacak perubahan untuk kebijakan terkel AWS ola ini

Kebijakan ini memungkinkan AWS Config untuk memperbaiki sumber NON_COMPLIANT daya atas nama Anda.

7 Maret 2023

AWSConfigServiceRolePolicy— Tambah auditmanager:GetAccountStatus

Kebijakan ini sekarang memberikan izin untuk mengembalikan status pendaftaran akun di AWS Audit Manager.

3 Maret 2023

AWS_ConfigRole— Tambah auditmanager:GetAccountStatus

Kebijakan ini sekarang memberikan izin untuk mengembalikan status pendaftaran akun di AWS Audit Manager.

3 Maret 2023

AWSConfigMultiAccountSetupPolicy— AWS Config mulai melacak perubahan untuk kebijakan terkel AWS ola ini

Kebijakan ini memungkinkan AWS Config untuk memanggil AWS layanan dan menyebarkan AWS Config sumber daya di seluruh organisasi dengan AWS Organizations.

27 Februari 2023

AWSConfigServiceRolePolicy— Tambah airflow:ListTagsForResource, iot:ListCustomMetrics, iot:DescribeCustomMetric, appstream:DescribeDirectoryConfigs, appstream:ListTagsForResource, codeguru-reviewer:DescribeRepositoryAssociation, codeguru-reviewer:ListRepositoryAssociations, healthlake:ListFHIRDatastores, healthlake:DescribeFHIRDatastore, healthlake:ListTagsForResource, kinesisvideo:DescribeStream, kinesisvideo:ListStreams, kinesisvideo:ListTagsForStream, kinesisvideo:DescribeSignalingChannel, kinesisvideo:ListTagsForResource, kinesisvideo:ListSignalingChannels, route53-recovery-control-config:DescribeCluster, route53-recovery-control-config:DescribeRoutingControl, route53-recovery-control-config:DescribeSafetyRule, route53-recovery-control-config:ListClusters, route53-recovery-control-config:ListRoutingControls, route53-recovery-control-config:ListSafetyRules, devicefarm:GetTestGridProject, devicefarm:ListTestGridProjects, ec2:DescribeCapacityReservationFleets, ec2:DescribeIpamPools, ec2:DescribeIpams, ec2:GetInstanceTypesFromInstanceRequirement, mobiletargeting:GetApplicationSettings, mobiletargeting:ListTagsForResource, ecr:BatchGetRepositoryScanningConfiguration, iam:ListServerCertificates, guardduty:ListPublishingDestinations, guardduty:DescribePublishingDestination, logs:GetLogDelivery, and logs:ListLogDeliveries

Kebijakan ini sekarang mendukung izin tambahan untuk Alur Kerja Terkelola Amazon untuk Apache Airflow AWS IoT,, WorkSpaces Aplikasi Amazon, Amazon CodeGuru Reviewer AWS HealthLake, Amazon Kinesis Video Streams, Amazon Application Recovery Controller (ARC) AWS Device Farm, Amazon Elastic Compute Cloud (Amazon EC2), Amazon Pinpoint, AWS Identity and Access Management (IAM), Amazon, dan Amazon Logs. GuardDuty CloudWatch

1 Februari 2023

AWS_ConfigRole— Tambah airflow:ListTagsForResource, iot:ListCustomMetrics, iot:DescribeCustomMetric, appstream:DescribeDirectoryConfigs, appstream:ListTagsForResource, codeguru-reviewer:DescribeRepositoryAssociation, codeguru-reviewer:ListRepositoryAssociations, healthlake:ListFHIRDatastores, healthlake:DescribeFHIRDatastore, healthlake:ListTagsForResource, kinesisvideo:DescribeStream, kinesisvideo:ListStreams, kinesisvideo:ListTagsForStream, kinesisvideo:DescribeSignalingChannel, kinesisvideo:ListTagsForResource, kinesisvideo:ListSignalingChannels, route53-recovery-control-config:DescribeCluster, route53-recovery-control-config:DescribeRoutingControl, route53-recovery-control-config:DescribeSafetyRule, route53-recovery-control-config:ListClusters, route53-recovery-control-config:ListRoutingControls, route53-recovery-control-config:ListSafetyRules, devicefarm:GetTestGridProject, devicefarm:ListTestGridProjects, ec2:DescribeCapacityReservationFleets, ec2:DescribeIpamPools, ec2:DescribeIpams, ec2:GetInstanceTypesFromInstanceRequirement, mobiletargeting:GetApplicationSettings, mobiletargeting:ListTagsForResource, ecr:BatchGetRepositoryScanningConfiguration, iam:ListServerCertificates, guardduty:ListPublishingDestinations, guardduty:DescribePublishingDestination, logs:GetLogDelivery, and logs:ListLogDeliveries

Kebijakan ini sekarang mendukung izin tambahan untuk Alur Kerja Terkelola Amazon untuk Apache Airflow AWS IoT,, WorkSpaces Aplikasi Amazon, Amazon CodeGuru Reviewer AWS HealthLake, Amazon Kinesis Video Streams, Amazon Application Recovery Controller (ARC) AWS Device Farm, Amazon Elastic Compute Cloud (Amazon EC2), Amazon Pinpoint, AWS Identity and Access Management (IAM), Amazon, dan Amazon Logs. GuardDuty CloudWatch

1 Februari 2023

ConfigConformsServiceRolePolicy— Perbarui config:DescribeConfigRules

Sebagai praktik terbaik keamanan, kebijakan ini sekarang menghapus izin tingkat sumber daya yang luas untuk. config:DescribeConfigRules

Januari 12, 2023

AWSConfigServiceRolePolicy— Tambah APS:DescribeRuleGroupsNamespace, APS:DescribeWorkspace, APS:ListWorkspaces, auditmanager:GetAssessment, auditmanager:ListAssessments, devicefarm:GetNetworkProfile, AWS Transfer Family devicefarm:GetProject, devicefarm:ListNetworkProfiles, devicefarm:ListTagsForResource, dms:DescribeEndpoints, ds:ListTagsForResource, ec2:DescribeTags, ec2:DescribeTrafficMirrorSessions, ec2:DescribeTrafficMirrorTargets, ec2:GetIpamPoolAllocations, ec2:GetIpamPoolCidrs, glue:GetMLTransform, glue:GetMLTransforms, glue:ListMLTransforms, iot:DescribeScheduledAudit, iot:ListScheduledAudits, ivs:GetChannel, lightsail:GetRelationalDatabases, mediapackage-vod:DescribePackagingConfiguration, mediapackage-vod:ListPackagingConfigurations, networkmanager:DescribeGlobalNetworks, networkmanager:GetTransitGatewayRegistrations, networkmanager:ListTagsForResource, quicksight:DescribeDashboard, quicksight:DescribeDashboardPermissions, quicksight:DescribeTemplate, quicksight:DescribeTemplatePermissions, quicksight:ListDashboards, quicksight:ListTemplates, ram:ListResources, route53-recovery-control-config:DescribeControlPanel, route53-recovery-control-config:ListControlPanels, route53-recovery-control-config:ListTagsForResource, route53resolver:GetResolverQueryLogConfigAssociation, route53resolver:ListResolverQueryLogConfigAssociations, s3:GetAccessPointForObjectLambda, s3:GetAccessPointPolicyForObjectLambda, s3:GetAccessPointPolicyStatusForObjectLambda, s3:GetMultiRegionAccessPoint, s3:ListAccessPointsForObjectLambda, s3:ListMultiRegionAccessPoints, timestream:DescribeEndpoints, transfer:DescribeConnector, transfer:ListConnectors, and transfer:ListTagsForResource

Kebijakan ini sekarang mendukung izin tambahan untuk Layanan Terkelola Amazon untuk Prometheus,, AWS Audit Manager, AWS Database Migration Service (AWS DMS) AWS Device Farm, AWS Directory Service, Amazon Elastic Compute Cloud (Amazon EC2),,, Amazon Lightsail AWS Glue, AWS IoT, Amazon Quick, AWS Elemental MediaPackage AWS Network Manager, Amazon Application Recovery Controller (ARC) AWS Resource Access Manager, Amazon Simple Storage Service (Amazon S3), dan Amazon Timestream.

Desember 15, 2022

AWS_ConfigRole— Tambah APS:DescribeRuleGroupsNamespace, APS:DescribeWorkspace, APS:ListWorkspaces, auditmanager:GetAssessment, auditmanager:ListAssessments, devicefarm:GetNetworkProfile, devicefarm:GetProject, devicefarm:ListNetworkProfiles, devicefarm:ListTagsForResource, dms:DescribeEndpoints, ds:ListTagsForResource, ec2:DescribeTags, ec2:DescribeTrafficMirrorSessions, ec2:DescribeTrafficMirrorTargets, ec2:GetIpamPoolAllocations, ec2:GetIpamPoolCidrs, glue:GetMLTransform, glue:GetMLTransforms, glue:ListMLTransforms, iot:DescribeScheduledAudit, iot:ListScheduledAudits, ivs:GetChannel, lightsail:GetRelationalDatabases, mediapackage-vod:DescribePackagingConfiguration, mediapackage-vod:ListPackagingConfigurations, networkmanager:DescribeGlobalNetworks, networkmanager:GetTransitGatewayRegistrations, networkmanager:ListTagsForResource, quicksight:DescribeDashboard, quicksight:DescribeDashboardPermissions, quicksight:DescribeTemplate, quicksight:DescribeTemplatePermissions, quicksight:ListDashboards, quicksight:ListTemplates, ram:ListResources, route53-recovery-control-config:DescribeControlPanel, route53-recovery-control-config:ListControlPanels, route53-recovery-control-config:ListTagsForResource, route53resolver:GetResolverQueryLogConfigAssociation, route53resolver:ListResolverQueryLogConfigAssociations, s3:GetAccessPointForObjectLambda, s3:GetAccessPointPolicyForObjectLambda, s3:GetAccessPointPolicyStatusForObjectLambda, s3:GetMultiRegionAccessPoint, s3:ListAccessPointsForObjectLambda, s3:ListMultiRegionAccessPoints, timestream:DescribeEndpoints, transfer:DescribeConnector, transfer:ListConnectors, and transfer:ListTagsForResource

Kebijakan ini sekarang mendukung izin tambahan untuk Layanan Terkelola Amazon untuk Prometheus,, AWS Audit Manager, AWS Database Migration Service (AWS DMS) AWS Device Farm, AWS Directory Service, Amazon Elastic Compute Cloud (Amazon EC2),,, Amazon Lightsail AWS Glue, AWS IoT, Amazon Quick, AWS Elemental MediaPackage AWS Network Manager, Amazon Application Recovery Controller (ARC) AWS Resource Access Manager, Amazon Simple Storage Service (Amazon S3), dan Amazon Timestream.

Desember 15, 2022

AWSConfigServiceRolePolicy— Tambah cloudformation:ListStackResources and cloudformation:ListStacks

Kebijakan ini sekarang memberikan izin untuk mengembalikan deskripsi semua sumber daya dari AWS CloudFormation tumpukan tertentu dan mengembalikan informasi ringkasan untuk tumpukan yang statusnya cocok dengan yang ditentukanStackStatusFilter.

7 November 2022

AWS_ConfigRole— Tambah cloudformation:ListStackResources and cloudformation:ListStacks

Kebijakan ini sekarang memberikan izin untuk mengembalikan deskripsi semua sumber daya dari AWS CloudFormation tumpukan tertentu dan mengembalikan informasi ringkasan untuk tumpukan yang statusnya cocok dengan yang ditentukanStackStatusFilter.

7 November 2022

AWSConfigServiceRolePolicy— Tambah acm-pca:GetCertificateAuthorityCsr, acm-pca:ListCertificateAuthorities, acm-pca:ListTags, airflow:GetEnvironment, airflow:ListEnvironments, amplifyuibuilder:ListThemes, appconfig:ListConfigurationProfiles, appconfig:ListDeployments, appconfig:ListDeploymentStrategies, appconfig:ListEnvironments, appconfig:ListHostedConfigurationVersions, cassandra:Select, cloudwatch:DescribeAnomalyDetectors, cloudwatch:GetDashboard, cloudwatch:ListDashboards, connect:DescribePhoneNumber, connect:ListPhoneNumbers, connect:ListPhoneNumbersV2, connect:SearchAvailablePhoneNumbers, databrew:DescribeDataset, databrew:DescribeJob, databrew:DescribeProject, databrew:DescribeRecipe, databrew:DescribeRuleset, databrew:DescribeSchedule, databrew:ListDatasets, databrew:ListJobs, databrew:ListProjects, databrew:ListRecipes, databrew:ListRecipeVersions, databrew:ListRulesets, databrew:ListSchedules, ec2:DescribeRouteTables, eks:DescribeAddon, eks:DescribeIdentityProviderConfig, eks:ListAddons, eks:ListIdentityProviderConfigs, events:DescribeConnection, events:ListApiDestinations, events:ListConnections, fis:GetExperimentTemplate, fis:ListExperimentTemplates, frauddetector:GetRules, fsx:DescribeBackups, fsx:DescribeSnapshots, fsx:DescribeStorageVirtualMachines, gamelift:DescribeMatchmakingRuleSets, gamelift:DescribeVpcPeeringConnections, geo:ListGeofenceCollections, geo:ListPlaceIndexes, geo:ListRouteCalculators, geo:ListTrackers, iot:DescribeAccountAuditConfiguration, iot:DescribeAuthorizer, iot:DescribeDomainConfiguration, iot:DescribeMitigationAction, iot:ListAuthorizers, iot:ListDomainConfigurations, iot:ListMitigationActions, iotsitewise:DescribeAssetModel, iotsitewise:DescribeDashboard, iotsitewise:DescribeGateway, iotsitewise:DescribePortal, iotsitewise:DescribeProject, iotsitewise:ListAssetModels, iotsitewise:ListDashboards, iotsitewise:ListGateways, iotsitewise:ListPortals, iotsitewise:ListProjectAssets, iotsitewise:ListProjects, iotsitewise:ListTagsForResource, iotwireless:GetServiceProfile, iotwireless:GetWirelessDevice, iotwireless:GetWirelessGatewayTaskDefinition, iotwireless:ListServiceProfiles, iotwireless:ListTagsForResource, iotwireless:ListWirelessDevices, iotwireless:ListWirelessGatewayTaskDefinitions, lex:DescribeBotVersion, lex:ListBotVersions, lightsail:GetContainerServices, lightsail:GetDistributions, lightsail:GetRelationalDatabase, lightsail:GetRelationalDatabaseParameters, mobiletargeting:GetApps, mobiletargeting:GetCampaign, mobiletargeting:GetSegment, mobiletargeting:GetSegments, opsworks:DescribeInstances, opsworks:DescribeTimeBasedAutoScaling, opsworks:DescribeVolumes, panorama:DescribeApplicationInstance, panorama:DescribeApplicationInstanceDetails, panorama:DescribePackage, panorama:DescribePackageVersion, panorama:ListApplicationInstances, panorama:ListPackages, quicksight:ListDataSources, ram:ListResourceSharePermissions, rds:DescribeDBProxies, rds:DescribeGlobalClusters, rekognition:ListStreamProcessors, resource-groups:GetGroup, resource-groups:GetGroupConfiguration, resource-groups:GetGroupQuery, resource-groups:GetTags, resource-groups:ListGroupResources, resource-groups:ListGroups, robomaker:ListRobotApplications, robomaker:ListSimulationApplications, route53resolver:GetResolverDnssecConfig, route53resolver:ListResolverDnssecConfigs, s3:ListStorageLensConfigurations, schemas:GetResourcePolicy, servicediscovery:ListInstances, sts:GetCallerIdentity, synthetics:GetGroup, synthetics:ListAssociatedGroups, synthetics:ListGroupResources, and synthetics:ListGroups

Kebijakan ini sekarang mendukung izin tambahan untuk AWS Certificate Manager, Alur Kerja Terkelola Amazon untuk Apache Airflow, AWS Amplify AWS AppConfig, Amazon Keyspaces, Amazon, Connect Customer CloudWatch, AWS Glue DataBrew, Amazon Elastic Compute Cloud (Amazon EC2), Amazon Elastic Kubernetes Service (Amazon EKS), Amazon,, Amazon Fraud Detector EventBridge AWS Fault Injection Service, Amazon FSx, Amazon GameLift Servers, Amazon Location Service,, Amazon Lex, Amazon Lightsail AWS IoT, Amazon Pinpoint,,, Amazon Quick, Amazon Relational Database Service (Amazon) RDS) OpsWorks AWS Panorama AWS Resource Access Manager, Amazon Rekognition,, AWS RoboMaker AWS Resource Groups, Amazon Route 53, Layanan Penyimpanan Sederhana Amazon (Amazon S3), AWS Cloud Map, dan. AWS Security Token Service

Oktober 19, 2022

AWS_ConfigRole— Tambah acm-pca:GetCertificateAuthorityCsr, acm-pca:ListCertificateAuthorities, acm-pca:ListTags, airflow:GetEnvironment, airflow:ListEnvironments, amplifyuibuilder:ListThemes, appconfig:ListConfigurationProfiles, appconfig:ListDeployments, appconfig:ListDeploymentStrategies, appconfig:ListEnvironments, appconfig:ListHostedConfigurationVersions, cassandra:Select, cloudwatch:DescribeAnomalyDetectors, cloudwatch:GetDashboard, cloudwatch:ListDashboards, connect:DescribePhoneNumber, connect:ListPhoneNumbers, connect:ListPhoneNumbersV2, connect:SearchAvailablePhoneNumbers, databrew:DescribeDataset, databrew:DescribeJob, databrew:DescribeProject, databrew:DescribeRecipe, databrew:DescribeRuleset, databrew:DescribeSchedule, databrew:ListDatasets, databrew:ListJobs, databrew:ListProjects, databrew:ListRecipes, databrew:ListRecipeVersions, databrew:ListRulesets, databrew:ListSchedules, ec2:DescribeRouteTables, eks:DescribeAddon, eks:DescribeIdentityProviderConfig, eks:ListAddons, eks:ListIdentityProviderConfigs, events:DescribeConnection, events:ListApiDestinations, events:ListConnections, fis:GetExperimentTemplate, fis:ListExperimentTemplates, frauddetector:GetRules, fsx:DescribeBackups, fsx:DescribeSnapshots, fsx:DescribeStorageVirtualMachines, gamelift:DescribeMatchmakingRuleSets, gamelift:DescribeVpcPeeringConnections, geo:ListGeofenceCollections, geo:ListPlaceIndexes, geo:ListRouteCalculators, geo:ListTrackers, iot:DescribeAccountAuditConfiguration, iot:DescribeAuthorizer, iot:DescribeDomainConfiguration, iot:DescribeMitigationAction, iot:ListAuthorizers, iot:ListDomainConfigurations, iot:ListMitigationActions, iotsitewise:DescribeAssetModel, iotsitewise:DescribeDashboard, iotsitewise:DescribeGateway, iotsitewise:DescribePortal, iotsitewise:DescribeProject, iotsitewise:ListAssetModels, iotsitewise:ListDashboards, iotsitewise:ListGateways, iotsitewise:ListPortals, iotsitewise:ListProjectAssets, iotsitewise:ListProjects, iotsitewise:ListTagsForResource, iotwireless:GetServiceProfile, iotwireless:GetWirelessDevice, iotwireless:GetWirelessGatewayTaskDefinition, iotwireless:ListServiceProfiles, iotwireless:ListTagsForResource, iotwireless:ListWirelessDevices, iotwireless:ListWirelessGatewayTaskDefinitions, lex:DescribeBotVersion, lex:ListBotVersions, lightsail:GetContainerServices, lightsail:GetDistributions, lightsail:GetRelationalDatabase, lightsail:GetRelationalDatabaseParameters, mobiletargeting:GetApps, mobiletargeting:GetCampaign, mobiletargeting:GetSegment, mobiletargeting:GetSegments, opsworks:DescribeInstances, opsworks:DescribeTimeBasedAutoScaling, opsworks:DescribeVolumes, panorama:DescribeApplicationInstance, panorama:DescribeApplicationInstanceDetails, panorama:DescribePackage, panorama:DescribePackageVersion, panorama:ListApplicationInstances, panorama:ListPackages, quicksight:ListDataSources, ram:ListResourceSharePermissions, rds:DescribeDBProxies, rds:DescribeGlobalClusters, rekognition:ListStreamProcessors, resource-groups:GetGroup, resource-groups:GetGroupConfiguration, resource-groups:GetGroupQuery, resource-groups:GetTags, resource-groups:ListGroupResources, resource-groups:ListGroups, robomaker:ListRobotApplications, robomaker:ListSimulationApplications, route53resolver:GetResolverDnssecConfig, route53resolver:ListResolverDnssecConfigs, s3:ListStorageLensConfigurations, schemas:GetResourcePolicy, servicediscovery:ListInstances, sts:GetCallerIdentity, synthetics:GetGroup, synthetics:ListAssociatedGroups, synthetics:ListGroupResources, and synthetics:ListGroups

Kebijakan ini sekarang mendukung izin tambahan untuk AWS Certificate Manager, Alur Kerja Terkelola Amazon untuk Apache Airflow, AWS Amplify AWS AppConfig, Amazon Keyspaces, Amazon, Connect Customer CloudWatch, AWS Glue DataBrew, Amazon Elastic Compute Cloud (Amazon EC2), Amazon Elastic Kubernetes Service (Amazon EKS), Amazon,, Amazon Fraud Detector EventBridge AWS Fault Injection Service, Amazon FSx, Amazon GameLift Servers, Amazon Location Service,, Amazon Lex, Amazon Lightsail AWS IoT, Amazon Pinpoint,,, Amazon Quick, Amazon Relational Database Service (Amazon) RDS) OpsWorks AWS Panorama AWS Resource Access Manager, Amazon Rekognition,, AWS RoboMaker AWS Resource Groups, Amazon Route 53, Layanan Penyimpanan Sederhana Amazon (Amazon S3), AWS Cloud Map, dan. AWS Security Token Service

Oktober 19, 2022

AWSConfigServiceRolePolicy— Tambah Glue::GetTable

Kebijakan ini sekarang memberikan izin untuk mengambil definisi AWS Glue Tabel dalam Katalog Data untuk tabel tertentu.

14 September 2022

AWS_ConfigRole— Tambah Glue::GetTable

Kebijakan ini sekarang memberikan izin untuk mengambil definisi AWS Glue Tabel dalam Katalog Data untuk tabel tertentu.

14 September 2022

AWSConfigServiceRolePolicy— Tambah appconfig:ListApplications, appflow:DescribeConnectorProfiles, appsync:GetApiCache, autoscaling-plans:DescribeScalingPlanResources, autoscaling-plans:DescribeScalingPlans, autoscaling-plans:GetScalingPlanResourceForecastData, autoscaling:DescribeWarmPool, backup:DescribeFramework, backup:DescribeReportPlan, backup:ListFrameworks, backup:ListReportPlans, budgets:DescribeBudgetAction, budgets:DescribeBudgetActionsForAccount, budgets:DescribeBudgetActionsForBudget, budgets:ViewBudget, ce:GetAnomalyMonitors, ce:GetAnomalySubscriptions, cloud9:DescribeEnvironmentMemberships, cloud9:DescribeEnvironments, cloud9:ListEnvironments, cloud9:ListTagsForResource, cloudwatch:GetMetricStream, cloudwatch:ListMetricStreams, datasync:DescribeLocationFsxWindows, devops-guru:GetResourceCollection, ds:DescribeDirectories, ec2:DescribeTrafficMirrorFilters, ec2:DescribeTrafficMirrorTargets, ec2:GetNetworkInsightsAccessScopeAnalysisFindings, ec2:GetNetworkInsightsAccessScopeContent, elasticmapreduce:DescribeStudio, elasticmapreduce:GetStudioSessionMapping, elasticmapreduce:ListStudios, elasticmapreduce:ListStudioSessionMappings, events:DescribeEndpoint, events:DescribeEventBus, events:DescribeRule, events:ListArchives, events:ListEndpoints, events:ListEventBuses, events:ListRules, events:ListTagsForResource, events:ListTargetsByRule, finspace:GetEnvironment, finspace:ListEnvironments, frauddetector:GetDetectors, frauddetector:GetDetectorVersion, frauddetector:GetEntityTypes, frauddetector:GetEventTypes, frauddetector:GetExternalModels, frauddetector:GetLabels, frauddetector:GetModels, frauddetector:GetOutcomes, frauddetector:GetVariables, frauddetector:ListTagsForResource, gamelift:DescribeAlias, gamelift:DescribeBuild, gamelift:DescribeFleetAttributes, gamelift:DescribeFleetCapacity, gamelift:DescribeFleetLocationAttributes, gamelift:DescribeFleetLocationCapacity, gamelift:DescribeFleetPortSettings, gamelift:DescribeGameServerGroup, gamelift:DescribeGameSessionQueues, gamelift:DescribeMatchmakingConfigurations, gamelift:DescribeMatchmakingRuleSets, gamelift:DescribeRuntimeConfiguration, gamelift:DescribeScript, gamelift:DescribeVpcPeeringAuthorizations, gamelift:ListAliases, gamelift:ListBuilds, gamelift:ListFleets, gamelift:ListGameServerGroups, gamelift:ListScripts, gamelift:ListTagsForResource, geo:ListMaps, glue:GetClassifier, glue:GetClassifiers, imagebuilder:GetContainerRecipe, imagebuilder:GetImage, imagebuilder:GetImagePipeline, imagebuilder:GetImageRecipe, imagebuilder:ListContainerRecipes, imagebuilder:ListImageBuildVersions, imagebuilder:ListImagePipelines, imagebuilder:ListImageRecipes, imagebuilder:ListImages, iot:DescribeCertificate, iot:DescribeDimension, iot:DescribeRoleAlias, iot:DescribeSecurityProfile, iot:GetPolicy, iot:GetTopicRule, iot:GetTopicRuleDestination, iot:ListCertificates, iot:ListDimensions, iot:ListPolicies, iot:ListRoleAliases, iot:ListSecurityProfiles, iot:ListSecurityProfilesForTarget, iot:ListTagsForResource, iot:ListTargetsForSecurityProfile, iot:ListTopicRuleDestinations, iot:ListTopicRules, iot:ListV2LoggingLevels, iot:ValidateSecurityProfileBehaviors, iotanalytics:DescribeChannel, iotanalytics:DescribeDataset, iotanalytics:DescribeDatastore, iotanalytics:DescribePipeline, iotanalytics:ListChannels, iotanalytics:ListDatasets, iotanalytics:ListDatastores, iotanalytics:ListPipelines, iotanalytics:ListTagsForResource, iotevents:DescribeAlarmModel, iotevents:DescribeDetectorModel, iotevents:DescribeInput, iotevents:ListAlarmModels, iotevents:ListDetectorModels, iotevents:ListInputs, iotevents:ListTagsForResource, iotsitewise:DescribeAccessPolicy, iotsitewise:DescribeAsset, iotsitewise:ListAccessPolicies, iotsitewise:ListAssets, iottwinmaker:GetEntity, iottwinmaker:GetScene, iottwinmaker:GetWorkspace, iottwinmaker:ListEntities, iottwinmaker:ListScenes, iottwinmaker:ListTagsForResource, iottwinmaker:ListWorkspaces, ivs:GetPlaybackKeyPair, ivs:GetRecordingConfiguration, ivs:GetStreamKey, ivs:ListChannels, ivs:ListPlaybackKeyPairs, ivs:ListRecordingConfigurations, ivs:ListStreamKeys, ivs:ListTagsForResource, kinesisanalytics:ListApplications, lakeformation:DescribeResource, lakeformation:GetDataLakeSettings, lakeformation:ListPermissions, lakeformation:ListResources, lex:DescribeBot, lex:DescribeBotAlias, lex:DescribeResourcePolicy, lex:ListBotAliases, lex:ListBotLocales, lex:ListBots, lex:ListTagsForResource, license-manager:GetGrant, license-manager:GetLicense, license-manager:ListDistributedGrants, license-manager:ListLicenses, license-manager:ListReceivedGrants, lightsail:GetAlarms, lightsail:GetBuckets, lightsail:GetCertificates, lightsail:GetDisk, lightsail:GetDisks, lightsail:GetInstance, lightsail:GetInstances, lightsail:GetKeyPair, lightsail:GetLoadBalancer, lightsail:GetLoadBalancers, lightsail:GetLoadBalancerTlsCertificates, lightsail:GetStaticIp, lightsail:GetStaticIps, lookoutequipment:DescribeInferenceScheduler, lookoutequipment:ListTagsForResource, lookoutmetrics:DescribeAlert, lookoutmetrics:DescribeAnomalyDetector, lookoutmetrics:ListAlerts, lookoutmetrics:ListAnomalyDetectors, lookoutmetrics:ListMetricSets, lookoutmetrics:ListTagsForResource, lookoutvision:DescribeProject, lookoutvision:ListProjects, managedblockchain:GetMember, managedblockchain:GetNetwork, managedblockchain:GetNode, managedblockchain:ListInvitations, managedblockchain:ListMembers, managedblockchain:ListNodes, mediapackage-vod:DescribePackagingGroup, mediapackage-vod:ListPackagingGroups, mediapackage-vod:ListTagsForResource, mobiletargeting:GetInAppTemplate, mobiletargeting:ListTemplates, mq:DescribeBroker, mq:ListBrokers, nimble:GetLaunchProfile, nimble:GetLaunchProfileDetails, nimble:GetStreamingImage, nimble:GetStudio, nimble:GetStudioComponent, nimble:ListLaunchProfiles, nimble:ListStreamingImages, nimble:ListStudioComponents, nimble:ListStudios, profile:GetDomain, profile:GetIntegration, profile:GetProfileObjectType, profile:ListDomains, profile:ListIntegrations, profile:ListProfileObjectTypes, profile:ListTagsForResource, quicksight:DescribeAnalysis, quicksight:DescribeAnalysisPermissions, quicksight:DescribeDataSet, quicksight:DescribeDataSetPermissions, quicksight:DescribeTheme, quicksight:DescribeThemePermissions, quicksight:ListAnalyses, quicksight:ListDataSets, quicksight:ListThemes, resiliencehub:DescribeApp, resiliencehub:DescribeAppVersionTemplate, resiliencehub:DescribeResiliencyPolicy, resiliencehub:ListApps, resiliencehub:ListAppVersionResourceMappings, resiliencehub:ListResiliencyPolicies, route53-recovery-readiness:GetCell, route53-recovery-readiness:GetReadinessCheck, route53-recovery-readiness:GetRecoveryGroup, route53-recovery-readiness:GetResourceSet, route53-recovery-readiness:ListCells, route53-recovery-readiness:ListReadinessChecks, route53-recovery-readiness:ListRecoveryGroups, route53-recovery-readiness:ListResourceSets, route53resolver:GetFirewallDomainList, route53resolver:GetFirewallRuleGroup, route53resolver:GetFirewallRuleGroupAssociation, route53resolver:GetResolverQueryLogConfig, route53resolver:ListFirewallDomainLists, route53resolver:ListFirewallDomains, route53resolver:ListFirewallRuleGroupAssociations, route53resolver:ListFirewallRuleGroups, route53resolver:ListFirewallRules, route53resolver:ListResolverQueryLogConfigs, rum:GetAppMonitor, rum:GetAppMonitorData, rum:ListAppMonitors, rum:ListTagsForResource, s3-outposts:GetAccessPoint, s3-outposts:GetAccessPointPolicy, s3-outposts:GetBucket, s3-outposts:GetBucketPolicy, s3-outposts:GetBucketTagging, s3-outposts:GetLifecycleConfiguration, s3-outposts:ListAccessPoints, s3-outposts:ListEndpoints, s3-outposts:ListRegionalBuckets, schemas:DescribeDiscoverer, schemas:DescribeRegistry, schemas:DescribeSchema, schemas:ListDiscoverers, schemas:ListRegistries, schemas:ListSchemas, sdb:GetAttributes, sdb:ListDomains, ses:ListEmailTemplates, ses:ListReceiptFilters, ses:ListReceiptRuleSets, ses:ListTemplates, signer:GetSigningProfile, signer:ListProfilePermissions, signer:ListSigningProfiles, synthetics:DescribeCanaries, synthetics:DescribeCanariesLastRun, synthetics:DescribeRuntimeVersions, synthetics:GetCanary, synthetics:GetCanaryRuns, synthetics:ListTagsForResource, timestream:DescribeDatabase, timestream:DescribeTable, timestream:ListDatabases, timestream:ListTables, timestream:ListTagsForResource, transfer:DescribeServer, transfer:DescribeUser, transfer:DescribeWorkflow, transfer:ListServers, transfer:ListUsers, transfer:ListWorkflows, voiceid:DescribeDomain, and voiceid:ListTagsForResource

Kebijakan ini sekarang mendukung izin tambahan untuk Amazon AppFlow, Amazon, Amazon CloudWatch RUM CloudWatch, Amazon CloudWatch Synthetics, Profil Pelanggan Amazon Connect, ID Suara Pelanggan Amazon Connect, Amazon DevOps Guru, Amazon Elastic Compute Cloud (Amazon EC2), Amazon EC2 Auto Scaling, Amazon EMR, Amazon, Amazon EventBridge Schemas,, Amazon Fraud Detector EventBridge, Amazon GameLift Server Amazon FinSpace, Amazon Interactive Video Service (Amazon IVS), Amazon Managed Service untuk Apache Flink, EC2 Image Builder, Amazon Lex, Layar Cahaya Amazon, Layanan Lokasi Amazon, Amazon Lookout untuk Peralatan, Amazon Lookout untuk Metrik, Amazon Lookout untuk Visi, Amazon Managed Blockchain, Amazon MQ, Amazon Nimble StudioAmazon Pinpoint, Amazon Quick, Pengontrol Pemulihan Aplikasi Amazon (ARC), Amazon Route 53 Resolver, Layanan Penyimpanan Sederhana Amazon (Amazon S3), Amazon SimpleDB, Layanan Email Sederhana Amazon (Amazon SES), Amazon Timestream, AWS AppConfig, AWS AppSync, AWS Auto Scaling, AWS Backup, AWS Budgets,, AWS Cost Explorer, AWS Cloud9, AWS Directory Service AWS DataSync AWS Elemental MediaPackage AWS Glue AWS IoT AWS IoT Analytics AWS IoT Events AWS IoT SiteWise, AWS IoT TwinMaker, AWS Lake Formation, AWS License Manager, AWS Resilience Hub, AWS Signer, dan AWS Transfer Family.

7 September 2022

AWS_ConfigRole— Tambah appconfig:ListApplications, appflow:DescribeConnectorProfiles, appsync:GetApiCache, autoscaling-plans:DescribeScalingPlanResources, autoscaling-plans:DescribeScalingPlans, autoscaling-plans:GetScalingPlanResourceForecastData, autoscaling:DescribeWarmPool, backup:DescribeFramework, backup:DescribeReportPlan, backup:ListFrameworks, backup:ListReportPlans, budgets:DescribeBudgetAction, budgets:DescribeBudgetActionsForAccount, budgets:DescribeBudgetActionsForBudget, budgets:ViewBudget, ce:GetAnomalyMonitors, ce:GetAnomalySubscriptions, cloud9:DescribeEnvironmentMemberships, cloud9:DescribeEnvironments, cloud9:ListEnvironments, cloud9:ListTagsForResource, cloudwatch:GetMetricStream, cloudwatch:ListMetricStreams, datasync:DescribeLocationFsxWindows, devops-guru:GetResourceCollection, ds:DescribeDirectories, ec2:DescribeTrafficMirrorTargets, ec2:GetNetworkInsightsAccessScopeAnalysisFindings, ec2:GetNetworkInsightsAccessScopeContent, elasticmapreduce:DescribeStudio, elasticmapreduce:GetStudioSessionMapping, elasticmapreduce:ListStudios, elasticmapreduce:ListStudioSessionMappings, events:DescribeEndpoint, events:DescribeEventBus, events:DescribeRule, events:ListArchives, events:ListEndpoints, events:ListEventBuses, events:ListRules, events:ListTagsForResource, events:ListTargetsByRule, finspace:GetEnvironment, finspace:ListEnvironments, frauddetector:GetDetectors, frauddetector:GetDetectorVersion, frauddetector:GetEntityTypes, frauddetector:GetEventTypes, frauddetector:GetExternalModels, frauddetector:GetLabels, frauddetector:GetModels, frauddetector:GetOutcomes, frauddetector:GetVariables, frauddetector:ListTagsForResource, gamelift:DescribeAlias, gamelift:DescribeBuild, gamelift:DescribeFleetAttributes, gamelift:DescribeFleetCapacity, gamelift:DescribeFleetLocationAttributes, gamelift:DescribeFleetLocationCapacity, gamelift:DescribeFleetPortSettings, gamelift:DescribeGameServerGroup, gamelift:DescribeGameSessionQueues, gamelift:DescribeMatchmakingConfigurations, gamelift:DescribeMatchmakingRuleSets, gamelift:DescribeRuntimeConfiguration, gamelift:DescribeScript, gamelift:DescribeVpcPeeringAuthorizations, gamelift:ListAliases, gamelift:ListBuilds, gamelift:ListFleets, gamelift:ListGameServerGroups, gamelift:ListScripts, gamelift:ListTagsForResource, geo:ListMaps, glue:GetClassifier, glue:GetClassifiers, imagebuilder:GetContainerRecipe, imagebuilder:GetImage, imagebuilder:GetImagePipeline, imagebuilder:GetImageRecipe, imagebuilder:ListContainerRecipes, imagebuilder:ListImageBuildVersions, imagebuilder:ListImagePipelines, imagebuilder:ListImageRecipes, imagebuilder:ListImages, iot:DescribeCertificate, iot:DescribeDimension, iot:DescribeRoleAlias, iot:DescribeSecurityProfile, iot:GetPolicy, iot:GetTopicRule, iot:GetTopicRuleDestination, iot:ListCertificates, iot:ListDimensions, iot:ListPolicies, iot:ListRoleAliases, iot:ListSecurityProfiles, iot:ListSecurityProfilesForTarget, iot:ListTagsForResource, iot:ListTargetsForSecurityProfile, iot:ListTopicRuleDestinations, iot:ListTopicRules, iot:ListV2LoggingLevels, iot:ValidateSecurityProfileBehaviors, iotanalytics:DescribeChannel, iotanalytics:DescribeDataset, iotanalytics:DescribeDatastore, iotanalytics:DescribePipeline, iotanalytics:ListChannels, iotanalytics:ListDatasets, iotanalytics:ListDatastores, iotanalytics:ListPipelines, iotanalytics:ListTagsForResource, iotevents:DescribeAlarmModel, iotevents:DescribeDetectorModel, iotevents:DescribeInput, iotevents:ListAlarmModels, iotevents:ListDetectorModels, iotevents:ListInputs, iotevents:ListTagsForResource, iotsitewise:DescribeAccessPolicy, iotsitewise:DescribeAsset, iotsitewise:ListAccessPolicies, iotsitewise:ListAssets, iottwinmaker:GetEntity, iottwinmaker:GetScene, iottwinmaker:GetWorkspace, iottwinmaker:ListEntities, iottwinmaker:ListScenes, iottwinmaker:ListTagsForResource, iottwinmaker:ListWorkspaces, ivs:GetPlaybackKeyPair, ivs:GetRecordingConfiguration, ivs:GetStreamKey, ivs:ListChannels, ivs:ListPlaybackKeyPairs, ivs:ListRecordingConfigurations, ivs:ListStreamKeys, ivs:ListTagsForResource, kinesisanalytics:ListApplications, lakeformation:DescribeResource, lakeformation:GetDataLakeSettings, lakeformation:ListPermissions, lakeformation:ListResources, lex:DescribeBot, lex:DescribeBotAlias, lex:DescribeResourcePolicy, lex:ListBotAliases, lex:ListBotLocales, lex:ListBots, lex:ListTagsForResource, license-manager:GetGrant, license-manager:GetLicense, license-manager:ListDistributedGrants, license-manager:ListLicenses, license-manager:ListReceivedGrants, lightsail:GetAlarms, lightsail:GetBuckets, lightsail:GetCertificates, lightsail:GetDisk, lightsail:GetDisks, lightsail:GetInstance, lightsail:GetInstances, lightsail:GetKeyPair, lightsail:GetLoadBalancer, lightsail:GetLoadBalancers, lightsail:GetLoadBalancerTlsCertificates, lightsail:GetStaticIp, lightsail:GetStaticIps, lookoutequipment:DescribeInferenceScheduler, lookoutequipment:ListTagsForResource, lookoutmetrics:DescribeAlert, lookoutmetrics:DescribeAnomalyDetector, lookoutmetrics:ListAlerts, lookoutmetrics:ListAnomalyDetectors, lookoutmetrics:ListMetricSets, lookoutmetrics:ListTagsForResource, lookoutvision:DescribeProject, lookoutvision:ListProjects, managedblockchain:GetMember, managedblockchain:GetNetwork, managedblockchain:GetNode, managedblockchain:ListInvitations, managedblockchain:ListMembers, managedblockchain:ListNodes, mediapackage-vod:DescribePackagingGroup, mediapackage-vod:ListPackagingGroups, mediapackage-vod:ListTagsForResource, mobiletargeting:GetInAppTemplate, mobiletargeting:ListTemplates, mq:DescribeBroker, mq:ListBrokers, nimble:GetLaunchProfile, nimble:GetLaunchProfileDetails, nimble:GetStreamingImage, nimble:GetStudio, nimble:GetStudioComponent, nimble:ListLaunchProfiles, nimble:ListStreamingImages, nimble:ListStudioComponents, nimble:ListStudios, profile:GetDomain, profile:GetIntegration, profile:GetProfileObjectType, profile:ListDomains, profile:ListIntegrations, profile:ListProfileObjectTypes, profile:ListTagsForResource, quicksight:DescribeAnalysis, quicksight:DescribeAnalysisPermissions, quicksight:DescribeDataSet, quicksight:DescribeDataSetPermissions, quicksight:DescribeTheme, quicksight:DescribeThemePermissions, quicksight:ListAnalyses, quicksight:ListDataSets, quicksight:ListThemes, resiliencehub:DescribeApp, resiliencehub:DescribeAppVersionTemplate, resiliencehub:DescribeResiliencyPolicy, resiliencehub:ListApps, resiliencehub:ListAppVersionResourceMappings, resiliencehub:ListResiliencyPolicies, route53-recovery-readiness:GetCell, route53-recovery-readiness:GetReadinessCheck, route53-recovery-readiness:GetRecoveryGroup, route53-recovery-readiness:GetResourceSet, route53-recovery-readiness:ListCells, route53-recovery-readiness:ListReadinessChecks, route53-recovery-readiness:ListRecoveryGroups, route53-recovery-readiness:ListResourceSets, route53resolver:GetFirewallDomainList, route53resolver:GetFirewallRuleGroup, route53resolver:GetFirewallRuleGroupAssociation, route53resolver:GetResolverQueryLogConfig, route53resolver:ListFirewallDomainLists, route53resolver:ListFirewallDomains, route53resolver:ListFirewallRuleGroupAssociations, route53resolver:ListFirewallRuleGroups, route53resolver:ListFirewallRules, route53resolver:ListResolverQueryLogConfigs, rum:GetAppMonitor, rum:GetAppMonitorData, rum:ListAppMonitors, rum:ListTagsForResource, s3-outposts:GetAccessPoint, s3-outposts:GetAccessPointPolicy, s3-outposts:GetBucket, s3-outposts:GetBucketPolicy, s3-outposts:GetBucketTagging, s3-outposts:GetLifecycleConfiguration, s3-outposts:ListAccessPoints, s3-outposts:ListEndpoints, s3-outposts:ListRegionalBuckets, schemas:DescribeDiscoverer, schemas:DescribeRegistry, schemas:DescribeSchema, schemas:ListDiscoverers, schemas:ListRegistries, schemas:ListSchemas, sdb:GetAttributes, sdb:ListDomains, ses:ListEmailTemplates, ses:ListReceiptFilters, ses:ListReceiptRuleSets, ses:ListTemplates, signer:GetSigningProfile, signer:ListProfilePermissions, signer:ListSigningProfiles, synthetics:DescribeCanaries, synthetics:DescribeCanariesLastRun, synthetics:DescribeRuntimeVersions, synthetics:GetCanary, synthetics:GetCanaryRuns, synthetics:ListTagsForResource, timestream:DescribeDatabase, timestream:DescribeTable, timestream:ListDatabases, timestream:ListTables, timestream:ListTagsForResource, transfer:DescribeServer, transfer:DescribeUser, transfer:DescribeWorkflow, transfer:ListServers, transfer:ListUsers, transfer:ListWorkflows, voiceid:DescribeDomain, and voiceid:ListTagsForResource

Kebijakan ini sekarang mendukung izin tambahan untuk Amazon AppFlow, Amazon, Amazon CloudWatch RUM CloudWatch, Amazon CloudWatch Synthetics, Profil Pelanggan Amazon Connect, ID Suara Pelanggan Amazon Connect, Amazon DevOps Guru, Amazon Elastic Compute Cloud (Amazon EC2), Amazon EC2 Auto Scaling, Amazon EMR, Amazon, Amazon EventBridge Schemas,, Amazon Fraud Detector EventBridge, Amazon GameLift Server Amazon FinSpace, Amazon Interactive Video Service (Amazon IVS), Amazon Managed Service untuk Apache Flink, EC2 Image Builder, Amazon Lex, Layar Cahaya Amazon, Layanan Lokasi Amazon, Amazon Lookout untuk Peralatan, Amazon Lookout untuk Metrik, Amazon Lookout untuk Visi, Amazon Managed Blockchain, Amazon MQ, Amazon Nimble StudioAmazon Pinpoint, Amazon Quick, Pengontrol Pemulihan Aplikasi Amazon (ARC), Amazon Route 53 Resolver, Layanan Penyimpanan Sederhana Amazon (Amazon S3), Amazon SimpleDB, Layanan Email Sederhana Amazon (Amazon SES), Amazon Timestream, AWS AppConfig, AWS AppSync, AWS Auto Scaling, AWS Backup, AWS Budgets,, AWS Cost Explorer, AWS Cloud9, AWS Directory Service AWS DataSync AWS Elemental MediaPackage AWS Glue AWS IoT AWS IoT Analytics AWS IoT Events AWS IoT SiteWise, AWS IoT TwinMaker, AWS Lake Formation, AWS License Manager, AWS Resilience Hub, AWS Signer, dan AWS Transfer Family

7 September 2022
AWSConfigServiceRolePolicy— Tambah airflow:ListTagsForResource, iot:ListCustomMetrics, iot:DescribeCustomMetric, appstream:DescribeDirectoryConfigs, appstream:ListTagsForResource, codeguru-reviewer:DescribeRepositoryAssociation, codeguru-reviewer:ListRepositoryAssociations, healthlake:ListFHIRDatastores, healthlake:DescribeFHIRDatastore, healthlake:ListTagsForResource, kinesisvideo:DescribeStream, kinesisvideo:ListStreams, kinesisvideo:ListTagsForStream, kinesisvideo:DescribeSignalingChannel, kinesisvideo:ListTagsForResource, kinesisvideo:ListSignalingChannels, route53-recovery-control-config:DescribeCluster, route53-recovery-control-config:DescribeRoutingControl, route53-recovery-control-config:DescribeSafetyRule, route53-recovery-control-config:ListClusters, route53-recovery-control-config:ListRoutingControls, route53-recovery-control-config:ListSafetyRules, devicefarm:GetTestGridProject, devicefarm:ListTestGridProjects, ec2:DescribeCapacityReservationFleets, ec2:DescribeIpamPools, ec2:DescribeIpams, ec2:GetInstanceTypesFromInstanceRequirement, mobiletargeting:GetApplicationSettings, mobiletargeting:ListTagsForResource, ecr:BatchGetRepositoryScanningConfiguration, iam:ListServerCertificates, guardduty:ListPublishingDestinations, guardduty:DescribePublishingDestination, logs:GetLogDelivery, and logs:ListLogDeliveries Kebijakan ini sekarang mendukung izin tambahan untuk Alur Kerja Terkelola Amazon untuk Apache Airflow AWS IoT,, WorkSpaces Aplikasi Amazon, Amazon CodeGuru Reviewer AWS HealthLake, Amazon Kinesis Video Streams, Amazon Application Recovery Controller (ARC) AWS Device Farm, Amazon Elastic Compute Cloud (Amazon EC2), Amazon Pinpoint, AWS Identity and Access Management (IAM), Amazon, dan Amazon Logs. GuardDuty CloudWatch 1 Februari 2023

AWS_ConfigRole— Tambah airflow:ListTagsForResource, iot:ListCustomMetrics, iot:DescribeCustomMetric, appstream:DescribeDirectoryConfigs, appstream:ListTagsForResource, codeguru-reviewer:DescribeRepositoryAssociation, codeguru-reviewer:ListRepositoryAssociations, healthlake:ListFHIRDatastores, healthlake:DescribeFHIRDatastore, healthlake:ListTagsForResource, kinesisvideo:DescribeStream, kinesisvideo:ListStreams, kinesisvideo:ListTagsForStream, kinesisvideo:DescribeSignalingChannel, kinesisvideo:ListTagsForResource, kinesisvideo:ListSignalingChannels, route53-recovery-control-config:DescribeCluster, route53-recovery-control-config:DescribeRoutingControl, route53-recovery-control-config:DescribeSafetyRule, route53-recovery-control-config:ListClusters, route53-recovery-control-config:ListRoutingControls, route53-recovery-control-config:ListSafetyRules, devicefarm:GetTestGridProject, devicefarm:ListTestGridProjects, ec2:DescribeCapacityReservationFleets, ec2:DescribeIpamPools, ec2:DescribeIpams, ec2:GetInstanceTypesFromInstanceRequirement, mobiletargeting:GetApplicationSettings, mobiletargeting:ListTagsForResource, ecr:BatchGetRepositoryScanningConfiguration, iam:ListServerCertificates, guardduty:ListPublishingDestinations, guardduty:DescribePublishingDestination, logs:GetLogDelivery, and logs:ListLogDeliveries

Kebijakan ini sekarang mendukung izin tambahan untuk Alur Kerja Terkelola Amazon untuk Apache Airflow AWS IoT,, WorkSpaces Aplikasi Amazon, Amazon CodeGuru Reviewer AWS HealthLake, Amazon Kinesis Video Streams, Amazon Application Recovery Controller (ARC) AWS Device Farm, Amazon Elastic Compute Cloud (Amazon EC2), Amazon Pinpoint, AWS Identity and Access Management (IAM), Amazon, dan Amazon Logs. GuardDuty CloudWatch

1 Februari 2023

ConfigConformsServiceRolePolicy— Perbarui config:DescribeConfigRules

Sebagai praktik terbaik keamanan, kebijakan ini sekarang menghapus izin tingkat sumber daya yang luas untuk. config:DescribeConfigRules

Januari 12, 2023

AWSConfigServiceRolePolicy— Tambah APS:DescribeRuleGroupsNamespace, APS:DescribeWorkspace, APS:ListWorkspaces, auditmanager:GetAssessment, auditmanager:ListAssessments, devicefarm:GetNetworkProfile, AWS Transfer Family devicefarm:GetProject, devicefarm:ListNetworkProfiles, devicefarm:ListTagsForResource, dms:DescribeEndpoints, ds:ListTagsForResource, ec2:DescribeTags, ec2:DescribeTrafficMirrorSessions, ec2:DescribeTrafficMirrorTargets, ec2:GetIpamPoolAllocations, ec2:GetIpamPoolCidrs, glue:GetMLTransform, glue:GetMLTransforms, glue:ListMLTransforms, iot:DescribeScheduledAudit, iot:ListScheduledAudits, ivs:GetChannel, lightsail:GetRelationalDatabases, mediapackage-vod:DescribePackagingConfiguration, mediapackage-vod:ListPackagingConfigurations, networkmanager:DescribeGlobalNetworks, networkmanager:GetTransitGatewayRegistrations, networkmanager:ListTagsForResource, quicksight:DescribeDashboard, quicksight:DescribeDashboardPermissions, quicksight:DescribeTemplate, quicksight:DescribeTemplatePermissions, quicksight:ListDashboards, quicksight:ListTemplates, ram:ListResources, route53-recovery-control-config:DescribeControlPanel, route53-recovery-control-config:ListControlPanels, route53-recovery-control-config:ListTagsForResource, route53resolver:GetResolverQueryLogConfigAssociation, route53resolver:ListResolverQueryLogConfigAssociations, s3:GetAccessPointForObjectLambda, s3:GetAccessPointPolicyForObjectLambda, s3:GetAccessPointPolicyStatusForObjectLambda, s3:GetMultiRegionAccessPoint, s3:ListAccessPointsForObjectLambda, s3:ListMultiRegionAccessPoints, timestream:DescribeEndpoints, transfer:DescribeConnector, transfer:ListConnectors, and transfer:ListTagsForResource

Kebijakan ini sekarang mendukung izin tambahan untuk Layanan Terkelola Amazon untuk Prometheus,, AWS Audit Manager, AWS Database Migration Service (AWS DMS) AWS Device Farm, AWS Directory Service, Amazon Elastic Compute Cloud (Amazon EC2),,, Amazon Lightsail AWS Glue, AWS IoT, Amazon Quick, AWS Elemental MediaPackage AWS Network Manager, Amazon Application Recovery Controller (ARC) AWS Resource Access Manager, Amazon Simple Storage Service (Amazon S3), dan Amazon Timestream.

Desember 15, 2022

AWS_ConfigRole— Tambah APS:DescribeRuleGroupsNamespace, APS:DescribeWorkspace, APS:ListWorkspaces, auditmanager:GetAssessment, auditmanager:ListAssessments, devicefarm:GetNetworkProfile, devicefarm:GetProject, devicefarm:ListNetworkProfiles, devicefarm:ListTagsForResource, dms:DescribeEndpoints, ds:ListTagsForResource, ec2:DescribeTags, ec2:DescribeTrafficMirrorSessions, ec2:DescribeTrafficMirrorTargets, ec2:GetIpamPoolAllocations, ec2:GetIpamPoolCidrs, glue:GetMLTransform, glue:GetMLTransforms, glue:ListMLTransforms, iot:DescribeScheduledAudit, iot:ListScheduledAudits, ivs:GetChannel, lightsail:GetRelationalDatabases, mediapackage-vod:DescribePackagingConfiguration, mediapackage-vod:ListPackagingConfigurations, networkmanager:DescribeGlobalNetworks, networkmanager:GetTransitGatewayRegistrations, networkmanager:ListTagsForResource, quicksight:DescribeDashboard, quicksight:DescribeDashboardPermissions, quicksight:DescribeTemplate, quicksight:DescribeTemplatePermissions, quicksight:ListDashboards, quicksight:ListTemplates, ram:ListResources, route53-recovery-control-config:DescribeControlPanel, route53-recovery-control-config:ListControlPanels, route53-recovery-control-config:ListTagsForResource, route53resolver:GetResolverQueryLogConfigAssociation, route53resolver:ListResolverQueryLogConfigAssociations, s3:GetAccessPointForObjectLambda, s3:GetAccessPointPolicyForObjectLambda, s3:GetAccessPointPolicyStatusForObjectLambda, s3:GetMultiRegionAccessPoint, s3:ListAccessPointsForObjectLambda, s3:ListMultiRegionAccessPoints, timestream:DescribeEndpoints, transfer:DescribeConnector, transfer:ListConnectors, and transfer:ListTagsForResource

Kebijakan ini sekarang mendukung izin tambahan untuk Layanan Terkelola Amazon untuk Prometheus,, AWS Audit Manager, AWS Database Migration Service (AWS DMS) AWS Device Farm, AWS Directory Service, Amazon Elastic Compute Cloud (Amazon EC2),,, Amazon Lightsail AWS Glue, AWS IoT, Amazon Quick, AWS Elemental MediaPackage AWS Network Manager, Amazon Application Recovery Controller (ARC) AWS Resource Access Manager, Amazon Simple Storage Service (Amazon S3), dan Amazon Timestream.

15 Desember 2022

AWSConfigServiceRolePolicy— Tambah cloudformation:ListStackResources and cloudformation:ListStacks

Kebijakan ini sekarang memberikan izin untuk mengembalikan deskripsi semua sumber daya dari AWS CloudFormation tumpukan tertentu dan mengembalikan informasi ringkasan untuk tumpukan yang statusnya cocok dengan yang ditentukanStackStatusFilter.

7 November 2022

AWS_ConfigRole— Tambah cloudformation:ListStackResources and cloudformation:ListStacks

Kebijakan ini sekarang memberikan izin untuk mengembalikan deskripsi semua sumber daya dari AWS CloudFormation tumpukan tertentu dan mengembalikan informasi ringkasan untuk tumpukan yang statusnya cocok dengan yang ditentukanStackStatusFilter.

7 November 2022

AWSConfigServiceRolePolicy— Tambah acm-pca:GetCertificateAuthorityCsr, acm-pca:ListCertificateAuthorities, acm-pca:ListTags, airflow:GetEnvironment, airflow:ListEnvironments, amplifyuibuilder:ListThemes, appconfig:ListConfigurationProfiles, appconfig:ListDeployments, appconfig:ListDeploymentStrategies, appconfig:ListEnvironments, appconfig:ListHostedConfigurationVersions, cassandra:Select, cloudwatch:DescribeAnomalyDetectors, cloudwatch:GetDashboard, cloudwatch:ListDashboards, connect:DescribePhoneNumber, connect:ListPhoneNumbers, connect:ListPhoneNumbersV2, connect:SearchAvailablePhoneNumbers, databrew:DescribeDataset, databrew:DescribeJob, databrew:DescribeProject, databrew:DescribeRecipe, databrew:DescribeRuleset, databrew:DescribeSchedule, databrew:ListDatasets, databrew:ListJobs, databrew:ListProjects, databrew:ListRecipes, databrew:ListRecipeVersions, databrew:ListRulesets, databrew:ListSchedules, ec2:DescribeRouteTables, eks:DescribeAddon, eks:DescribeIdentityProviderConfig, eks:ListAddons, eks:ListIdentityProviderConfigs, events:DescribeConnection, events:ListApiDestinations, events:ListConnections, fis:GetExperimentTemplate, fis:ListExperimentTemplates, frauddetector:GetRules, fsx:DescribeBackups, fsx:DescribeSnapshots, fsx:DescribeStorageVirtualMachines, gamelift:DescribeMatchmakingRuleSets, gamelift:DescribeVpcPeeringConnections, geo:ListGeofenceCollections, geo:ListPlaceIndexes, geo:ListRouteCalculators, geo:ListTrackers, iot:DescribeAccountAuditConfiguration, iot:DescribeAuthorizer, iot:DescribeDomainConfiguration, iot:DescribeMitigationAction, iot:ListAuthorizers, iot:ListDomainConfigurations, iot:ListMitigationActions, iotsitewise:DescribeAssetModel, iotsitewise:DescribeDashboard, iotsitewise:DescribeGateway, iotsitewise:DescribePortal, iotsitewise:DescribeProject, iotsitewise:ListAssetModels, iotsitewise:ListDashboards, iotsitewise:ListGateways, iotsitewise:ListPortals, iotsitewise:ListProjectAssets, iotsitewise:ListProjects, iotsitewise:ListTagsForResource, iotwireless:GetServiceProfile, iotwireless:GetWirelessDevice, iotwireless:GetWirelessGatewayTaskDefinition, iotwireless:ListServiceProfiles, iotwireless:ListTagsForResource, iotwireless:ListWirelessDevices, iotwireless:ListWirelessGatewayTaskDefinitions, lex:DescribeBotVersion, lex:ListBotVersions, lightsail:GetContainerServices, lightsail:GetDistributions, lightsail:GetRelationalDatabase, lightsail:GetRelationalDatabaseParameters, mobiletargeting:GetApps, mobiletargeting:GetCampaign, mobiletargeting:GetSegment, mobiletargeting:GetSegments, opsworks:DescribeInstances, opsworks:DescribeTimeBasedAutoScaling, opsworks:DescribeVolumes, panorama:DescribeApplicationInstance, panorama:DescribeApplicationInstanceDetails, panorama:DescribePackage, panorama:DescribePackageVersion, panorama:ListApplicationInstances, panorama:ListPackages, quicksight:ListDataSources, ram:ListResourceSharePermissions, rds:DescribeDBProxies, rds:DescribeGlobalClusters, rekognition:ListStreamProcessors, resource-groups:GetGroup, resource-groups:GetGroupConfiguration, resource-groups:GetGroupQuery, resource-groups:GetTags, resource-groups:ListGroupResources, resource-groups:ListGroups, robomaker:ListRobotApplications, robomaker:ListSimulationApplications, route53resolver:GetResolverDnssecConfig, route53resolver:ListResolverDnssecConfigs, s3:ListStorageLensConfigurations, schemas:GetResourcePolicy, servicediscovery:ListInstances, sts:GetCallerIdentity, synthetics:GetGroup, synthetics:ListAssociatedGroups, synthetics:ListGroupResources, and synthetics:ListGroups

Kebijakan ini sekarang mendukung izin tambahan untuk AWS Certificate Manager, Alur Kerja Terkelola Amazon untuk Apache Airflow, AWS Amplify AWS AppConfig, Amazon Keyspaces, Amazon, Connect Customer CloudWatch, AWS Glue DataBrew, Amazon Elastic Compute Cloud (Amazon EC2), Amazon Elastic Kubernetes Service (Amazon EKS), Amazon,, Amazon Fraud Detector EventBridge AWS Fault Injection Service, Amazon FSx, Amazon GameLift Servers, Amazon Location Service,, Amazon Lex, Amazon Lightsail AWS IoT, Amazon Pinpoint,,, Amazon Quick, Amazon Relational Database Service (Amazon) RDS) OpsWorks AWS Panorama AWS Resource Access Manager, Amazon Rekognition,, AWS RoboMaker AWS Resource Groups, Amazon Route 53, Layanan Penyimpanan Sederhana Amazon (Amazon S3), AWS Cloud Map, dan. AWS Security Token Service

Oktober 19, 2022

AWS_ConfigRole— Tambah acm-pca:GetCertificateAuthorityCsr, acm-pca:ListCertificateAuthorities, acm-pca:ListTags, airflow:GetEnvironment, airflow:ListEnvironments, amplifyuibuilder:ListThemes, appconfig:ListConfigurationProfiles, appconfig:ListDeployments, appconfig:ListDeploymentStrategies, appconfig:ListEnvironments, appconfig:ListHostedConfigurationVersions, cassandra:Select, cloudwatch:DescribeAnomalyDetectors, cloudwatch:GetDashboard, cloudwatch:ListDashboards, connect:DescribePhoneNumber, connect:ListPhoneNumbers, connect:ListPhoneNumbersV2, connect:SearchAvailablePhoneNumbers, databrew:DescribeDataset, databrew:DescribeJob, databrew:DescribeProject, databrew:DescribeRecipe, databrew:DescribeRuleset, databrew:DescribeSchedule, databrew:ListDatasets, databrew:ListJobs, databrew:ListProjects, databrew:ListRecipes, databrew:ListRecipeVersions, databrew:ListRulesets, databrew:ListSchedules, ec2:DescribeRouteTables, eks:DescribeAddon, eks:DescribeIdentityProviderConfig, eks:ListAddons, eks:ListIdentityProviderConfigs, events:DescribeConnection, events:ListApiDestinations, events:ListConnections, fis:GetExperimentTemplate, fis:ListExperimentTemplates, frauddetector:GetRules, fsx:DescribeBackups, fsx:DescribeSnapshots, fsx:DescribeStorageVirtualMachines, gamelift:DescribeMatchmakingRuleSets, gamelift:DescribeVpcPeeringConnections, geo:ListGeofenceCollections, geo:ListPlaceIndexes, geo:ListRouteCalculators, geo:ListTrackers, iot:DescribeAccountAuditConfiguration, iot:DescribeAuthorizer, iot:DescribeDomainConfiguration, iot:DescribeMitigationAction, iot:ListAuthorizers, iot:ListDomainConfigurations, iot:ListMitigationActions, iotsitewise:DescribeAssetModel, iotsitewise:DescribeDashboard, iotsitewise:DescribeGateway, iotsitewise:DescribePortal, iotsitewise:DescribeProject, iotsitewise:ListAssetModels, iotsitewise:ListDashboards, iotsitewise:ListGateways, iotsitewise:ListPortals, iotsitewise:ListProjectAssets, iotsitewise:ListProjects, iotsitewise:ListTagsForResource, iotwireless:GetServiceProfile, iotwireless:GetWirelessDevice, iotwireless:GetWirelessGatewayTaskDefinition, iotwireless:ListServiceProfiles, iotwireless:ListTagsForResource, iotwireless:ListWirelessDevices, iotwireless:ListWirelessGatewayTaskDefinitions, lex:DescribeBotVersion, lex:ListBotVersions, lightsail:GetContainerServices, lightsail:GetDistributions, lightsail:GetRelationalDatabase, lightsail:GetRelationalDatabaseParameters, mobiletargeting:GetApps, mobiletargeting:GetCampaign, mobiletargeting:GetSegment, mobiletargeting:GetSegments, opsworks:DescribeInstances, opsworks:DescribeTimeBasedAutoScaling, opsworks:DescribeVolumes, panorama:DescribeApplicationInstance, panorama:DescribeApplicationInstanceDetails, panorama:DescribePackage, panorama:DescribePackageVersion, panorama:ListApplicationInstances, panorama:ListPackages, quicksight:ListDataSources, ram:ListResourceSharePermissions, rds:DescribeDBProxies, rds:DescribeGlobalClusters, rekognition:ListStreamProcessors, resource-groups:GetGroup, resource-groups:GetGroupConfiguration, resource-groups:GetGroupQuery, resource-groups:GetTags, resource-groups:ListGroupResources, resource-groups:ListGroups, robomaker:ListRobotApplications, robomaker:ListSimulationApplications, route53resolver:GetResolverDnssecConfig, route53resolver:ListResolverDnssecConfigs, s3:ListStorageLensConfigurations, schemas:GetResourcePolicy, servicediscovery:ListInstances, sts:GetCallerIdentity, synthetics:GetGroup, synthetics:ListAssociatedGroups, synthetics:ListGroupResources, and synthetics:ListGroups

Kebijakan ini sekarang mendukung izin tambahan untuk AWS Certificate Manager, Alur Kerja Terkelola Amazon untuk Apache Airflow, AWS Amplify AWS AppConfig, Amazon Keyspaces, Amazon, Connect Customer CloudWatch, AWS Glue DataBrew, Amazon Elastic Compute Cloud (Amazon EC2), Amazon Elastic Kubernetes Service (Amazon EKS), Amazon,, Amazon Fraud Detector EventBridge AWS Fault Injection Service, Amazon FSx, Amazon GameLift Servers, Amazon Location Service,, Amazon Lex, Amazon Lightsail AWS IoT, Amazon Pinpoint,,, Amazon Quick, Amazon Relational Database Service (Amazon) RDS) OpsWorks AWS Panorama AWS Resource Access Manager, Amazon Rekognition,, AWS RoboMaker AWS Resource Groups, Amazon Route 53, Layanan Penyimpanan Sederhana Amazon (Amazon S3), AWS Cloud Map, dan. AWS Security Token Service

Oktober 19, 2022

AWSConfigServiceRolePolicy— Tambah Glue::GetTable

Kebijakan ini sekarang memberikan izin untuk mengambil definisi AWS Glue Tabel dalam Katalog Data untuk tabel tertentu.

14 September 2022

AWS_ConfigRole— Tambah Glue::GetTable

Kebijakan ini sekarang memberikan izin untuk mengambil definisi AWS Glue Tabel dalam Katalog Data untuk tabel tertentu.

14 September 2022

AWSConfigServiceRolePolicy— Tambah appconfig:ListApplications, appflow:DescribeConnectorProfiles, appsync:GetApiCache, autoscaling-plans:DescribeScalingPlanResources, autoscaling-plans:DescribeScalingPlans, autoscaling-plans:GetScalingPlanResourceForecastData, autoscaling:DescribeWarmPool, backup:DescribeFramework, backup:DescribeReportPlan, backup:ListFrameworks, backup:ListReportPlans, budgets:DescribeBudgetAction, budgets:DescribeBudgetActionsForAccount, budgets:DescribeBudgetActionsForBudget, budgets:ViewBudget, ce:GetAnomalyMonitors, ce:GetAnomalySubscriptions, cloud9:DescribeEnvironmentMemberships, cloud9:DescribeEnvironments, cloud9:ListEnvironments, cloud9:ListTagsForResource, cloudwatch:GetMetricStream, cloudwatch:ListMetricStreams, datasync:DescribeLocationFsxWindows, devops-guru:GetResourceCollection, ds:DescribeDirectories, ec2:DescribeTrafficMirrorFilters, ec2:DescribeTrafficMirrorTargets, ec2:GetNetworkInsightsAccessScopeAnalysisFindings, ec2:GetNetworkInsightsAccessScopeContent, elasticmapreduce:DescribeStudio, elasticmapreduce:GetStudioSessionMapping, elasticmapreduce:ListStudios, elasticmapreduce:ListStudioSessionMappings, events:DescribeEndpoint, events:DescribeEventBus, events:DescribeRule, events:ListArchives, events:ListEndpoints, events:ListEventBuses, events:ListRules, events:ListTagsForResource, events:ListTargetsByRule, finspace:GetEnvironment, finspace:ListEnvironments, frauddetector:GetDetectors, frauddetector:GetDetectorVersion, frauddetector:GetEntityTypes, frauddetector:GetEventTypes, frauddetector:GetExternalModels, frauddetector:GetLabels, frauddetector:GetModels, frauddetector:GetOutcomes, frauddetector:GetVariables, frauddetector:ListTagsForResource, gamelift:DescribeAlias, gamelift:DescribeBuild, gamelift:DescribeFleetAttributes, gamelift:DescribeFleetCapacity, gamelift:DescribeFleetLocationAttributes, gamelift:DescribeFleetLocationCapacity, gamelift:DescribeFleetPortSettings, gamelift:DescribeGameServerGroup, gamelift:DescribeGameSessionQueues, gamelift:DescribeMatchmakingConfigurations, gamelift:DescribeMatchmakingRuleSets, gamelift:DescribeRuntimeConfiguration, gamelift:DescribeScript, gamelift:DescribeVpcPeeringAuthorizations, gamelift:ListAliases, gamelift:ListBuilds, gamelift:ListFleets, gamelift:ListGameServerGroups, gamelift:ListScripts, gamelift:ListTagsForResource, geo:ListMaps, glue:GetClassifier, glue:GetClassifiers, imagebuilder:GetContainerRecipe, imagebuilder:GetImage, imagebuilder:GetImagePipeline, imagebuilder:GetImageRecipe, imagebuilder:ListContainerRecipes, imagebuilder:ListImageBuildVersions, imagebuilder:ListImagePipelines, imagebuilder:ListImageRecipes, imagebuilder:ListImages, iot:DescribeCertificate, iot:DescribeDimension, iot:DescribeRoleAlias, iot:DescribeSecurityProfile, iot:GetPolicy, iot:GetTopicRule, iot:GetTopicRuleDestination, iot:ListCertificates, iot:ListDimensions, iot:ListPolicies, iot:ListRoleAliases, iot:ListSecurityProfiles, iot:ListSecurityProfilesForTarget, iot:ListTagsForResource, iot:ListTargetsForSecurityProfile, iot:ListTopicRuleDestinations, iot:ListTopicRules, iot:ListV2LoggingLevels, iot:ValidateSecurityProfileBehaviors, iotanalytics:DescribeChannel, iotanalytics:DescribeDataset, iotanalytics:DescribeDatastore, iotanalytics:DescribePipeline, iotanalytics:ListChannels, iotanalytics:ListDatasets, iotanalytics:ListDatastores, iotanalytics:ListPipelines, iotanalytics:ListTagsForResource, iotevents:DescribeAlarmModel, iotevents:DescribeDetectorModel, iotevents:DescribeInput, iotevents:ListAlarmModels, iotevents:ListDetectorModels, iotevents:ListInputs, iotevents:ListTagsForResource, iotsitewise:DescribeAccessPolicy, iotsitewise:DescribeAsset, iotsitewise:ListAccessPolicies, iotsitewise:ListAssets, iottwinmaker:GetEntity, iottwinmaker:GetScene, iottwinmaker:GetWorkspace, iottwinmaker:ListEntities, iottwinmaker:ListScenes, iottwinmaker:ListTagsForResource, iottwinmaker:ListWorkspaces, ivs:GetPlaybackKeyPair, ivs:GetRecordingConfiguration, ivs:GetStreamKey, ivs:ListChannels, ivs:ListPlaybackKeyPairs, ivs:ListRecordingConfigurations, ivs:ListStreamKeys, ivs:ListTagsForResource, kinesisanalytics:ListApplications, lakeformation:DescribeResource, lakeformation:GetDataLakeSettings, lakeformation:ListPermissions, lakeformation:ListResources, lex:DescribeBot, lex:DescribeBotAlias, lex:DescribeResourcePolicy, lex:ListBotAliases, lex:ListBotLocales, lex:ListBots, lex:ListTagsForResource, license-manager:GetGrant, license-manager:GetLicense, license-manager:ListDistributedGrants, license-manager:ListLicenses, license-manager:ListReceivedGrants, lightsail:GetAlarms, lightsail:GetBuckets, lightsail:GetCertificates, lightsail:GetDisk, lightsail:GetDisks, lightsail:GetInstance, lightsail:GetInstances, lightsail:GetKeyPair, lightsail:GetLoadBalancer, lightsail:GetLoadBalancers, lightsail:GetLoadBalancerTlsCertificates, lightsail:GetStaticIp, lightsail:GetStaticIps, lookoutequipment:DescribeInferenceScheduler, lookoutequipment:ListTagsForResource, lookoutmetrics:DescribeAlert, lookoutmetrics:DescribeAnomalyDetector, lookoutmetrics:ListAlerts, lookoutmetrics:ListAnomalyDetectors, lookoutmetrics:ListMetricSets, lookoutmetrics:ListTagsForResource, lookoutvision:DescribeProject, lookoutvision:ListProjects, managedblockchain:GetMember, managedblockchain:GetNetwork, managedblockchain:GetNode, managedblockchain:ListInvitations, managedblockchain:ListMembers, managedblockchain:ListNodes, mediapackage-vod:DescribePackagingGroup, mediapackage-vod:ListPackagingGroups, mediapackage-vod:ListTagsForResource, mobiletargeting:GetInAppTemplate, mobiletargeting:ListTemplates, mq:DescribeBroker, mq:ListBrokers, nimble:GetLaunchProfile, nimble:GetLaunchProfileDetails, nimble:GetStreamingImage, nimble:GetStudio, nimble:GetStudioComponent, nimble:ListLaunchProfiles, nimble:ListStreamingImages, nimble:ListStudioComponents, nimble:ListStudios, profile:GetDomain, profile:GetIntegration, profile:GetProfileObjectType, profile:ListDomains, profile:ListIntegrations, profile:ListProfileObjectTypes, profile:ListTagsForResource, quicksight:DescribeAnalysis, quicksight:DescribeAnalysisPermissions, quicksight:DescribeDataSet, quicksight:DescribeDataSetPermissions, quicksight:DescribeTheme, quicksight:DescribeThemePermissions, quicksight:ListAnalyses, quicksight:ListDataSets, quicksight:ListThemes, resiliencehub:DescribeApp, resiliencehub:DescribeAppVersionTemplate, resiliencehub:DescribeResiliencyPolicy, resiliencehub:ListApps, resiliencehub:ListAppVersionResourceMappings, resiliencehub:ListResiliencyPolicies, route53-recovery-readiness:GetCell, route53-recovery-readiness:GetReadinessCheck, route53-recovery-readiness:GetRecoveryGroup, route53-recovery-readiness:GetResourceSet, route53-recovery-readiness:ListCells, route53-recovery-readiness:ListReadinessChecks, route53-recovery-readiness:ListRecoveryGroups, route53-recovery-readiness:ListResourceSets, route53resolver:GetFirewallDomainList, route53resolver:GetFirewallRuleGroup, route53resolver:GetFirewallRuleGroupAssociation, route53resolver:GetResolverQueryLogConfig, route53resolver:ListFirewallDomainLists, route53resolver:ListFirewallDomains, route53resolver:ListFirewallRuleGroupAssociations, route53resolver:ListFirewallRuleGroups, route53resolver:ListFirewallRules, route53resolver:ListResolverQueryLogConfigs, rum:GetAppMonitor, rum:GetAppMonitorData, rum:ListAppMonitors, rum:ListTagsForResource, s3-outposts:GetAccessPoint, s3-outposts:GetAccessPointPolicy, s3-outposts:GetBucket, s3-outposts:GetBucketPolicy, s3-outposts:GetBucketTagging, s3-outposts:GetLifecycleConfiguration, s3-outposts:ListAccessPoints, s3-outposts:ListEndpoints, s3-outposts:ListRegionalBuckets, schemas:DescribeDiscoverer, schemas:DescribeRegistry, schemas:DescribeSchema, schemas:ListDiscoverers, schemas:ListRegistries, schemas:ListSchemas, sdb:GetAttributes, sdb:ListDomains, ses:ListEmailTemplates, ses:ListReceiptFilters, ses:ListReceiptRuleSets, ses:ListTemplates, signer:GetSigningProfile, signer:ListProfilePermissions, signer:ListSigningProfiles, synthetics:DescribeCanaries, synthetics:DescribeCanariesLastRun, synthetics:DescribeRuntimeVersions, synthetics:GetCanary, synthetics:GetCanaryRuns, synthetics:ListTagsForResource, timestream:DescribeDatabase, timestream:DescribeTable, timestream:ListDatabases, timestream:ListTables, timestream:ListTagsForResource, transfer:DescribeServer, transfer:DescribeUser, transfer:DescribeWorkflow, transfer:ListServers, transfer:ListUsers, transfer:ListWorkflows, voiceid:DescribeDomain, and voiceid:ListTagsForResource

Kebijakan ini sekarang mendukung izin tambahan untuk Amazon AppFlow, Amazon, Amazon CloudWatch RUM CloudWatch, Amazon CloudWatch Synthetics, Profil Pelanggan Amazon Connect, ID Suara Pelanggan Amazon Connect, Amazon DevOps Guru, Amazon Elastic Compute Cloud (Amazon EC2), Amazon EC2 Auto Scaling, Amazon EMR, Amazon, Amazon EventBridge Schemas,, Amazon Fraud Detector EventBridge, Amazon GameLift Server Amazon FinSpace, Amazon Interactive Video Service (Amazon IVS), Amazon Managed Service untuk Apache Flink, EC2 Image Builder, Amazon Lex, Layar Cahaya Amazon, Layanan Lokasi Amazon, Amazon Lookout untuk Peralatan, Amazon Lookout untuk Metrik, Amazon Lookout untuk Visi, Amazon Managed Blockchain, Amazon MQ, Amazon Nimble StudioAmazon Pinpoint, Amazon Quick, Pengontrol Pemulihan Aplikasi Amazon (ARC), Amazon Route 53 Resolver, Layanan Penyimpanan Sederhana Amazon (Amazon S3), Amazon SimpleDB, Layanan Email Sederhana Amazon (Amazon SES), Amazon Timestream, AWS AppConfig, AWS AppSync, AWS Auto Scaling, AWS Backup, AWS Budgets,, AWS Cost Explorer, AWS Cloud9, AWS Directory Service AWS DataSync AWS Elemental MediaPackage AWS Glue AWS IoT AWS IoT Analytics AWS IoT Events AWS IoT SiteWise, AWS IoT TwinMaker, AWS Lake Formation, AWS License Manager, AWS Resilience Hub, AWS Signer, dan AWS Transfer Family.

7 September 2022

AWS_ConfigRole— Tambah appconfig:ListApplications, appflow:DescribeConnectorProfiles, appsync:GetApiCache, autoscaling-plans:DescribeScalingPlanResources, autoscaling-plans:DescribeScalingPlans, autoscaling-plans:GetScalingPlanResourceForecastData, autoscaling:DescribeWarmPool, backup:DescribeFramework, backup:DescribeReportPlan, backup:ListFrameworks, backup:ListReportPlans, budgets:DescribeBudgetAction, budgets:DescribeBudgetActionsForAccount, budgets:DescribeBudgetActionsForBudget, budgets:ViewBudget, ce:GetAnomalyMonitors, ce:GetAnomalySubscriptions, cloud9:DescribeEnvironmentMemberships, cloud9:DescribeEnvironments, cloud9:ListEnvironments, cloud9:ListTagsForResource, cloudwatch:GetMetricStream, cloudwatch:ListMetricStreams, datasync:DescribeLocationFsxWindows, devops-guru:GetResourceCollection, ds:DescribeDirectories, ec2:DescribeTrafficMirrorTargets, ec2:GetNetworkInsightsAccessScopeAnalysisFindings, ec2:GetNetworkInsightsAccessScopeContent, elasticmapreduce:DescribeStudio, elasticmapreduce:GetStudioSessionMapping, elasticmapreduce:ListStudios, elasticmapreduce:ListStudioSessionMappings, events:DescribeEndpoint, events:DescribeEventBus, events:DescribeRule, events:ListArchives, events:ListEndpoints, events:ListEventBuses, events:ListRules, events:ListTagsForResource, events:ListTargetsByRule, finspace:GetEnvironment, finspace:ListEnvironments, frauddetector:GetDetectors, frauddetector:GetDetectorVersion, frauddetector:GetEntityTypes, frauddetector:GetEventTypes, frauddetector:GetExternalModels, frauddetector:GetLabels, frauddetector:GetModels, frauddetector:GetOutcomes, frauddetector:GetVariables, frauddetector:ListTagsForResource, gamelift:DescribeAlias, gamelift:DescribeBuild, gamelift:DescribeFleetAttributes, gamelift:DescribeFleetCapacity, gamelift:DescribeFleetLocationAttributes, gamelift:DescribeFleetLocationCapacity, gamelift:DescribeFleetPortSettings, gamelift:DescribeGameServerGroup, gamelift:DescribeGameSessionQueues, gamelift:DescribeMatchmakingConfigurations, gamelift:DescribeMatchmakingRuleSets, gamelift:DescribeRuntimeConfiguration, gamelift:DescribeScript, gamelift:DescribeVpcPeeringAuthorizations, gamelift:ListAliases, gamelift:ListBuilds, gamelift:ListFleets, gamelift:ListGameServerGroups, gamelift:ListScripts, gamelift:ListTagsForResource, geo:ListMaps, glue:GetClassifier, glue:GetClassifiers, imagebuilder:GetContainerRecipe, imagebuilder:GetImage, imagebuilder:GetImagePipeline, imagebuilder:GetImageRecipe, imagebuilder:ListContainerRecipes, imagebuilder:ListImageBuildVersions, imagebuilder:ListImagePipelines, imagebuilder:ListImageRecipes, imagebuilder:ListImages, iot:DescribeCertificate, iot:DescribeDimension, iot:DescribeRoleAlias, iot:DescribeSecurityProfile, iot:GetPolicy, iot:GetTopicRule, iot:GetTopicRuleDestination, iot:ListCertificates, iot:ListDimensions, iot:ListPolicies, iot:ListRoleAliases, iot:ListSecurityProfiles, iot:ListSecurityProfilesForTarget, iot:ListTagsForResource, iot:ListTargetsForSecurityProfile, iot:ListTopicRuleDestinations, iot:ListTopicRules, iot:ListV2LoggingLevels, iot:ValidateSecurityProfileBehaviors, iotanalytics:DescribeChannel, iotanalytics:DescribeDataset, iotanalytics:DescribeDatastore, iotanalytics:DescribePipeline, iotanalytics:ListChannels, iotanalytics:ListDatasets, iotanalytics:ListDatastores, iotanalytics:ListPipelines, iotanalytics:ListTagsForResource, iotevents:DescribeAlarmModel, iotevents:DescribeDetectorModel, iotevents:DescribeInput, iotevents:ListAlarmModels, iotevents:ListDetectorModels, iotevents:ListInputs, iotevents:ListTagsForResource, iotsitewise:DescribeAccessPolicy, iotsitewise:DescribeAsset, iotsitewise:ListAccessPolicies, iotsitewise:ListAssets, iottwinmaker:GetEntity, iottwinmaker:GetScene, iottwinmaker:GetWorkspace, iottwinmaker:ListEntities, iottwinmaker:ListScenes, iottwinmaker:ListTagsForResource, iottwinmaker:ListWorkspaces, ivs:GetPlaybackKeyPair, ivs:GetRecordingConfiguration, ivs:GetStreamKey, ivs:ListChannels, ivs:ListPlaybackKeyPairs, ivs:ListRecordingConfigurations, ivs:ListStreamKeys, ivs:ListTagsForResource, kinesisanalytics:ListApplications, lakeformation:DescribeResource, lakeformation:GetDataLakeSettings, lakeformation:ListPermissions, lakeformation:ListResources, lex:DescribeBot, lex:DescribeBotAlias, lex:DescribeResourcePolicy, lex:ListBotAliases, lex:ListBotLocales, lex:ListBots, lex:ListTagsForResource, license-manager:GetGrant, license-manager:GetLicense, license-manager:ListDistributedGrants, license-manager:ListLicenses, license-manager:ListReceivedGrants, lightsail:GetAlarms, lightsail:GetBuckets, lightsail:GetCertificates, lightsail:GetDisk, lightsail:GetDisks, lightsail:GetInstance, lightsail:GetInstances, lightsail:GetKeyPair, lightsail:GetLoadBalancer, lightsail:GetLoadBalancers, lightsail:GetLoadBalancerTlsCertificates, lightsail:GetStaticIp, lightsail:GetStaticIps, lookoutequipment:DescribeInferenceScheduler, lookoutequipment:ListTagsForResource, lookoutmetrics:DescribeAlert, lookoutmetrics:DescribeAnomalyDetector, lookoutmetrics:ListAlerts, lookoutmetrics:ListAnomalyDetectors, lookoutmetrics:ListMetricSets, lookoutmetrics:ListTagsForResource, lookoutvision:DescribeProject, lookoutvision:ListProjects, managedblockchain:GetMember, managedblockchain:GetNetwork, managedblockchain:GetNode, managedblockchain:ListInvitations, managedblockchain:ListMembers, managedblockchain:ListNodes, mediapackage-vod:DescribePackagingGroup, mediapackage-vod:ListPackagingGroups, mediapackage-vod:ListTagsForResource, mobiletargeting:GetInAppTemplate, mobiletargeting:ListTemplates, mq:DescribeBroker, mq:ListBrokers, nimble:GetLaunchProfile, nimble:GetLaunchProfileDetails, nimble:GetStreamingImage, nimble:GetStudio, nimble:GetStudioComponent, nimble:ListLaunchProfiles, nimble:ListStreamingImages, nimble:ListStudioComponents, nimble:ListStudios, profile:GetDomain, profile:GetIntegration, profile:GetProfileObjectType, profile:ListDomains, profile:ListIntegrations, profile:ListProfileObjectTypes, profile:ListTagsForResource, quicksight:DescribeAnalysis, quicksight:DescribeAnalysisPermissions, quicksight:DescribeDataSet, quicksight:DescribeDataSetPermissions, quicksight:DescribeTheme, quicksight:DescribeThemePermissions, quicksight:ListAnalyses, quicksight:ListDataSets, quicksight:ListThemes, resiliencehub:DescribeApp, resiliencehub:DescribeAppVersionTemplate, resiliencehub:DescribeResiliencyPolicy, resiliencehub:ListApps, resiliencehub:ListAppVersionResourceMappings, resiliencehub:ListResiliencyPolicies, route53-recovery-readiness:GetCell, route53-recovery-readiness:GetReadinessCheck, route53-recovery-readiness:GetRecoveryGroup, route53-recovery-readiness:GetResourceSet, route53-recovery-readiness:ListCells, route53-recovery-readiness:ListReadinessChecks, route53-recovery-readiness:ListRecoveryGroups, route53-recovery-readiness:ListResourceSets, route53resolver:GetFirewallDomainList, route53resolver:GetFirewallRuleGroup, route53resolver:GetFirewallRuleGroupAssociation, route53resolver:GetResolverQueryLogConfig, route53resolver:ListFirewallDomainLists, route53resolver:ListFirewallDomains, route53resolver:ListFirewallRuleGroupAssociations, route53resolver:ListFirewallRuleGroups, route53resolver:ListFirewallRules, route53resolver:ListResolverQueryLogConfigs, rum:GetAppMonitor, rum:GetAppMonitorData, rum:ListAppMonitors, rum:ListTagsForResource, s3-outposts:GetAccessPoint, s3-outposts:GetAccessPointPolicy, s3-outposts:GetBucket, s3-outposts:GetBucketPolicy, s3-outposts:GetBucketTagging, s3-outposts:GetLifecycleConfiguration, s3-outposts:ListAccessPoints, s3-outposts:ListEndpoints, s3-outposts:ListRegionalBuckets, schemas:DescribeDiscoverer, schemas:DescribeRegistry, schemas:DescribeSchema, schemas:ListDiscoverers, schemas:ListRegistries, schemas:ListSchemas, sdb:GetAttributes, sdb:ListDomains, ses:ListEmailTemplates, ses:ListReceiptFilters, ses:ListReceiptRuleSets, ses:ListTemplates, signer:GetSigningProfile, signer:ListProfilePermissions, signer:ListSigningProfiles, synthetics:DescribeCanaries, synthetics:DescribeCanariesLastRun, synthetics:DescribeRuntimeVersions, synthetics:GetCanary, synthetics:GetCanaryRuns, synthetics:ListTagsForResource, timestream:DescribeDatabase, timestream:DescribeTable, timestream:ListDatabases, timestream:ListTables, timestream:ListTagsForResource, transfer:DescribeServer, transfer:DescribeUser, transfer:DescribeWorkflow, transfer:ListServers, transfer:ListUsers, transfer:ListWorkflows, voiceid:DescribeDomain, and voiceid:ListTagsForResource

Kebijakan ini sekarang mendukung izin tambahan untuk Amazon AppFlow, Amazon, Amazon CloudWatch RUM CloudWatch, Amazon CloudWatch Synthetics, Profil Pelanggan Amazon Connect, ID Suara Pelanggan Amazon Connect, Amazon DevOps Guru, Amazon Elastic Compute Cloud (Amazon EC2), Amazon EC2 Auto Scaling, Amazon EMR, Amazon, Amazon EventBridge Schemas,, Amazon Fraud Detector EventBridge, Amazon GameLift Server Amazon FinSpace, Amazon Interactive Video Service (Amazon IVS), Amazon Managed Service untuk Apache Flink, EC2 Image Builder, Amazon Lex, Layar Cahaya Amazon, Layanan Lokasi Amazon, Amazon Lookout untuk Peralatan, Amazon Lookout untuk Metrik, Amazon Lookout untuk Visi, Amazon Managed Blockchain, Amazon MQ, Amazon Nimble StudioAmazon Pinpoint, Amazon Quick, Pengontrol Pemulihan Aplikasi Amazon (ARC), Amazon Route 53 Resolver, Layanan Penyimpanan Sederhana Amazon (Amazon S3), Amazon SimpleDB, Layanan Email Sederhana Amazon (Amazon SES), Amazon Timestream, AWS AppConfig, AWS AppSync, AWS Auto Scaling, AWS Backup, AWS Budgets,, AWS Cost Explorer, AWS Cloud9, AWS Directory Service AWS DataSync AWS Elemental MediaPackage AWS Glue AWS IoT AWS IoT Analytics AWS IoT Events AWS IoT SiteWise, AWS IoT TwinMaker, AWS Lake Formation, AWS License Manager, AWS Resilience Hub, AWS Signer, dan AWS Transfer Family

7 September 2022

AWSConfigServiceRolePolicy— Tambah datasync:ListAgents, datasync:ListLocations, datasync:ListTasks, servicediscovery:ListNamespaces, servicediscovery:ListServices, and ses:ListContactLists

Kebijakan ini sekarang memberikan izin untuk mengembalikan daftar AWS DataSync agen, lokasi DataSync sumber dan tujuan, serta DataSync tugas dalam daftar informasi ringkasan tentang ruang nama dan layanan yang terkait dengan satu atau beberapa ruang nama tertentu dalam Akun AWS; dan daftar semua daftar kontak Amazon Simple Email Service (Amazon SES) yang tersedia di. Akun AWS AWS Cloud Map Akun AWS

22 Agustus 2022

AWS_ConfigRole— Tambah datasync:ListAgents, datasync:ListLocations, datasync:ListTasks, servicediscovery:ListNamespaces, servicediscovery:ListServices, and ses:ListContactLists

Kebijakan ini sekarang memberikan izin untuk mengembalikan daftar AWS DataSync agen, lokasi DataSync sumber dan tujuan, serta DataSync tugas dalam daftar informasi ringkasan tentang ruang nama dan layanan yang terkait dengan satu atau beberapa ruang nama tertentu dalam Akun AWS; dan daftar semua daftar kontak Amazon Simple Email Service (Amazon SES) yang tersedia di. Akun AWS AWS Cloud Map Akun AWS

22 Agustus 2022

ConfigConformsServiceRolePolicy— Tambah cloudwatch:PutMetricData

Kebijakan ini sekarang memberikan izin untuk mempublikasikan titik data metrik ke Amazon CloudWatch.

25 Juli 2022

AWSConfigServiceRolePolicy— Tambah amplifyuibuilder:ExportThemes, amplifyuibuilder:GetTheme, appconfig:GetApplication, appconfig:GetApplication, appconfig:GetConfigurationProfile, appconfig:GetConfigurationProfile, appconfig:GetDeployment, appconfig:GetDeploymentStrategy, appconfig:GetEnvironment, appconfig:GetHostedConfigurationVersion, appconfig:ListTagsForResource, appsync:GetGraphqlApi, appsync:ListGraphqlApis, billingconductor: ListPricingRulesAssociatedToPricingPlan, billingconductor:ListAccountAssociations, billingconductor:ListBillingGroups, billingconductor:ListCustomLineItems, billingconductor:ListPricingPlans, billingconductor:ListPricingRules, billingconductor:ListTagsForResource, datasync:DescribeAgent, datasync:DescribeLocationEfs, datasync:DescribeLocationFsxLustre, datasync:DescribeLocationHdfs, datasync:DescribeLocationNfs, datasync:DescribeLocationObjectStorage, datasync:DescribeLocationS3, datasync:DescribeLocationSmb, datasync:DescribeTask, datasync:ListTagsForResource, ecr:DescribePullThroughCacheRules, ecr:DescribeRegistry, ecr:GetRegistryPolicy, elasticache:DescribeCacheParameters, elasticloadbalancing:DescribeListenerCertificates, elasticloadbalancing:DescribeTargetGroupAttributes, elasticloadbalancing:DescribeTargetGroups, elasticloadbalancing:DescribeTargetHealth, events:DescribeApiDestination, events:DescribeArchive, fms:GetNotificationChannel, fms:GetPolicy, fms:ListPolicies, fms:ListTagsForResource, fsx:DescribeVolumes, geo:DescribeGeofenceCollection, geo:DescribeMap, geo:DescribePlaceIndex, geo:DescribeRouteCalculator, geo:DescribeTracker, geo:ListTrackerConsumers, glue:BatchGetJobs, glue:BatchGetWorkflows, glue:GetCrawler, glue:GetCrawlers, glue:GetJob, glue:GetJobs, glue:GetWorkflow, imagebuilder: GetComponent, imagebuilder: ListComponentBuildVersions, imagebuilder: ListComponents, imagebuilder:GetDistributionConfiguration, imagebuilder:GetInfrastructureConfiguration, imagebuilder:ListDistributionConfigurations, imagebuilder:ListInfrastructureConfigurations, kafka:DescribeClusterV2, kafka:ListClustersV2, kinesisanalytics:DescribeApplication, kinesisanalytics:ListTagsForResource, quicksight:DescribeDataSource, quicksight:DescribeDataSourcePermissions, quicksight:ListTagsForResource, rekognition:DescribeStreamProcessor, rekognition:ListTagsForResource, robomaker:DescribeRobotApplication, robomaker:DescribeSimulationApplication, s3:GetStorageLensConfiguration, s3:GetStorageLensConfigurationTagging, servicediscovery:GetInstance, servicediscovery:GetNamespace, servicediscovery:GetService, servicediscovery:ListTagsForResource, ses:DescribeReceiptRule, ses:DescribeReceiptRuleSet, ses:GetContactList, ses:GetEmailTemplate, ses:GetTemplate, and sso:GetInlinePolicyForPermissionSet

Kebijakan ini sekarang mendukung izin tambahan untuk Amazon Elastic Container Service (Amazon ECS), Amazon, Amazon FSx ElastiCache EventBridge, Amazon Managed Service untuk Apache Flink, Layanan Lokasi Amazon, Streaming Terkelola Amazon untuk Apache Kafka, Amazon Quick, Amazon Rekognition,, Layanan Penyimpanan Sederhana Amazon (Amazon S3) AWS RoboMaker, Amazon Simple Email Service (Amazon SES),,,,, AWS Amplify, (Pusat Identitas IAM) AWS AppConfig AWS AppSync AWS Billing Conductor AWS DataSync AWS Firewall Manager, Pembuat Gambar EC2 AWS Glue, AWS IAM Identity Center Elastic dan Menyeimbangkan.

15 Juli 2022

AWS_ConfigRole— Tambah amplifyuibuilder:ExportThemes, amplifyuibuilder:GetTheme, appconfig:GetApplication, appconfig:GetApplication, appconfig:GetConfigurationProfile, appconfig:GetConfigurationProfile, appconfig:GetDeployment, appconfig:GetDeploymentStrategy, appconfig:GetEnvironment, appconfig:GetHostedConfigurationVersion, appconfig:ListTagsForResource, appsync:GetGraphqlApi, appsync:ListGraphqlApis, billingconductor: ListPricingRulesAssociatedToPricingPlan, billingconductor:ListAccountAssociations, billingconductor:ListBillingGroups, billingconductor:ListCustomLineItems, billingconductor:ListPricingPlans, billingconductor:ListPricingRules, billingconductor:ListTagsForResource, datasync:DescribeAgent, datasync:DescribeLocationEfs, datasync:DescribeLocationFsxLustre, datasync:DescribeLocationHdfs, datasync:DescribeLocationNfs, datasync:DescribeLocationObjectStorage, datasync:DescribeLocationS3, datasync:DescribeLocationSmb, datasync:DescribeTask, datasync:ListTagsForResource, ecr:DescribePullThroughCacheRules, ecr:DescribeRegistry, ecr:GetRegistryPolicy, elasticache:DescribeCacheParameters, elasticloadbalancing:DescribeListenerCertificates, elasticloadbalancing:DescribeTargetGroupAttributes, elasticloadbalancing:DescribeTargetGroups, elasticloadbalancing:DescribeTargetHealth, events:DescribeApiDestination, events:DescribeArchive, fms:GetNotificationChannel, fms:GetPolicy, fms:ListPolicies, fms:ListTagsForResource, fsx:DescribeVolumes, geo:DescribeGeofenceCollection, geo:DescribeMap, geo:DescribePlaceIndex, geo:DescribeRouteCalculator, geo:DescribeTracker, geo:ListTrackerConsumers, glue:BatchGetJobs, glue:BatchGetWorkflows, glue:GetCrawler, glue:GetCrawlers, glue:GetJob, glue:GetJobs, glue:GetWorkflow, imagebuilder: GetComponent, imagebuilder: ListComponentBuildVersions, imagebuilder: ListComponents, imagebuilder:GetDistributionConfiguration, imagebuilder:GetInfrastructureConfiguration, imagebuilder:ListDistributionConfigurations, imagebuilder:ListInfrastructureConfigurations, kafka:DescribeClusterV2, kafka:ListClustersV2, kinesisanalytics:DescribeApplication, kinesisanalytics:ListTagsForResource, quicksight:DescribeDataSource, quicksight:DescribeDataSourcePermissions, quicksight:ListTagsForResource, rekognition:DescribeStreamProcessor, rekognition:ListTagsForResource, robomaker:DescribeRobotApplication, robomaker:DescribeSimulationApplication, s3:GetStorageLensConfiguration, s3:GetStorageLensConfigurationTagging, servicediscovery:GetInstance, servicediscovery:GetNamespace, servicediscovery:GetService, servicediscovery:ListTagsForResource, ses:DescribeReceiptRule, ses:DescribeReceiptRuleSet, ses:GetContactList, ses:GetEmailTemplate, ses:GetTemplate, and sso:GetInlinePolicyForPermissionSet

Kebijakan ini sekarang mendukung izin tambahan untuk Amazon Elastic Container Service (Amazon ECS), Amazon, Amazon FSx ElastiCache EventBridge, Amazon Managed Service untuk Apache Flink, Layanan Lokasi Amazon, Streaming Terkelola Amazon untuk Apache Kafka, Amazon Quick, Amazon Rekognition,, Layanan Penyimpanan Sederhana Amazon (Amazon S3) AWS RoboMaker, Amazon Simple Email Service (Amazon SES),,,,, AWS Amplify, (Pusat Identitas IAM) AWS AppConfig AWS AppSync AWS Billing Conductor AWS DataSync AWS Firewall Manager, Pembuat Gambar EC2 AWS Glue, AWS IAM Identity Center Elastic dan Menyeimbangkan.

15 Juli 2022

AWSConfigServiceRolePolicy— Tambah athena:GetDataCatalog, athena:ListDataCatalogs, athena:ListTagsForResource, detective:ListGraphs, detective:ListTagsForResource, glue:BatchGetDevEndpoints, glue:GetDevEndpoint, glue:GetDevEndpoints, glue:GetSecurityConfiguration, glue:GetSecurityConfigurations, glue:GetTags glue:GetWorkGroup, glue:ListCrawlers, glue:ListDevEndpoints, glue:ListJobs, glue:ListMembers, glue:ListWorkflows, glue:ListWorkGroups, guardduty:GetFilter, guardduty:GetIPSet, guardduty:GetThreatIntelSet, guardduty:GetMembers, guardduty:ListFilters, guardduty:ListIPSets, guardduty:ListTagsForResource, guardduty:ListThreatIntelSets, macie:GetMacieSession, ram:GetResourceShareAssociations, ram:GetResourceShares, ses:GetConfigurationSet, ses:GetConfigurationSetEventDestinations, ses:ListConfigurationSets, sso:DescribeInstanceAccessControlAttributeConfiguration, sso:DescribePermissionSet, sso:ListManagedPoliciesInPermissionSet, sso:ListPermissionSets, and sso:ListTagsForResource

Kebijakan ini sekarang memberikan izin untuk mendapatkan katalog data Amazon Athena tertentu, mencantumkan katalog data Athena dalam Akun AWS, dan daftar tag yang terkait dengan kelompok kerja Athena atau sumber daya katalog data; untuk mendapatkan daftar grafik perilaku Amazon Detective dan tag daftar untuk grafik perilaku Detektif; mendapatkan daftar metadata sumber daya untuk daftar nama titik akhir AWS Glue pengembangan tertentu, dapatkan informasi tentang titik akhir AWS Glue pengembangan tertentu, dapatkan semua titik akhir AWS Glue pengembangan dalam, ambil keamanan yang Akun AWS ditentukan AWS Glue konfigurasi, dapatkan semua konfigurasi AWS Glue keamanan, dapatkan daftar tag yang terkait dengan AWS Glue sumber daya, dapatkan informasi tentang AWS Glue kelompok kerja dengan nama yang ditentukan, ambil nama semua sumber daya AWS Glue crawler dalam AWS akun, dapatkan nama semua AWS Glue DevEndpoint sumber daya dalam Akun AWS, daftar nama semua sumber daya AWS Glue pekerjaan di sebuah Akun AWS, dapatkan detail tentang akun AWS Glue anggota, daftar nama alur AWS Glue kerja yang dibuat di akun, dan daftar AWS Glue grup kerja yang tersedia untuk akun; untuk mengambil detail tentang GuardDuty filter Amazon, mengambil GuardDuty IPset, mengambil, mengambil akun GuardDuty anggota, mendapatkan daftar GuardDuty filter, mendapatkan IPset layanan, mengambil tag untuk GuardDuty Layanan, dan mendapatkan GuardDuty layanan; untuk mendapatkan status saat ini dan pengaturan konfigurasi untuk akun Amazon Macie; untuk mengambil sumber daya dan asosiasi utama untuk AWS Resource Access Manager (AWS RAM) berbagi sumber daya dan mengambil detail tentang pembagian sumber AWS RAM daya; untuk GuardDuty ThreatIntelSet ThreatIntelSets GuardDuty dapatkan informasi tentang kumpulan konfigurasi Amazon Simple Email Service (Amazon SES) yang ada, dapatkan daftar tujuan acara yang terkait dengan kumpulan konfigurasi Amazon SES, dan daftar semua set konfigurasi yang terkait dengan akun Amazon SES; dan untuk mendapatkan daftar atribut direktori Identity Center, dapatkan detail kumpulan AWS IAM Identity Center izin, dapatkan kebijakan yang dikelola IAM yang dilampirkan ke kumpulan izin Pusat Identitas IAM tertentu, dapatkan izin yang ditetapkan untuk Pusat Identitas IAM contoh, dan dapatkan tag untuk Pusat Identitas IAM sumber daya.

31 Mei 2022

AWS_ConfigRole— Tambah athena:GetDataCatalog, athena:ListDataCatalogs, athena:ListTagsForResource, detective:ListGraphs, detective:ListTagsForResource, glue:BatchGetDevEndpoints, glue:GetDevEndpoint, glue:GetDevEndpoints, glue:GetSecurityConfiguration, glue:GetSecurityConfigurations, glue:GetTags glue:GetWorkGroup, glue:ListCrawlers, glue:ListDevEndpoints, glue:ListJobs, glue:ListMembers, glue:ListWorkflows, glue:ListWorkGroups, guardduty:GetFilter, guardduty:GetIPSet, guardduty:GetThreatIntelSet, guardduty:GetMembers, guardduty:ListFilters, guardduty:ListIPSets, guardduty:ListTagsForResource, guardduty:ListThreatIntelSets, macie:GetMacieSession, ram:GetResourceShareAssociations, ram:GetResourceShares, ses:GetConfigurationSet, ses:GetConfigurationSetEventDestinations, ses:ListConfigurationSets, sso:DescribeInstanceAccessControlAttributeConfiguration, sso:DescribePermissionSet, sso:ListManagedPoliciesInPermissionSet, sso:ListPermissionSets, and sso:ListTagsForResource

Kebijakan ini sekarang memberikan izin untuk mendapatkan katalog data Amazon Athena tertentu, mencantumkan katalog data Athena dalam Akun AWS, dan daftar tag yang terkait dengan kelompok kerja Athena atau sumber daya katalog data; untuk mendapatkan daftar grafik perilaku Amazon Detective dan tag daftar untuk grafik perilaku Detektif; mendapatkan daftar metadata sumber daya untuk daftar nama titik akhir AWS Glue pengembangan tertentu, dapatkan informasi tentang titik akhir AWS Glue pengembangan tertentu, dapatkan semua titik akhir AWS Glue pengembangan dalam, ambil keamanan yang Akun AWS ditentukan AWS Glue konfigurasi, dapatkan semua konfigurasi AWS Glue keamanan, dapatkan daftar tag yang terkait dengan AWS Glue sumber daya, dapatkan informasi tentang AWS Glue kelompok kerja dengan nama yang ditentukan, ambil nama semua sumber daya AWS Glue crawler dalam AWS akun, dapatkan nama semua AWS Glue DevEndpoint sumber daya dalam Akun AWS, daftar nama semua sumber daya AWS Glue pekerjaan di sebuah Akun AWS, dapatkan detail tentang akun AWS Glue anggota, daftar nama alur AWS Glue kerja yang dibuat di akun, dan daftar AWS Glue grup kerja yang tersedia untuk akun; untuk mengambil detail tentang GuardDuty filter Amazon, mengambil GuardDuty IPset, mengambil, mengambil akun GuardDuty anggota, mendapatkan daftar GuardDuty filter, mendapatkan IPset layanan, mengambil tag untuk GuardDuty Layanan, dan mendapatkan GuardDuty layanan; untuk mendapatkan status saat ini dan pengaturan konfigurasi untuk akun Amazon Macie; untuk mengambil sumber daya dan asosiasi utama untuk AWS Resource Access Manager (AWS RAM) berbagi sumber daya dan mengambil detail tentang pembagian sumber AWS RAM daya; untuk GuardDuty ThreatIntelSet ThreatIntelSets GuardDuty dapatkan informasi tentang kumpulan konfigurasi Amazon Simple Email Service (Amazon SES) yang ada, dapatkan daftar tujuan acara yang terkait dengan kumpulan konfigurasi Amazon SES, dan daftar semua set konfigurasi yang terkait dengan akun Amazon SES; dan untuk mendapatkan daftar atribut direktori Identity Center, dapatkan detail kumpulan AWS IAM Identity Center izin, dapatkan kebijakan yang dikelola IAM yang dilampirkan ke kumpulan izin Pusat Identitas IAM tertentu, dapatkan izin yang ditetapkan untuk Pusat Identitas IAM contoh, dan dapatkan tag untuk Pusat Identitas IAM sumber daya.

31 Mei 2022

AWSConfigServiceRolePolicy— Tambah cloudformation:GetResource, cloudformation:ListResources, cloudtrail:GetEventDataStore, cloudtrail:ListEventDataStores, dax:DescribeParameterGroups, dax:DescribeParameters, dax:DescribeSubnetGroups, DMS:DescribeReplicationTasks, and organizations:ListPolicies

Kebijakan ini sekarang memberikan izin untuk mendapatkan informasi tentang semua atau penyimpanan data AWS CloudTrail peristiwa tertentu (EDS), mendapatkan informasi tentang semua atau AWS CloudFormation sumber daya tertentu, mendapatkan daftar grup parameter atau grup subnet DynamoDB Accelerator (DAX), mendapatkan informasi tentang tugas replikasi AWS Database Migration Service (AWS DMS) untuk akun Anda di wilayah yang diakses saat ini, dan mendapatkan daftar semua kebijakan dalam AWS Organizations jenis tertentu.

7 April 2022

AWS_ConfigRole— Tambahkan cloudformation:GetResource, cloudformation:ListResources, cloudtrail:GetEventDataStore, cloudtrail:ListEventDataStores, dax:DescribeParameterGroups, dax:DescribeParameters, dax:DescribeSubnetGroups, DMS:DescribeReplicationTasks, and organizations:ListPolicies

Kebijakan ini sekarang memberikan izin untuk mendapatkan informasi tentang semua atau penyimpanan data AWS CloudTrail peristiwa tertentu (EDS), mendapatkan informasi tentang semua atau AWS CloudFormation sumber daya tertentu, mendapatkan daftar grup parameter atau grup subnet DynamoDB Accelerator (DAX), mendapatkan informasi tentang tugas replikasi AWS Database Migration Service (AWS DMS) untuk akun Anda di wilayah yang diakses saat ini, dan mendapatkan daftar semua kebijakan dalam AWS Organizations jenis tertentu.

7 April 2022

AWSConfigServiceRolePolicy— Tambahkan backup-gateway:ListTagsForResource, backup-gateway:ListVirtualMachines, batch:DescribeComputeEnvironments, batch:DescribeJobQueues, batch:ListTagsForResource, dax:ListTags, dms:DescribeCertificates, dynamodb:DescribeGlobalTable, dynamodb:DescribeGlobalTableSettings, ec2:DescribeClientVpnAuthorizationRules, ec2:DescribeClientVpnEndpoints, ec2:DescribeDhcpOptions, ec2:DescribeFleets, ec2:DescribeNetworkAcls, ec2:DescribePlacementGroups, ec2:DescribeSpotFleetRequests, ec2:DescribeVolumeAttribute, ec2:DescribeVolumes, eks:DescribeFargateProfile, eks:ListFargateProfiles, eks:ListTagsForResource, fsx:ListTagsForResource, guardduty:ListOrganizationAdminAccounts, kms:ListAliases, opsworks:DescribeLayers, opsworks:DescribeStacks, opsworks:ListTags, rds:DescribeDBClusterParameterGroups, rds:DescribeDBClusterParameters, states:DescribeActivity, states:ListActivities, wafv2:GetRuleGroup, wafv2:ListRuleGroups, wafv2:ListTagsForResource, workspaces:DescribeConnectionAliases, workspaces:DescribeTags, and workspaces:DescribeWorkspaces

Kebijakan ini sekarang mendukung izin tambahan untuk AWS Backup, AWS Batch, DynamoDB Accelerator,, Amazon DynamoDB AWS Database Migration Service, Amazon Elastic Compute Cloud (Amazon EC2), Amazon Elastic Kubernetes Service, Amazon FSx, Amazon,,, Amazon Relational Database Service, V2 GuardDuty AWS Key Management Service AWS OpsWorks, dan Amazon. AWS WAF WorkSpaces

Maret 14, 2022

AWS_ConfigRole— Tambahkan backup-gateway:ListTagsForResource, backup-gateway:ListVirtualMachines, batch:DescribeComputeEnvironments, batch:DescribeJobQueues, batch:ListTagsForResource, dax:ListTags, dms:DescribeCertificates, dynamodb:DescribeGlobalTable, dynamodb:DescribeGlobalTableSettings, ec2:DescribeClientVpnAuthorizationRules, ec2:DescribeClientVpnEndpoints, ec2:DescribeDhcpOptions, ec2:DescribeFleets, ec2:DescribeNetworkAcls, ec2:DescribePlacementGroups, ec2:DescribeSpotFleetRequests, ec2:DescribeVolumeAttribute, ec2:DescribeVolumes, eks:DescribeFargateProfile, eks:ListFargateProfiles, eks:ListTagsForResource, fsx:ListTagsForResource, guardduty:ListOrganizationAdminAccounts, kms:ListAliases, opsworks:DescribeLayers, opsworks:DescribeStacks, opsworks:ListTags, rds:DescribeDBClusterParameterGroups, rds:DescribeDBClusterParameters, states:DescribeActivity, states:ListActivities, wafv2:GetRuleGroup, wafv2:ListRuleGroups, wafv2:ListTagsForResource, workspaces:DescribeConnectionAliases, workspaces:DescribeTags, and workspaces:DescribeWorkspaces

Kebijakan ini sekarang mendukung izin tambahan untuk AWS Backup, AWS Batch, DynamoDB Accelerator,, Amazon DynamoDB AWS Database Migration Service, Amazon Elastic Compute Cloud (Amazon EC2), Amazon Elastic Kubernetes Service, Amazon FSx, Amazon,,, Amazon Relational Database Service, V2 GuardDuty AWS Key Management Service AWS OpsWorks, dan Amazon. AWS WAF WorkSpaces

Maret 14, 2022

AWSConfigServiceRolePolicy— Tambahkan elasticbeanstalk:DescribeEnvironments, elasticbeanstalk:DescribeConfigurationSettings, account:GetAlternateContact, organizations:DescribePolicy, organizations:ListParents, organizations:ListPoliciesForTarget, es:GetCompatibleElasticsearchVersions, rds:DescribeOptionGroups, rds:DescribeOptionGroups, es:GetCompatibleVersions, codedeploy:GetDeploymentConfig, ecr-public:GetRepositoryPolicy, access-analyzer:GetArchiveRule, and ecs:ListTaskDefinitionFamilies

Kebijakan ini sekarang memberikan izin untuk mendapatkan detail tentang lingkungan Elastic Beanstalk dan deskripsi pengaturan untuk kumpulan konfigurasi Elastic Beanstalk yang ditentukan, mendapatkan peta OpenSearch atau versi Elasticsearch, menjelaskan grup opsi Amazon RDS yang tersedia untuk database, dan mendapatkan informasi tentang konfigurasi penerapan. CodeDeploy Kebijakan ini juga sekarang memberikan izin untuk mengambil kontak alternatif tertentu yang dilampirkan pada sebuah Akun AWS, mengambil informasi tentang AWS Organizations kebijakan, mengambil kebijakan repositori Amazon ECR, mengambil informasi tentang AWS Config aturan yang diarsipkan, mengambil daftar keluarga definisi tugas Amazon ECS, mencantumkan root atau unit organisasi induk (OU) dari OU anak atau akun tertentu, dan mencantumkan kebijakan yang dilampirkan ke root target, unit organisasi, atau akun yang ditentukan.

Februari 10, 2022

AWS_ConfigRole— Tambahkan elasticbeanstalk:DescribeEnvironments, elasticbeanstalk:DescribeConfigurationSettings, account:GetAlternateContact, organizations:DescribePolicy, organizations:ListParents, organizations:ListPoliciesForTarget, es:GetCompatibleElasticsearchVersions, rds:DescribeOptionGroups, rds:DescribeOptionGroups, es:GetCompatibleVersions, codedeploy:GetDeploymentConfig, ecr-public:GetRepositoryPolicy, access-analyzer:GetArchiveRule, and ecs:ListTaskDefinitionFamilies

Kebijakan ini sekarang memberikan izin untuk mendapatkan detail tentang lingkungan Elastic Beanstalk dan deskripsi pengaturan untuk kumpulan konfigurasi Elastic Beanstalk yang ditentukan, mendapatkan peta OpenSearch atau versi Elasticsearch, menjelaskan grup opsi Amazon RDS yang tersedia untuk database, dan mendapatkan informasi tentang konfigurasi penerapan. CodeDeploy Kebijakan ini juga sekarang memberikan izin untuk mengambil kontak alternatif tertentu yang dilampirkan pada sebuah Akun AWS, mengambil informasi tentang AWS Organizations kebijakan, mengambil kebijakan repositori Amazon ECR, mengambil informasi tentang AWS Config aturan yang diarsipkan, mengambil daftar keluarga definisi tugas Amazon ECS, mencantumkan root atau unit organisasi induk (OU) dari OU anak atau akun tertentu, dan mencantumkan kebijakan yang dilampirkan ke root target, unit organisasi, atau akun yang ditentukan.

Februari 10, 2022

AWSConfigServiceRolePolicy— Tambahkan logs:CreateLogStream, logs:CreateLogGroup, and logs:PutLogEvent

Kebijakan ini sekarang memberikan izin untuk membuat grup dan aliran CloudWatch log Amazon serta menulis log ke aliran log yang dibuat.

Desember 15, 2021

AWS_ConfigRole— Tambahkan logs:CreateLogStream, logs:CreateLogGroup, and logs:PutLogEvent

Kebijakan ini sekarang memberikan izin untuk membuat grup dan aliran CloudWatch log Amazon serta menulis log ke aliran log yang dibuat.

Desember 15, 2021

AWSConfigServiceRolePolicy— Tambah es:DescribeDomain, es:DescribeDomains, rds:DescribeDBParameters, and, elasticache:DescribeSnapshots

Kebijakan ini sekarang memberikan izin untuk mendapatkan detail tentang OpenSearch Layanan Amazon (OpenSearch Layanan) domain/domains dan untuk mendapatkan daftar parameter terperinci untuk grup parameter DB Layanan Database Relasional Amazon (Amazon RDS) tertentu. Kebijakan ini juga memberikan izin untuk mendapatkan detail tentang ElastiCache snapshot Amazon.

8 September 2021

AWS_ConfigRole— Tambah es:DescribeDomain, es:DescribeDomains, rds:DescribeDBParameters, and, elasticache:DescribeSnapshots

Kebijakan ini sekarang memberikan izin untuk mendapatkan detail tentang OpenSearch Layanan Amazon (OpenSearch Layanan) domain/domains dan untuk mendapatkan daftar parameter terperinci untuk grup parameter DB Layanan Database Relasional Amazon (Amazon RDS) tertentu. Kebijakan ini juga memberikan izin untuk mendapatkan detail tentang ElastiCache snapshot Amazon.

8 September 2021

AWSConfigServiceRolePolicy— Tambahlogs:ListTagsLogGroup, states:ListTagsForResource, states:ListStateMachines, states:DescribeStateMachine, dan izin tambahan untuk jenis AWS sumber daya

Kebijakan ini sekarang memberikan izin untuk mencantumkan tag untuk grup log, tag daftar untuk mesin status, dan daftar semua mesin status. Kebijakan ini sekarang memberikan izin untuk mendapatkan detail tentang mesin status. Kebijakan ini juga sekarang mendukung izin tambahan untuk Amazon EC2 Systems Manager (SSM), Amazon Elastic Container Registry, Amazon FSx, Amazon Data Firehose, Amazon Managed Streaming untuk Apache Kafka (Amazon MSK), Amazon Relational Database Service (Amazon RDS), Amazon Route 53, Amazon SageMaker AI, Amazon Simple Notification Service,, dan. AWS Database Migration Service AWS Global Accelerator AWS Storage Gateway

28 Juli 2021

AWS_ConfigRole— Tambahkan logs:ListTagsLogGroup, states:ListTagsForResource, states:ListStateMachines, states:DescribeStateMachine, dan izin tambahan untuk jenis AWS sumber daya

Kebijakan ini sekarang memberikan izin untuk mencantumkan tag untuk grup log, tag daftar untuk mesin status, dan daftar semua mesin status. Kebijakan ini sekarang memberikan izin untuk mendapatkan detail tentang mesin status. Kebijakan ini juga sekarang mendukung izin tambahan untuk Amazon EC2 Systems Manager (SSM), Amazon Elastic Container Registry, Amazon FSx, Amazon Data Firehose, Amazon Managed Streaming untuk Apache Kafka (Amazon MSK), Amazon Relational Database Service (Amazon RDS), Amazon Route 53, Amazon SageMaker AI, Amazon Simple Notification Service,, dan. AWS Database Migration Service AWS Global Accelerator AWS Storage Gateway

28 Juli 2021

AWSConfigServiceRolePolicy— Tambah ssm:DescribeDocumentPermission dan izin tambahan untuk jenis AWS sumber daya

Kebijakan ini sekarang memberikan izin untuk melihat izin AWS Systems Manager dokumen dan informasi tentang Penganalisis Akses IAM. Kebijakan ini sekarang mendukung jenis AWS sumber daya tambahan untuk Amazon Kinesis, Amazon ElastiCache, Amazon EMR,, Amazon Route 53 AWS Network Firewall, dan Amazon Relational Database Service (Amazon RDS). Perubahan izin ini memungkinkan AWS Config untuk memanggil API read-only yang diperlukan untuk mendukung jenis sumber daya ini. Kebijakan ini juga sekarang mendukung pemfilteran fungsi Lambda @Edge untuk aturan terkelola lambda- AWS Config inside-vpc.

8 Juni 2021

AWS_ConfigRole— Tambah ssm:DescribeDocumentPermission dan izin tambahan untuk jenis AWS sumber daya

Kebijakan ini sekarang memberikan izin untuk melihat izin AWS Systems Manager dokumen dan informasi tentang Penganalisis Akses IAM. Kebijakan ini sekarang mendukung jenis AWS sumber daya tambahan untuk Amazon Kinesis, Amazon ElastiCache, Amazon EMR,, Amazon Route 53 AWS Network Firewall, dan Amazon Relational Database Service (Amazon RDS). Perubahan izin ini memungkinkan AWS Config untuk memanggil API read-only yang diperlukan untuk mendukung jenis sumber daya ini. Kebijakan ini juga sekarang mendukung pemfilteran fungsi Lambda @Edge untuk aturan terkelola lambda- AWS Config inside-vpc.

8 Juni 2021

AWSConfigServiceRolePolicy— Tambahkan apigateway:GET izin untuk membuat panggilan GET read-only ke API Gateway dan s3:GetAccessPointPolicy izin serta s3:GetAccessPointPolicyStatus izin untuk memanggil API read-only Amazon S3

Kebijakan ini sekarang memberikan izin yang memungkinkan AWS Config untuk membuat panggilan GET read-only ke API Gateway untuk mendukung A AWS Config turan untuk API Gateway. Kebijakan ini juga menambahkan izin yang memungkinkan AWS Config untuk memanggil API read-only Amazon Simple Storage Service (Amazon S3), yang diperlukan untuk mendukung jenis sumber daya baruAWS::S3::AccessPoint.

10 Mei 2021

AWS_ ConfigRole — Tambahkan apigateway:GET izin untuk membuat panggilan GET read-only ke API Gateway dan s3:GetAccessPointPolicy s3:GetAccessPointPolicyStatus izin serta izin untuk memanggil API read-only Amazon S3

Kebijakan ini sekarang memberikan izin yang memungkinkan AWS Config untuk membuat panggilan GET read-only ke API Gateway untuk mendukung Gateway API. AWS Config Kebijakan ini juga menambahkan izin yang memungkinkan AWS Config untuk memanggil API read-only Amazon Simple Storage Service (Amazon S3), yang diperlukan untuk mendukung jenis sumber daya baruAWS::S3::AccessPoint.

10 Mei 2021

AWSConfigServiceRolePolicy— Tambahkan ssm:ListDocuments izin dan izin tambahan untuk jenis AWS sumber daya

Kebijakan ini sekarang memberikan izin untuk melihat informasi tentang dokumen AWS Systems Manager tertentu. Kebijakan ini juga sekarang mendukung jenis AWS sumber daya tambahan untuk AWS Backup, Amazon Elastic File System, Amazon ElastiCache, Amazon Simple Storage Service (Amazon S3), Amazon Elastic Compute Cloud (Amazon EC2), Amazon Kinesis, Amazon SageMaker AI AWS Database Migration Service, dan Amazon Route 53. Perubahan izin ini memungkinkan AWS Config untuk memanggil API read-only yang diperlukan untuk mendukung jenis sumber daya ini.

1 April 2021

AWS_ConfigRole— Tambahkan ssm:ListDocuments izin dan izin tambahan untuk jenis AWS sumber daya

Kebijakan ini sekarang memberikan izin untuk melihat informasi tentang dokumen AWS Systems Manager tertentu. Kebijakan ini juga sekarang mendukung jenis AWS sumber daya tambahan untuk AWS Backup, Amazon Elastic File System, Amazon ElastiCache, Amazon Simple Storage Service (Amazon S3), Amazon Elastic Compute Cloud (Amazon EC2), Amazon Kinesis, Amazon SageMaker AI AWS Database Migration Service, dan Amazon Route 53. Perubahan izin ini memungkinkan AWS Config untuk memanggil API read-only yang diperlukan untuk mendukung jenis sumber daya ini.

1 April 2021

AWSConfigRoletidak digunakan lagi

AWSConfigRoletidak digunakan lagi. Kebijakan penggantian adalah AWS_ConfigRole

1 April 2021

AWS Config mulai melacak perubahan

AWS Config mulai melacak perubahan untuk kebijakan yang AWS dikelolanya.

1 April 2021