翻訳は機械翻訳により提供されています。提供された翻訳内容と英語版の間で齟齬、不一致または矛盾がある場合、英語版が優先します。
AWSWAFConsoleFullAccess
説明: 経由で AWS WAF へのフルアクセスを提供します AWS マネジメントコンソール。このポリシーは、Amazon CloudFront ディストリビューションを一覧表示および更新するアクセス許可、 AWS Elastic Load Balancing でロードバランサーを表示するアクセス許可、Amazon API Gateway REST APIs およびステージを表示するアクセス許可、Amazon CloudWatch メトリクスを一覧表示および表示するアクセス許可、アカウント内で有効になっているリージョンを表示するアクセス許可も付与することに注意してください。
AWSWAFConsoleFullAccess は AWS マネージドポリシーです。
このポリシーを使用すると
ユーザー、グループおよびロールに AWSWAFConsoleFullAccess をアタッチできます。
ポリシーの詳細
-
タイプ: AWS 管理ポリシー
-
作成日時: 2020 年 4 月 6 日 18:38 UTC
-
編集日時: 2025 年 11 月 19 日 02:34 UTC
-
ARN:
arn:aws:iam::aws:policy/AWSWAFConsoleFullAccess
ポリシーのバージョン
ポリシーのバージョン: v12 (デフォルト)
ポリシーのデフォルトバージョンは、ポリシーのアクセス許可を定義するバージョンです。ポリシーを持つユーザーまたはロールが AWS リソースへのアクセスをリクエストすると、 はポリシーのデフォルトバージョン AWS をチェックして、リクエストを許可するかどうかを決定します。
JSON ポリシードキュメント
{ "Version" : "2012-10-17", "Statement" : [ { "Sid" : "AllowUseOfAWSWAFClassic", "Effect" : "Allow", "Action" : [ "waf:*", "waf-regional:*" ], "Resource" : [ "arn:aws:waf::*:bytematchset/*", "arn:aws:waf::*:ipset/*", "arn:aws:waf::*:ratebasedrule/*", "arn:aws:waf::*:rule/*", "arn:aws:waf::*:sizeconstraintset/*", "arn:aws:waf::*:sqlinjectionset/*", "arn:aws:waf::*:webacl/*", "arn:aws:waf::*:xssmatchset/*", "arn:aws:waf::*:regexmatch/*", "arn:aws:waf::*:regexpatternset/*", "arn:aws:waf::*:geomatchset/*", "arn:aws:waf::*:rulegroup/*", "arn:aws:waf:*:*:changetoken/*", "arn:aws:waf-regional:*:*:bytematchset/*", "arn:aws:waf-regional:*:*:ipset/*", "arn:aws:waf-regional:*:*:ratebasedrule/*", "arn:aws:waf-regional:*:*:rule/*", "arn:aws:waf-regional:*:*:sizeconstraintset/*", "arn:aws:waf-regional:*:*:sqlinjectionset/*", "arn:aws:waf-regional:*:*:webacl/*", "arn:aws:waf-regional:*:*:xssmatchset/*", "arn:aws:waf-regional:*:*:regexmatch/*", "arn:aws:waf-regional:*:*:regexpatternset/*", "arn:aws:waf-regional:*:*:geomatchset/*", "arn:aws:waf-regional:*:*:rulegroup/*", "arn:aws:waf-regional:*:*:changetoken/*" ] }, { "Sid" : "AllowWAFClassicGetWebACLForResource", "Effect" : "Allow", "Action" : [ "waf-regional:GetWebACLForResource" ], "Resource" : "arn:aws:waf-regional:*:*:*/*" }, { "Sid" : "AllowUseOfAWSWAF", "Effect" : "Allow", "Action" : [ "wafv2:*" ], "Resource" : [ "arn:aws:wafv2:*:*:*/webacl/*/*", "arn:aws:wafv2:*:*:*/ipset/*/*", "arn:aws:wafv2:*:*:*/managedruleset/*/*", "arn:aws:wafv2:*:*:*/rulegroup/*/*", "arn:aws:wafv2:*:*:*/regexpatternset/*/*" ] }, { "Sid" : "AllowDisassociateWebACL", "Effect" : "Allow", "Action" : [ "wafv2:DisassociateWebACL" ], "Resource" : "*" }, { "Sid" : "AllowS3ListAllMyBuckets", "Effect" : "Allow", "Action" : [ "s3:ListAllMyBuckets" ], "Resource" : "*" }, { "Sid" : "AllowEC2DescribeRegions", "Effect" : "Allow", "Action" : [ "ec2:DescribeRegions" ], "Resource" : "*" }, { "Sid" : "AllowListActionsForCloudWatch", "Effect" : "Allow", "Action" : [ "cloudwatch:GetMetricData", "cloudwatch:GetMetricStatistics", "cloudwatch:ListMetrics" ], "Resource" : "*" }, { "Sid" : "AllowActionsForCloudFront", "Effect" : "Allow", "Action" : [ "cloudfront:GetDistributionConfig", "cloudfront:GetDistribution", "cloudfront:UpdateDistribution", "cloudfront:AssociateDistributionWebACL", "cloudfront:DisassociateDistributionWebACL" ], "Resource" : "arn:aws:cloudfront::*:distribution/*" }, { "Sid" : "AllowListActionsForCloudFront", "Effect" : "Allow", "Action" : [ "cloudfront:ListDistributions", "cloudfront:ListDistributionsByWebACLId" ], "Resource" : "*" }, { "Sid" : "AllowActionsForCloudFrontTenant", "Effect" : "Allow", "Action" : [ "cloudfront:GetDistributionTenant", "cloudfront:AssociateDistributionTenantWebACL", "cloudfront:DisassociateDistributionTenantWebACL" ], "Resource" : "arn:aws:cloudfront::*:distribution-tenant/*" }, { "Sid" : "AllowListActionsForCloudFrontTenant", "Effect" : "Allow", "Action" : [ "cloudfront:ListDistributionTenants", "cloudfront:ListDistributionTenantsByCustomization" ], "Resource" : "*" }, { "Sid" : "AllowActionsForALB", "Effect" : "Allow", "Action" : [ "elasticloadbalancing:SetWebAcl" ], "Resource" : "arn:aws:elasticloadbalancing:*:*:loadbalancer/app/*/*" }, { "Sid" : "AllowListActionsForALB", "Effect" : "Allow", "Action" : [ "elasticloadbalancing:DescribeLoadBalancers" ], "Resource" : "*" }, { "Sid" : "AllowActionsForAPIGateway", "Effect" : "Allow", "Action" : [ "apigateway:SetWebACL" ], "Resource" : "arn:aws:apigateway:*::/restapis/*/stages/*" }, { "Sid" : "AllowListActionsForAPIGateway", "Effect" : "Allow", "Action" : [ "apigateway:GET" ], "Resource" : "arn:aws:apigateway:*::/*" }, { "Sid" : "AllowActionsForAppSync", "Effect" : "Allow", "Action" : [ "appsync:SetWebACL" ], "Resource" : "arn:aws:appsync:*:*:apis/*" }, { "Sid" : "AllowListActionsForAppSync", "Effect" : "Allow", "Action" : [ "appsync:ListGraphqlApis", "appsync:ListApis" ], "Resource" : "*" }, { "Sid" : "AllowActionsForCognito", "Effect" : "Allow", "Action" : [ "cognito-idp:AssociateWebACL", "cognito-idp:DisassociateWebACL", "cognito-idp:GetWebACLForResource" ], "Resource" : "arn:aws:cognito-idp:*:*:userpool/*" }, { "Sid" : "AllowListActionsForCognito", "Effect" : "Allow", "Action" : [ "cognito-idp:ListUserPools", "cognito-idp:ListResourcesForWebACL" ], "Resource" : "*" }, { "Sid" : "AllowActionsForAppRunner", "Effect" : "Allow", "Action" : [ "apprunner:AssociateWebAcl", "apprunner:DisassociateWebAcl", "apprunner:DescribeWebAclForService" ], "Resource" : "arn:aws:apprunner:*:*:service/*/*" }, { "Sid" : "AllowListActionsForAppRunner", "Effect" : "Allow", "Action" : [ "apprunner:ListServices", "apprunner:ListAssociatedServicesForWebAcl" ], "Resource" : "*" }, { "Sid" : "AllowActionsForAVA", "Effect" : "Allow", "Action" : [ "ec2:AssociateVerifiedAccessInstanceWebAcl", "ec2:DisassociateVerifiedAccessInstanceWebAcl", "ec2:GetVerifiedAccessInstanceWebAcl" ], "Resource" : "arn:aws:ec2:*:*:verified-access-instance/*" }, { "Sid" : "AllowListActionsForAVA", "Effect" : "Allow", "Action" : [ "ec2:DescribeVerifiedAccessInstances", "ec2:DescribeVerifiedAccessInstanceWebAclAssociations" ], "Resource" : "*" }, { "Sid" : "AllowActionsForAmplify", "Effect" : "Allow", "Action" : [ "amplify:AssociateWebACL", "amplify:DisassociateWebACL", "amplify:GetWebACLForResource" ], "Resource" : "arn:aws:amplify:*:*:apps/*" }, { "Sid" : "AllowListActionsForAmplify", "Effect" : "Allow", "Action" : [ "amplify:ListApps", "amplify:ListResourcesForWebACL" ], "Resource" : "*" }, { "Sid" : "AllowLogQueryActions", "Effect" : "Allow", "Action" : [ "logs:StartQuery", "logs:DescribeQueryDefinitions", "logs:GetQueryResults" ], "Resource" : "arn:aws:logs:*:*:log-group:aws-waf-logs-*" }, { "Sid" : "AllowLogGroupDescribeActions", "Effect" : "Allow", "Action" : [ "logs:DescribeResourcePolicies", "logs:DescribeLogGroups" ], "Resource" : "*" }, { "Sid" : "AllowLogDeliverySubscription", "Effect" : "Allow", "Action" : [ "logs:CreateLogDelivery", "logs:DeleteLogDelivery" ], "Resource" : "*" }, { "Sid" : "GrantLogDeliveryPermissionForS3Bucket", "Effect" : "Allow", "Action" : [ "s3:PutBucketPolicy", "s3:GetBucketPolicy" ], "Resource" : [ "arn:aws:s3:::aws-waf-logs-*" ] }, { "Sid" : "GrantLogDeliveryPermissionForCloudWatchLogGroup", "Effect" : "Allow", "Action" : [ "logs:PutResourcePolicy" ], "Resource" : "*", "Condition" : { "ForAnyValue:StringEquals" : { "aws:CalledVia" : [ "wafv2.amazonaws.com" ] } } }, { "Sid" : "AllowListActionForFirehoseStream", "Effect" : "Allow", "Action" : [ "firehose:ListDeliveryStreams" ], "Resource" : "*" }, { "Sid" : "AllowActionsForPricing", "Effect" : "Allow", "Action" : [ "pricing:ListPriceLists", "pricing:GetPriceListFileUrl" ], "Resource" : "*" }, { "Sid" : "AllowMarketplaceViewSubscriptions", "Effect" : "Allow", "Action" : [ "aws-marketplace:ViewSubscriptions" ], "Resource" : "*" }, { "Sid" : "AllowActionsForPricingPlanManager", "Effect" : "Allow", "Action" : [ "pricingplanmanager:GetSubscription", "pricingplanmanager:UpdateSubscription", "pricingplanmanager:CancelSubscription", "pricingplanmanager:CancelSubscriptionChange" ], "Resource" : "arn:aws:pricingplanmanager::*:subscription:*" }, { "Sid" : "AllowListActionsForRoute53", "Effect" : "Allow", "Action" : [ "route53:ListHostedZones", "route53:GetHostedZone" ], "Resource" : "*" }, { "Sid" : "AllowListActionsForPricingPlanManager", "Effect" : "Allow", "Action" : "pricingplanmanager:ListSubscriptions", "Resource" : "*" } ] }