

# Actions, resources, and condition keys for Amazon EC2
<a name="list_amazonec2"></a>

Amazon EC2 (service prefix: `ec2`) provides the following service-specific resources, actions, and condition context keys for use in IAM permission policies.

References:
+ Learn how to [configure this service](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/).
+ View a list of the [API operations available for this service](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/).
+ Learn how to secure this service and its resources by [using IAM](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/security-iam.html) permission policies.

**Topics**
+ [Actions defined by Amazon EC2](#amazonec2-actions-as-permissions)
+ [Resource types defined by Amazon EC2](#amazonec2-resources-for-iam-policies)
+ [Condition keys for Amazon EC2](#amazonec2-policy-keys)

## Actions defined by Amazon EC2
<a name="amazonec2-actions-as-permissions"></a>

You can specify the following actions in the `Action` element of an IAM policy statement. Use policies to grant permissions to perform an operation in AWS. When you use an action in a policy, you usually allow or deny access to the API operation or CLI command with the same name. However, in some cases, a single action controls access to more than one operation. Alternatively, some operations require several different actions.

The **Access level** column of the Actions table describes how the action is classified (List, Read, Permissions management, or Tagging). This classification can help you understand the level of access that an action grants when you use it in a policy. For more information about access levels, see [Access levels in policy summaries](https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_understand-policy-summary-access-level-summaries.html).

The **Resource types** column of the Actions table indicates whether each action supports resource-level permissions. If there is no value for this column, you must specify all resources ("\*") to which the policy applies in the `Resource` element of your policy statement. If the column includes a resource type, then you can specify an ARN of that type in a statement with that action. If the action has one or more required resources, the caller must have permission to use the action with those resources. Required resources are indicated in the table with an asterisk (\*). If you limit resource access with the `Resource` element in an IAM policy, you must include an ARN or pattern for each required resource type. Some actions support multiple resource types. If the resource type is optional (not indicated as required), then you can choose to use one of the optional resource types.

The **Condition keys** column of the Actions table includes keys that you can specify in a policy statement's `Condition` element. For more information on the condition keys that are associated with resources for the service, see the **Condition keys** column of the Resource types table.

The **Dependent actions** column of the Actions table shows additional permissions that may be required to successfully call an action. These permissions may be needed in addition to the permission for the action itself. When an action specifies dependent actions, those dependencies may apply to additional resources defined for that action, not only the first resource listed in the table.

**Note**  
Resource condition keys are listed in the [Resource types](#amazonec2-resources-for-iam-policies) table. You can find a link to the resource type that applies to an action in the **Resource types (\*required)** column of the Actions table. The resource type in the Resource types table includes the **Condition keys** column, which are the resource condition keys that apply to an action in the Actions table.

For details about the columns in the following table, see [Actions table](reference_policies_actions-resources-contextkeys.html#actions_table).


****  


- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AcceptAddressTransfer.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AcceptAddressTransfer.html) **
  - **Description:** Grants permission to accept an Elastic IP address transfer
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-elastic-ip](#amazonec2-elastic-ip)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_AllocationId](#amazonec2-ec2_AllocationId) <br /> [#amazonec2-ec2_Domain](#amazonec2-ec2_Domain) <br /> [#amazonec2-ec2_PublicIpAddress](#amazonec2-ec2_PublicIpAddress)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AcceptCapacityReservationBillingOwnership.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AcceptCapacityReservationBillingOwnership.html) **
  - **Description:** Grants permission to accept assign billing of the available capacity of a shared Capacity Reservation to the calling account
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-capacity-reservation](#amazonec2-capacity-reservation)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_CapacityReservationFleet](#amazonec2-ec2_CapacityReservationFleet) <br /> [#amazonec2-ec2_CreateDate](#amazonec2-ec2_CreateDate) <br /> [#amazonec2-ec2_DestinationCapacityReservationId](#amazonec2-ec2_DestinationCapacityReservationId) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_EndDate](#amazonec2-ec2_EndDate) <br /> [#amazonec2-ec2_EndDateType](#amazonec2-ec2_EndDateType) <br /> [#amazonec2-ec2_InstanceCount](#amazonec2-ec2_InstanceCount) <br /> [#amazonec2-ec2_InstanceMatchCriteria](#amazonec2-ec2_InstanceMatchCriteria) <br /> [#amazonec2-ec2_InstancePlatform](#amazonec2-ec2_InstancePlatform) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_OutpostArn](#amazonec2-ec2_OutpostArn) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SourceCapacityReservationId](#amazonec2-ec2_SourceCapacityReservationId) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AcceptReservedInstancesExchangeQuote.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AcceptReservedInstancesExchangeQuote.html) **
  - **Description:** Grants permission to accept a Convertible Reserved Instance exchange quote
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-reserved-instances](#amazonec2-reserved-instances)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ReservedInstancesOfferingType](#amazonec2-ec2_ReservedInstancesOfferingType) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AcceptTransitGatewayMulticastDomainAssociations.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AcceptTransitGatewayMulticastDomainAssociations.html) **
  - **Description:** Grants permission to accept a request to associate subnets with a transit gateway multicast domain
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-attachment](#amazonec2-transit-gateway-attachment)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayAttachmentId](#amazonec2-ec2_transitGatewayAttachmentId)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-multicast-domain](#amazonec2-transit-gateway-multicast-domain)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayMulticastDomainId](#amazonec2-ec2_transitGatewayMulticastDomainId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AcceptTransitGatewayPeeringAttachment.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AcceptTransitGatewayPeeringAttachment.html) **
  - **Description:** Grants permission to accept a transit gateway peering attachment request
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-attachment](#amazonec2-transit-gateway-attachment)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayAttachmentId](#amazonec2-ec2_transitGatewayAttachmentId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AcceptTransitGatewayVpcAttachment.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AcceptTransitGatewayVpcAttachment.html) **
  - **Description:** Grants permission to accept a request to attach a VPC to a transit gateway
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-attachment](#amazonec2-transit-gateway-attachment)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayAttachmentId](#amazonec2-ec2_transitGatewayAttachmentId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AcceptVpcEndpointConnections.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AcceptVpcEndpointConnections.html) **
  - **Description:** Grants permission to accept one or more interface VPC endpoint connections to your VPC endpoint service
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpc-endpoint-service](#amazonec2-vpc-endpoint-service)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VpceMultiRegion](#amazonec2-ec2_VpceMultiRegion) <br /> [#amazonec2-ec2_VpceSupportedRegion](#amazonec2-ec2_VpceSupportedRegion)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AcceptVpcPeeringConnection.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AcceptVpcPeeringConnection.html) **
  - **Description:** Grants permission to accept a VPC peering connection request
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc-peering-connection](#amazonec2-vpc-peering-connection)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AccepterVpc](#amazonec2-ec2_AccepterVpc) <br /> [#amazonec2-ec2_RequesterVpc](#amazonec2-ec2_RequesterVpc) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VpcPeeringConnectionID](#amazonec2-ec2_VpcPeeringConnectionID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AdvertiseByoipCidr.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AdvertiseByoipCidr.html) **
  - **Description:** Grants permission to advertise an IP address range that is provisioned for use in AWS through bring your own IP addresses (BYOIP)
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AllocateAddress.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AllocateAddress.html) **
  - **Description:** Grants permission to allocate an Elastic IP address (EIP) to your account
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-elastic-ip](#amazonec2-elastic-ip)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-ipam-pool](#amazonec2-ipam-pool)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipv4pool-ec2](#amazonec2-ipv4pool-ec2)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AllocateHosts.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AllocateHosts.html) **
  - **Description:** Grants permission to allocate a Dedicated Host to your account
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-dedicated-host](#amazonec2-dedicated-host)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_AutoPlacement](#amazonec2-ec2_AutoPlacement) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_HostRecovery](#amazonec2-ec2_HostRecovery) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_Quantity](#amazonec2-ec2_Quantity)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AllocateIpamPoolCidr.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AllocateIpamPoolCidr.html) **
  - **Description:** Grants permission to allocate a CIDR from an Amazon VPC IP Address Manager (IPAM) pool
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipam-pool](#amazonec2-ipam-pool)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ApplySecurityGroupsToClientVpnTargetNetwork.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ApplySecurityGroupsToClientVpnTargetNetwork.html) **
  - **Description:** Grants permission to apply a security group to the association between a Client VPN endpoint and a target network
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-client-vpn-endpoint](#amazonec2-client-vpn-endpoint)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ClientRootCertificateChainArn](#amazonec2-ec2_ClientRootCertificateChainArn) <br /> [#amazonec2-ec2_CloudwatchLogGroupArn](#amazonec2-ec2_CloudwatchLogGroupArn) <br /> [#amazonec2-ec2_CloudwatchLogStreamArn](#amazonec2-ec2_CloudwatchLogStreamArn) <br /> [#amazonec2-ec2_DirectoryArn](#amazonec2-ec2_DirectoryArn) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SamlProviderArn](#amazonec2-ec2_SamlProviderArn) <br /> [#amazonec2-ec2_ServerCertificateArn](#amazonec2-ec2_ServerCertificateArn)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-security-group](#amazonec2-security-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SecurityGroupID](#amazonec2-ec2_SecurityGroupID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssignIpv6Addresses.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssignIpv6Addresses.html) **
  - **Description:** Grants permission to assign one or more IPv6 addresses to a network interface
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-network-interface](#amazonec2-network-interface)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_NetworkInterfaceID](#amazonec2-ec2_NetworkInterfaceID) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Subnet](#amazonec2-ec2_Subnet) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssignPrivateIpAddresses.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssignPrivateIpAddresses.html) **
  - **Description:** Grants permission to assign one or more secondary private IP addresses to a network interface
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-network-interface](#amazonec2-network-interface)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_NetworkInterfaceID](#amazonec2-ec2_NetworkInterfaceID) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Subnet](#amazonec2-ec2_Subnet) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssignPrivateNatGatewayAddress.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssignPrivateNatGatewayAddress.html) **
  - **Description:** Grants permission to assign one or more secondary private IP addresses to a private NAT gateway
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-natgateway](#amazonec2-natgateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssociateAddress.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssociateAddress.html) **
  - **Description:** Grants permission to associate an Elastic IP address (EIP) with an instance or a network interface
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-elastic-ip](#amazonec2-elastic-ip)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AllocationId](#amazonec2-ec2_AllocationId) <br /> [#amazonec2-ec2_Domain](#amazonec2-ec2_Domain) <br /> [#amazonec2-ec2_PublicIpAddress](#amazonec2-ec2_PublicIpAddress) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ProductCode](#amazonec2-ec2_ProductCode) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-network-interface](#amazonec2-network-interface)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_NetworkInterfaceID](#amazonec2-ec2_NetworkInterfaceID) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Subnet](#amazonec2-ec2_Subnet) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssociateCapacityReservationBillingOwner.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssociateCapacityReservationBillingOwner.html) **
  - **Description:** Grants permission to assign billing of the unused capacity of a shared Capacity Reservation to a consumer account
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-capacity-reservation](#amazonec2-capacity-reservation)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_CapacityReservationFleet](#amazonec2-ec2_CapacityReservationFleet) <br /> [#amazonec2-ec2_CreateDate](#amazonec2-ec2_CreateDate) <br /> [#amazonec2-ec2_DestinationCapacityReservationId](#amazonec2-ec2_DestinationCapacityReservationId) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_EndDate](#amazonec2-ec2_EndDate) <br /> [#amazonec2-ec2_EndDateType](#amazonec2-ec2_EndDateType) <br /> [#amazonec2-ec2_InstanceCount](#amazonec2-ec2_InstanceCount) <br /> [#amazonec2-ec2_InstanceMatchCriteria](#amazonec2-ec2_InstanceMatchCriteria) <br /> [#amazonec2-ec2_InstancePlatform](#amazonec2-ec2_InstancePlatform) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_OutpostArn](#amazonec2-ec2_OutpostArn) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SourceCapacityReservationId](#amazonec2-ec2_SourceCapacityReservationId) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssociateClientVpnTargetNetwork.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssociateClientVpnTargetNetwork.html) **
  - **Description:** Grants permission to associate a target network with a Client VPN endpoint
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-client-vpn-endpoint](#amazonec2-client-vpn-endpoint)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ClientRootCertificateChainArn](#amazonec2-ec2_ClientRootCertificateChainArn) <br /> [#amazonec2-ec2_CloudwatchLogGroupArn](#amazonec2-ec2_CloudwatchLogGroupArn) <br /> [#amazonec2-ec2_CloudwatchLogStreamArn](#amazonec2-ec2_CloudwatchLogStreamArn) <br /> [#amazonec2-ec2_DirectoryArn](#amazonec2-ec2_DirectoryArn) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SamlProviderArn](#amazonec2-ec2_SamlProviderArn) <br /> [#amazonec2-ec2_ServerCertificateArn](#amazonec2-ec2_ServerCertificateArn)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-subnet](#amazonec2-subnet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssociateDhcpOptions.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssociateDhcpOptions.html) **
  - **Description:** Grants permission to associate or disassociate a set of DHCP options with a VPC
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-dhcp-options](#amazonec2-dhcp-options)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_DhcpOptionsID](#amazonec2-ec2_DhcpOptionsID) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssociateEnclaveCertificateIamRole.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssociateEnclaveCertificateIamRole.html) **
  - **Description:** Grants permission to associate an ACM certificate with an IAM role to be used in an EC2 Enclave
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-certificate](#amazonec2-certificate)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-role](#amazonec2-role)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssociateIamInstanceProfile.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssociateIamInstanceProfile.html) **
  - **Description:** Grants permission to associate an IAM instance profile with a running or stopped instance
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_NewInstanceProfile](#amazonec2-ec2_NewInstanceProfile) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ProductCode](#amazonec2-ec2_ProductCode) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:**  iam:PassRole 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssociateInstanceEventWindow.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssociateInstanceEventWindow.html) **
  - **Description:** Grants permission to associate one or more targets with an event window
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance-event-window](#amazonec2-instance-event-window)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssociateIpamByoasn.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssociateIpamByoasn.html) **
  - **Description:** Grants permission to associate an Autonomous System Number (ASN) with a BYOIP CIDR
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssociateIpamResourceDiscovery.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssociateIpamResourceDiscovery.html) **
  - **Description:** Grants permission to associate an IPAM resource discovery with an Amazon VPC IPAM
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipam](#amazonec2-ipam)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-ipam-resource-discovery](#amazonec2-ipam-resource-discovery)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipam-resource-discovery-association](#amazonec2-ipam-resource-discovery-association)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssociateNatGatewayAddress.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssociateNatGatewayAddress.html) **
  - **Description:** Grants permission to associate an Elastic IP address and private IP address with a public Nat gateway
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-elastic-ip](#amazonec2-elastic-ip)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AllocationId](#amazonec2-ec2_AllocationId) <br /> [#amazonec2-ec2_Domain](#amazonec2-ec2_Domain) <br /> [#amazonec2-ec2_PublicIpAddress](#amazonec2-ec2_PublicIpAddress) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-natgateway](#amazonec2-natgateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssociateRouteServer.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssociateRouteServer.html) **
  - **Description:** Grants permission to associate a route server with a VPC
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-route-server](#amazonec2-route-server)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Ipv4IpamPoolId](#amazonec2-ec2_Ipv4IpamPoolId) <br /> [#amazonec2-ec2_Ipv6IpamPoolId](#amazonec2-ec2_Ipv6IpamPoolId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssociateRouteTable.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssociateRouteTable.html) **
  - **Description:** Grants permission to associate a subnet or gateway with a route table
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-route-table](#amazonec2-route-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RouteTableID](#amazonec2-ec2_RouteTableID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-internet-gateway](#amazonec2-internet-gateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_InternetGatewayID](#amazonec2-ec2_InternetGatewayID) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipv4pool-ec2](#amazonec2-ipv4pool-ec2)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-subnet](#amazonec2-subnet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpn-gateway](#amazonec2-vpn-gateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssociateSecurityGroupVpc.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssociateSecurityGroupVpc.html) **
  - **Description:** Grants permission to associate a security group with another VPC in the same Region
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-security-group](#amazonec2-security-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SecurityGroupID](#amazonec2-ec2_SecurityGroupID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Ipv4IpamPoolId](#amazonec2-ec2_Ipv4IpamPoolId) <br /> [#amazonec2-ec2_Ipv6IpamPoolId](#amazonec2-ec2_Ipv6IpamPoolId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssociateSubnetCidrBlock.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssociateSubnetCidrBlock.html) **
  - **Description:** Grants permission to associate a CIDR block with a subnet
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-subnet](#amazonec2-subnet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_Ipv6IpamPoolId](#amazonec2-ec2_Ipv6IpamPoolId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipam-pool](#amazonec2-ipam-pool)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssociateTransitGatewayMulticastDomain.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssociateTransitGatewayMulticastDomain.html) **
  - **Description:** Grants permission to associate an attachment and list of subnets with a transit gateway multicast domain
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-subnet](#amazonec2-subnet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-attachment](#amazonec2-transit-gateway-attachment)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayAttachmentId](#amazonec2-ec2_transitGatewayAttachmentId)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-multicast-domain](#amazonec2-transit-gateway-multicast-domain)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayMulticastDomainId](#amazonec2-ec2_transitGatewayMulticastDomainId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssociateTransitGatewayPolicyTable.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssociateTransitGatewayPolicyTable.html) **
  - **Description:** Grants permission to associate a policy table with a transit gateway attachment
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-attachment](#amazonec2-transit-gateway-attachment)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayAttachmentId](#amazonec2-ec2_transitGatewayAttachmentId)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-policy-table](#amazonec2-transit-gateway-policy-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayPolicyTableId](#amazonec2-ec2_transitGatewayPolicyTableId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssociateTransitGatewayRouteTable.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssociateTransitGatewayRouteTable.html) **
  - **Description:** Grants permission to associate an attachment with a transit gateway route table
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-attachment](#amazonec2-transit-gateway-attachment)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayAttachmentId](#amazonec2-ec2_transitGatewayAttachmentId)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-route-table](#amazonec2-transit-gateway-route-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayRouteTableId](#amazonec2-ec2_transitGatewayRouteTableId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssociateTrunkInterface.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssociateTrunkInterface.html) **
  - **Description:** Grants permission to associate a branch network interface with a trunk network interface
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/verified-access/latest/ug/waf-integration.html](https://docs.aws.amazon.com/verified-access/latest/ug/waf-integration.html) [permission only]**
  - **Description:** Grants permission to associate an AWS Web Application Firewall (WAF) web access control list (ACL) with a Verified Access instance
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-verified-access-instance](#amazonec2-verified-access-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssociateVpcCidrBlock.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AssociateVpcCidrBlock.html) **
  - **Description:** Grants permission to associate a CIDR block with a VPC
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Ipv4IpamPoolId](#amazonec2-ec2_Ipv4IpamPoolId) <br /> [#amazonec2-ec2_Ipv6IpamPoolId](#amazonec2-ec2_Ipv6IpamPoolId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipam-pool](#amazonec2-ipam-pool)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipv6pool-ec2](#amazonec2-ipv6pool-ec2)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AttachApplianceToNatGateway.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AttachApplianceToNatGateway.html) [permission only]**
  - **Description:** Grants permission to attach an appliance with a public/private Natgateway
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#amazonec2-natgateway](#amazonec2-natgateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AttachClassicLinkVpc.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AttachClassicLinkVpc.html) **
  - **Description:** Grants permission to link an EC2-Classic instance to a ClassicLink-enabled VPC through one or more of the VPC's security groups
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-security-group](#amazonec2-security-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SecurityGroupID](#amazonec2-ec2_SecurityGroupID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AttachInternetGateway.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AttachInternetGateway.html) **
  - **Description:** Grants permission to attach an internet gateway to a VPC
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-internet-gateway](#amazonec2-internet-gateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_InternetGatewayID](#amazonec2-ec2_InternetGatewayID) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AttachNetworkInterface.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AttachNetworkInterface.html) **
  - **Description:** Grants permission to attach a network interface to an instance
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ProductCode](#amazonec2-ec2_ProductCode) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-network-interface](#amazonec2-network-interface)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_NetworkInterfaceID](#amazonec2-ec2_NetworkInterfaceID) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Subnet](#amazonec2-ec2_Subnet) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/UserGuide/placement-groups.html](https://docs.aws.amazon.com/UserGuide/placement-groups.html) [permission only]**
  - **Description:** Grants permission to attach resources to a placement group
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#amazonec2-placement-group](#amazonec2-placement-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_PlacementGroupName](#amazonec2-ec2_PlacementGroupName) <br /> [#amazonec2-ec2_PlacementGroupStrategy](#amazonec2-ec2_PlacementGroupStrategy) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AttachVerifiedAccessTrustProvider.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AttachVerifiedAccessTrustProvider.html) **
  - **Description:** Grants permission to attach a trust provider to a Verified Access instance
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-verified-access-instance](#amazonec2-verified-access-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-verified-access-trust-provider](#amazonec2-verified-access-trust-provider)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AttachVolume.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AttachVolume.html) **
  - **Description:** Grants permission to attach an EBS volume to a running or stopped instance and expose it to the instance with the specified device name
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ProductCode](#amazonec2-ec2_ProductCode) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-volume](#amazonec2-volume)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_Encrypted](#amazonec2-ec2_Encrypted) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_ParentSnapshot](#amazonec2-ec2_ParentSnapshot) <br /> [#amazonec2-ec2_ParentVolume](#amazonec2-ec2_ParentVolume) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VolumeID](#amazonec2-ec2_VolumeID) <br /> [#amazonec2-ec2_VolumeInitializationRate](#amazonec2-ec2_VolumeInitializationRate) <br /> [#amazonec2-ec2_VolumeIops](#amazonec2-ec2_VolumeIops) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize) <br /> [#amazonec2-ec2_VolumeThroughput](#amazonec2-ec2_VolumeThroughput) <br /> [#amazonec2-ec2_VolumeType](#amazonec2-ec2_VolumeType)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AttachVpnGateway.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AttachVpnGateway.html) **
  - **Description:** Grants permission to attach a virtual private gateway to a VPC
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpn-gateway](#amazonec2-vpn-gateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AuthorizeClientVpnIngress.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AuthorizeClientVpnIngress.html) **
  - **Description:** Grants permission to add an inbound authorization rule to a Client VPN endpoint
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-client-vpn-endpoint](#amazonec2-client-vpn-endpoint)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ClientRootCertificateChainArn](#amazonec2-ec2_ClientRootCertificateChainArn) <br /> [#amazonec2-ec2_CloudwatchLogGroupArn](#amazonec2-ec2_CloudwatchLogGroupArn) <br /> [#amazonec2-ec2_CloudwatchLogStreamArn](#amazonec2-ec2_CloudwatchLogStreamArn) <br /> [#amazonec2-ec2_DirectoryArn](#amazonec2-ec2_DirectoryArn) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SamlProviderArn](#amazonec2-ec2_SamlProviderArn) <br /> [#amazonec2-ec2_ServerCertificateArn](#amazonec2-ec2_ServerCertificateArn)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AuthorizeSecurityGroupEgress.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AuthorizeSecurityGroupEgress.html) **
  - **Description:** Grants permission to add one or more outbound rules to a VPC security group. Policies using the security-group-rule resource-level permission are only enforced when the API request includes TagSpecifications
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-security-group](#amazonec2-security-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SecurityGroupID](#amazonec2-ec2_SecurityGroupID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-security-group-rule](#amazonec2-security-group-rule)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AuthorizeSecurityGroupIngress.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AuthorizeSecurityGroupIngress.html) **
  - **Description:** Grants permission to add one or more inbound rules to a VPC security group. Policies using the security-group-rule resource-level permission are only enforced when the API request includes TagSpecifications
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-security-group](#amazonec2-security-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SecurityGroupID](#amazonec2-ec2_SecurityGroupID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-security-group-rule](#amazonec2-security-group-rule)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_BundleInstance.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_BundleInstance.html) **
  - **Description:** Grants permission to bundle an instance store-backed Windows instance
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CancelBundleTask.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CancelBundleTask.html) **
  - **Description:** Grants permission to cancel a bundling operation
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CancelCapacityReservation.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CancelCapacityReservation.html) **
  - **Description:** Grants permission to cancel a Capacity Reservation and release the reserved capacity
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-capacity-reservation](#amazonec2-capacity-reservation)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_CapacityReservationFleet](#amazonec2-ec2_CapacityReservationFleet)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CancelCapacityReservationFleets.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CancelCapacityReservationFleets.html) **
  - **Description:** Grants permission to cancel one or more Capacity Reservation Fleets
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-capacity-reservation-fleet](#amazonec2-capacity-reservation-fleet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:**  ec2:CancelCapacityReservation 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CancelConversionTask.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CancelConversionTask.html) **
  - **Description:** Grants permission to cancel an active conversion task
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CancelDeclarativePoliciesReport.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CancelDeclarativePoliciesReport.html) **
  - **Description:** Grants permission to cancel a declarative policies report
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-declarative-policies-report](#amazonec2-declarative-policies-report)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CancelExportTask.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CancelExportTask.html) **
  - **Description:** Grants permission to cancel an active export task
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-export-image-task](#amazonec2-export-image-task)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-export-instance-task](#amazonec2-export-instance-task)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CancelImageLaunchPermission.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CancelImageLaunchPermission.html) **
  - **Description:** Grants permission to remove your AWS account from the launch permissions for the specified AMI
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#amazonec2-image](#amazonec2-image)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ImageID](#amazonec2-ec2_ImageID) <br /> [#amazonec2-ec2_ImageType](#amazonec2-ec2_ImageType) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_Public](#amazonec2-ec2_Public) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CancelImportTask.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CancelImportTask.html) **
  - **Description:** Grants permission to cancel an in-process import virtual machine or import snapshot task
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-import-image-task](#amazonec2-import-image-task)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-import-snapshot-task](#amazonec2-import-snapshot-task)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CancelReservedInstancesListing.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CancelReservedInstancesListing.html) **
  - **Description:** Grants permission to cancel a Reserved Instance listing on the Reserved Instance Marketplace
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CancelSpotFleetRequests.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CancelSpotFleetRequests.html) **
  - **Description:** Grants permission to cancel one or more Spot Fleet requests
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-spot-fleet-request](#amazonec2-spot-fleet-request)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CancelSpotInstanceRequests.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CancelSpotInstanceRequests.html) **
  - **Description:** Grants permission to cancel one or more Spot Instance requests
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-spot-instances-request](#amazonec2-spot-instances-request)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ConfirmProductInstance.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ConfirmProductInstance.html) **
  - **Description:** Grants permission to determine whether an owned product code is associated with an instance
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CopyFpgaImage.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CopyFpgaImage.html) **
  - **Description:** Grants permission to copy a source Amazon FPGA image (AFI) to the current Region. Resource-level permissions specified for this action apply to the new AFI only. They do not apply to the source AFI
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-fpga-image](#amazonec2-fpga-image)  / **Condition keys:**  [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CopyImage.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CopyImage.html) **
  - **Description:** Grants permission to copy an Amazon Machine Image (AMI) from a source Region to the current Region
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-image](#amazonec2-image)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ImageID](#amazonec2-ec2_ImageID) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-snapshot](#amazonec2-snapshot)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CopySnapshot.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CopySnapshot.html) **
  - **Description:** Grants permission to copy a point-in-time snapshot of an EBS volume and store it in Amazon S3. Resource-level permissions specified for this action apply to both the snapshot copy and the source snapshot
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-snapshot](#amazonec2-snapshot)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Encrypted](#amazonec2-ec2_Encrypted) <br /> [#amazonec2-ec2_OutpostArn](#amazonec2-ec2_OutpostArn) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_ParentSnapshot](#amazonec2-ec2_ParentSnapshot) <br /> [#amazonec2-ec2_ParentVolume](#amazonec2-ec2_ParentVolume) <br /> [#amazonec2-ec2_ProductCode](#amazonec2-ec2_ProductCode) <br /> [#amazonec2-ec2_SnapshotID](#amazonec2-ec2_SnapshotID) <br /> [#amazonec2-ec2_SnapshotTime](#amazonec2-ec2_SnapshotTime) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CopyVolumes.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CopyVolumes.html) **
  - **Description:** Grants permission to create a copy of an EBS volume. Resource-level permissions specified for this action apply to the source and copied volume. Condition keys for the copied volume correspond to parameters specified in the CopyVolumes API request
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-volume](#amazonec2-volume)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_Encrypted](#amazonec2-ec2_Encrypted) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_ParentSnapshot](#amazonec2-ec2_ParentSnapshot) <br /> [#amazonec2-ec2_ParentVolume](#amazonec2-ec2_ParentVolume) <br /> [#amazonec2-ec2_VolumeInitializationRate](#amazonec2-ec2_VolumeInitializationRate) <br /> [#amazonec2-ec2_VolumeIops](#amazonec2-ec2_VolumeIops) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize) <br /> [#amazonec2-ec2_VolumeThroughput](#amazonec2-ec2_VolumeThroughput) <br /> [#amazonec2-ec2_VolumeType](#amazonec2-ec2_VolumeType)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateCapacityManagerDataExport.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateCapacityManagerDataExport.html) **
  - **Description:** Grants permission to create a new S3 Data Export for Capacity Manager
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-capacity-manager-data-export](#amazonec2-capacity-manager-data-export)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateCapacityReservation.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateCapacityReservation.html) **
  - **Description:** Grants permission to create a Capacity Reservation
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-capacity-reservation](#amazonec2-capacity-reservation)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CapacityReservationFleet](#amazonec2-ec2_CapacityReservationFleet) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_EndDate](#amazonec2-ec2_EndDate) <br /> [#amazonec2-ec2_EndDateType](#amazonec2-ec2_EndDateType) <br /> [#amazonec2-ec2_EphemeralStorage](#amazonec2-ec2_EphemeralStorage) <br /> [#amazonec2-ec2_InstanceCount](#amazonec2-ec2_InstanceCount) <br /> [#amazonec2-ec2_InstanceMatchCriteria](#amazonec2-ec2_InstanceMatchCriteria) <br /> [#amazonec2-ec2_InstancePlatform](#amazonec2-ec2_InstancePlatform) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_OutpostArn](#amazonec2-ec2_OutpostArn) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateCapacityReservationBySplitting.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateCapacityReservationBySplitting.html) **
  - **Description:** Grants permission to create a new Capacity Reservation by splitting the available capacity of the source Capacity Reservation
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-capacity-reservation](#amazonec2-capacity-reservation)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_CapacityReservationFleet](#amazonec2-ec2_CapacityReservationFleet) <br /> [#amazonec2-ec2_CreateDate](#amazonec2-ec2_CreateDate) <br /> [#amazonec2-ec2_DestinationCapacityReservationId](#amazonec2-ec2_DestinationCapacityReservationId) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_EndDate](#amazonec2-ec2_EndDate) <br /> [#amazonec2-ec2_EndDateType](#amazonec2-ec2_EndDateType) <br /> [#amazonec2-ec2_InstanceCount](#amazonec2-ec2_InstanceCount) <br /> [#amazonec2-ec2_InstanceMatchCriteria](#amazonec2-ec2_InstanceMatchCriteria) <br /> [#amazonec2-ec2_InstancePlatform](#amazonec2-ec2_InstancePlatform) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_OutpostArn](#amazonec2-ec2_OutpostArn) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SourceCapacityReservationId](#amazonec2-ec2_SourceCapacityReservationId) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateCapacityReservationFleet.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateCapacityReservationFleet.html) **
  - **Description:** Grants permission to create a Capacity Reservation Fleet
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-capacity-reservation-fleet](#amazonec2-capacity-reservation-fleet)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:**  ec2:CreateCapacityReservation <br /> ec2:CreateTags <br /> ec2:DescribeCapacityReservations <br /> ec2:DescribeInstances 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateCarrierGateway.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateCarrierGateway.html) **
  - **Description:** Grants permission to create a carrier gateway and provides CSP connectivity to VPC customers
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-carrier-gateway](#amazonec2-carrier-gateway)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateClientVpnEndpoint.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateClientVpnEndpoint.html) **
  - **Description:** Grants permission to create a Client VPN endpoint
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-client-vpn-endpoint](#amazonec2-client-vpn-endpoint)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ClientRootCertificateChainArn](#amazonec2-ec2_ClientRootCertificateChainArn) <br /> [#amazonec2-ec2_CloudwatchLogGroupArn](#amazonec2-ec2_CloudwatchLogGroupArn) <br /> [#amazonec2-ec2_CloudwatchLogStreamArn](#amazonec2-ec2_CloudwatchLogStreamArn) <br /> [#amazonec2-ec2_DirectoryArn](#amazonec2-ec2_DirectoryArn) <br /> [#amazonec2-ec2_SamlProviderArn](#amazonec2-ec2_SamlProviderArn) <br /> [#amazonec2-ec2_ServerCertificateArn](#amazonec2-ec2_ServerCertificateArn)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-security-group](#amazonec2-security-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SecurityGroupID](#amazonec2-ec2_SecurityGroupID)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateClientVpnRoute.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateClientVpnRoute.html) **
  - **Description:** Grants permission to add a network route to a Client VPN endpoint's route table
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-client-vpn-endpoint](#amazonec2-client-vpn-endpoint)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ClientRootCertificateChainArn](#amazonec2-ec2_ClientRootCertificateChainArn) <br /> [#amazonec2-ec2_CloudwatchLogGroupArn](#amazonec2-ec2_CloudwatchLogGroupArn) <br /> [#amazonec2-ec2_CloudwatchLogStreamArn](#amazonec2-ec2_CloudwatchLogStreamArn) <br /> [#amazonec2-ec2_DirectoryArn](#amazonec2-ec2_DirectoryArn) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SamlProviderArn](#amazonec2-ec2_SamlProviderArn) <br /> [#amazonec2-ec2_ServerCertificateArn](#amazonec2-ec2_ServerCertificateArn)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-subnet](#amazonec2-subnet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateCoipCidr.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateCoipCidr.html) **
  - **Description:** Grants permission to create a range of customer-owned IP (CoIP) addresses
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-coip-pool](#amazonec2-coip-pool)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateCoipPool.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateCoipPool.html) **
  - **Description:** Grants permission to create a pool of customer-owned IP (CoIP) addresses
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-coip-pool](#amazonec2-coip-pool)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-local-gateway-route-table](#amazonec2-local-gateway-route-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/outposts/latest/userguide/identity-access-management.html](https://docs.aws.amazon.com/outposts/latest/userguide/identity-access-management.html) [permission only]**
  - **Description:** Grants permission to allow a service to access a customer-owned IP (CoIP) pool
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#amazonec2-coip-pool](#amazonec2-coip-pool)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateCustomerGateway.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateCustomerGateway.html) **
  - **Description:** Grants permission to create a customer gateway, which provides information to AWS about your customer gateway device
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-customer-gateway](#amazonec2-customer-gateway)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateDefaultSubnet.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateDefaultSubnet.html) **
  - **Description:** Grants permission to create a default subnet in a specified Availability Zone in a default VPC
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateDefaultVpc.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateDefaultVpc.html) **
  - **Description:** Grants permission to create a default VPC with a default subnet in each Availability Zone
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateDelegateMacVolumeOwnershipTask.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateDelegateMacVolumeOwnershipTask.html) **
  - **Description:** Grants permission to create a volume ownership delegation task for an Apple silicon Mac instance
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-mac-modification-task](#amazonec2-mac-modification-task)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateDhcpOptions.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateDhcpOptions.html) **
  - **Description:** Grants permission to create a set of DHCP options for a VPC
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-dhcp-options](#amazonec2-dhcp-options)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_DhcpOptionsID](#amazonec2-ec2_DhcpOptionsID)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateEgressOnlyInternetGateway.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateEgressOnlyInternetGateway.html) **
  - **Description:** Grants permission to create an egress-only internet gateway for a VPC
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-egress-only-internet-gateway](#amazonec2-egress-only-internet-gateway)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateFleet.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateFleet.html) **
  - **Description:** Grants permission to launch an EC2 Fleet. Resource-level permissions for this action do not include the resources specified in a launch template. To specify resource-level permissions for resources specified in a launch template, you must include the resources in the RunInstances action statement
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-fleet](#amazonec2-fleet)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-image](#amazonec2-image)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ImageID](#amazonec2-ec2_ImageID) <br /> [#amazonec2-ec2_ImageType](#amazonec2-ec2_ImageType) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_Public](#amazonec2-ec2_Public) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-launch-template](#amazonec2-launch-template)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-placement-group](#amazonec2-placement-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_PlacementGroupName](#amazonec2-ec2_PlacementGroupName) <br /> [#amazonec2-ec2_PlacementGroupStrategy](#amazonec2-ec2_PlacementGroupStrategy) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-subnet](#amazonec2-subnet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-volume](#amazonec2-volume)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_Encrypted](#amazonec2-ec2_Encrypted) <br /> [#amazonec2-ec2_KmsKeyId](#amazonec2-ec2_KmsKeyId) <br /> [#amazonec2-ec2_ParentSnapshot](#amazonec2-ec2_ParentSnapshot) <br /> [#amazonec2-ec2_VolumeID](#amazonec2-ec2_VolumeID) <br /> [#amazonec2-ec2_VolumeIops](#amazonec2-ec2_VolumeIops) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize) <br /> [#amazonec2-ec2_VolumeThroughput](#amazonec2-ec2_VolumeThroughput) <br /> [#amazonec2-ec2_VolumeType](#amazonec2-ec2_VolumeType)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateFlowLogs.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateFlowLogs.html) **
  - **Description:** Grants permission to create one or more flow logs to capture IP traffic for a network interface
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpc-flow-log](#amazonec2-vpc-flow-log)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:**  ec2:CreateTags <br /> ecs:ListClusters <br /> ecs:ListContainerInstances <br /> ecs:ListServices <br /> ecs:ListTaskDefinitions <br /> ecs:ListTasks <br /> iam:PassRole 
  - **Resource types (\*required):**  [#amazonec2-natgateway](#amazonec2-natgateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-network-interface](#amazonec2-network-interface)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_NetworkInterfaceID](#amazonec2-ec2_NetworkInterfaceID) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Subnet](#amazonec2-ec2_Subnet) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-subnet](#amazonec2-subnet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway](#amazonec2-transit-gateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayId](#amazonec2-ec2_transitGatewayId)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-attachment](#amazonec2-transit-gateway-attachment)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayAttachmentId](#amazonec2-ec2_transitGatewayAttachmentId)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateFpgaImage.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateFpgaImage.html) **
  - **Description:** Grants permission to create an Amazon FPGA Image (AFI) from a design checkpoint (DCP)
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-fpga-image](#amazonec2-fpga-image)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_Public](#amazonec2-ec2_Public)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateImage.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateImage.html) **
  - **Description:** Grants permission to create an Amazon EBS-backed AMI from a stopped or running Amazon EBS-backed instance. This action can reboot instances as part of the image creation process, even without RebootInstances permissions. To prevent instance reboots during image creation, use the NoReboot parameter
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-image](#amazonec2-image)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ImageID](#amazonec2-ec2_ImageID) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ProductCode](#amazonec2-ec2_ProductCode) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-snapshot](#amazonec2-snapshot)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_OutpostArn](#amazonec2-ec2_OutpostArn) <br /> [#amazonec2-ec2_ParentVolume](#amazonec2-ec2_ParentVolume) <br /> [#amazonec2-ec2_SnapshotID](#amazonec2-ec2_SnapshotID) <br /> [#amazonec2-ec2_SnapshotTime](#amazonec2-ec2_SnapshotTime) <br /> [#amazonec2-ec2_SourceOutpostArn](#amazonec2-ec2_SourceOutpostArn) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateImageUsageReport.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateImageUsageReport.html) **
  - **Description:** Grants permission to create an AMI usage report
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-image](#amazonec2-image)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ImageID](#amazonec2-ec2_ImageID) <br /> [#amazonec2-ec2_ImageType](#amazonec2-ec2_ImageType) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_Public](#amazonec2-ec2_Public) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-image-usage-report](#amazonec2-image-usage-report)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateInstanceConnectEndpoint.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateInstanceConnectEndpoint.html) **
  - **Description:** Grants permission to create an EC2 Instance Connect Endpoint that allows you to connect to an instance without a public IPv4 address
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance-connect-endpoint](#amazonec2-instance-connect-endpoint)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-subnet](#amazonec2-subnet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-security-group](#amazonec2-security-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SecurityGroupID](#amazonec2-ec2_SecurityGroupID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateInstanceEventWindow.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateInstanceEventWindow.html) **
  - **Description:** Grants permission to create an event window in which scheduled events for the associated Amazon EC2 instances can run
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance-event-window](#amazonec2-instance-event-window)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateInstanceExportTask.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateInstanceExportTask.html) **
  - **Description:** Grants permission to export a running or stopped instance to an Amazon S3 bucket
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-export-instance-task](#amazonec2-export-instance-task)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_ProductCode](#amazonec2-ec2_ProductCode) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateInternetGateway.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateInternetGateway.html) **
  - **Description:** Grants permission to create an internet gateway for a VPC
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-internet-gateway](#amazonec2-internet-gateway)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_InternetGatewayID](#amazonec2-ec2_InternetGatewayID)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateInterruptibleCapacityReservationAllocation.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateInterruptibleCapacityReservationAllocation.html) **
  - **Description:** Grants permission to create an interruptible Capacity Reservation by specifying the number of unused instances you want to allocate from your source reservation
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-capacity-reservation](#amazonec2-capacity-reservation)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CreateDate](#amazonec2-ec2_CreateDate) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_EndDate](#amazonec2-ec2_EndDate) <br /> [#amazonec2-ec2_EndDateType](#amazonec2-ec2_EndDateType) <br /> [#amazonec2-ec2_InstanceCount](#amazonec2-ec2_InstanceCount) <br /> [#amazonec2-ec2_InstanceMatchCriteria](#amazonec2-ec2_InstanceMatchCriteria) <br /> [#amazonec2-ec2_InstancePlatform](#amazonec2-ec2_InstancePlatform) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_InterruptibleCapacityReservationId](#amazonec2-ec2_InterruptibleCapacityReservationId) <br /> [#amazonec2-ec2_InterruptionType](#amazonec2-ec2_InterruptionType) <br /> [#amazonec2-ec2_IsInterruptible](#amazonec2-ec2_IsInterruptible) <br /> [#amazonec2-ec2_SourceCapacityReservationId](#amazonec2-ec2_SourceCapacityReservationId) <br /> [#amazonec2-ec2_TargetInstanceCount](#amazonec2-ec2_TargetInstanceCount) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateIpam.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateIpam.html) **
  - **Description:** Grants permission to create an Amazon VPC IP Address Manager (IPAM)
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipam](#amazonec2-ipam)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:**  ec2:CreateTags <br /> iam:CreateServiceLinkedRole 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateIpamExternalResourceVerificationToken.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateIpamExternalResourceVerificationToken.html) **
  - **Description:** Grants permission to create a verification token, which proves ownership of an external resource
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipam](#amazonec2-ipam)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-ipam-external-resource-verification-token](#amazonec2-ipam-external-resource-verification-token)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateIpamPolicy.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateIpamPolicy.html) **
  - **Description:** Grants permission to create a policy in Amazon VPC IP Address Manager (IPAM) that defines rules for allocating public IPv4 addresses from IPAM pools to AWS resources
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipam](#amazonec2-ipam)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-ipam-policy](#amazonec2-ipam-policy)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateIpamPool.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateIpamPool.html) **
  - **Description:** Grants permission to create an IP address pool for Amazon VPC IP Address Manager (IPAM), which is a collection of contiguous IP address CIDRs
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipam-pool](#amazonec2-ipam-pool)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-ipam-scope](#amazonec2-ipam-scope)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateIpamPrefixListResolver.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateIpamPrefixListResolver.html) **
  - **Description:** Grants permission to create an IPAM prefix list resolver that defines rules for selecting CIDRs to include in prefix lists
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipam](#amazonec2-ipam)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-ipam-prefix-list-resolver](#amazonec2-ipam-prefix-list-resolver)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipam-scope](#amazonec2-ipam-scope)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateIpamPrefixListResolverTarget.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateIpamPrefixListResolverTarget.html) **
  - **Description:** Grants permission to create an IPAM prefix list resolver target that links a resolver to a managed prefix list
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipam-prefix-list-resolver](#amazonec2-ipam-prefix-list-resolver)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-ipam-prefix-list-resolver-target](#amazonec2-ipam-prefix-list-resolver-target)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateIpamResourceDiscovery.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateIpamResourceDiscovery.html) **
  - **Description:** Grants permission to create an IPAM resource discovery
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipam-resource-discovery](#amazonec2-ipam-resource-discovery)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:**  ec2:CreateTags <br /> iam:CreateServiceLinkedRole 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateIpamScope.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateIpamScope.html) **
  - **Description:** Grants permission to create an Amazon VPC IP Address Manager (IPAM) scope, which is the highest-level container within IPAM
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipam](#amazonec2-ipam)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-ipam-scope](#amazonec2-ipam-scope)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateKeyPair.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateKeyPair.html) **
  - **Description:** Grants permission to create a 2048-bit RSA key pair
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-key-pair](#amazonec2-key-pair)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_KeyPairType](#amazonec2-ec2_KeyPairType)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateLaunchTemplate.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateLaunchTemplate.html) **
  - **Description:** Grants permission to create a launch template
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-launch-template](#amazonec2-launch-template)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:**  ec2:CreateTags <br /> ssm:GetParameters 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateLaunchTemplateVersion.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateLaunchTemplateVersion.html) **
  - **Description:** Grants permission to create a new version of a launch template
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-launch-template](#amazonec2-launch-template)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:**  ssm:GetParameters 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateLocalGatewayRoute.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateLocalGatewayRoute.html) **
  - **Description:** Grants permission to create a static route for a local gateway route table
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-local-gateway-route-table](#amazonec2-local-gateway-route-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-local-gateway-virtual-interface-group](#amazonec2-local-gateway-virtual-interface-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-network-interface](#amazonec2-network-interface)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_NetworkInterfaceID](#amazonec2-ec2_NetworkInterfaceID) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Subnet](#amazonec2-ec2_Subnet) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-prefix-list](#amazonec2-prefix-list)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateLocalGatewayRouteTable.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateLocalGatewayRouteTable.html) **
  - **Description:** Grants permission to create a local gateway route table
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-local-gateway](#amazonec2-local-gateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-local-gateway-route-table](#amazonec2-local-gateway-route-table)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/outposts/latest/userguide/identity-access-management.html](https://docs.aws.amazon.com/outposts/latest/userguide/identity-access-management.html) [permission only]**
  - **Description:** Grants permission to allow a service to access a local gateway route table
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#amazonec2-local-gateway-route-table](#amazonec2-local-gateway-route-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateLocalGatewayRouteTableVirtualInterfaceGroupAssociation.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateLocalGatewayRouteTableVirtualInterfaceGroupAssociation.html) **
  - **Description:** Grants permission to create a local gateway route table virtual interface group association
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-local-gateway-route-table](#amazonec2-local-gateway-route-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-local-gateway-route-table-virtual-interface-group-association](#amazonec2-local-gateway-route-table-virtual-interface-group-association)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-local-gateway-virtual-interface-group](#amazonec2-local-gateway-virtual-interface-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateLocalGatewayRouteTableVpcAssociation.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateLocalGatewayRouteTableVpcAssociation.html) **
  - **Description:** Grants permission to associate a VPC with a local gateway route table
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-local-gateway-route-table](#amazonec2-local-gateway-route-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-local-gateway-route-table-vpc-association](#amazonec2-local-gateway-route-table-vpc-association)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateLocalGatewayVirtualInterface.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateLocalGatewayVirtualInterface.html) **
  - **Description:** Grants permission to create a local gateway virtual interface
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-local-gateway-virtual-interface](#amazonec2-local-gateway-virtual-interface)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-local-gateway-virtual-interface-group](#amazonec2-local-gateway-virtual-interface-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-outpost-lag](#amazonec2-outpost-lag)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateLocalGatewayVirtualInterfaceGroup.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateLocalGatewayVirtualInterfaceGroup.html) **
  - **Description:** Grants permission to create a local gateway virtual interface group
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-local-gateway](#amazonec2-local-gateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-local-gateway-virtual-interface-group](#amazonec2-local-gateway-virtual-interface-group)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateMacSystemIntegrityProtectionModificationTask.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateMacSystemIntegrityProtectionModificationTask.html) **
  - **Description:** Grants permission to create a System Integrity Protection (SIP) modification task for an Amazon EC2 Mac instance
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-mac-modification-task](#amazonec2-mac-modification-task)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateManagedPrefixList.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateManagedPrefixList.html) **
  - **Description:** Grants permission to create a managed prefix list
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-prefix-list](#amazonec2-prefix-list)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateNatGateway.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateNatGateway.html) **
  - **Description:** Grants permission to create a NAT gateway in a subnet
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-natgateway](#amazonec2-natgateway)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-elastic-ip](#amazonec2-elastic-ip)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AllocationId](#amazonec2-ec2_AllocationId) <br /> [#amazonec2-ec2_Domain](#amazonec2-ec2_Domain) <br /> [#amazonec2-ec2_PublicIpAddress](#amazonec2-ec2_PublicIpAddress) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-subnet](#amazonec2-subnet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Ipv4IpamPoolId](#amazonec2-ec2_Ipv4IpamPoolId) <br /> [#amazonec2-ec2_Ipv6IpamPoolId](#amazonec2-ec2_Ipv6IpamPoolId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateNetworkAcl.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateNetworkAcl.html) **
  - **Description:** Grants permission to create a network ACL in a VPC
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-network-acl](#amazonec2-network-acl)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_NetworkAclID](#amazonec2-ec2_NetworkAclID)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateNetworkAclEntry.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateNetworkAclEntry.html) **
  - **Description:** Grants permission to create a numbered entry (a rule) in a network ACL
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-network-acl](#amazonec2-network-acl)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_NetworkAclID](#amazonec2-ec2_NetworkAclID) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateNetworkInsightsAccessScope.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateNetworkInsightsAccessScope.html) **
  - **Description:** Grants permission to create a Network Access Scope
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-network-insights-access-scope](#amazonec2-network-insights-access-scope)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateNetworkInsightsPath.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateNetworkInsightsPath.html) **
  - **Description:** Grants permission to create a path to analyze for reachability
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-network-insights-path](#amazonec2-network-insights-path)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ProductCode](#amazonec2-ec2_ProductCode) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-internet-gateway](#amazonec2-internet-gateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_InternetGatewayID](#amazonec2-ec2_InternetGatewayID) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-network-interface](#amazonec2-network-interface)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_NetworkInterfaceID](#amazonec2-ec2_NetworkInterfaceID) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Subnet](#amazonec2-ec2_Subnet) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway](#amazonec2-transit-gateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayId](#amazonec2-ec2_transitGatewayId)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc-endpoint](#amazonec2-vpc-endpoint)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc-endpoint-service](#amazonec2-vpc-endpoint-service)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc-peering-connection](#amazonec2-vpc-peering-connection)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AccepterVpc](#amazonec2-ec2_AccepterVpc) <br /> [#amazonec2-ec2_RequesterVpc](#amazonec2-ec2_RequesterVpc) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VpcPeeringConnectionID](#amazonec2-ec2_VpcPeeringConnectionID)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpn-gateway](#amazonec2-vpn-gateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateNetworkInterface.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateNetworkInterface.html) **
  - **Description:** Grants permission to create a network interface in a subnet
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-network-interface](#amazonec2-network-interface)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_NetworkInterfaceID](#amazonec2-ec2_NetworkInterfaceID)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-subnet](#amazonec2-subnet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-security-group](#amazonec2-security-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SecurityGroupID](#amazonec2-ec2_SecurityGroupID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateNetworkInterfacePermission.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateNetworkInterfacePermission.html) **
  - **Description:** Grants permission to create a permission for an AWS-authorized user to perform certain operations on a network interface
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#amazonec2-network-interface](#amazonec2-network-interface)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AuthorizedService](#amazonec2-ec2_AuthorizedService) <br /> [#amazonec2-ec2_AuthorizedUser](#amazonec2-ec2_AuthorizedUser) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_NetworkInterfaceID](#amazonec2-ec2_NetworkInterfaceID) <br /> [#amazonec2-ec2_Permission](#amazonec2-ec2_Permission) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Subnet](#amazonec2-ec2_Subnet) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateOdbNetworkPeering.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateOdbNetworkPeering.html) [permission only]**
  - **Description:** Grants permission to allow Oracle Database@AWS to create a peering connection between an ODB network and a VPC
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreatePlacementGroup.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreatePlacementGroup.html) **
  - **Description:** Grants permission to create a placement group
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-placement-group](#amazonec2-placement-group)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_PlacementGroupName](#amazonec2-ec2_PlacementGroupName) <br /> [#amazonec2-ec2_PlacementGroupStrategy](#amazonec2-ec2_PlacementGroupStrategy)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreatePublicIpv4Pool.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreatePublicIpv4Pool.html) **
  - **Description:** Grants permission to create a public IPv4 address pool for public IPv4 CIDRs that you own and bring to Amazon to manage with Amazon VPC IP Address Manager (IPAM)
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipv4pool-ec2](#amazonec2-ipv4pool-ec2)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateReplaceRootVolumeTask.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateReplaceRootVolumeTask.html) **
  - **Description:** Grants permission to create a root volume replacement task
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ProductCode](#amazonec2-ec2_ProductCode) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-replace-root-volume-task](#amazonec2-replace-root-volume-task)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-volume](#amazonec2-volume)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_VolumeID](#amazonec2-ec2_VolumeID) <br /> [#amazonec2-ec2_VolumeInitializationRate](#amazonec2-ec2_VolumeInitializationRate)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-image](#amazonec2-image)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ImageID](#amazonec2-ec2_ImageID) <br /> [#amazonec2-ec2_ImageType](#amazonec2-ec2_ImageType) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_Public](#amazonec2-ec2_Public) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-snapshot](#amazonec2-snapshot)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_ParentVolume](#amazonec2-ec2_ParentVolume) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SnapshotID](#amazonec2-ec2_SnapshotID) <br /> [#amazonec2-ec2_SnapshotTime](#amazonec2-ec2_SnapshotTime) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateReservedInstancesListing.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateReservedInstancesListing.html) **
  - **Description:** Grants permission to create a listing for Standard Reserved Instances to be sold in the Reserved Instance Marketplace
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateRestoreImageTask.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateRestoreImageTask.html) **
  - **Description:** Grants permission to start a task that restores an AMI from an S3 object previously created by using CreateStoreImageTask
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-image](#amazonec2-image)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ImageID](#amazonec2-ec2_ImageID) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateRoute.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateRoute.html) **
  - **Description:** Grants permission to create a route in a VPC route table
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-route-table](#amazonec2-route-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RouteTableID](#amazonec2-ec2_RouteTableID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateRouteServer.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateRouteServer.html) **
  - **Description:** Grants permission to create a route server
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-route-server](#amazonec2-route-server)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:**  ec2:CreateTags <br /> sns:CreateTopic 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateRouteServerEndpoint.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateRouteServerEndpoint.html) **
  - **Description:** Grants permission to create a route server endpoint
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-route-server](#amazonec2-route-server)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:**  ec2:AuthorizeSecurityGroupIngress <br /> ec2:CreateNetworkInterface <br /> ec2:CreateNetworkInterfacePermission <br /> ec2:CreateSecurityGroup <br /> ec2:CreateTags <br /> ec2:DescribeSecurityGroups 
  - **Resource types (\*required):**  [#amazonec2-route-server-endpoint](#amazonec2-route-server-endpoint)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-subnet](#amazonec2-subnet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateRouteServerPeer.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateRouteServerPeer.html) **
  - **Description:** Grants permission to create a route server peer
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-route-server-endpoint](#amazonec2-route-server-endpoint)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:**  ec2:AuthorizeSecurityGroupIngress <br /> ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-route-server-peer](#amazonec2-route-server-peer)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateRouteTable.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateRouteTable.html) **
  - **Description:** Grants permission to create a route table for a VPC
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-route-table](#amazonec2-route-table)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_RouteTableID](#amazonec2-ec2_RouteTableID)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateSecondaryNetwork.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateSecondaryNetwork.html) **
  - **Description:** Grants permission to create a secondary network
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-secondary-network](#amazonec2-secondary-network)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateSecondarySubnet.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateSecondarySubnet.html) **
  - **Description:** Grants permission to create a secondary subnet
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-secondary-network](#amazonec2-secondary-network)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-secondary-subnet](#amazonec2-secondary-subnet)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateSecurityGroup.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateSecurityGroup.html) **
  - **Description:** Grants permission to create a security group
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-security-group](#amazonec2-security-group)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_SecurityGroupID](#amazonec2-ec2_SecurityGroupID)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateSnapshot.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateSnapshot.html) **
  - **Description:** Grants permission to create a snapshot of an EBS volume and store it in Amazon S3
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-snapshot](#amazonec2-snapshot)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Location](#amazonec2-ec2_Location) <br /> [#amazonec2-ec2_OutpostArn](#amazonec2-ec2_OutpostArn) <br /> [#amazonec2-ec2_ParentVolume](#amazonec2-ec2_ParentVolume) <br /> [#amazonec2-ec2_SnapshotID](#amazonec2-ec2_SnapshotID) <br /> [#amazonec2-ec2_SourceAvailabilityZone](#amazonec2-ec2_SourceAvailabilityZone) <br /> [#amazonec2-ec2_SourceOutpostArn](#amazonec2-ec2_SourceOutpostArn) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-volume](#amazonec2-volume)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_Encrypted](#amazonec2-ec2_Encrypted) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_ParentVolume](#amazonec2-ec2_ParentVolume) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VolumeID](#amazonec2-ec2_VolumeID) <br /> [#amazonec2-ec2_VolumeInitializationRate](#amazonec2-ec2_VolumeInitializationRate) <br /> [#amazonec2-ec2_VolumeIops](#amazonec2-ec2_VolumeIops) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize) <br /> [#amazonec2-ec2_VolumeThroughput](#amazonec2-ec2_VolumeThroughput) <br /> [#amazonec2-ec2_VolumeType](#amazonec2-ec2_VolumeType)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateSnapshots.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateSnapshots.html) **
  - **Description:** Grants permission to create crash-consistent snapshots of multiple EBS volumes and store them in Amazon S3
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-snapshot](#amazonec2-snapshot)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Location](#amazonec2-ec2_Location) <br /> [#amazonec2-ec2_OutpostArn](#amazonec2-ec2_OutpostArn) <br /> [#amazonec2-ec2_ParentVolume](#amazonec2-ec2_ParentVolume) <br /> [#amazonec2-ec2_SnapshotID](#amazonec2-ec2_SnapshotID) <br /> [#amazonec2-ec2_SourceAvailabilityZone](#amazonec2-ec2_SourceAvailabilityZone) <br /> [#amazonec2-ec2_SourceOutpostArn](#amazonec2-ec2_SourceOutpostArn) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-volume](#amazonec2-volume)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Encrypted](#amazonec2-ec2_Encrypted) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VolumeID](#amazonec2-ec2_VolumeID) <br /> [#amazonec2-ec2_VolumeInitializationRate](#amazonec2-ec2_VolumeInitializationRate) <br /> [#amazonec2-ec2_VolumeIops](#amazonec2-ec2_VolumeIops) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize) <br /> [#amazonec2-ec2_VolumeThroughput](#amazonec2-ec2_VolumeThroughput) <br /> [#amazonec2-ec2_VolumeType](#amazonec2-ec2_VolumeType)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateSpotDatafeedSubscription.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateSpotDatafeedSubscription.html) **
  - **Description:** Grants permission to create a data feed for Spot Instances to view Spot Instance usage logs
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateStoreImageTask.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateStoreImageTask.html) **
  - **Description:** Grants permission to store an AMI as a single object in an S3 bucket
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-image](#amazonec2-image)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ImageID](#amazonec2-ec2_ImageID) <br /> [#amazonec2-ec2_ImageType](#amazonec2-ec2_ImageType) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_Public](#amazonec2-ec2_Public) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateSubnet.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateSubnet.html) **
  - **Description:** Grants permission to create a subnet in a VPC
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-subnet](#amazonec2-subnet)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Ipv4IpamPoolId](#amazonec2-ec2_Ipv4IpamPoolId) <br /> [#amazonec2-ec2_Ipv6IpamPoolId](#amazonec2-ec2_Ipv6IpamPoolId) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipam-pool](#amazonec2-ipam-pool)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateSubnetCidrReservation.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateSubnetCidrReservation.html) **
  - **Description:** Grants permission to create a subnet CIDR reservation
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-subnet](#amazonec2-subnet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTags.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTags.html) **
  - **Description:** Grants permission to add or overwrite one or more tags for Amazon EC2 resources
  - **Access level:** Tagging
  - **Resource types (\*required):**  [#amazonec2-capacity-block](#amazonec2-capacity-block)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-capacity-manager-data-export](#amazonec2-capacity-manager-data-export)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-capacity-reservation](#amazonec2-capacity-reservation)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-capacity-reservation-fleet](#amazonec2-capacity-reservation-fleet)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-carrier-gateway](#amazonec2-carrier-gateway)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-client-vpn-endpoint](#amazonec2-client-vpn-endpoint)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ClientRootCertificateChainArn](#amazonec2-ec2_ClientRootCertificateChainArn) <br /> [#amazonec2-ec2_CloudwatchLogGroupArn](#amazonec2-ec2_CloudwatchLogGroupArn) <br /> [#amazonec2-ec2_CloudwatchLogStreamArn](#amazonec2-ec2_CloudwatchLogStreamArn) <br /> [#amazonec2-ec2_DirectoryArn](#amazonec2-ec2_DirectoryArn) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SamlProviderArn](#amazonec2-ec2_SamlProviderArn) <br /> [#amazonec2-ec2_ServerCertificateArn](#amazonec2-ec2_ServerCertificateArn)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-coip-pool](#amazonec2-coip-pool)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-customer-gateway](#amazonec2-customer-gateway)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-declarative-policies-report](#amazonec2-declarative-policies-report)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-dedicated-host](#amazonec2-dedicated-host)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_AutoPlacement](#amazonec2-ec2_AutoPlacement) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_HostRecovery](#amazonec2-ec2_HostRecovery) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_Quantity](#amazonec2-ec2_Quantity) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-dhcp-options](#amazonec2-dhcp-options)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_DhcpOptionsID](#amazonec2-ec2_DhcpOptionsID) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-egress-only-internet-gateway](#amazonec2-egress-only-internet-gateway)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-elastic-gpu](#amazonec2-elastic-gpu)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ElasticGpuType](#amazonec2-ec2_ElasticGpuType) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-elastic-ip](#amazonec2-elastic-ip)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_AllocationId](#amazonec2-ec2_AllocationId) <br /> [#amazonec2-ec2_Domain](#amazonec2-ec2_Domain) <br /> [#amazonec2-ec2_PublicIpAddress](#amazonec2-ec2_PublicIpAddress) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-export-image-task](#amazonec2-export-image-task)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-export-instance-task](#amazonec2-export-instance-task)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-fleet](#amazonec2-fleet)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-fpga-image](#amazonec2-fpga-image)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_Public](#amazonec2-ec2_Public) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-host-reservation](#amazonec2-host-reservation)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-image](#amazonec2-image)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ImageID](#amazonec2-ec2_ImageID) <br /> [#amazonec2-ec2_ImageType](#amazonec2-ec2_ImageType) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_Public](#amazonec2-ec2_Public) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-image-usage-report](#amazonec2-image-usage-report)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-import-image-task](#amazonec2-import-image-task)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-import-snapshot-task](#amazonec2-import-snapshot-task)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ProductCode](#amazonec2-ec2_ProductCode) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-instance-connect-endpoint](#amazonec2-instance-connect-endpoint)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-instance-event-window](#amazonec2-instance-event-window)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-internet-gateway](#amazonec2-internet-gateway)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_InternetGatewayID](#amazonec2-ec2_InternetGatewayID) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipam](#amazonec2-ipam)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipam-external-resource-verification-token](#amazonec2-ipam-external-resource-verification-token)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipam-policy](#amazonec2-ipam-policy)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipam-pool](#amazonec2-ipam-pool)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipam-prefix-list-resolver](#amazonec2-ipam-prefix-list-resolver)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipam-prefix-list-resolver-target](#amazonec2-ipam-prefix-list-resolver-target)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipam-resource-discovery](#amazonec2-ipam-resource-discovery)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipam-resource-discovery-association](#amazonec2-ipam-resource-discovery-association)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipam-scope](#amazonec2-ipam-scope)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipv4pool-ec2](#amazonec2-ipv4pool-ec2)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipv6pool-ec2](#amazonec2-ipv6pool-ec2)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-key-pair](#amazonec2-key-pair)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_KeyPairName](#amazonec2-ec2_KeyPairName) <br /> [#amazonec2-ec2_KeyPairType](#amazonec2-ec2_KeyPairType) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-launch-template](#amazonec2-launch-template)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-local-gateway](#amazonec2-local-gateway)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-local-gateway-route-table](#amazonec2-local-gateway-route-table)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-local-gateway-route-table-virtual-interface-group-association](#amazonec2-local-gateway-route-table-virtual-interface-group-association)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-local-gateway-route-table-vpc-association](#amazonec2-local-gateway-route-table-vpc-association)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-local-gateway-virtual-interface](#amazonec2-local-gateway-virtual-interface)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-local-gateway-virtual-interface-group](#amazonec2-local-gateway-virtual-interface-group)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-natgateway](#amazonec2-natgateway)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-network-acl](#amazonec2-network-acl)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_NetworkAclID](#amazonec2-ec2_NetworkAclID) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-network-insights-access-scope](#amazonec2-network-insights-access-scope)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-network-insights-access-scope-analysis](#amazonec2-network-insights-access-scope-analysis)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-network-insights-analysis](#amazonec2-network-insights-analysis)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-network-insights-path](#amazonec2-network-insights-path)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-network-interface](#amazonec2-network-interface)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_AuthorizedUser](#amazonec2-ec2_AuthorizedUser) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_NetworkInterfaceID](#amazonec2-ec2_NetworkInterfaceID) <br /> [#amazonec2-ec2_Permission](#amazonec2-ec2_Permission) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Subnet](#amazonec2-ec2_Subnet) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-placement-group](#amazonec2-placement-group)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_PlacementGroupName](#amazonec2-ec2_PlacementGroupName) <br /> [#amazonec2-ec2_PlacementGroupStrategy](#amazonec2-ec2_PlacementGroupStrategy) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-prefix-list](#amazonec2-prefix-list)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_IpamPrefixListResolverTargetId](#amazonec2-ec2_IpamPrefixListResolverTargetId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-replace-root-volume-task](#amazonec2-replace-root-volume-task)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-reserved-instances](#amazonec2-reserved-instances)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ReservedInstancesOfferingType](#amazonec2-ec2_ReservedInstancesOfferingType) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-route-server](#amazonec2-route-server)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-route-server-endpoint](#amazonec2-route-server-endpoint)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-route-server-peer](#amazonec2-route-server-peer)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-route-table](#amazonec2-route-table)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RouteTableID](#amazonec2-ec2_RouteTableID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-secondary-interface](#amazonec2-secondary-interface)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-secondary-network](#amazonec2-secondary-network)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-secondary-subnet](#amazonec2-secondary-subnet)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-security-group](#amazonec2-security-group)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SecurityGroupID](#amazonec2-ec2_SecurityGroupID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-security-group-rule](#amazonec2-security-group-rule)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-snapshot](#amazonec2-snapshot)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Encrypted](#amazonec2-ec2_Encrypted) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_ParentVolume](#amazonec2-ec2_ParentVolume) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SnapshotID](#amazonec2-ec2_SnapshotID) <br /> [#amazonec2-ec2_SnapshotTime](#amazonec2-ec2_SnapshotTime) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-spot-fleet-request](#amazonec2-spot-fleet-request)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-spot-instances-request](#amazonec2-spot-instances-request)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-subnet](#amazonec2-subnet)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-subnet-cidr-reservation](#amazonec2-subnet-cidr-reservation)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-traffic-mirror-filter](#amazonec2-traffic-mirror-filter)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-traffic-mirror-filter-rule](#amazonec2-traffic-mirror-filter-rule)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-traffic-mirror-session](#amazonec2-traffic-mirror-session)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-traffic-mirror-target](#amazonec2-traffic-mirror-target)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway](#amazonec2-transit-gateway)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayId](#amazonec2-ec2_transitGatewayId)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-attachment](#amazonec2-transit-gateway-attachment)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayAttachmentId](#amazonec2-ec2_transitGatewayAttachmentId)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-connect-peer](#amazonec2-transit-gateway-connect-peer)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayConnectPeerId](#amazonec2-ec2_transitGatewayConnectPeerId)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-metering-policy](#amazonec2-transit-gateway-metering-policy)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayMeteringPolicyId](#amazonec2-ec2_transitGatewayMeteringPolicyId)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-multicast-domain](#amazonec2-transit-gateway-multicast-domain)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayMulticastDomainId](#amazonec2-ec2_transitGatewayMulticastDomainId)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-policy-table](#amazonec2-transit-gateway-policy-table)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayPolicyTableId](#amazonec2-ec2_transitGatewayPolicyTableId)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-route-table](#amazonec2-transit-gateway-route-table)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayRouteTableId](#amazonec2-ec2_transitGatewayRouteTableId)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-route-table-announcement](#amazonec2-transit-gateway-route-table-announcement)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayRouteTableAnnouncementId](#amazonec2-ec2_transitGatewayRouteTableAnnouncementId)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-verified-access-endpoint](#amazonec2-verified-access-endpoint)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-verified-access-endpoint-target](#amazonec2-verified-access-endpoint-target)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-verified-access-group](#amazonec2-verified-access-group)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-verified-access-instance](#amazonec2-verified-access-instance)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-verified-access-policy](#amazonec2-verified-access-policy)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-verified-access-trust-provider](#amazonec2-verified-access-trust-provider)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-volume](#amazonec2-volume)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_Encrypted](#amazonec2-ec2_Encrypted) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_ParentSnapshot](#amazonec2-ec2_ParentSnapshot) <br /> [#amazonec2-ec2_ParentVolume](#amazonec2-ec2_ParentVolume) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VolumeID](#amazonec2-ec2_VolumeID) <br /> [#amazonec2-ec2_VolumeInitializationRate](#amazonec2-ec2_VolumeInitializationRate) <br /> [#amazonec2-ec2_VolumeIops](#amazonec2-ec2_VolumeIops) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize) <br /> [#amazonec2-ec2_VolumeThroughput](#amazonec2-ec2_VolumeThroughput) <br /> [#amazonec2-ec2_VolumeType](#amazonec2-ec2_VolumeType)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc-block-public-access-exclusion](#amazonec2-vpc-block-public-access-exclusion)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc-encryption-control](#amazonec2-vpc-encryption-control)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc-endpoint](#amazonec2-vpc-endpoint)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc-endpoint-connection](#amazonec2-vpc-endpoint-connection)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc-endpoint-service](#amazonec2-vpc-endpoint-service)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VpceMultiRegion](#amazonec2-ec2_VpceMultiRegion) <br /> [#amazonec2-ec2_VpceServiceRegion](#amazonec2-ec2_VpceServiceRegion) <br /> [#amazonec2-ec2_VpceSupportedRegion](#amazonec2-ec2_VpceSupportedRegion)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc-endpoint-service-permission](#amazonec2-vpc-endpoint-service-permission)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc-flow-log](#amazonec2-vpc-flow-log)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc-peering-connection](#amazonec2-vpc-peering-connection)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_AccepterVpc](#amazonec2-ec2_AccepterVpc) <br /> [#amazonec2-ec2_RequesterVpc](#amazonec2-ec2_RequesterVpc) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VpcPeeringConnectionID](#amazonec2-ec2_VpcPeeringConnectionID)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpn-concentrator](#amazonec2-vpn-concentrator)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpn-connection](#amazonec2-vpn-connection)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_AuthenticationType](#amazonec2-ec2_AuthenticationType) <br /> [#amazonec2-ec2_DPDTimeoutSeconds](#amazonec2-ec2_DPDTimeoutSeconds) <br /> [#amazonec2-ec2_GatewayType](#amazonec2-ec2_GatewayType) <br /> [#amazonec2-ec2_IKEVersions](#amazonec2-ec2_IKEVersions) <br /> [#amazonec2-ec2_InsideTunnelCidr](#amazonec2-ec2_InsideTunnelCidr) <br /> [#amazonec2-ec2_InsideTunnelIpv6Cidr](#amazonec2-ec2_InsideTunnelIpv6Cidr) <br /> [#amazonec2-ec2_Phase1DHGroup](#amazonec2-ec2_Phase1DHGroup) <br /> [#amazonec2-ec2_Phase1EncryptionAlgorithms](#amazonec2-ec2_Phase1EncryptionAlgorithms) <br /> [#amazonec2-ec2_Phase1IntegrityAlgorithms](#amazonec2-ec2_Phase1IntegrityAlgorithms) <br /> [#amazonec2-ec2_Phase1LifetimeSeconds](#amazonec2-ec2_Phase1LifetimeSeconds) <br /> [#amazonec2-ec2_Phase2DHGroup](#amazonec2-ec2_Phase2DHGroup) <br /> [#amazonec2-ec2_Phase2EncryptionAlgorithms](#amazonec2-ec2_Phase2EncryptionAlgorithms) <br /> [#amazonec2-ec2_Phase2IntegrityAlgorithms](#amazonec2-ec2_Phase2IntegrityAlgorithms) <br /> [#amazonec2-ec2_Phase2LifetimeSeconds](#amazonec2-ec2_Phase2LifetimeSeconds) <br /> [#amazonec2-ec2_RekeyFuzzPercentage](#amazonec2-ec2_RekeyFuzzPercentage) <br /> [#amazonec2-ec2_RekeyMarginTimeSeconds](#amazonec2-ec2_RekeyMarginTimeSeconds) <br /> [#amazonec2-ec2_ReplayWindowSizePackets](#amazonec2-ec2_ReplayWindowSizePackets) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RoutingType](#amazonec2-ec2_RoutingType)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpn-gateway](#amazonec2-vpn-gateway)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_CreateAction](#amazonec2-ec2_CreateAction) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTrafficMirrorFilter.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTrafficMirrorFilter.html) **
  - **Description:** Grants permission to create a traffic mirror filter
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-traffic-mirror-filter](#amazonec2-traffic-mirror-filter)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTrafficMirrorFilterRule.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTrafficMirrorFilterRule.html) **
  - **Description:** Grants permission to create a traffic mirror filter rule
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-traffic-mirror-filter](#amazonec2-traffic-mirror-filter)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-traffic-mirror-filter-rule](#amazonec2-traffic-mirror-filter-rule)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTrafficMirrorSession.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTrafficMirrorSession.html) **
  - **Description:** Grants permission to create a traffic mirror session
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-network-interface](#amazonec2-network-interface)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_NetworkInterfaceID](#amazonec2-ec2_NetworkInterfaceID) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Subnet](#amazonec2-ec2_Subnet) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-traffic-mirror-filter](#amazonec2-traffic-mirror-filter)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-traffic-mirror-session](#amazonec2-traffic-mirror-session)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-traffic-mirror-target](#amazonec2-traffic-mirror-target)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTrafficMirrorTarget.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTrafficMirrorTarget.html) **
  - **Description:** Grants permission to create a traffic mirror target
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-traffic-mirror-target](#amazonec2-traffic-mirror-target)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-network-interface](#amazonec2-network-interface)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_NetworkInterfaceID](#amazonec2-ec2_NetworkInterfaceID) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc-endpoint](#amazonec2-vpc-endpoint)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VpceServiceName](#amazonec2-ec2_VpceServiceName) <br /> [#amazonec2-ec2_VpceServiceOwner](#amazonec2-ec2_VpceServiceOwner)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTransitGateway.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTransitGateway.html) **
  - **Description:** Grants permission to create a transit gateway
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-transit-gateway](#amazonec2-transit-gateway)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_transitGatewayId](#amazonec2-ec2_transitGatewayId)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTransitGatewayConnect.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTransitGatewayConnect.html) **
  - **Description:** Grants permission to create a Connect attachment from a specified transit gateway attachment
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-attachment](#amazonec2-transit-gateway-attachment)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_transitGatewayAttachmentId](#amazonec2-ec2_transitGatewayAttachmentId)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTransitGatewayConnectPeer.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTransitGatewayConnectPeer.html) **
  - **Description:** Grants permission to create a Connect peer between a transit gateway and an appliance
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-attachment](#amazonec2-transit-gateway-attachment)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayAttachmentId](#amazonec2-ec2_transitGatewayAttachmentId)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-connect-peer](#amazonec2-transit-gateway-connect-peer)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_transitGatewayConnectPeerId](#amazonec2-ec2_transitGatewayConnectPeerId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTransitGatewayMeteringPolicy.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTransitGatewayMeteringPolicy.html) **
  - **Description:** Grants permission to create a metering policy for a transit gateway
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-transit-gateway](#amazonec2-transit-gateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayId](#amazonec2-ec2_transitGatewayId)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-metering-policy](#amazonec2-transit-gateway-metering-policy)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_transitGatewayMeteringPolicyId](#amazonec2-ec2_transitGatewayMeteringPolicyId)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-attachment](#amazonec2-transit-gateway-attachment)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayAttachmentId](#amazonec2-ec2_transitGatewayAttachmentId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTransitGatewayMeteringPolicyEntry.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTransitGatewayMeteringPolicyEntry.html) **
  - **Description:** Grants permission to create an entry for a transit gateway metering policy
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-metering-policy](#amazonec2-transit-gateway-metering-policy)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayMeteringPolicyId](#amazonec2-ec2_transitGatewayMeteringPolicyId)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-attachment](#amazonec2-transit-gateway-attachment)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayAttachmentId](#amazonec2-ec2_transitGatewayAttachmentId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTransitGatewayMulticastDomain.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTransitGatewayMulticastDomain.html) **
  - **Description:** Grants permission to create a multicast domain for a transit gateway
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-transit-gateway](#amazonec2-transit-gateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayId](#amazonec2-ec2_transitGatewayId)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-multicast-domain](#amazonec2-transit-gateway-multicast-domain)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_transitGatewayMulticastDomainId](#amazonec2-ec2_transitGatewayMulticastDomainId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTransitGatewayPeeringAttachment.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTransitGatewayPeeringAttachment.html) **
  - **Description:** Grants permission to request a transit gateway peering attachment between a requester and accepter transit gateway
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-transit-gateway](#amazonec2-transit-gateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayId](#amazonec2-ec2_transitGatewayId)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-attachment](#amazonec2-transit-gateway-attachment)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_transitGatewayAttachmentId](#amazonec2-ec2_transitGatewayAttachmentId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTransitGatewayPolicyTable.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTransitGatewayPolicyTable.html) **
  - **Description:** Grants permission to create a transit gateway policy table
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-transit-gateway](#amazonec2-transit-gateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayId](#amazonec2-ec2_transitGatewayId)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-policy-table](#amazonec2-transit-gateway-policy-table)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_transitGatewayPolicyTableId](#amazonec2-ec2_transitGatewayPolicyTableId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTransitGatewayPrefixListReference.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTransitGatewayPrefixListReference.html) **
  - **Description:** Grants permission to create a transit gateway prefix list reference
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-prefix-list](#amazonec2-prefix-list)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-route-table](#amazonec2-transit-gateway-route-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayRouteTableId](#amazonec2-ec2_transitGatewayRouteTableId)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-attachment](#amazonec2-transit-gateway-attachment)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayAttachmentId](#amazonec2-ec2_transitGatewayAttachmentId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTransitGatewayRoute.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTransitGatewayRoute.html) **
  - **Description:** Grants permission to create a static route for a transit gateway route table
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-route-table](#amazonec2-transit-gateway-route-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayRouteTableId](#amazonec2-ec2_transitGatewayRouteTableId)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-attachment](#amazonec2-transit-gateway-attachment)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayAttachmentId](#amazonec2-ec2_transitGatewayAttachmentId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTransitGatewayRouteTable.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTransitGatewayRouteTable.html) **
  - **Description:** Grants permission to create a route table for a transit gateway
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-transit-gateway](#amazonec2-transit-gateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayId](#amazonec2-ec2_transitGatewayId)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-route-table](#amazonec2-transit-gateway-route-table)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_transitGatewayRouteTableId](#amazonec2-ec2_transitGatewayRouteTableId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTransitGatewayRouteTableAnnouncement.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTransitGatewayRouteTableAnnouncement.html) **
  - **Description:** Grants permission to create an announcement for a transit gateway route table
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-attachment](#amazonec2-transit-gateway-attachment)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayAttachmentId](#amazonec2-ec2_transitGatewayAttachmentId)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-route-table](#amazonec2-transit-gateway-route-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayRouteTableId](#amazonec2-ec2_transitGatewayRouteTableId)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-route-table-announcement](#amazonec2-transit-gateway-route-table-announcement)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_transitGatewayRouteTableAnnouncementId](#amazonec2-ec2_transitGatewayRouteTableAnnouncementId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTransitGatewayVpcAttachment.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTransitGatewayVpcAttachment.html) **
  - **Description:** Grants permission to attach a VPC to a transit gateway
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-subnet](#amazonec2-subnet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway](#amazonec2-transit-gateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayId](#amazonec2-ec2_transitGatewayId)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-attachment](#amazonec2-transit-gateway-attachment)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_transitGatewayAttachmentId](#amazonec2-ec2_transitGatewayAttachmentId)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateVerifiedAccessEndpoint.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateVerifiedAccessEndpoint.html) **
  - **Description:** Grants permission to create a Verified Access endpoint
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-verified-access-endpoint](#amazonec2-verified-access-endpoint)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-verified-access-group](#amazonec2-verified-access-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-network-interface](#amazonec2-network-interface)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AuthorizedUser](#amazonec2-ec2_AuthorizedUser) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_NetworkInterfaceID](#amazonec2-ec2_NetworkInterfaceID) <br /> [#amazonec2-ec2_Permission](#amazonec2-ec2_Permission) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Subnet](#amazonec2-ec2_Subnet) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-security-group](#amazonec2-security-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SecurityGroupID](#amazonec2-ec2_SecurityGroupID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-subnet](#amazonec2-subnet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateVerifiedAccessGroup.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateVerifiedAccessGroup.html) **
  - **Description:** Grants permission to create a Verified Access group
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-verified-access-group](#amazonec2-verified-access-group)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-verified-access-instance](#amazonec2-verified-access-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateVerifiedAccessInstance.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateVerifiedAccessInstance.html) **
  - **Description:** Grants permission to create a Verified Access instance
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-verified-access-instance](#amazonec2-verified-access-instance)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateVerifiedAccessTrustProvider.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateVerifiedAccessTrustProvider.html) **
  - **Description:** Grants permission to create a verified trust provider
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-verified-access-trust-provider](#amazonec2-verified-access-trust-provider)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateVolume.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateVolume.html) **
  - **Description:** Grants permission to create an EBS volume
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-volume](#amazonec2-volume)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_Encrypted](#amazonec2-ec2_Encrypted) <br /> [#amazonec2-ec2_KmsKeyId](#amazonec2-ec2_KmsKeyId) <br /> [#amazonec2-ec2_ParentSnapshot](#amazonec2-ec2_ParentSnapshot) <br /> [#amazonec2-ec2_VolumeID](#amazonec2-ec2_VolumeID) <br /> [#amazonec2-ec2_VolumeInitializationRate](#amazonec2-ec2_VolumeInitializationRate) <br /> [#amazonec2-ec2_VolumeIops](#amazonec2-ec2_VolumeIops) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize) <br /> [#amazonec2-ec2_VolumeThroughput](#amazonec2-ec2_VolumeThroughput) <br /> [#amazonec2-ec2_VolumeType](#amazonec2-ec2_VolumeType)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-snapshot](#amazonec2-snapshot)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Encrypted](#amazonec2-ec2_Encrypted) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_ParentVolume](#amazonec2-ec2_ParentVolume) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SnapshotTime](#amazonec2-ec2_SnapshotTime) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateVpc.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateVpc.html) **
  - **Description:** Grants permission to create a VPC with a specified CIDR block
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Ipv4IpamPoolId](#amazonec2-ec2_Ipv4IpamPoolId) <br /> [#amazonec2-ec2_Ipv6IpamPoolId](#amazonec2-ec2_Ipv6IpamPoolId) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-ipam-pool](#amazonec2-ipam-pool)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipv6pool-ec2](#amazonec2-ipv6pool-ec2)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateVpcBlockPublicAccessExclusion.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateVpcBlockPublicAccessExclusion.html) **
  - **Description:** Grants permission to create an exclusion list for blocked public access on a VPC
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpc-block-public-access-exclusion](#amazonec2-vpc-block-public-access-exclusion)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-subnet](#amazonec2-subnet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Ipv4IpamPoolId](#amazonec2-ec2_Ipv4IpamPoolId) <br /> [#amazonec2-ec2_Ipv6IpamPoolId](#amazonec2-ec2_Ipv6IpamPoolId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateVpcEncryptionControl.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateVpcEncryptionControl.html) **
  - **Description:** Grants permission to create a VPC Encryption Control
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-vpc-encryption-control](#amazonec2-vpc-encryption-control)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateVpcEndpoint.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateVpcEndpoint.html) **
  - **Description:** Grants permission to create a VPC endpoint for an AWS service
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:**  ec2:CreateTags <br /> ec2:DescribeSecurityGroups <br /> ec2:DescribeSubnets <br /> ec2:DescribeVpcs <br /> route53:AssociateVPCWithHostedZone 
  - **Resource types (\*required):**  [#amazonec2-vpc-endpoint](#amazonec2-vpc-endpoint)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_VpceMultiRegion](#amazonec2-ec2_VpceMultiRegion) <br /> [#amazonec2-ec2_VpcePrivateDnsPreference](#amazonec2-ec2_VpcePrivateDnsPreference) <br /> [#amazonec2-ec2_VpcePrivateDnsSpecifiedDomains](#amazonec2-ec2_VpcePrivateDnsSpecifiedDomains) <br /> [#amazonec2-ec2_VpceServiceName](#amazonec2-ec2_VpceServiceName) <br /> [#amazonec2-ec2_VpceServiceOwner](#amazonec2-ec2_VpceServiceOwner) <br /> [#amazonec2-ec2_VpceServiceRegion](#amazonec2-ec2_VpceServiceRegion)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-route-table](#amazonec2-route-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RouteTableID](#amazonec2-ec2_RouteTableID)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-security-group](#amazonec2-security-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SecurityGroupID](#amazonec2-ec2_SecurityGroupID)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-subnet](#amazonec2-subnet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateVpcEndpointConnectionNotification.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateVpcEndpointConnectionNotification.html) **
  - **Description:** Grants permission to create a connection notification for a VPC endpoint or VPC endpoint service
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpc-endpoint](#amazonec2-vpc-endpoint)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc-endpoint-service](#amazonec2-vpc-endpoint-service)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VpceMultiRegion](#amazonec2-ec2_VpceMultiRegion) <br /> [#amazonec2-ec2_VpceServiceRegion](#amazonec2-ec2_VpceServiceRegion)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateVpcEndpointServiceConfiguration.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateVpcEndpointServiceConfiguration.html) **
  - **Description:** Grants permission to create a VPC endpoint service configuration to which service consumers (AWS accounts, IAM users, and IAM roles) can connect
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpc-endpoint-service](#amazonec2-vpc-endpoint-service)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_VpceMultiRegion](#amazonec2-ec2_VpceMultiRegion) <br /> [#amazonec2-ec2_VpceServicePrivateDnsName](#amazonec2-ec2_VpceServicePrivateDnsName) <br /> [#amazonec2-ec2_VpceServiceRegion](#amazonec2-ec2_VpceServiceRegion)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateVpcPeeringConnection.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateVpcPeeringConnection.html) **
  - **Description:** Grants permission to request a VPC peering connection between two VPCs
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-vpc-peering-connection](#amazonec2-vpc-peering-connection)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_AccepterVpc](#amazonec2-ec2_AccepterVpc) <br /> [#amazonec2-ec2_RequesterVpc](#amazonec2-ec2_RequesterVpc) <br /> [#amazonec2-ec2_VpcPeeringConnectionID](#amazonec2-ec2_VpcPeeringConnectionID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateVpnConcentrator.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateVpnConcentrator.html) **
  - **Description:** Grants permission to create a VPN concentrator that aggregates multiple VPN connections to a transit gateway
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpn-concentrator](#amazonec2-vpn-concentrator)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway](#amazonec2-transit-gateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayId](#amazonec2-ec2_transitGatewayId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateVpnConnection.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateVpnConnection.html) **
  - **Description:** Grants permission to create a VPN connection between a virtual private gateway or transit gateway and a customer gateway
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-customer-gateway](#amazonec2-customer-gateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-vpn-connection](#amazonec2-vpn-connection)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_AuthenticationType](#amazonec2-ec2_AuthenticationType) <br /> [#amazonec2-ec2_DPDTimeoutSeconds](#amazonec2-ec2_DPDTimeoutSeconds) <br /> [#amazonec2-ec2_GatewayType](#amazonec2-ec2_GatewayType) <br /> [#amazonec2-ec2_IKEVersions](#amazonec2-ec2_IKEVersions) <br /> [#amazonec2-ec2_InsideTunnelCidr](#amazonec2-ec2_InsideTunnelCidr) <br /> [#amazonec2-ec2_InsideTunnelIpv6Cidr](#amazonec2-ec2_InsideTunnelIpv6Cidr) <br /> [#amazonec2-ec2_Phase1DHGroup](#amazonec2-ec2_Phase1DHGroup) <br /> [#amazonec2-ec2_Phase1EncryptionAlgorithms](#amazonec2-ec2_Phase1EncryptionAlgorithms) <br /> [#amazonec2-ec2_Phase1IntegrityAlgorithms](#amazonec2-ec2_Phase1IntegrityAlgorithms) <br /> [#amazonec2-ec2_Phase1LifetimeSeconds](#amazonec2-ec2_Phase1LifetimeSeconds) <br /> [#amazonec2-ec2_Phase2DHGroup](#amazonec2-ec2_Phase2DHGroup) <br /> [#amazonec2-ec2_Phase2EncryptionAlgorithms](#amazonec2-ec2_Phase2EncryptionAlgorithms) <br /> [#amazonec2-ec2_Phase2IntegrityAlgorithms](#amazonec2-ec2_Phase2IntegrityAlgorithms) <br /> [#amazonec2-ec2_Phase2LifetimeSeconds](#amazonec2-ec2_Phase2LifetimeSeconds) <br /> [#amazonec2-ec2_RekeyFuzzPercentage](#amazonec2-ec2_RekeyFuzzPercentage) <br /> [#amazonec2-ec2_RekeyMarginTimeSeconds](#amazonec2-ec2_RekeyMarginTimeSeconds) <br /> [#amazonec2-ec2_ReplayWindowSizePackets](#amazonec2-ec2_ReplayWindowSizePackets) <br /> [#amazonec2-ec2_RoutingType](#amazonec2-ec2_RoutingType)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway](#amazonec2-transit-gateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayId](#amazonec2-ec2_transitGatewayId)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-attachment](#amazonec2-transit-gateway-attachment)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayAttachmentId](#amazonec2-ec2_transitGatewayAttachmentId)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpn-concentrator](#amazonec2-vpn-concentrator)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpn-gateway](#amazonec2-vpn-gateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateVpnConnectionRoute.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateVpnConnectionRoute.html) **
  - **Description:** Grants permission to create a static route for a VPN connection between a virtual private gateway and a customer gateway
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpn-connection](#amazonec2-vpn-connection)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateVpnGateway.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateVpnGateway.html) **
  - **Description:** Grants permission to create a virtual private gateway
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpn-gateway](#amazonec2-vpn-gateway)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteCapacityManagerDataExport.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteCapacityManagerDataExport.html) **
  - **Description:** Grants permission to delete an existing Capacity Manager data export configuration
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-capacity-manager-data-export](#amazonec2-capacity-manager-data-export)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteCarrierGateway.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteCarrierGateway.html) **
  - **Description:** Grants permission to delete a carrier gateway
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-carrier-gateway](#amazonec2-carrier-gateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteClientVpnEndpoint.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteClientVpnEndpoint.html) **
  - **Description:** Grants permission to delete a Client VPN endpoint
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-client-vpn-endpoint](#amazonec2-client-vpn-endpoint)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ClientRootCertificateChainArn](#amazonec2-ec2_ClientRootCertificateChainArn) <br /> [#amazonec2-ec2_CloudwatchLogGroupArn](#amazonec2-ec2_CloudwatchLogGroupArn) <br /> [#amazonec2-ec2_CloudwatchLogStreamArn](#amazonec2-ec2_CloudwatchLogStreamArn) <br /> [#amazonec2-ec2_DirectoryArn](#amazonec2-ec2_DirectoryArn) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SamlProviderArn](#amazonec2-ec2_SamlProviderArn) <br /> [#amazonec2-ec2_ServerCertificateArn](#amazonec2-ec2_ServerCertificateArn)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteClientVpnRoute.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteClientVpnRoute.html) **
  - **Description:** Grants permission to delete a route from a Client VPN endpoint
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-client-vpn-endpoint](#amazonec2-client-vpn-endpoint)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ClientRootCertificateChainArn](#amazonec2-ec2_ClientRootCertificateChainArn) <br /> [#amazonec2-ec2_CloudwatchLogGroupArn](#amazonec2-ec2_CloudwatchLogGroupArn) <br /> [#amazonec2-ec2_CloudwatchLogStreamArn](#amazonec2-ec2_CloudwatchLogStreamArn) <br /> [#amazonec2-ec2_DirectoryArn](#amazonec2-ec2_DirectoryArn) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SamlProviderArn](#amazonec2-ec2_SamlProviderArn) <br /> [#amazonec2-ec2_ServerCertificateArn](#amazonec2-ec2_ServerCertificateArn)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-subnet](#amazonec2-subnet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteCoipCidr.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteCoipCidr.html) **
  - **Description:** Grants permission to delete a range of customer-owned IP (CoIP) addresses
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-coip-pool](#amazonec2-coip-pool)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteCoipPool.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteCoipPool.html) **
  - **Description:** Grants permission to delete a pool of customer-owned IP (CoIP) addresses
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-coip-pool](#amazonec2-coip-pool)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/outposts/latest/userguide/identity-access-management.html](https://docs.aws.amazon.com/outposts/latest/userguide/identity-access-management.html) [permission only]**
  - **Description:** Grants permission to deny a service from accessing a customer-owned IP (CoIP) pool
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#amazonec2-coip-pool](#amazonec2-coip-pool)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteCustomerGateway.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteCustomerGateway.html) **
  - **Description:** Grants permission to delete a customer gateway
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-customer-gateway](#amazonec2-customer-gateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteDhcpOptions.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteDhcpOptions.html) **
  - **Description:** Grants permission to delete a set of DHCP options
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-dhcp-options](#amazonec2-dhcp-options)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_DhcpOptionsID](#amazonec2-ec2_DhcpOptionsID) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteEgressOnlyInternetGateway.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteEgressOnlyInternetGateway.html) **
  - **Description:** Grants permission to delete an egress-only internet gateway
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-egress-only-internet-gateway](#amazonec2-egress-only-internet-gateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteFleets.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteFleets.html) **
  - **Description:** Grants permission to delete one or more EC2 Fleets
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-fleet](#amazonec2-fleet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteFlowLogs.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteFlowLogs.html) **
  - **Description:** Grants permission to delete one or more flow logs
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpc-flow-log](#amazonec2-vpc-flow-log)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteFpgaImage.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteFpgaImage.html) **
  - **Description:** Grants permission to delete an Amazon FPGA Image (AFI)
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-fpga-image](#amazonec2-fpga-image)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_Public](#amazonec2-ec2_Public) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteImageUsageReport.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteImageUsageReport.html) **
  - **Description:** Grants permission to delete an AMI usage report
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-image-usage-report](#amazonec2-image-usage-report)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteInstanceConnectEndpoint.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteInstanceConnectEndpoint.html) **
  - **Description:** Grants permission to delete an EC2 Instance Connect Endpoint
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance-connect-endpoint](#amazonec2-instance-connect-endpoint)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteInstanceEventWindow.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteInstanceEventWindow.html) **
  - **Description:** Grants permission to delete the specified event window
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance-event-window](#amazonec2-instance-event-window)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteInternetGateway.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteInternetGateway.html) **
  - **Description:** Grants permission to delete an internet gateway
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-internet-gateway](#amazonec2-internet-gateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_InternetGatewayID](#amazonec2-ec2_InternetGatewayID) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteIpam.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteIpam.html) **
  - **Description:** Grants permission to delete an Amazon VPC IP Address Manager (IPAM) and remove all monitored data associated with the IPAM including the historical data for CIDRs
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipam](#amazonec2-ipam)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteIpamExternalResourceVerificationToken.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteIpamExternalResourceVerificationToken.html) **
  - **Description:** Grants permission to delete a verification token, which proves ownership of an external resource
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipam-external-resource-verification-token](#amazonec2-ipam-external-resource-verification-token)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteIpamPolicy.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteIpamPolicy.html) **
  - **Description:** Grants permission to delete an Amazon VPC IP Address Manager (IPAM) policy
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipam-policy](#amazonec2-ipam-policy)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteIpamPool.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteIpamPool.html) **
  - **Description:** Grants permission to delete an Amazon VPC IP Address Manager (IPAM) pool
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipam-pool](#amazonec2-ipam-pool)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteIpamPrefixListResolver.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteIpamPrefixListResolver.html) **
  - **Description:** Grants permission to delete an IPAM prefix list resolver
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipam-prefix-list-resolver](#amazonec2-ipam-prefix-list-resolver)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteIpamPrefixListResolverTarget.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteIpamPrefixListResolverTarget.html) **
  - **Description:** Grants permission to delete an IPAM prefix list resolver target
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipam-prefix-list-resolver-target](#amazonec2-ipam-prefix-list-resolver-target)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteIpamResourceDiscovery.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteIpamResourceDiscovery.html) **
  - **Description:** Grants permission to delete an IPAM resource discovery
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipam-resource-discovery](#amazonec2-ipam-resource-discovery)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteIpamScope.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteIpamScope.html) **
  - **Description:** Grants permission to delete the scope for an Amazon VPC IP Address Manager (IPAM)
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipam-scope](#amazonec2-ipam-scope)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteKeyPair.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteKeyPair.html) **
  - **Description:** Grants permission to delete a key pair by removing the public key from Amazon EC2
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-key-pair](#amazonec2-key-pair)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_KeyPairName](#amazonec2-ec2_KeyPairName) <br /> [#amazonec2-ec2_KeyPairType](#amazonec2-ec2_KeyPairType) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteLaunchTemplate.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteLaunchTemplate.html) **
  - **Description:** Grants permission to delete a launch template and its associated versions
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-launch-template](#amazonec2-launch-template)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteLaunchTemplateVersions.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteLaunchTemplateVersions.html) **
  - **Description:** Grants permission to delete one or more versions of a launch template
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-launch-template](#amazonec2-launch-template)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteLocalGatewayRoute.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteLocalGatewayRoute.html) **
  - **Description:** Grants permission to delete a route from a local gateway route table
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-local-gateway-route-table](#amazonec2-local-gateway-route-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-prefix-list](#amazonec2-prefix-list)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteLocalGatewayRouteTable.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteLocalGatewayRouteTable.html) **
  - **Description:** Grants permission to delete a local gateway route table
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-local-gateway-route-table](#amazonec2-local-gateway-route-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/outposts/latest/userguide/identity-access-management.html](https://docs.aws.amazon.com/outposts/latest/userguide/identity-access-management.html) [permission only]**
  - **Description:** Grants permission to deny a service from accessing a local gateway route table
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#amazonec2-local-gateway-route-table](#amazonec2-local-gateway-route-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteLocalGatewayRouteTableVirtualInterfaceGroupAssociation.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteLocalGatewayRouteTableVirtualInterfaceGroupAssociation.html) **
  - **Description:** Grants permission to delete a local gateway route table virtual interface group association
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-local-gateway-route-table-virtual-interface-group-association](#amazonec2-local-gateway-route-table-virtual-interface-group-association)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteLocalGatewayRouteTableVpcAssociation.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteLocalGatewayRouteTableVpcAssociation.html) **
  - **Description:** Grants permission to delete an association between a VPC and local gateway route table
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-local-gateway-route-table-vpc-association](#amazonec2-local-gateway-route-table-vpc-association)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteLocalGatewayVirtualInterface.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteLocalGatewayVirtualInterface.html) **
  - **Description:** Grants permission to delete a local gateway virtual interface
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-local-gateway-virtual-interface](#amazonec2-local-gateway-virtual-interface)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteLocalGatewayVirtualInterfaceGroup.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteLocalGatewayVirtualInterfaceGroup.html) **
  - **Description:** Grants permission to delete a local gateway virtual interface group
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-local-gateway-virtual-interface-group](#amazonec2-local-gateway-virtual-interface-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteManagedPrefixList.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteManagedPrefixList.html) **
  - **Description:** Grants permission to delete a managed prefix list
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-prefix-list](#amazonec2-prefix-list)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_IpamPrefixListResolverTargetId](#amazonec2-ec2_IpamPrefixListResolverTargetId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteNatGateway.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteNatGateway.html) **
  - **Description:** Grants permission to delete a NAT gateway
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-natgateway](#amazonec2-natgateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteNetworkAcl.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteNetworkAcl.html) **
  - **Description:** Grants permission to delete a network ACL
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-network-acl](#amazonec2-network-acl)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_NetworkAclID](#amazonec2-ec2_NetworkAclID) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteNetworkAclEntry.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteNetworkAclEntry.html) **
  - **Description:** Grants permission to delete an inbound or outbound entry (rule) from a network ACL
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-network-acl](#amazonec2-network-acl)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_NetworkAclID](#amazonec2-ec2_NetworkAclID) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteNetworkInsightsAccessScope.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteNetworkInsightsAccessScope.html) **
  - **Description:** Grants permission to delete a Network Access Scope
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-network-insights-access-scope](#amazonec2-network-insights-access-scope)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteNetworkInsightsAccessScopeAnalysis.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteNetworkInsightsAccessScopeAnalysis.html) **
  - **Description:** Grants permission to delete a Network Access Scope analysis
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-network-insights-access-scope-analysis](#amazonec2-network-insights-access-scope-analysis)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteNetworkInsightsAnalysis.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteNetworkInsightsAnalysis.html) **
  - **Description:** Grants permission to delete a network insights analysis
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-network-insights-analysis](#amazonec2-network-insights-analysis)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteNetworkInsightsPath.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteNetworkInsightsPath.html) **
  - **Description:** Grants permission to delete a network insights path
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-network-insights-path](#amazonec2-network-insights-path)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteNetworkInterface.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteNetworkInterface.html) **
  - **Description:** Grants permission to delete a detached network interface
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-network-interface](#amazonec2-network-interface)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_NetworkInterfaceID](#amazonec2-ec2_NetworkInterfaceID) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Subnet](#amazonec2-ec2_Subnet) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteNetworkInterfacePermission.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteNetworkInterfacePermission.html) **
  - **Description:** Grants permission to delete a permission that is associated with a network interface
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#amazonec2-network-interface](#amazonec2-network-interface)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_NetworkInterfaceID](#amazonec2-ec2_NetworkInterfaceID) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Subnet](#amazonec2-ec2_Subnet) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteOdbNetworkPeering.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteOdbNetworkPeering.html) [permission only]**
  - **Description:** Grants permission to allow Oracle Database@AWS to delete a peering connection between an ODB network and a VPC
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeletePlacementGroup.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeletePlacementGroup.html) **
  - **Description:** Grants permission to delete a placement group
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-placement-group](#amazonec2-placement-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_PlacementGroupName](#amazonec2-ec2_PlacementGroupName) <br /> [#amazonec2-ec2_PlacementGroupStrategy](#amazonec2-ec2_PlacementGroupStrategy) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeletePublicIpv4Pool.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeletePublicIpv4Pool.html) **
  - **Description:** Grants permission to delete a public IPv4 address pool for public IPv4 CIDRs that you own and brought to Amazon to manage with Amazon VPC IP Address Manager (IPAM)
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipv4pool-ec2](#amazonec2-ipv4pool-ec2)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteQueuedReservedInstances.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteQueuedReservedInstances.html) **
  - **Description:** Grants permission to delete the queued purchases for the specified Reserved Instances
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-reserved-instances](#amazonec2-reserved-instances)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ReservedInstancesOfferingType](#amazonec2-ec2_ReservedInstancesOfferingType) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/vpc/latest/ipam/share-pool-ipam.html](https://docs.aws.amazon.com/vpc/latest/ipam/share-pool-ipam.html) [permission only]**
  - **Description:** Grants permission to remove an IAM policy that enables cross-account sharing from a resource
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#amazonec2-ipam-pool](#amazonec2-ipam-pool)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-placement-group](#amazonec2-placement-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_PlacementGroupName](#amazonec2-ec2_PlacementGroupName) <br /> [#amazonec2-ec2_PlacementGroupStrategy](#amazonec2-ec2_PlacementGroupStrategy) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-verified-access-group](#amazonec2-verified-access-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteRoute.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteRoute.html) **
  - **Description:** Grants permission to delete a route from a route table
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-route-table](#amazonec2-route-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RouteTableID](#amazonec2-ec2_RouteTableID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteRouteServer.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteRouteServer.html) **
  - **Description:** Grants permission to delete a route server 
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-route-server](#amazonec2-route-server)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:**  sns:DeleteTopic 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteRouteServerEndpoint.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteRouteServerEndpoint.html) **
  - **Description:** Grants permission to delete a route server endpoint
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-route-server-endpoint](#amazonec2-route-server-endpoint)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:**  ec2:DeleteNetworkInterface <br /> ec2:DeleteSecurityGroup <br /> ec2:RevokeSecurityGroupIngress 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteRouteServerPeer.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteRouteServerPeer.html) **
  - **Description:** Grants permission to delete a route server peer
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-route-server-peer](#amazonec2-route-server-peer)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:**  ec2:RevokeSecurityGroupIngress 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteRouteTable.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteRouteTable.html) **
  - **Description:** Grants permission to delete a route table
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-route-table](#amazonec2-route-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RouteTableID](#amazonec2-ec2_RouteTableID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteSecondaryNetwork.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteSecondaryNetwork.html) **
  - **Description:** Grants permission to delete a secondary network
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-secondary-network](#amazonec2-secondary-network)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteSecondarySubnet.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteSecondarySubnet.html) **
  - **Description:** Grants permission to delete a secondary subnet
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-secondary-subnet](#amazonec2-secondary-subnet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteSecurityGroup.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteSecurityGroup.html) **
  - **Description:** Grants permission to delete a security group
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-security-group](#amazonec2-security-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SecurityGroupID](#amazonec2-ec2_SecurityGroupID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteSnapshot.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteSnapshot.html) **
  - **Description:** Grants permission to delete a snapshot of an EBS volume
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-snapshot](#amazonec2-snapshot)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_OutpostArn](#amazonec2-ec2_OutpostArn) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_ParentVolume](#amazonec2-ec2_ParentVolume) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SnapshotID](#amazonec2-ec2_SnapshotID) <br /> [#amazonec2-ec2_SnapshotTime](#amazonec2-ec2_SnapshotTime) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteSpotDatafeedSubscription.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteSpotDatafeedSubscription.html) **
  - **Description:** Grants permission to delete a data feed for Spot Instances
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteSubnet.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteSubnet.html) **
  - **Description:** Grants permission to delete a subnet
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-subnet](#amazonec2-subnet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteSubnetCidrReservation.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteSubnetCidrReservation.html) **
  - **Description:** Grants permission to delete a subnet CIDR reservation
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteTags.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteTags.html) **
  - **Description:** Grants permission to delete one or more tags from Amazon EC2 resources
  - **Access level:** Tagging
  - **Resource types (\*required):**  [#amazonec2-capacity-block](#amazonec2-capacity-block)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-capacity-manager-data-export](#amazonec2-capacity-manager-data-export)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-capacity-reservation](#amazonec2-capacity-reservation)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-capacity-reservation-fleet](#amazonec2-capacity-reservation-fleet)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-carrier-gateway](#amazonec2-carrier-gateway)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-client-vpn-endpoint](#amazonec2-client-vpn-endpoint)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-coip-pool](#amazonec2-coip-pool)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-customer-gateway](#amazonec2-customer-gateway)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-declarative-policies-report](#amazonec2-declarative-policies-report)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-dedicated-host](#amazonec2-dedicated-host)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-dhcp-options](#amazonec2-dhcp-options)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-egress-only-internet-gateway](#amazonec2-egress-only-internet-gateway)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-elastic-gpu](#amazonec2-elastic-gpu)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-elastic-ip](#amazonec2-elastic-ip)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-export-image-task](#amazonec2-export-image-task)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-export-instance-task](#amazonec2-export-instance-task)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-fleet](#amazonec2-fleet)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-fpga-image](#amazonec2-fpga-image)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-host-reservation](#amazonec2-host-reservation)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-image](#amazonec2-image)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-image-usage-report](#amazonec2-image-usage-report)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-import-image-task](#amazonec2-import-image-task)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-import-snapshot-task](#amazonec2-import-snapshot-task)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-instance-connect-endpoint](#amazonec2-instance-connect-endpoint)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-instance-event-window](#amazonec2-instance-event-window)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-internet-gateway](#amazonec2-internet-gateway)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipam](#amazonec2-ipam)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipam-external-resource-verification-token](#amazonec2-ipam-external-resource-verification-token)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipam-policy](#amazonec2-ipam-policy)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipam-pool](#amazonec2-ipam-pool)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipam-prefix-list-resolver](#amazonec2-ipam-prefix-list-resolver)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipam-prefix-list-resolver-target](#amazonec2-ipam-prefix-list-resolver-target)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipam-resource-discovery](#amazonec2-ipam-resource-discovery)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipam-resource-discovery-association](#amazonec2-ipam-resource-discovery-association)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipam-scope](#amazonec2-ipam-scope)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipv4pool-ec2](#amazonec2-ipv4pool-ec2)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipv6pool-ec2](#amazonec2-ipv6pool-ec2)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-key-pair](#amazonec2-key-pair)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-launch-template](#amazonec2-launch-template)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-local-gateway](#amazonec2-local-gateway)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-local-gateway-route-table](#amazonec2-local-gateway-route-table)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-local-gateway-route-table-virtual-interface-group-association](#amazonec2-local-gateway-route-table-virtual-interface-group-association)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-local-gateway-route-table-vpc-association](#amazonec2-local-gateway-route-table-vpc-association)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-local-gateway-virtual-interface](#amazonec2-local-gateway-virtual-interface)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-local-gateway-virtual-interface-group](#amazonec2-local-gateway-virtual-interface-group)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-natgateway](#amazonec2-natgateway)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-network-acl](#amazonec2-network-acl)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-network-insights-access-scope](#amazonec2-network-insights-access-scope)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-network-insights-access-scope-analysis](#amazonec2-network-insights-access-scope-analysis)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-network-insights-analysis](#amazonec2-network-insights-analysis)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-network-insights-path](#amazonec2-network-insights-path)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-network-interface](#amazonec2-network-interface)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-placement-group](#amazonec2-placement-group)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-prefix-list](#amazonec2-prefix-list)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-replace-root-volume-task](#amazonec2-replace-root-volume-task)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-reserved-instances](#amazonec2-reserved-instances)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-route-server](#amazonec2-route-server)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-route-server-endpoint](#amazonec2-route-server-endpoint)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-route-server-peer](#amazonec2-route-server-peer)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-route-table](#amazonec2-route-table)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-secondary-interface](#amazonec2-secondary-interface)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-secondary-network](#amazonec2-secondary-network)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-secondary-subnet](#amazonec2-secondary-subnet)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-security-group](#amazonec2-security-group)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-security-group-rule](#amazonec2-security-group-rule)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-snapshot](#amazonec2-snapshot)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-spot-fleet-request](#amazonec2-spot-fleet-request)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-spot-instances-request](#amazonec2-spot-instances-request)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-subnet](#amazonec2-subnet)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-subnet-cidr-reservation](#amazonec2-subnet-cidr-reservation)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-traffic-mirror-filter](#amazonec2-traffic-mirror-filter)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-traffic-mirror-filter-rule](#amazonec2-traffic-mirror-filter-rule)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-traffic-mirror-session](#amazonec2-traffic-mirror-session)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-traffic-mirror-target](#amazonec2-traffic-mirror-target)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway](#amazonec2-transit-gateway)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-attachment](#amazonec2-transit-gateway-attachment)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-connect-peer](#amazonec2-transit-gateway-connect-peer)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-metering-policy](#amazonec2-transit-gateway-metering-policy)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-multicast-domain](#amazonec2-transit-gateway-multicast-domain)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-policy-table](#amazonec2-transit-gateway-policy-table)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-route-table](#amazonec2-transit-gateway-route-table)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-route-table-announcement](#amazonec2-transit-gateway-route-table-announcement)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-verified-access-endpoint](#amazonec2-verified-access-endpoint)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-verified-access-endpoint-target](#amazonec2-verified-access-endpoint-target)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-verified-access-group](#amazonec2-verified-access-group)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-verified-access-instance](#amazonec2-verified-access-instance)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-verified-access-policy](#amazonec2-verified-access-policy)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-verified-access-trust-provider](#amazonec2-verified-access-trust-provider)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-volume](#amazonec2-volume)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc-block-public-access-exclusion](#amazonec2-vpc-block-public-access-exclusion)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc-encryption-control](#amazonec2-vpc-encryption-control)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc-endpoint](#amazonec2-vpc-endpoint)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc-endpoint-connection](#amazonec2-vpc-endpoint-connection)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc-endpoint-service](#amazonec2-vpc-endpoint-service)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc-endpoint-service-permission](#amazonec2-vpc-endpoint-service-permission)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc-flow-log](#amazonec2-vpc-flow-log)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc-peering-connection](#amazonec2-vpc-peering-connection)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpn-concentrator](#amazonec2-vpn-concentrator)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpn-connection](#amazonec2-vpn-connection)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpn-gateway](#amazonec2-vpn-gateway)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteTrafficMirrorFilter.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteTrafficMirrorFilter.html) **
  - **Description:** Grants permission to delete a traffic mirror filter
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-traffic-mirror-filter](#amazonec2-traffic-mirror-filter)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteTrafficMirrorFilterRule.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteTrafficMirrorFilterRule.html) **
  - **Description:** Grants permission to delete a traffic mirror filter rule
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-traffic-mirror-filter](#amazonec2-traffic-mirror-filter)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-traffic-mirror-filter-rule](#amazonec2-traffic-mirror-filter-rule)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteTrafficMirrorSession.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteTrafficMirrorSession.html) **
  - **Description:** Grants permission to delete a traffic mirror session
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-traffic-mirror-session](#amazonec2-traffic-mirror-session)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteTrafficMirrorTarget.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteTrafficMirrorTarget.html) **
  - **Description:** Grants permission to delete a traffic mirror target
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-traffic-mirror-target](#amazonec2-traffic-mirror-target)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteTransitGateway.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteTransitGateway.html) **
  - **Description:** Grants permission to delete a transit gateway
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-transit-gateway](#amazonec2-transit-gateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayId](#amazonec2-ec2_transitGatewayId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteTransitGatewayConnect.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteTransitGatewayConnect.html) **
  - **Description:** Grants permission to delete a transit gateway connect attachment
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-attachment](#amazonec2-transit-gateway-attachment)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayAttachmentId](#amazonec2-ec2_transitGatewayAttachmentId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteTransitGatewayConnectPeer.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteTransitGatewayConnectPeer.html) **
  - **Description:** Grants permission to delete a transit gateway connect peer
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-connect-peer](#amazonec2-transit-gateway-connect-peer)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayConnectPeerId](#amazonec2-ec2_transitGatewayConnectPeerId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteTransitGatewayMeteringPolicy.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteTransitGatewayMeteringPolicy.html) **
  - **Description:** Grants permission to delete a transit gateway metering policy
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-metering-policy](#amazonec2-transit-gateway-metering-policy)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayMeteringPolicyId](#amazonec2-ec2_transitGatewayMeteringPolicyId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteTransitGatewayMeteringPolicyEntry.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteTransitGatewayMeteringPolicyEntry.html) **
  - **Description:** Grants permission to delete an entry from a transit gateway metering policy
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-metering-policy](#amazonec2-transit-gateway-metering-policy)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayMeteringPolicyId](#amazonec2-ec2_transitGatewayMeteringPolicyId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteTransitGatewayMulticastDomain.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteTransitGatewayMulticastDomain.html) **
  - **Description:** Grants permission to delete a transit gateway multicast domain
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-multicast-domain](#amazonec2-transit-gateway-multicast-domain)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayMulticastDomainId](#amazonec2-ec2_transitGatewayMulticastDomainId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteTransitGatewayPeeringAttachment.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteTransitGatewayPeeringAttachment.html) **
  - **Description:** Grants permission to delete a peering attachment from a transit gateway
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-attachment](#amazonec2-transit-gateway-attachment)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayAttachmentId](#amazonec2-ec2_transitGatewayAttachmentId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteTransitGatewayPolicyTable.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteTransitGatewayPolicyTable.html) **
  - **Description:** Grants permission to delete a transit gateway policy table
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-policy-table](#amazonec2-transit-gateway-policy-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayPolicyTableId](#amazonec2-ec2_transitGatewayPolicyTableId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteTransitGatewayPrefixListReference.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteTransitGatewayPrefixListReference.html) **
  - **Description:** Grants permission to delete a transit gateway prefix list reference
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-prefix-list](#amazonec2-prefix-list)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-route-table](#amazonec2-transit-gateway-route-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayRouteTableId](#amazonec2-ec2_transitGatewayRouteTableId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteTransitGatewayRoute.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteTransitGatewayRoute.html) **
  - **Description:** Grants permission to delete a route from a transit gateway route table
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-route-table](#amazonec2-transit-gateway-route-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayRouteTableId](#amazonec2-ec2_transitGatewayRouteTableId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteTransitGatewayRouteTable.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteTransitGatewayRouteTable.html) **
  - **Description:** Grants permission to delete a transit gateway route table
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-route-table](#amazonec2-transit-gateway-route-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayRouteTableId](#amazonec2-ec2_transitGatewayRouteTableId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteTransitGatewayRouteTableAnnouncement.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteTransitGatewayRouteTableAnnouncement.html) **
  - **Description:** Grants permission to delete a transit gateway route table announcement
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-route-table-announcement](#amazonec2-transit-gateway-route-table-announcement)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayRouteTableAnnouncementId](#amazonec2-ec2_transitGatewayRouteTableAnnouncementId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteTransitGatewayVpcAttachment.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteTransitGatewayVpcAttachment.html) **
  - **Description:** Grants permission to delete a VPC attachment from a transit gateway
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-attachment](#amazonec2-transit-gateway-attachment)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayAttachmentId](#amazonec2-ec2_transitGatewayAttachmentId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteVerifiedAccessEndpoint.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteVerifiedAccessEndpoint.html) **
  - **Description:** Grants permission to delete a Verified Access endpoint
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-verified-access-endpoint](#amazonec2-verified-access-endpoint)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteVerifiedAccessGroup.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteVerifiedAccessGroup.html) **
  - **Description:** Grants permission to delete a Verified Access group
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-verified-access-group](#amazonec2-verified-access-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteVerifiedAccessInstance.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteVerifiedAccessInstance.html) **
  - **Description:** Grants permission to delete a Verified Access instance
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-verified-access-instance](#amazonec2-verified-access-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteVerifiedAccessTrustProvider.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteVerifiedAccessTrustProvider.html) **
  - **Description:** Grants permission to delete a verified trust provider
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-verified-access-trust-provider](#amazonec2-verified-access-trust-provider)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteVolume.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteVolume.html) **
  - **Description:** Grants permission to delete an EBS volume
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-volume](#amazonec2-volume)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_Encrypted](#amazonec2-ec2_Encrypted) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_ParentSnapshot](#amazonec2-ec2_ParentSnapshot) <br /> [#amazonec2-ec2_ParentVolume](#amazonec2-ec2_ParentVolume) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VolumeID](#amazonec2-ec2_VolumeID) <br /> [#amazonec2-ec2_VolumeInitializationRate](#amazonec2-ec2_VolumeInitializationRate) <br /> [#amazonec2-ec2_VolumeIops](#amazonec2-ec2_VolumeIops) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize) <br /> [#amazonec2-ec2_VolumeThroughput](#amazonec2-ec2_VolumeThroughput) <br /> [#amazonec2-ec2_VolumeType](#amazonec2-ec2_VolumeType)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteVpc.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteVpc.html) **
  - **Description:** Grants permission to delete a VPC
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteVpcBlockPublicAccessExclusion.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteVpcBlockPublicAccessExclusion.html) **
  - **Description:** Grants permission to delete an exclusion list for blocked public access on a VPC
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpc-block-public-access-exclusion](#amazonec2-vpc-block-public-access-exclusion)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteVpcEncryptionControl.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteVpcEncryptionControl.html) **
  - **Description:** Grants permission to delete a VPC Encryption Control
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpc-encryption-control](#amazonec2-vpc-encryption-control)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteVpcEndpointConnectionNotifications.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteVpcEndpointConnectionNotifications.html) **
  - **Description:** Grants permission to delete one or more VPC endpoint connection notifications
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpc-endpoint](#amazonec2-vpc-endpoint)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc-endpoint-service](#amazonec2-vpc-endpoint-service)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VpceMultiRegion](#amazonec2-ec2_VpceMultiRegion) <br /> [#amazonec2-ec2_VpceSupportedRegion](#amazonec2-ec2_VpceSupportedRegion)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteVpcEndpointServiceConfigurations.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteVpcEndpointServiceConfigurations.html) **
  - **Description:** Grants permission to delete one or more VPC endpoint service configurations
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpc-endpoint-service](#amazonec2-vpc-endpoint-service)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VpceMultiRegion](#amazonec2-ec2_VpceMultiRegion) <br /> [#amazonec2-ec2_VpceSupportedRegion](#amazonec2-ec2_VpceSupportedRegion)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteVpcEndpoints.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteVpcEndpoints.html) **
  - **Description:** Grants permission to delete one or more VPC endpoints
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpc-endpoint](#amazonec2-vpc-endpoint)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VpceMultiRegion](#amazonec2-ec2_VpceMultiRegion) <br /> [#amazonec2-ec2_VpceServiceName](#amazonec2-ec2_VpceServiceName) <br /> [#amazonec2-ec2_VpceServiceRegion](#amazonec2-ec2_VpceServiceRegion)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteVpcPeeringConnection.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteVpcPeeringConnection.html) **
  - **Description:** Grants permission to delete a VPC peering connection
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpc-peering-connection](#amazonec2-vpc-peering-connection)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AccepterVpc](#amazonec2-ec2_AccepterVpc) <br /> [#amazonec2-ec2_RequesterVpc](#amazonec2-ec2_RequesterVpc) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VpcPeeringConnectionID](#amazonec2-ec2_VpcPeeringConnectionID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteVpnConcentrator.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteVpnConcentrator.html) **
  - **Description:** Grants permission to delete a VPN concentrator
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpn-concentrator](#amazonec2-vpn-concentrator)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteVpnConnection.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteVpnConnection.html) **
  - **Description:** Grants permission to delete a VPN connection
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpn-connection](#amazonec2-vpn-connection)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteVpnConnectionRoute.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteVpnConnectionRoute.html) **
  - **Description:** Grants permission to delete a static route for a VPN connection between a virtual private gateway and a customer gateway
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpn-connection](#amazonec2-vpn-connection)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteVpnGateway.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteVpnGateway.html) **
  - **Description:** Grants permission to delete a virtual private gateway
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpn-gateway](#amazonec2-vpn-gateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeprovisionByoipCidr.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeprovisionByoipCidr.html) **
  - **Description:** Grants permission to release an IP address range that was provisioned through bring your own IP addresses (BYOIP), and to delete the corresponding address pool
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeprovisionIpamByoasn.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeprovisionIpamByoasn.html) **
  - **Description:** Grants permission to deprovision an Autonomous System Number (ASN) from an Amazon Web Services account
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipam](#amazonec2-ipam)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeprovisionIpamPoolCidr.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeprovisionIpamPoolCidr.html) **
  - **Description:** Grants permission to deprovision a CIDR provisioned from an Amazon VPC IP Address Manager (IPAM) pool
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipam-pool](#amazonec2-ipam-pool)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeprovisionPublicIpv4PoolCidr.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeprovisionPublicIpv4PoolCidr.html) **
  - **Description:** Grants permission to deprovision a CIDR from a public IPv4 pool
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipv4pool-ec2](#amazonec2-ipv4pool-ec2)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeregisterImage.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeregisterImage.html) **
  - **Description:** Grants permission to deregister an Amazon Machine Image (AMI)
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-image](#amazonec2-image)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ImageID](#amazonec2-ec2_ImageID) <br /> [#amazonec2-ec2_ImageType](#amazonec2-ec2_ImageType) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_Public](#amazonec2-ec2_Public) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeregisterInstanceEventNotificationAttributes.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeregisterInstanceEventNotificationAttributes.html) **
  - **Description:** Grants permission to remove tags from the set of tags to include in notifications about scheduled events for your instances
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeregisterTransitGatewayMulticastGroupMembers.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeregisterTransitGatewayMulticastGroupMembers.html) **
  - **Description:** Grants permission to deregister one or more network interface members from a group IP address in a transit gateway multicast domain
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-network-interface](#amazonec2-network-interface)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_NetworkInterfaceID](#amazonec2-ec2_NetworkInterfaceID) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Subnet](#amazonec2-ec2_Subnet) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-multicast-domain](#amazonec2-transit-gateway-multicast-domain)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayMulticastDomainId](#amazonec2-ec2_transitGatewayMulticastDomainId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeregisterTransitGatewayMulticastGroupSources.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeregisterTransitGatewayMulticastGroupSources.html) **
  - **Description:** Grants permission to deregister one or more network interface sources from a group IP address in a transit gateway multicast domain
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-network-interface](#amazonec2-network-interface)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_NetworkInterfaceID](#amazonec2-ec2_NetworkInterfaceID) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Subnet](#amazonec2-ec2_Subnet) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-multicast-domain](#amazonec2-transit-gateway-multicast-domain)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayMulticastDomainId](#amazonec2-ec2_transitGatewayMulticastDomainId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeAccountAttributes.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeAccountAttributes.html) **
  - **Description:** Grants permission to describe the attributes of the AWS account
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeAddressTransfers.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeAddressTransfers.html) **
  - **Description:** Grants permission to describe an Elastic IP address transfer
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeAddresses.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeAddresses.html) **
  - **Description:** Grants permission to describe one or more Elastic IP addresses
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeAddressesAttribute.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeAddressesAttribute.html) **
  - **Description:** Grants permission to describe the attributes of the specified Elastic IP addresses
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeAggregateIdFormat.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeAggregateIdFormat.html) **
  - **Description:** Grants permission to describe the longer ID format settings for all resource types
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeAvailabilityZones.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeAvailabilityZones.html) **
  - **Description:** Grants permission to describe one or more of the Availability Zones that are available to you
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeAwsNetworkPerformanceMetricSubscriptions.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeAwsNetworkPerformanceMetricSubscriptions.html) **
  - **Description:** Grants permission to describe the current infrastructure performance metric subscriptions
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeBundleTasks.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeBundleTasks.html) **
  - **Description:** Grants permission to describe one or more bundling tasks
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeByoipCidrs.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeByoipCidrs.html) **
  - **Description:** Grants permission to describe the IP address ranges that were provisioned through bring your own IP addresses (BYOIP)
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeCapacityBlockExtensionHistory.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeCapacityBlockExtensionHistory.html) **
  - **Description:** Grants permission to describe Capacity Block extensions history
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeCapacityBlockExtensionOfferings.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeCapacityBlockExtensionOfferings.html) **
  - **Description:** Grants permission to describe Capacity Block extensions offerings
  - **Access level:** List
  - **Resource types (\*required):**  [#amazonec2-capacity-reservation](#amazonec2-capacity-reservation)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_CapacityReservationFleet](#amazonec2-ec2_CapacityReservationFleet) <br /> [#amazonec2-ec2_CreateDate](#amazonec2-ec2_CreateDate) <br /> [#amazonec2-ec2_DestinationCapacityReservationId](#amazonec2-ec2_DestinationCapacityReservationId) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_EndDate](#amazonec2-ec2_EndDate) <br /> [#amazonec2-ec2_EndDateType](#amazonec2-ec2_EndDateType) <br /> [#amazonec2-ec2_InstanceCount](#amazonec2-ec2_InstanceCount) <br /> [#amazonec2-ec2_InstanceMatchCriteria](#amazonec2-ec2_InstanceMatchCriteria) <br /> [#amazonec2-ec2_InstancePlatform](#amazonec2-ec2_InstancePlatform) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_OutpostArn](#amazonec2-ec2_OutpostArn) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SourceCapacityReservationId](#amazonec2-ec2_SourceCapacityReservationId) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeCapacityBlockOfferings.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeCapacityBlockOfferings.html) **
  - **Description:** Grants permission to describe Capacity Block offerings available for purchase
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeCapacityBlockStatus.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeCapacityBlockStatus.html) **
  - **Description:** Grants permission to describe the availability of capacity for the specified Capacity blocks, or all of your Capacity Blocks
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeCapacityBlocks.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeCapacityBlocks.html) **
  - **Description:** Grants permission to describe details about Capacity Blocks in the AWS Region that you're currently using
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeCapacityManagerDataExports.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeCapacityManagerDataExports.html) **
  - **Description:** Grants permission to describe one or more Capacity Manager data export configurations
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeCapacityReservationBillingRequests.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeCapacityReservationBillingRequests.html) **
  - **Description:** Grants permission to describe one or more requests to assign the billing of the unused capacity of a Capacity Reservation
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeCapacityReservationFleets.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeCapacityReservationFleets.html) **
  - **Description:** Grants permission to describe one or more Capacity Reservation Fleets
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeCapacityReservationTopology.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeCapacityReservationTopology.html) **
  - **Description:** Grants permission to describe the topology of one or more Capacity Reservations
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeCapacityReservations.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeCapacityReservations.html) **
  - **Description:** Grants permission to describe one or more Capacity Reservations
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeCarrierGateways.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeCarrierGateways.html) **
  - **Description:** Grants permission to describe one or more Carrier Gateways
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeClassicLinkInstances.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeClassicLinkInstances.html) **
  - **Description:** Grants permission to describe one or more linked EC2-Classic instances
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeClientVpnAuthorizationRules.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeClientVpnAuthorizationRules.html) **
  - **Description:** Grants permission to describe the authorization rules for a Client VPN endpoint
  - **Access level:** List
  - **Resource types (\*required):**  [#amazonec2-client-vpn-endpoint](#amazonec2-client-vpn-endpoint)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeClientVpnConnections.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeClientVpnConnections.html) **
  - **Description:** Grants permission to describe active client connections and connections that have been terminated within the last 60 minutes for a Client VPN endpoint
  - **Access level:** List
  - **Resource types (\*required):**  [#amazonec2-client-vpn-endpoint](#amazonec2-client-vpn-endpoint)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ClientRootCertificateChainArn](#amazonec2-ec2_ClientRootCertificateChainArn) <br /> [#amazonec2-ec2_CloudwatchLogGroupArn](#amazonec2-ec2_CloudwatchLogGroupArn) <br /> [#amazonec2-ec2_CloudwatchLogStreamArn](#amazonec2-ec2_CloudwatchLogStreamArn) <br /> [#amazonec2-ec2_DirectoryArn](#amazonec2-ec2_DirectoryArn) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SamlProviderArn](#amazonec2-ec2_SamlProviderArn) <br /> [#amazonec2-ec2_ServerCertificateArn](#amazonec2-ec2_ServerCertificateArn)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeClientVpnEndpoints.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeClientVpnEndpoints.html) **
  - **Description:** Grants permission to describe one or more Client VPN endpoints
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeClientVpnRoutes.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeClientVpnRoutes.html) **
  - **Description:** Grants permission to describe the routes for a Client VPN endpoint
  - **Access level:** List
  - **Resource types (\*required):**  [#amazonec2-client-vpn-endpoint](#amazonec2-client-vpn-endpoint)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ClientRootCertificateChainArn](#amazonec2-ec2_ClientRootCertificateChainArn) <br /> [#amazonec2-ec2_CloudwatchLogGroupArn](#amazonec2-ec2_CloudwatchLogGroupArn) <br /> [#amazonec2-ec2_CloudwatchLogStreamArn](#amazonec2-ec2_CloudwatchLogStreamArn) <br /> [#amazonec2-ec2_DirectoryArn](#amazonec2-ec2_DirectoryArn) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SamlProviderArn](#amazonec2-ec2_SamlProviderArn) <br /> [#amazonec2-ec2_ServerCertificateArn](#amazonec2-ec2_ServerCertificateArn)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeClientVpnTargetNetworks.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeClientVpnTargetNetworks.html) **
  - **Description:** Grants permission to describe the target networks that are associated with a Client VPN endpoint
  - **Access level:** List
  - **Resource types (\*required):**  [#amazonec2-client-vpn-endpoint](#amazonec2-client-vpn-endpoint)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ClientRootCertificateChainArn](#amazonec2-ec2_ClientRootCertificateChainArn) <br /> [#amazonec2-ec2_CloudwatchLogGroupArn](#amazonec2-ec2_CloudwatchLogGroupArn) <br /> [#amazonec2-ec2_CloudwatchLogStreamArn](#amazonec2-ec2_CloudwatchLogStreamArn) <br /> [#amazonec2-ec2_DirectoryArn](#amazonec2-ec2_DirectoryArn) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SamlProviderArn](#amazonec2-ec2_SamlProviderArn) <br /> [#amazonec2-ec2_ServerCertificateArn](#amazonec2-ec2_ServerCertificateArn)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeCoipPools.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeCoipPools.html) **
  - **Description:** Grants permission to describe the specified customer-owned address pools or all of your customer-owned address pools
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeConversionTasks.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeConversionTasks.html) **
  - **Description:** Grants permission to describe one or more conversion tasks
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeCustomerGateways.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeCustomerGateways.html) **
  - **Description:** Grants permission to describe one or more customer gateways
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeDeclarativePoliciesReports.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeDeclarativePoliciesReports.html) **
  - **Description:** Grants permission to describe one or more declarative policies reports
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeDhcpOptions.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeDhcpOptions.html) **
  - **Description:** Grants permission to describe one or more DHCP options sets
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeEgressOnlyInternetGateways.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeEgressOnlyInternetGateways.html) **
  - **Description:** Grants permission to describe one or more egress-only internet gateways
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeElasticGpus.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeElasticGpus.html) **
  - **Description:** Grants permission to describe an Elastic Graphics accelerator that is associated with an instance
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeExportImageTasks.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeExportImageTasks.html) **
  - **Description:** Grants permission to describe one or more export image tasks
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeExportTasks.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeExportTasks.html) **
  - **Description:** Grants permission to describe one or more export instance tasks
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeFastLaunchImages.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeFastLaunchImages.html) **
  - **Description:** Grants permission to describe fast-launch enabled Windows AMIs
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeFastSnapshotRestores.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeFastSnapshotRestores.html) **
  - **Description:** Grants permission to describe the state of fast snapshot restores for snapshots
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeFleetHistory.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeFleetHistory.html) **
  - **Description:** Grants permission to describe the events for an EC2 Fleet during a specified time
  - **Access level:** List
  - **Resource types (\*required):**  [#amazonec2-fleet](#amazonec2-fleet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeFleetInstances.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeFleetInstances.html) **
  - **Description:** Grants permission to describe the running instances for an EC2 Fleet
  - **Access level:** List
  - **Resource types (\*required):**  [#amazonec2-fleet](#amazonec2-fleet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeFleets.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeFleets.html) **
  - **Description:** Grants permission to describe one or more EC2 Fleets
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeFlowLogs.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeFlowLogs.html) **
  - **Description:** Grants permission to describe one or more flow logs
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeFpgaImageAttribute.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeFpgaImageAttribute.html) **
  - **Description:** Grants permission to describe the attributes of an Amazon FPGA Image (AFI)
  - **Access level:** List
  - **Resource types (\*required):**  [#amazonec2-fpga-image](#amazonec2-fpga-image)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeFpgaImages.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeFpgaImages.html) **
  - **Description:** Grants permission to describe one or more Amazon FPGA Images (AFIs)
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeHostReservationOfferings.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeHostReservationOfferings.html) **
  - **Description:** Grants permission to describe the Dedicated Host Reservations that are available to purchase
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeHostReservations.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeHostReservations.html) **
  - **Description:** Grants permission to describe the Dedicated Host Reservations that are associated with Dedicated Hosts in the AWS account
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeHosts.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeHosts.html) **
  - **Description:** Grants permission to describe one or more Dedicated Hosts
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeIamInstanceProfileAssociations.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeIamInstanceProfileAssociations.html) **
  - **Description:** Grants permission to describe the IAM instance profile associations
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeIdFormat.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeIdFormat.html) **
  - **Description:** Grants permission to describe the ID format settings for resources
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeIdentityIdFormat.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeIdentityIdFormat.html) **
  - **Description:** Grants permission to describe the ID format settings for resources for an IAM user, IAM role, or root user
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeImageAttribute.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeImageAttribute.html) **
  - **Description:** Grants permission to describe an attribute of an Amazon Machine Image (AMI)
  - **Access level:** List
  - **Resource types (\*required):**  [#amazonec2-image](#amazonec2-image)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ImageID](#amazonec2-ec2_ImageID) <br /> [#amazonec2-ec2_ImageType](#amazonec2-ec2_ImageType) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_Public](#amazonec2-ec2_Public) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeImageReferences.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeImageReferences.html) **
  - **Description:** Grants permission to describe your AWS resources that are referencing specified images
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeImageUsageReportEntries.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeImageUsageReportEntries.html) **
  - **Description:** Grants permission to describe the entries of an AMI usage report
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeImageUsageReports.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeImageUsageReports.html) **
  - **Description:** Grants permission to describe the configuration and status of an AMI usage report
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeImages.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeImages.html) **
  - **Description:** Grants permission to describe one or more images (AMIs, AKIs, and ARIs)
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeImportImageTasks.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeImportImageTasks.html) **
  - **Description:** Grants permission to describe import virtual machine or import snapshot tasks
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeImportSnapshotTasks.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeImportSnapshotTasks.html) **
  - **Description:** Grants permission to describe import snapshot tasks
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeInstanceAttribute.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeInstanceAttribute.html) **
  - **Description:** Grants permission to describe the attributes of an instance
  - **Access level:** List
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ProductCode](#amazonec2-ec2_ProductCode) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeInstanceConnectEndpoints.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeInstanceConnectEndpoints.html) **
  - **Description:** Grants permission to describe EC2 Instance Connect Endpoints
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeInstanceCreditSpecifications.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeInstanceCreditSpecifications.html) **
  - **Description:** Grants permission to describe the credit option for CPU usage of one or more burstable performance instances
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeInstanceEventNotificationAttributes.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeInstanceEventNotificationAttributes.html) **
  - **Description:** Grants permission to describe the set of tags to include in notifications about scheduled events for your instances
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeInstanceEventWindows.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeInstanceEventWindows.html) **
  - **Description:** Grants permission to describe the specified event windows or all event windows
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeInstanceImageMetadata.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeInstanceImageMetadata.html) **
  - **Description:** Grants permission to describe the AMI that was used to launch an instance
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeInstanceSqlHaHistoryStates.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeInstanceSqlHaHistoryStates.html) **
  - **Description:** Grants permission to describe EC2 instance SQL HA history states
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeInstanceSqlHaStates.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeInstanceSqlHaStates.html) **
  - **Description:** Grants permission to describe EC2 instance SQL HA states
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeInstanceStatus.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeInstanceStatus.html) **
  - **Description:** Grants permission to describe the status of one or more instances
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeInstanceTopology.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeInstanceTopology.html) **
  - **Description:** Grants permission to describe a tree-based hierarchy that represents the physical host placement of EC2 instances
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeInstanceTypeOfferings.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeInstanceTypeOfferings.html) **
  - **Description:** Grants permission to describe the set of instance types that are offered in a location
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeInstanceTypes.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeInstanceTypes.html) **
  - **Description:** Grants permission to describe the details of instance types that are offered in a location
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeInstances.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeInstances.html) **
  - **Description:** Grants permission to describe one or more instances
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeInternetGateways.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeInternetGateways.html) **
  - **Description:** Grants permission to describe one or more internet gateways
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeIpamByoasn.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeIpamByoasn.html) **
  - **Description:** Grants permission to describe a bring your own Autonomous System Number (BYOASN) that you've brought to IPAM
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeIpamExternalResourceVerificationTokens.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeIpamExternalResourceVerificationTokens.html) **
  - **Description:** Grants permission to describe verification tokens, which proves ownership of an external resource
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeIpamPolicies.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeIpamPolicies.html) **
  - **Description:** Grants permission to describe Amazon VPC IP Address Manager (IPAM) policies
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeIpamPools.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeIpamPools.html) **
  - **Description:** Grants permission to describe Amazon VPC IP Address Manager (IPAM) pools
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeIpamPrefixListResolverTargets.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeIpamPrefixListResolverTargets.html) **
  - **Description:** Grants permission to describe IPAM prefix list resolver targets
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeIpamPrefixListResolvers.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeIpamPrefixListResolvers.html) **
  - **Description:** Grants permission to describe IPAM prefix list resolvers
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeIpamResourceDiscoveries.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeIpamResourceDiscoveries.html) **
  - **Description:** Grants permission to describe IPAM resource discoveries
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeIpamResourceDiscoveryAssociations.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeIpamResourceDiscoveryAssociations.html) **
  - **Description:** Grants permission to describe resource discovery associations with an Amazon VPC IPAM
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeIpamScopes.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeIpamScopes.html) **
  - **Description:** Grants permission to describe Amazon VPC IP Address Manager (IPAM) scopes
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeIpams.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeIpams.html) **
  - **Description:** Grants permission to describe an Amazon VPC IP Address Manager (IPAM)
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeIpv6Pools.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeIpv6Pools.html) **
  - **Description:** Grants permission to describe one or more IPv6 address pools
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeKeyPairs.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeKeyPairs.html) **
  - **Description:** Grants permission to describe one or more key pairs
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeLaunchTemplateVersions.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeLaunchTemplateVersions.html) **
  - **Description:** Grants permission to describe one or more launch template versions
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:**  ssm:GetParameters 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeLaunchTemplates.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeLaunchTemplates.html) **
  - **Description:** Grants permission to describe one or more launch templates
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/outposts/latest/userguide/identity-access-management.html](https://docs.aws.amazon.com/outposts/latest/userguide/identity-access-management.html) [permission only]**
  - **Description:** Grants permission to allow a service to describe local gateway route table permissions
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeLocalGatewayRouteTableVirtualInterfaceGroupAssociations.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeLocalGatewayRouteTableVirtualInterfaceGroupAssociations.html) **
  - **Description:** Grants permission to describe the associations between virtual interface groups and local gateway route tables
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeLocalGatewayRouteTableVpcAssociations.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeLocalGatewayRouteTableVpcAssociations.html) **
  - **Description:** Grants permission to describe an association between VPCs and local gateway route tables
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeLocalGatewayRouteTables.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeLocalGatewayRouteTables.html) **
  - **Description:** Grants permission to describe one or more local gateway route tables
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeLocalGatewayVirtualInterfaceGroups.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeLocalGatewayVirtualInterfaceGroups.html) **
  - **Description:** Grants permission to describe local gateway virtual interface groups
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeLocalGatewayVirtualInterfaces.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeLocalGatewayVirtualInterfaces.html) **
  - **Description:** Grants permission to describe local gateway virtual interfaces
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeLocalGateways.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeLocalGateways.html) **
  - **Description:** Grants permission to describe one or more local gateways
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeLockedSnapshots.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeLockedSnapshots.html) **
  - **Description:** Grants permission to describe the lock status for a snapshot
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeMacHosts.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeMacHosts.html) **
  - **Description:** Grants permission to describe your EC2 Mac Dedicated hosts
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeMacModificationTasks.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeMacModificationTasks.html) **
  - **Description:** Grants permission to describe a System Integrity Protection (SIP) modification task or volume ownership delegation task for an Amazon EC2 Mac instance
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeManagedPrefixLists.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeManagedPrefixLists.html) **
  - **Description:** Grants permission to describe your managed prefix lists and any AWS-managed prefix lists
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeMovingAddresses.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeMovingAddresses.html) **
  - **Description:** Grants permission to describe Elastic IP addresses that are being moved to the EC2-VPC platform
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNatGateways.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNatGateways.html) **
  - **Description:** Grants permission to describe one or more NAT gateways
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkAcls.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkAcls.html) **
  - **Description:** Grants permission to describe one or more network ACLs
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAccessScopeAnalyses.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAccessScopeAnalyses.html) **
  - **Description:** Grants permission to describe one or more Network Access Scope analyses
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAccessScopes.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAccessScopes.html) **
  - **Description:** Grants permission to describe the Network Access Scopes
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsAnalyses.html) **
  - **Description:** Grants permission to describe one or more network insights analyses
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsPaths.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInsightsPaths.html) **
  - **Description:** Grants permission to describe one or more network insights paths
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInterfaceAttribute.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInterfaceAttribute.html) **
  - **Description:** Grants permission to describe a network interface attribute
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInterfacePermissions.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInterfacePermissions.html) **
  - **Description:** Grants permission to describe the permissions that are associated with a network interface
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInterfaces.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeNetworkInterfaces.html) **
  - **Description:** Grants permission to describe one or more network interfaces
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeOutpostLags.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeOutpostLags.html) **
  - **Description:** Grants permission to describe Outpost LAGs
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribePlacementGroups.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribePlacementGroups.html) **
  - **Description:** Grants permission to describe one or more placement groups
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribePrefixLists.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribePrefixLists.html) **
  - **Description:** Grants permission to describe available AWS services in a prefix list format
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribePrincipalIdFormat.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribePrincipalIdFormat.html) **
  - **Description:** Grants permission to describe the ID format settings for the root user and all IAM roles and IAM users that have explicitly specified a longer ID (17-character ID) preference
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribePublicIpv4Pools.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribePublicIpv4Pools.html) **
  - **Description:** Grants permission to describe one or more IPv4 address pools
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeRegions.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeRegions.html) **
  - **Description:** Grants permission to describe one or more AWS Regions that are currently available in your account
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeReplaceRootVolumeTasks.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeReplaceRootVolumeTasks.html) **
  - **Description:** Grants permission to describe a root volume replacement task
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeReservedInstances.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeReservedInstances.html) **
  - **Description:** Grants permission to describe one or more purchased Reserved Instances in your account
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeReservedInstancesListings.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeReservedInstancesListings.html) **
  - **Description:** Grants permission to describe your account's Reserved Instance listings in the Reserved Instance Marketplace
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeReservedInstancesModifications.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeReservedInstancesModifications.html) **
  - **Description:** Grants permission to describe the modifications made to one or more Reserved Instances
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeReservedInstancesOfferings.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeReservedInstancesOfferings.html) **
  - **Description:** Grants permission to describe the Reserved Instance offerings that are available for purchase
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeRouteServerEndpoints.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeRouteServerEndpoints.html) **
  - **Description:** Grants permission to describe one or more route server endpoints
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeRouteServerPeers.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeRouteServerPeers.html) **
  - **Description:** Grants permission to describe one or more route server peers
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeRouteServers.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeRouteServers.html) **
  - **Description:** Grants permission to describe one or more route servers
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeRouteTables.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeRouteTables.html) **
  - **Description:** Grants permission to describe one or more route tables
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeScheduledInstanceAvailability.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeScheduledInstanceAvailability.html) **
  - **Description:** Grants permission to find available schedules for Scheduled Instances
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeScheduledInstances.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeScheduledInstances.html) **
  - **Description:** Grants permission to describe one or more Scheduled Instances in your account
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSecondaryInterfaces.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSecondaryInterfaces.html) **
  - **Description:** Grants permission to describe one or more secondary interfaces
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSecondaryNetworks.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSecondaryNetworks.html) **
  - **Description:** Grants permission to describe one or more secondary networks
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSecondarySubnets.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSecondarySubnets.html) **
  - **Description:** Grants permission to describe one or more secondary subnets
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSecurityGroupReferences.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSecurityGroupReferences.html) **
  - **Description:** Grants permission to describe the VPCs on the other side of a VPC peering connection that are referencing specified VPC security groups
  - **Access level:** List
  - **Resource types (\*required):**  [#amazonec2-security-group](#amazonec2-security-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SecurityGroupID](#amazonec2-ec2_SecurityGroupID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSecurityGroupRules.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSecurityGroupRules.html) **
  - **Description:** Grants permission to describe one or more of your security group rules
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSecurityGroupVpcAssociations.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSecurityGroupVpcAssociations.html) **
  - **Description:** Grants permission to describe security group VPC associations
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSecurityGroups.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSecurityGroups.html) **
  - **Description:** Grants permission to describe one or more security groups
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeServiceLinkVirtualInterfaces.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeServiceLinkVirtualInterfaces.html) **
  - **Description:** Grants permission to describe service link virtual interfaces
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSnapshotAttribute.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSnapshotAttribute.html) **
  - **Description:** Grants permission to describe an attribute of a snapshot
  - **Access level:** List
  - **Resource types (\*required):**  [#amazonec2-snapshot](#amazonec2-snapshot)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Encrypted](#amazonec2-ec2_Encrypted) <br /> [#amazonec2-ec2_OutpostArn](#amazonec2-ec2_OutpostArn) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_ParentVolume](#amazonec2-ec2_ParentVolume) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SnapshotID](#amazonec2-ec2_SnapshotID) <br /> [#amazonec2-ec2_SnapshotTime](#amazonec2-ec2_SnapshotTime) <br /> [#amazonec2-ec2_SourceOutpostArn](#amazonec2-ec2_SourceOutpostArn) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSnapshotTierStatus.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSnapshotTierStatus.html) **
  - **Description:** Grants permission to describe the storage tier status for Amazon EBS snapshots
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSnapshots.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSnapshots.html) **
  - **Description:** Grants permission to describe one or more EBS snapshots
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSpotDatafeedSubscription.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSpotDatafeedSubscription.html) **
  - **Description:** Grants permission to describe the data feed for Spot Instances
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSpotFleetInstances.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSpotFleetInstances.html) **
  - **Description:** Grants permission to describe the running instances for a Spot Fleet
  - **Access level:** List
  - **Resource types (\*required):**  [#amazonec2-spot-fleet-request](#amazonec2-spot-fleet-request)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSpotFleetRequestHistory.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSpotFleetRequestHistory.html) **
  - **Description:** Grants permission to describe the events for a Spot Fleet request during a specified time
  - **Access level:** List
  - **Resource types (\*required):**  [#amazonec2-spot-fleet-request](#amazonec2-spot-fleet-request)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSpotFleetRequests.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSpotFleetRequests.html) **
  - **Description:** Grants permission to describe one or more Spot Fleet requests
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSpotInstanceRequests.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSpotInstanceRequests.html) **
  - **Description:** Grants permission to describe one or more Spot Instance requests
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSpotPriceHistory.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSpotPriceHistory.html) **
  - **Description:** Grants permission to describe the Spot Instance price history
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeStaleSecurityGroups.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeStaleSecurityGroups.html) **
  - **Description:** Grants permission to describe the stale security group rules for security groups in a specified VPC
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeStoreImageTasks.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeStoreImageTasks.html) **
  - **Description:** Grants permission to describe the progress of the AMI store tasks
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSubnets.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSubnets.html) **
  - **Description:** Grants permission to describe one or more subnets
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTags.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTags.html) **
  - **Description:** Grants permission to describe one or more tags for an Amazon EC2 resource
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTrafficMirrorFilterRules.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTrafficMirrorFilterRules.html) **
  - **Description:** Grants permission to describe traffic mirror filters that determine the traffic that is mirrored
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTrafficMirrorFilters.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTrafficMirrorFilters.html) **
  - **Description:** Grants permission to describe one or more traffic mirror filters
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTrafficMirrorSessions.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTrafficMirrorSessions.html) **
  - **Description:** Grants permission to describe one or more traffic mirror sessions
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTrafficMirrorTargets.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTrafficMirrorTargets.html) **
  - **Description:** Grants permission to describe one or more traffic mirror targets
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTransitGatewayAttachments.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTransitGatewayAttachments.html) **
  - **Description:** Grants permission to describe one or more attachments between resources and transit gateways
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTransitGatewayConnectPeers.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTransitGatewayConnectPeers.html) **
  - **Description:** Grants permission to describe one or more transit gateway connect peers
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTransitGatewayConnects.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTransitGatewayConnects.html) **
  - **Description:** Grants permission to describe one or more transit gateway connect attachments
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTransitGatewayMeteringPolicies.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTransitGatewayMeteringPolicies.html) **
  - **Description:** Grants permission to describe one or more transit gateway metering policies
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTransitGatewayMulticastDomains.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTransitGatewayMulticastDomains.html) **
  - **Description:** Grants permission to describe one or more transit gateway multicast domains
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTransitGatewayPeeringAttachments.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTransitGatewayPeeringAttachments.html) **
  - **Description:** Grants permission to describe one or more transit gateway peering attachments
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTransitGatewayPolicyTables.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTransitGatewayPolicyTables.html) **
  - **Description:** Grants permission to describe a transit gateway policy table
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTransitGatewayRouteTableAnnouncements.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTransitGatewayRouteTableAnnouncements.html) **
  - **Description:** Grants permission to describe a transit gateway route table announcement
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTransitGatewayRouteTables.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTransitGatewayRouteTables.html) **
  - **Description:** Grants permission to describe one or more transit gateway route tables
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTransitGatewayVpcAttachments.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTransitGatewayVpcAttachments.html) **
  - **Description:** Grants permission to describe one or more VPC attachments on a transit gateway
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTransitGateways.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTransitGateways.html) **
  - **Description:** Grants permission to describe one or more transit gateways
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTrunkInterfaceAssociations.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTrunkInterfaceAssociations.html) **
  - **Description:** Grants permission to describe one or more network interface trunk associations
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVerifiedAccessEndpoints.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVerifiedAccessEndpoints.html) **
  - **Description:** Grants permission to describe the specified Verified Access endpoints or all Verified Access endpoints
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVerifiedAccessGroups.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVerifiedAccessGroups.html) **
  - **Description:** Grants permission to describe the specified Verified Access groups or all Verified Access groups
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVerifiedAccessInstanceLoggingConfigurations.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVerifiedAccessInstanceLoggingConfigurations.html) **
  - **Description:** Grants permission to describe the current logging configuration for the Verified Access instances
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/verified-access/latest/ug/waf-integration.html](https://docs.aws.amazon.com/verified-access/latest/ug/waf-integration.html) [permission only]**
  - **Description:** Grants permission to describe the AWS Web Application Firewall (WAF) web access control list (ACL) associations for a Verified Access instance
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVerifiedAccessInstances.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVerifiedAccessInstances.html) **
  - **Description:** Grants permission to describe the specified Verified Access instances or all Verified Access instances
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVerifiedAccessTrustProviders.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVerifiedAccessTrustProviders.html) **
  - **Description:** Grants permission to describe details of existing Verified Access trust providers
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVolumeAttribute.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVolumeAttribute.html) **
  - **Description:** Grants permission to describe an attribute of an EBS volume
  - **Access level:** List
  - **Resource types (\*required):**  [#amazonec2-volume](#amazonec2-volume)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_Encrypted](#amazonec2-ec2_Encrypted) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_ParentSnapshot](#amazonec2-ec2_ParentSnapshot) <br /> [#amazonec2-ec2_ParentVolume](#amazonec2-ec2_ParentVolume) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VolumeID](#amazonec2-ec2_VolumeID) <br /> [#amazonec2-ec2_VolumeInitializationRate](#amazonec2-ec2_VolumeInitializationRate) <br /> [#amazonec2-ec2_VolumeIops](#amazonec2-ec2_VolumeIops) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize) <br /> [#amazonec2-ec2_VolumeThroughput](#amazonec2-ec2_VolumeThroughput) <br /> [#amazonec2-ec2_VolumeType](#amazonec2-ec2_VolumeType)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVolumeStatus.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVolumeStatus.html) **
  - **Description:** Grants permission to describe the status of one or more EBS volumes
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVolumes.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVolumes.html) **
  - **Description:** Grants permission to describe one or more EBS volumes
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVolumesModifications.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVolumesModifications.html) **
  - **Description:** Grants permission to describe the current modification status of one or more EBS volumes
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpcAttribute.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpcAttribute.html) **
  - **Description:** Grants permission to describe an attribute of a VPC
  - **Access level:** List
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpcBlockPublicAccessExclusions.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpcBlockPublicAccessExclusions.html) **
  - **Description:** Grants permission to describe an exclusion list for blocked public access on a VPC
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpcBlockPublicAccessOptions.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpcBlockPublicAccessOptions.html) **
  - **Description:** Grants permission to describe options for blocked public access on a VPC
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpcClassicLink.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpcClassicLink.html) **
  - **Description:** Grants permission to describe the ClassicLink status of one or more VPCs
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpcClassicLinkDnsSupport.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpcClassicLinkDnsSupport.html) **
  - **Description:** Grants permission to describe the ClassicLink DNS support status of one or more VPCs
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpcEncryptionControls.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpcEncryptionControls.html) **
  - **Description:** Grants permission to describe one or more VPC Encryption Controls
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpcEndpointAssociations.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpcEndpointAssociations.html) **
  - **Description:** Grants permission to describe the VPC endpoint associations
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpcEndpointConnectionNotifications.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpcEndpointConnectionNotifications.html) **
  - **Description:** Grants permission to describe the connection notifications for VPC endpoints and VPC endpoint services
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpcEndpointConnections.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpcEndpointConnections.html) **
  - **Description:** Grants permission to describe the VPC endpoint connections to your VPC endpoint services
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpcEndpointServiceConfigurations.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpcEndpointServiceConfigurations.html) **
  - **Description:** Grants permission to describe VPC endpoint service configurations (your services)
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpcEndpointServicePermissions.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpcEndpointServicePermissions.html) **
  - **Description:** Grants permission to describe the principals (service consumers) that are permitted to discover your VPC endpoint service
  - **Access level:** List
  - **Resource types (\*required):**  [#amazonec2-vpc-endpoint-service](#amazonec2-vpc-endpoint-service)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VpceMultiRegion](#amazonec2-ec2_VpceMultiRegion) <br /> [#amazonec2-ec2_VpceSupportedRegion](#amazonec2-ec2_VpceSupportedRegion)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpcEndpointServices.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpcEndpointServices.html) **
  - **Description:** Grants permission to describe all supported AWS services that can be specified when creating a VPC endpoint
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpcEndpoints.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpcEndpoints.html) **
  - **Description:** Grants permission to describe one or more VPC endpoints
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpcPeeringConnections.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpcPeeringConnections.html) **
  - **Description:** Grants permission to describe one or more VPC peering connections
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpcs.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpcs.html) **
  - **Description:** Grants permission to describe one or more VPCs
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpnConcentrators.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpnConcentrators.html) **
  - **Description:** Grants permission to describe one or more VPN concentrators
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpnConnections.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpnConnections.html) **
  - **Description:** Grants permission to describe one or more VPN connections
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpnGateways.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeVpnGateways.html) **
  - **Description:** Grants permission to describe one or more virtual private gateways
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DetachApplianceFromNatGateway.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DetachApplianceFromNatGateway.html) [permission only]**
  - **Description:** Grants permission to detach an appliance from a public/private Natgateway
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#amazonec2-natgateway](#amazonec2-natgateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DetachClassicLinkVpc.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DetachClassicLinkVpc.html) **
  - **Description:** Grants permission to unlink (detach) a linked EC2-Classic instance from a VPC
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DetachInternetGateway.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DetachInternetGateway.html) **
  - **Description:** Grants permission to detach an internet gateway from a VPC
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-internet-gateway](#amazonec2-internet-gateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_InternetGatewayID](#amazonec2-ec2_InternetGatewayID) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DetachNetworkInterface.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DetachNetworkInterface.html) **
  - **Description:** Grants permission to detach a network interface from an instance
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ProductCode](#amazonec2-ec2_ProductCode) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-network-interface](#amazonec2-network-interface)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_NetworkInterfaceID](#amazonec2-ec2_NetworkInterfaceID) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Subnet](#amazonec2-ec2_Subnet) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/UserGuide/placement-groups.html](https://docs.aws.amazon.com/UserGuide/placement-groups.html) [permission only]**
  - **Description:** Grants permission to detach resources from a placement group
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#amazonec2-placement-group](#amazonec2-placement-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_PlacementGroupName](#amazonec2-ec2_PlacementGroupName) <br /> [#amazonec2-ec2_PlacementGroupStrategy](#amazonec2-ec2_PlacementGroupStrategy) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DetachVerifiedAccessTrustProvider.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DetachVerifiedAccessTrustProvider.html) **
  - **Description:** Grants permission to detach a trust provider from a Verified Access instance
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-verified-access-instance](#amazonec2-verified-access-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-verified-access-trust-provider](#amazonec2-verified-access-trust-provider)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DetachVolume.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DetachVolume.html) **
  - **Description:** Grants permission to detach an EBS volume from an instance
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-volume](#amazonec2-volume)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_Encrypted](#amazonec2-ec2_Encrypted) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_ParentSnapshot](#amazonec2-ec2_ParentSnapshot) <br /> [#amazonec2-ec2_ParentVolume](#amazonec2-ec2_ParentVolume) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VolumeID](#amazonec2-ec2_VolumeID) <br /> [#amazonec2-ec2_VolumeInitializationRate](#amazonec2-ec2_VolumeInitializationRate) <br /> [#amazonec2-ec2_VolumeIops](#amazonec2-ec2_VolumeIops) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize) <br /> [#amazonec2-ec2_VolumeThroughput](#amazonec2-ec2_VolumeThroughput) <br /> [#amazonec2-ec2_VolumeType](#amazonec2-ec2_VolumeType)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ProductCode](#amazonec2-ec2_ProductCode) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DetachVpnGateway.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DetachVpnGateway.html) **
  - **Description:** Grants permission to detach a virtual private gateway from a VPC
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpn-gateway](#amazonec2-vpn-gateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableAddressTransfer.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableAddressTransfer.html) **
  - **Description:** Grants permission to disable Elastic IP address transfer
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-elastic-ip](#amazonec2-elastic-ip)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AllocationId](#amazonec2-ec2_AllocationId) <br /> [#amazonec2-ec2_Domain](#amazonec2-ec2_Domain) <br /> [#amazonec2-ec2_PublicIpAddress](#amazonec2-ec2_PublicIpAddress) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableAllowedImagesSettings.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableAllowedImagesSettings.html) **
  - **Description:** Grants permission to disable allowed images settings
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableAwsNetworkPerformanceMetricSubscription.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableAwsNetworkPerformanceMetricSubscription.html) **
  - **Description:** Grants permission to disable infrastructure performance metric subscriptions
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableCapacityManager.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableCapacityManager.html) **
  - **Description:** Grants permission to disable EC2 Capacity Manager for your account
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableEbsEncryptionByDefault.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableEbsEncryptionByDefault.html) **
  - **Description:** Grants permission to disable EBS encryption by default for your account
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableFastLaunch.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableFastLaunch.html) **
  - **Description:** Grants permission to disable faster launching for Windows AMIs
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-image](#amazonec2-image)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ImageID](#amazonec2-ec2_ImageID) <br /> [#amazonec2-ec2_ImageType](#amazonec2-ec2_ImageType) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_Public](#amazonec2-ec2_Public) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableFastSnapshotRestores.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableFastSnapshotRestores.html) **
  - **Description:** Grants permission to disable fast snapshot restores for one or more snapshots in specified Availability Zones
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-snapshot](#amazonec2-snapshot)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_Encrypted](#amazonec2-ec2_Encrypted) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_ParentVolume](#amazonec2-ec2_ParentVolume) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SnapshotID](#amazonec2-ec2_SnapshotID) <br /> [#amazonec2-ec2_SnapshotTime](#amazonec2-ec2_SnapshotTime) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableImage.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableImage.html) **
  - **Description:** Grants permission to disable an AMI
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-image](#amazonec2-image)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ImageID](#amazonec2-ec2_ImageID) <br /> [#amazonec2-ec2_ImageType](#amazonec2-ec2_ImageType) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_Public](#amazonec2-ec2_Public) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableImageBlockPublicAccess.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableImageBlockPublicAccess.html) **
  - **Description:** Grants permission to disable block public access for AMIs at the account level in the specified AWS Region
  - **Access level:** Permissions management
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableImageDeprecation.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableImageDeprecation.html) **
  - **Description:** Grants permission to cancel the deprecation of the specified AMI
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-image](#amazonec2-image)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ImageID](#amazonec2-ec2_ImageID) <br /> [#amazonec2-ec2_ImageType](#amazonec2-ec2_ImageType) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_Public](#amazonec2-ec2_Public) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableImageDeregistrationProtection.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableImageDeregistrationProtection.html) **
  - **Description:** Grants permission to disable deregistration protection for an AMI. When deregistration protection is disabled, the AMI can be deregistered
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-image](#amazonec2-image)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ImageID](#amazonec2-ec2_ImageID) <br /> [#amazonec2-ec2_ImageType](#amazonec2-ec2_ImageType) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_Public](#amazonec2-ec2_Public) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableInstanceSqlHaStandbyDetections.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableInstanceSqlHaStandbyDetections.html) **
  - **Description:** Grants permission to disable EC2 instance SQL HA standby detections
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableIpamOrganizationAdminAccount.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableIpamOrganizationAdminAccount.html) **
  - **Description:** Grants permission to disable an AWS Organizations member account as an Amazon VPC IP Address Manager (IPAM) admin account
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:**  organizations:DeregisterDelegatedAdministrator 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableIpamPolicy.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableIpamPolicy.html) **
  - **Description:** Grants permission to disable a policy in Amazon VPC IP Address Manager (IPAM) that controls public IPv4 address allocation
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipam-policy](#amazonec2-ipam-policy)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableRouteServerPropagation.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableRouteServerPropagation.html) **
  - **Description:** Grants permission to disable route server propagation
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-route-server](#amazonec2-route-server)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-route-table](#amazonec2-route-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RouteTableID](#amazonec2-ec2_RouteTableID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableSerialConsoleAccess.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableSerialConsoleAccess.html) **
  - **Description:** Grants permission to disable access to the EC2 serial console of all instances for your account
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableSnapshotBlockPublicAccess.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableSnapshotBlockPublicAccess.html) **
  - **Description:** Grants permission to disable the block public access for snapshots setting for a Region
  - **Access level:** Permissions management
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableTransitGatewayRouteTablePropagation.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableTransitGatewayRouteTablePropagation.html) **
  - **Description:** Grants permission to disable a resource attachment from propagating routes to the specified propagation route table
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-route-table](#amazonec2-transit-gateway-route-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayRouteTableId](#amazonec2-ec2_transitGatewayRouteTableId)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-attachment](#amazonec2-transit-gateway-attachment)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayAttachmentId](#amazonec2-ec2_transitGatewayAttachmentId)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-route-table-announcement](#amazonec2-transit-gateway-route-table-announcement)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayRouteTableAnnouncementId](#amazonec2-ec2_transitGatewayRouteTableAnnouncementId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableVgwRoutePropagation.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableVgwRoutePropagation.html) **
  - **Description:** Grants permission to disable a virtual private gateway from propagating routes to a specified route table of a VPC
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-route-table](#amazonec2-route-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RouteTableID](#amazonec2-ec2_RouteTableID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpn-gateway](#amazonec2-vpn-gateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableVpcClassicLink.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableVpcClassicLink.html) **
  - **Description:** Grants permission to disable ClassicLink for a VPC
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableVpcClassicLinkDnsSupport.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableVpcClassicLinkDnsSupport.html) **
  - **Description:** Grants permission to disable ClassicLink DNS support for a VPC
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisassociateAddress.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisassociateAddress.html) **
  - **Description:** Grants permission to disassociate an Elastic IP address from an instance or network interface
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-elastic-ip](#amazonec2-elastic-ip)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AllocationId](#amazonec2-ec2_AllocationId) <br /> [#amazonec2-ec2_Domain](#amazonec2-ec2_Domain) <br /> [#amazonec2-ec2_PublicIpAddress](#amazonec2-ec2_PublicIpAddress) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-network-interface](#amazonec2-network-interface)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_NetworkInterfaceID](#amazonec2-ec2_NetworkInterfaceID) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Subnet](#amazonec2-ec2_Subnet) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisassociateCapacityReservationBillingOwner.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisassociateCapacityReservationBillingOwner.html) **
  - **Description:** Grants permission to cancel a pending request to assign billing of the unused capacity of a Capacity Reservation to a consumer account
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-capacity-reservation](#amazonec2-capacity-reservation)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_CapacityReservationFleet](#amazonec2-ec2_CapacityReservationFleet) <br /> [#amazonec2-ec2_CreateDate](#amazonec2-ec2_CreateDate) <br /> [#amazonec2-ec2_DestinationCapacityReservationId](#amazonec2-ec2_DestinationCapacityReservationId) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_EndDate](#amazonec2-ec2_EndDate) <br /> [#amazonec2-ec2_EndDateType](#amazonec2-ec2_EndDateType) <br /> [#amazonec2-ec2_InstanceCount](#amazonec2-ec2_InstanceCount) <br /> [#amazonec2-ec2_InstanceMatchCriteria](#amazonec2-ec2_InstanceMatchCriteria) <br /> [#amazonec2-ec2_InstancePlatform](#amazonec2-ec2_InstancePlatform) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_OutpostArn](#amazonec2-ec2_OutpostArn) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SourceCapacityReservationId](#amazonec2-ec2_SourceCapacityReservationId) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisassociateClientVpnTargetNetwork.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisassociateClientVpnTargetNetwork.html) **
  - **Description:** Grants permission to disassociate a target network from a Client VPN endpoint
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-client-vpn-endpoint](#amazonec2-client-vpn-endpoint)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ClientRootCertificateChainArn](#amazonec2-ec2_ClientRootCertificateChainArn) <br /> [#amazonec2-ec2_CloudwatchLogGroupArn](#amazonec2-ec2_CloudwatchLogGroupArn) <br /> [#amazonec2-ec2_CloudwatchLogStreamArn](#amazonec2-ec2_CloudwatchLogStreamArn) <br /> [#amazonec2-ec2_DirectoryArn](#amazonec2-ec2_DirectoryArn) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SamlProviderArn](#amazonec2-ec2_SamlProviderArn) <br /> [#amazonec2-ec2_ServerCertificateArn](#amazonec2-ec2_ServerCertificateArn)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisassociateEnclaveCertificateIamRole.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisassociateEnclaveCertificateIamRole.html) **
  - **Description:** Grants permission to disassociate an ACM certificate from a IAM role
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-certificate](#amazonec2-certificate)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-role](#amazonec2-role)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisassociateIamInstanceProfile.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisassociateIamInstanceProfile.html) **
  - **Description:** Grants permission to disassociate an IAM instance profile from a running or stopped instance
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ProductCode](#amazonec2-ec2_ProductCode) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisassociateInstanceEventWindow.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisassociateInstanceEventWindow.html) **
  - **Description:** Grants permission to disassociate one or more targets from an event window
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance-event-window](#amazonec2-instance-event-window)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisassociateIpamByoasn.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisassociateIpamByoasn.html) **
  - **Description:** Grants permission to disassociate an Autonomous System Number (ASN) from a BYOIP CIDR
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisassociateIpamResourceDiscovery.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisassociateIpamResourceDiscovery.html) **
  - **Description:** Grants permission to disassociate a resource discovery from an Amazon VPC IPAM
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipam-resource-discovery-association](#amazonec2-ipam-resource-discovery-association)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisassociateNatGatewayAddress.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisassociateNatGatewayAddress.html) **
  - **Description:** Grants permission to disassociate a secondary Elastic IP address from a public NAT gateway
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-elastic-ip](#amazonec2-elastic-ip)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AllocationId](#amazonec2-ec2_AllocationId) <br /> [#amazonec2-ec2_Domain](#amazonec2-ec2_Domain) <br /> [#amazonec2-ec2_PublicIpAddress](#amazonec2-ec2_PublicIpAddress) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-natgateway](#amazonec2-natgateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-network-interface](#amazonec2-network-interface)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AuthorizedUser](#amazonec2-ec2_AuthorizedUser) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_NetworkInterfaceID](#amazonec2-ec2_NetworkInterfaceID) <br /> [#amazonec2-ec2_Permission](#amazonec2-ec2_Permission) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Subnet](#amazonec2-ec2_Subnet) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisassociateRouteServer.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisassociateRouteServer.html) **
  - **Description:** Grants permission to disassociate a route server from a VPC
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-route-server](#amazonec2-route-server)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Ipv4IpamPoolId](#amazonec2-ec2_Ipv4IpamPoolId) <br /> [#amazonec2-ec2_Ipv6IpamPoolId](#amazonec2-ec2_Ipv6IpamPoolId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisassociateRouteTable.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisassociateRouteTable.html) **
  - **Description:** Grants permission to disassociate a subnet from a route table
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-internet-gateway](#amazonec2-internet-gateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_InternetGatewayID](#amazonec2-ec2_InternetGatewayID) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipv4pool-ec2](#amazonec2-ipv4pool-ec2)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipv6pool-ec2](#amazonec2-ipv6pool-ec2)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-route-table](#amazonec2-route-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RouteTableID](#amazonec2-ec2_RouteTableID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-subnet](#amazonec2-subnet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpn-gateway](#amazonec2-vpn-gateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisassociateSecurityGroupVpc.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisassociateSecurityGroupVpc.html) **
  - **Description:** Grants permission to disassociate a security group from a VPC
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-security-group](#amazonec2-security-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SecurityGroupID](#amazonec2-ec2_SecurityGroupID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Ipv4IpamPoolId](#amazonec2-ec2_Ipv4IpamPoolId) <br /> [#amazonec2-ec2_Ipv6IpamPoolId](#amazonec2-ec2_Ipv6IpamPoolId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisassociateSubnetCidrBlock.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisassociateSubnetCidrBlock.html) **
  - **Description:** Grants permission to disassociate a CIDR block from a subnet
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-subnet](#amazonec2-subnet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisassociateTransitGatewayMulticastDomain.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisassociateTransitGatewayMulticastDomain.html) **
  - **Description:** Grants permission to disassociate one or more subnets from a transit gateway multicast domain
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-subnet](#amazonec2-subnet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-attachment](#amazonec2-transit-gateway-attachment)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayAttachmentId](#amazonec2-ec2_transitGatewayAttachmentId)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-multicast-domain](#amazonec2-transit-gateway-multicast-domain)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayMulticastDomainId](#amazonec2-ec2_transitGatewayMulticastDomainId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisassociateTransitGatewayPolicyTable.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisassociateTransitGatewayPolicyTable.html) **
  - **Description:** Grants permission to disassociate a policy table from a transit gateway
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-attachment](#amazonec2-transit-gateway-attachment)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayAttachmentId](#amazonec2-ec2_transitGatewayAttachmentId)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-policy-table](#amazonec2-transit-gateway-policy-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayPolicyTableId](#amazonec2-ec2_transitGatewayPolicyTableId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisassociateTransitGatewayRouteTable.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisassociateTransitGatewayRouteTable.html) **
  - **Description:** Grants permission to disassociate a resource attachment from a transit gateway route table
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-attachment](#amazonec2-transit-gateway-attachment)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayAttachmentId](#amazonec2-ec2_transitGatewayAttachmentId)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-route-table](#amazonec2-transit-gateway-route-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayRouteTableId](#amazonec2-ec2_transitGatewayRouteTableId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisassociateTrunkInterface.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisassociateTrunkInterface.html) **
  - **Description:** Grants permission to disassociate a branch network interface to a trunk network interface
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/verified-access/latest/ug/waf-integration.html](https://docs.aws.amazon.com/verified-access/latest/ug/waf-integration.html) [permission only]**
  - **Description:** Grants permission to disassociate an AWS Web Application Firewall (WAF) web access control list (ACL) from a Verified Access instance
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-verified-access-instance](#amazonec2-verified-access-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisassociateVpcCidrBlock.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisassociateVpcCidrBlock.html) **
  - **Description:** Grants permission to disassociate a CIDR block from a VPC
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableAddressTransfer.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableAddressTransfer.html) **
  - **Description:** Grants permission to enable Elastic IP address transfer
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-elastic-ip](#amazonec2-elastic-ip)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AllocationId](#amazonec2-ec2_AllocationId) <br /> [#amazonec2-ec2_Domain](#amazonec2-ec2_Domain) <br /> [#amazonec2-ec2_PublicIpAddress](#amazonec2-ec2_PublicIpAddress) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableAllowedImagesSettings.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableAllowedImagesSettings.html) **
  - **Description:** Grants permission to enable allowed images settings
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableAwsNetworkPerformanceMetricSubscription.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableAwsNetworkPerformanceMetricSubscription.html) **
  - **Description:** Grants permission to enable infrastructure performance subscriptions
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableCapacityManager.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableCapacityManager.html) **
  - **Description:** Grants permission to enable EC2 Capacity Manager for your account
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableEbsEncryptionByDefault.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableEbsEncryptionByDefault.html) **
  - **Description:** Grants permission to enable EBS encryption by default for your account
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableFastLaunch.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableFastLaunch.html) **
  - **Description:** Grants permission to enable faster launching for Windows AMIs
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-image](#amazonec2-image)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ImageID](#amazonec2-ec2_ImageID) <br /> [#amazonec2-ec2_ImageType](#amazonec2-ec2_ImageType) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_Public](#amazonec2-ec2_Public) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType)  / **Dependent actions:**  ec2:CreateLaunchTemplate <br /> ec2:CreateSnapshot <br /> ec2:CreateTags <br /> ec2:DeleteSnapshot <br /> ec2:DescribeImages <br /> ec2:DescribeInstanceAttribute <br /> ec2:DescribeInstanceStatus <br /> ec2:DescribeInstanceTypeOfferings <br /> ec2:DescribeInstances <br /> ec2:DescribeLaunchTemplateVersions <br /> ec2:DescribeLaunchTemplates <br /> ec2:DescribeSnapshots <br /> ec2:DescribeSubnets <br /> ec2:RunInstances <br /> ec2:StopInstances <br /> ec2:TerminateInstances <br /> iam:PassRole 
  - **Resource types (\*required):**  [#amazonec2-launch-template](#amazonec2-launch-template)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableFastSnapshotRestores.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableFastSnapshotRestores.html) **
  - **Description:** Grants permission to enable fast snapshot restores for one or more snapshots in specified Availability Zones
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-snapshot](#amazonec2-snapshot)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_Encrypted](#amazonec2-ec2_Encrypted) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_ParentVolume](#amazonec2-ec2_ParentVolume) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SnapshotID](#amazonec2-ec2_SnapshotID) <br /> [#amazonec2-ec2_SnapshotTime](#amazonec2-ec2_SnapshotTime) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableImage.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableImage.html) **
  - **Description:** Grants permission to re-enable a disabled AMI
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-image](#amazonec2-image)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ImageID](#amazonec2-ec2_ImageID) <br /> [#amazonec2-ec2_ImageType](#amazonec2-ec2_ImageType) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_Public](#amazonec2-ec2_Public) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableImageBlockPublicAccess.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableImageBlockPublicAccess.html) **
  - **Description:** Grants permission to enable block public access for AMIs at the account level in the specified AWS Region
  - **Access level:** Permissions management
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableImageDeprecation.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableImageDeprecation.html) **
  - **Description:** Grants permission to enable deprecation of the specified AMI at the specified date and time
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-image](#amazonec2-image)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ImageID](#amazonec2-ec2_ImageID) <br /> [#amazonec2-ec2_ImageType](#amazonec2-ec2_ImageType) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_Public](#amazonec2-ec2_Public) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableImageDeregistrationProtection.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableImageDeregistrationProtection.html) **
  - **Description:** Grants permission to enable deregistration protection for an AMI. When deregistration protection is enabled, the AMI can't be deregistered
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-image](#amazonec2-image)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ImageID](#amazonec2-ec2_ImageID) <br /> [#amazonec2-ec2_ImageType](#amazonec2-ec2_ImageType) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_Public](#amazonec2-ec2_Public) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableInstanceSqlHaStandbyDetections.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableInstanceSqlHaStandbyDetections.html) **
  - **Description:** Grants permission to enable EC2 instance SQL HA standby detections
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableIpamOrganizationAdminAccount.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableIpamOrganizationAdminAccount.html) **
  - **Description:** Grants permission to enable an AWS Organizations member account as an Amazon VPC IP Address Manager (IPAM) admin account
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:**  iam:CreateServiceLinkedRole <br /> organizations:EnableAWSServiceAccess <br /> organizations:RegisterDelegatedAdministrator 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableIpamPolicy.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableIpamPolicy.html) **
  - **Description:** Grants permission to enable an Amazon VPC IP Address Manager (IPAM) policy
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipam-policy](#amazonec2-ipam-policy)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableReachabilityAnalyzerOrganizationSharing.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableReachabilityAnalyzerOrganizationSharing.html) **
  - **Description:** Grants permission to enable organization sharing of reachability analyzer
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:**  iam:CreateServiceLinkedRole <br /> organizations:EnableAWSServiceAccess 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableRouteServerPropagation.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableRouteServerPropagation.html) **
  - **Description:** Grants permission to enable route server propagation
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-route-server](#amazonec2-route-server)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-route-table](#amazonec2-route-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RouteTableID](#amazonec2-ec2_RouteTableID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableSerialConsoleAccess.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableSerialConsoleAccess.html) **
  - **Description:** Grants permission to enable access to the EC2 serial console of all instances for your account
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableSnapshotBlockPublicAccess.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableSnapshotBlockPublicAccess.html) **
  - **Description:** Grants permission to enable or modify the block public access for snapshots setting for a Region
  - **Access level:** Permissions management
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableTransitGatewayRouteTablePropagation.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableTransitGatewayRouteTablePropagation.html) **
  - **Description:** Grants permission to enable an attachment to propagate routes to a propagation route table
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-route-table](#amazonec2-transit-gateway-route-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayRouteTableId](#amazonec2-ec2_transitGatewayRouteTableId)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-attachment](#amazonec2-transit-gateway-attachment)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayAttachmentId](#amazonec2-ec2_transitGatewayAttachmentId)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-route-table-announcement](#amazonec2-transit-gateway-route-table-announcement)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayRouteTableAnnouncementId](#amazonec2-ec2_transitGatewayRouteTableAnnouncementId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableVgwRoutePropagation.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableVgwRoutePropagation.html) **
  - **Description:** Grants permission to enable a virtual private gateway to propagate routes to a VPC route table
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-route-table](#amazonec2-route-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RouteTableID](#amazonec2-ec2_RouteTableID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpn-gateway](#amazonec2-vpn-gateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableVolumeIO.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableVolumeIO.html) **
  - **Description:** Grants permission to enable I/O operations for a volume that had I/O operations disabled
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-volume](#amazonec2-volume)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_Encrypted](#amazonec2-ec2_Encrypted) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_ParentSnapshot](#amazonec2-ec2_ParentSnapshot) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VolumeID](#amazonec2-ec2_VolumeID) <br /> [#amazonec2-ec2_VolumeIops](#amazonec2-ec2_VolumeIops) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize) <br /> [#amazonec2-ec2_VolumeThroughput](#amazonec2-ec2_VolumeThroughput) <br /> [#amazonec2-ec2_VolumeType](#amazonec2-ec2_VolumeType)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableVpcClassicLink.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableVpcClassicLink.html) **
  - **Description:** Grants permission to enable a VPC for ClassicLink
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableVpcClassicLinkDnsSupport.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_EnableVpcClassicLinkDnsSupport.html) **
  - **Description:** Grants permission to enable a VPC to support DNS hostname resolution for ClassicLink
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ExportClientVpnClientCertificateRevocationList.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ExportClientVpnClientCertificateRevocationList.html) **
  - **Description:** Grants permission to download the client certificate revocation list for a Client VPN endpoint
  - **Access level:** Read
  - **Resource types (\*required):**  [#amazonec2-client-vpn-endpoint](#amazonec2-client-vpn-endpoint)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ClientRootCertificateChainArn](#amazonec2-ec2_ClientRootCertificateChainArn) <br /> [#amazonec2-ec2_CloudwatchLogGroupArn](#amazonec2-ec2_CloudwatchLogGroupArn) <br /> [#amazonec2-ec2_CloudwatchLogStreamArn](#amazonec2-ec2_CloudwatchLogStreamArn) <br /> [#amazonec2-ec2_DirectoryArn](#amazonec2-ec2_DirectoryArn) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SamlProviderArn](#amazonec2-ec2_SamlProviderArn) <br /> [#amazonec2-ec2_ServerCertificateArn](#amazonec2-ec2_ServerCertificateArn)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ExportClientVpnClientConfiguration.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ExportClientVpnClientConfiguration.html) **
  - **Description:** Grants permission to download the contents of the Client VPN endpoint configuration file for a Client VPN endpoint
  - **Access level:** Read
  - **Resource types (\*required):**  [#amazonec2-client-vpn-endpoint](#amazonec2-client-vpn-endpoint)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ClientRootCertificateChainArn](#amazonec2-ec2_ClientRootCertificateChainArn) <br /> [#amazonec2-ec2_CloudwatchLogGroupArn](#amazonec2-ec2_CloudwatchLogGroupArn) <br /> [#amazonec2-ec2_CloudwatchLogStreamArn](#amazonec2-ec2_CloudwatchLogStreamArn) <br /> [#amazonec2-ec2_DirectoryArn](#amazonec2-ec2_DirectoryArn) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SamlProviderArn](#amazonec2-ec2_SamlProviderArn) <br /> [#amazonec2-ec2_ServerCertificateArn](#amazonec2-ec2_ServerCertificateArn)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ExportImage.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ExportImage.html) **
  - **Description:** Grants permission to export an Amazon Machine Image (AMI) to a VM file
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-export-image-task](#amazonec2-export-image-task)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-image](#amazonec2-image)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ImageID](#amazonec2-ec2_ImageID) <br /> [#amazonec2-ec2_ImageType](#amazonec2-ec2_ImageType) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_Public](#amazonec2-ec2_Public) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ExportTransitGatewayRoutes.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ExportTransitGatewayRoutes.html) **
  - **Description:** Grants permission to export routes from a transit gateway route table to an Amazon S3 bucket
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ExportVerifiedAccessInstanceClientConfiguration.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ExportVerifiedAccessInstanceClientConfiguration.html) **
  - **Description:** Grants permission to export a verified access instance client configuration
  - **Access level:** Read
  - **Resource types (\*required):**  [#amazonec2-verified-access-instance](#amazonec2-verified-access-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetActiveVpnTunnelStatus.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetActiveVpnTunnelStatus.html) **
  - **Description:** Grants permission to retrieve the current security parameters for an active VPN tunnel
  - **Access level:** Read
  - **Resource types (\*required):**  [#amazonec2-vpn-connection](#amazonec2-vpn-connection)  / **Condition keys:**  [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetAllowedImagesSettings.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetAllowedImagesSettings.html) **
  - **Description:** Grants permission to get the allowed settings for images
  - **Access level:** Read
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetAssociatedEnclaveCertificateIamRoles.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetAssociatedEnclaveCertificateIamRoles.html) **
  - **Description:** Grants permission to get the list of roles associated with an ACM certificate
  - **Access level:** Read
  - **Resource types (\*required):**  [#amazonec2-certificate](#amazonec2-certificate)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetAssociatedIpv6PoolCidrs.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetAssociatedIpv6PoolCidrs.html) **
  - **Description:** Grants permission to get information about the IPv6 CIDR block associations for a specified IPv6 address pool
  - **Access level:** Read
  - **Resource types (\*required):**  [#amazonec2-ipv6pool-ec2](#amazonec2-ipv6pool-ec2)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetAwsNetworkPerformanceData.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetAwsNetworkPerformanceData.html) **
  - **Description:** Grants permission to get network performance data
  - **Access level:** Read
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetCapacityManagerAttributes.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetCapacityManagerAttributes.html) **
  - **Description:** Grants permission to retrieve the current configuration and status of EC2 Capacity Manager
  - **Access level:** Read
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetCapacityManagerMetricData.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetCapacityManagerMetricData.html) **
  - **Description:** Grants permission to retrieve capacity usage metrics for your EC2 resources
  - **Access level:** Read
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetCapacityManagerMetricDimensions.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetCapacityManagerMetricDimensions.html) **
  - **Description:** Grants permission to retrieve the available dimension values for capacity metrics within a specified time range
  - **Access level:** Read
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetCapacityReservationUsage.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetCapacityReservationUsage.html) **
  - **Description:** Grants permission to get usage information about a Capacity Reservation
  - **Access level:** Read
  - **Resource types (\*required):**  [#amazonec2-capacity-reservation](#amazonec2-capacity-reservation)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_CapacityReservationFleet](#amazonec2-ec2_CapacityReservationFleet)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetCoipPoolUsage.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetCoipPoolUsage.html) **
  - **Description:** Grants permission to describe the allocations from the specified customer-owned address pool
  - **Access level:** Read
  - **Resource types (\*required):**  [#amazonec2-coip-pool](#amazonec2-coip-pool)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetConsoleOutput.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetConsoleOutput.html) **
  - **Description:** Grants permission to get the console output for an instance
  - **Access level:** Read
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ProductCode](#amazonec2-ec2_ProductCode) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetConsoleScreenshot.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetConsoleScreenshot.html) **
  - **Description:** Grants permission to retrieve a JPG-format screenshot of a running instance
  - **Access level:** Read
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_NewInstanceProfile](#amazonec2-ec2_NewInstanceProfile) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ProductCode](#amazonec2-ec2_ProductCode) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetDeclarativePoliciesReportSummary.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetDeclarativePoliciesReportSummary.html) **
  - **Description:** Grants permission to get the report summary of declarative policies
  - **Access level:** Read
  - **Resource types (\*required):**  [#amazonec2-declarative-policies-report](#amazonec2-declarative-policies-report)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetDefaultCreditSpecification.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetDefaultCreditSpecification.html) **
  - **Description:** Grants permission to get the default credit option for CPU usage of a burstable performance instance family
  - **Access level:** Read
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetEbsDefaultKmsKeyId.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetEbsDefaultKmsKeyId.html) **
  - **Description:** Grants permission to get the ID of the default customer master key (CMK) for EBS encryption by default
  - **Access level:** Read
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetEbsEncryptionByDefault.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetEbsEncryptionByDefault.html) **
  - **Description:** Grants permission to describe whether EBS encryption by default is enabled for your account
  - **Access level:** Read
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetEnabledIpamPolicy.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetEnabledIpamPolicy.html) **
  - **Description:** Grants permission to describe the currently enabled policy in Amazon VPC IP Address Manager (IPAM)
  - **Access level:** Read
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetFlowLogsIntegrationTemplate.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetFlowLogsIntegrationTemplate.html) **
  - **Description:** Grants permission to generate a CloudFormation template to streamline the integration of VPC flow logs with Amazon Athena
  - **Access level:** Read
  - **Resource types (\*required):**  [#amazonec2-vpc-flow-log](#amazonec2-vpc-flow-log)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetGroupsForCapacityReservation.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetGroupsForCapacityReservation.html) **
  - **Description:** Grants permission to list the resource groups to which a Capacity Reservation has been added
  - **Access level:** List
  - **Resource types (\*required):**  [#amazonec2-capacity-reservation](#amazonec2-capacity-reservation)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_CapacityReservationFleet](#amazonec2-ec2_CapacityReservationFleet)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetHostReservationPurchasePreview.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetHostReservationPurchasePreview.html) **
  - **Description:** Grants permission to preview a reservation purchase with configurations that match those of a Dedicated Host
  - **Access level:** Read
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetImageAncestry.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetImageAncestry.html) **
  - **Description:** Grants permission to retrieve the ancestry chain of an AMI back to its root AMI
  - **Access level:** Read
  - **Resource types (\*required):**  [#amazonec2-image](#amazonec2-image)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ImageID](#amazonec2-ec2_ImageID) <br /> [#amazonec2-ec2_ImageType](#amazonec2-ec2_ImageType) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_Public](#amazonec2-ec2_Public) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetImageBlockPublicAccessState.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetImageBlockPublicAccessState.html) **
  - **Description:** Grants permission to get the current state of block public access for AMIs at the account level in the specified AWS Region
  - **Access level:** Read
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetInstanceMetadataDefaults.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetInstanceMetadataDefaults.html) **
  - **Description:** Grants permission to view the default instance metadata service (IMDS) settings set for your account in the specified Region
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetInstanceTpmEkPub.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetInstanceTpmEkPub.html) **
  - **Description:** Grants permission to get the public endorsement key associated with the Nitro Trusted Platform Module (NitroTPM) for the specified instance
  - **Access level:** Read
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetInstanceTypesFromInstanceRequirements.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetInstanceTypesFromInstanceRequirements.html) **
  - **Description:** Grants permission to view a list of instance types with specified instance attributes
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetInstanceUefiData.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetInstanceUefiData.html) **
  - **Description:** Grants permission to retrieve the binary representation of the UEFI variable store
  - **Access level:** Read
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_NewInstanceProfile](#amazonec2-ec2_NewInstanceProfile) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ProductCode](#amazonec2-ec2_ProductCode) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetIpamAddressHistory.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetIpamAddressHistory.html) **
  - **Description:** Grants permission to retrieve historical information about a CIDR within an Amazon VPC IP Address Manager (IPAM) scope
  - **Access level:** Read
  - **Resource types (\*required):**  [#amazonec2-ipam-scope](#amazonec2-ipam-scope)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetIpamDiscoveredAccounts.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetIpamDiscoveredAccounts.html) **
  - **Description:** Grants permission to retrieve IPAM discovered accounts
  - **Access level:** Read
  - **Resource types (\*required):**  [#amazonec2-ipam-resource-discovery](#amazonec2-ipam-resource-discovery)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetIpamDiscoveredPublicAddresses.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetIpamDiscoveredPublicAddresses.html) **
  - **Description:** Grants permission to retrieve the public IP addresses that have been discovered by IPAM
  - **Access level:** Read
  - **Resource types (\*required):**  [#amazonec2-ipam-resource-discovery](#amazonec2-ipam-resource-discovery)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetIpamDiscoveredResourceCidrs.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetIpamDiscoveredResourceCidrs.html) **
  - **Description:** Grants permission to retrieve the resource CIDRs that are monitored as part of a resource discovery
  - **Access level:** Read
  - **Resource types (\*required):**  [#amazonec2-ipam-resource-discovery](#amazonec2-ipam-resource-discovery)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetIpamPolicyAllocationRules.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetIpamPolicyAllocationRules.html) **
  - **Description:** Grants permission to describe the rules that define how Amazon VPC IP Address Manager (IPAM) pools allocate IP addresses to AWS resource types within an IPAM policy
  - **Access level:** List
  - **Resource types (\*required):**  [#amazonec2-ipam-policy](#amazonec2-ipam-policy)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetIpamPolicyOrganizationTargets.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetIpamPolicyOrganizationTargets.html) **
  - **Description:** Grants permission to retrieve the AWS Organizations targets associated with an Amazon VPC IP Address Manager (IPAM) policy
  - **Access level:** List
  - **Resource types (\*required):**  [#amazonec2-ipam-policy](#amazonec2-ipam-policy)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetIpamPoolAllocations.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetIpamPoolAllocations.html) **
  - **Description:** Grants permission to get a list of all the CIDR allocations in an Amazon VPC IP Address Manager (IPAM) pool
  - **Access level:** List
  - **Resource types (\*required):**  [#amazonec2-ipam-pool](#amazonec2-ipam-pool)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetIpamPoolCidrs.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetIpamPoolCidrs.html) **
  - **Description:** Grants permission to get the CIDRs provisioned to an Amazon VPC IP Address Manager (IPAM) pool
  - **Access level:** Read
  - **Resource types (\*required):**  [#amazonec2-ipam-pool](#amazonec2-ipam-pool)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetIpamPrefixListResolverRules.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetIpamPrefixListResolverRules.html) **
  - **Description:** Grants permission to get rules for an IPAM prefix list resolver
  - **Access level:** Read
  - **Resource types (\*required):**  [#amazonec2-ipam-prefix-list-resolver](#amazonec2-ipam-prefix-list-resolver)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetIpamPrefixListResolverVersionEntries.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetIpamPrefixListResolverVersionEntries.html) **
  - **Description:** Grants permission to get CIDR entries for a specific version of an IPAM prefix list resolver
  - **Access level:** Read
  - **Resource types (\*required):**  [#amazonec2-ipam-prefix-list-resolver](#amazonec2-ipam-prefix-list-resolver)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetIpamPrefixListResolverVersions.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetIpamPrefixListResolverVersions.html) **
  - **Description:** Grants permission to get versions of an IPAM prefix list resolver
  - **Access level:** Read
  - **Resource types (\*required):**  [#amazonec2-ipam-prefix-list-resolver](#amazonec2-ipam-prefix-list-resolver)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetIpamResourceCidrs.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetIpamResourceCidrs.html) **
  - **Description:** Grants permission to get information about the resources in an Amazon VPC IP Address Manager (IPAM) scope
  - **Access level:** Read
  - **Resource types (\*required):**  [#amazonec2-ipam-scope](#amazonec2-ipam-scope)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipam-pool](#amazonec2-ipam-pool)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetLaunchTemplateData.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetLaunchTemplateData.html) **
  - **Description:** Grants permission to get the configuration data of the specified instance for use with a new launch template or launch template version
  - **Access level:** Read
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ProductCode](#amazonec2-ec2_ProductCode) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetManagedPrefixListAssociations.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetManagedPrefixListAssociations.html) **
  - **Description:** Grants permission to get information about the resources that are associated with the specified managed prefix list
  - **Access level:** Read
  - **Resource types (\*required):**  [#amazonec2-prefix-list](#amazonec2-prefix-list)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_IpamPrefixListResolverTargetId](#amazonec2-ec2_IpamPrefixListResolverTargetId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetManagedPrefixListEntries.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetManagedPrefixListEntries.html) **
  - **Description:** Grants permission to get information about the entries for a specified managed prefix list
  - **Access level:** Read
  - **Resource types (\*required):**  [#amazonec2-prefix-list](#amazonec2-prefix-list)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_IpamPrefixListResolverTargetId](#amazonec2-ec2_IpamPrefixListResolverTargetId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetNetworkInsightsAccessScopeAnalysisFindings.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetNetworkInsightsAccessScopeAnalysisFindings.html) **
  - **Description:** Grants permission to get the findings for one or more Network Access Scope analyses
  - **Access level:** Read
  - **Resource types (\*required):**  [#amazonec2-network-insights-access-scope-analysis](#amazonec2-network-insights-access-scope-analysis)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetNetworkInsightsAccessScopeContent.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetNetworkInsightsAccessScopeContent.html) **
  - **Description:** Grants permission to get the content for a specified Network Access Scope
  - **Access level:** Read
  - **Resource types (\*required):**  [#amazonec2-network-insights-access-scope](#amazonec2-network-insights-access-scope)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetPasswordData.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetPasswordData.html) **
  - **Description:** Grants permission to retrieve the encrypted administrator password for a running Windows instance
  - **Access level:** Read
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ProductCode](#amazonec2-ec2_ProductCode) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetReservedInstancesExchangeQuote.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetReservedInstancesExchangeQuote.html) **
  - **Description:** Grants permission to return a quote and exchange information for exchanging one or more Convertible Reserved Instances for a new Convertible Reserved Instance
  - **Access level:** Read
  - **Resource types (\*required):**  [#amazonec2-reserved-instances](#amazonec2-reserved-instances)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ReservedInstancesOfferingType](#amazonec2-ec2_ReservedInstancesOfferingType) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/vpc/latest/ipam/share-pool-ipam.html](https://docs.aws.amazon.com/vpc/latest/ipam/share-pool-ipam.html) [permission only]**
  - **Description:** Grants permission to describe an IAM policy that enables cross-account sharing
  - **Access level:** Read
  - **Resource types (\*required):**  [#amazonec2-ipam-pool](#amazonec2-ipam-pool)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-placement-group](#amazonec2-placement-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_PlacementGroupName](#amazonec2-ec2_PlacementGroupName) <br /> [#amazonec2-ec2_PlacementGroupStrategy](#amazonec2-ec2_PlacementGroupStrategy) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-verified-access-group](#amazonec2-verified-access-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetRouteServerAssociations.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetRouteServerAssociations.html) **
  - **Description:** Grants permission to get associations for a route server
  - **Access level:** Read
  - **Resource types (\*required):**  [#amazonec2-route-server](#amazonec2-route-server)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetRouteServerPropagations.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetRouteServerPropagations.html) **
  - **Description:** Grants permission to get propagations for a route server
  - **Access level:** Read
  - **Resource types (\*required):**  [#amazonec2-route-server](#amazonec2-route-server)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-route-table](#amazonec2-route-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RouteTableID](#amazonec2-ec2_RouteTableID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetRouteServerRoutingDatabase.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetRouteServerRoutingDatabase.html) **
  - **Description:** Grants permission to get the routing database for a route server
  - **Access level:** Read
  - **Resource types (\*required):**  [#amazonec2-route-server](#amazonec2-route-server)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetSecurityGroupsForVpc.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetSecurityGroupsForVpc.html) **
  - **Description:** Grants permission to retrieve a list of security groups for a specified VPC
  - **Access level:** Read
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetSerialConsoleAccessStatus.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetSerialConsoleAccessStatus.html) **
  - **Description:** Grants permission to retrieve the access status of your account to the EC2 serial console of all instances
  - **Access level:** Read
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetSnapshotBlockPublicAccessState.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetSnapshotBlockPublicAccessState.html) **
  - **Description:** Grants permission to retrieve the current state of the block public access for snapshots setting for a Region
  - **Access level:** Read
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetSpotPlacementScores.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetSpotPlacementScores.html) **
  - **Description:** Grants permission to calculate the Spot placement score for a Region or Availability Zone based on the specified target capacity and compute requirements
  - **Access level:** Read
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetSubnetCidrReservations.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetSubnetCidrReservations.html) **
  - **Description:** Grants permission to retrieve information about the subnet CIDR reservations
  - **Access level:** Read
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetTransitGatewayAttachmentPropagations.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetTransitGatewayAttachmentPropagations.html) **
  - **Description:** Grants permission to list the route tables to which a resource attachment propagates routes
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetTransitGatewayMeteringPolicyEntries.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetTransitGatewayMeteringPolicyEntries.html) **
  - **Description:** Grants permission to list the entries for a transit gateway metering policy
  - **Access level:** List
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-metering-policy](#amazonec2-transit-gateway-metering-policy)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayMeteringPolicyId](#amazonec2-ec2_transitGatewayMeteringPolicyId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetTransitGatewayMulticastDomainAssociations.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetTransitGatewayMulticastDomainAssociations.html) **
  - **Description:** Grants permission to get information about the associations for a transit gateway multicast domain
  - **Access level:** List
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-multicast-domain](#amazonec2-transit-gateway-multicast-domain)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayMulticastDomainId](#amazonec2-ec2_transitGatewayMulticastDomainId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetTransitGatewayPolicyTableAssociations.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetTransitGatewayPolicyTableAssociations.html) **
  - **Description:** Grants permission to get information about associations for a transit gateway policy table
  - **Access level:** List
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-policy-table](#amazonec2-transit-gateway-policy-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayPolicyTableId](#amazonec2-ec2_transitGatewayPolicyTableId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetTransitGatewayPolicyTableEntries.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetTransitGatewayPolicyTableEntries.html) **
  - **Description:** Grants permission to get information about associations for a transit gateway policy table entry
  - **Access level:** List
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-policy-table](#amazonec2-transit-gateway-policy-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayPolicyTableId](#amazonec2-ec2_transitGatewayPolicyTableId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetTransitGatewayPrefixListReferences.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetTransitGatewayPrefixListReferences.html) **
  - **Description:** Grants permission to get information about prefix list references for a transit gateway route table
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetTransitGatewayRouteTableAssociations.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetTransitGatewayRouteTableAssociations.html) **
  - **Description:** Grants permission to get information about associations for a transit gateway route table
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetTransitGatewayRouteTablePropagations.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetTransitGatewayRouteTablePropagations.html) **
  - **Description:** Grants permission to get information about the route table propagations for a transit gateway route table
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetVerifiedAccessEndpointPolicy.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetVerifiedAccessEndpointPolicy.html) **
  - **Description:** Grants permission to show the Verified Access policy associated with the endpoint
  - **Access level:** List
  - **Resource types (\*required):**  [#amazonec2-verified-access-endpoint](#amazonec2-verified-access-endpoint)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetVerifiedAccessEndpointTargets.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetVerifiedAccessEndpointTargets.html) **
  - **Description:** Grants permission to get verified access endpoint targets
  - **Access level:** List
  - **Resource types (\*required):**  [#amazonec2-verified-access-endpoint](#amazonec2-verified-access-endpoint)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetVerifiedAccessGroupPolicy.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetVerifiedAccessGroupPolicy.html) **
  - **Description:** Grants permission to show the contents of the Verified Access policy associated with the group
  - **Access level:** List
  - **Resource types (\*required):**  [#amazonec2-verified-access-group](#amazonec2-verified-access-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/verified-access/latest/ug/waf-integration.html](https://docs.aws.amazon.com/verified-access/latest/ug/waf-integration.html) [permission only]**
  - **Description:** Grants permission to show the AWS Web Application Firewall (WAF) web access control list (ACL) for a Verified Access instance
  - **Access level:** List
  - **Resource types (\*required):**  [#amazonec2-verified-access-instance](#amazonec2-verified-access-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetVpcResourcesBlockingEncryptionEnforcement.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetVpcResourcesBlockingEncryptionEnforcement.html) **
  - **Description:** Grants permission to describe resources that would block VPC Encryption Control enforcement
  - **Access level:** List
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetVpnConnectionDeviceSampleConfiguration.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetVpnConnectionDeviceSampleConfiguration.html) **
  - **Description:** Grants permission to download an AWS-provided sample configuration file to be used with the customer gateway device
  - **Access level:** List
  - **Resource types (\*required):**  [#amazonec2-vpn-connection](#amazonec2-vpn-connection)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpn-connection-device-type](#amazonec2-vpn-connection-device-type)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetVpnConnectionDeviceTypes.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetVpnConnectionDeviceTypes.html) **
  - **Description:** Grants permission to obtain a list of customer gateway devices for which sample configuration files can be provided
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetVpnTunnelReplacementStatus.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetVpnTunnelReplacementStatus.html) **
  - **Description:** Grants permission to view available tunnel endpoint maintenance events
  - **Access level:** List
  - **Resource types (\*required):**  [#amazonec2-vpn-connection](#amazonec2-vpn-connection)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/vpc/latest/ipam/tutorials-byoip-ipam-transfer-ipv4.html](https://docs.aws.amazon.com/vpc/latest/ipam/tutorials-byoip-ipam-transfer-ipv4.html) [permission only]**
  - **Description:** Grants permission to transfer existing BYOIP IPv4 CIDRs to IPAM
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipam-pool](#amazonec2-ipam-pool)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ImportClientVpnClientCertificateRevocationList.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ImportClientVpnClientCertificateRevocationList.html) **
  - **Description:** Grants permission to upload a client certificate revocation list to a Client VPN endpoint
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-client-vpn-endpoint](#amazonec2-client-vpn-endpoint)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ClientRootCertificateChainArn](#amazonec2-ec2_ClientRootCertificateChainArn) <br /> [#amazonec2-ec2_CloudwatchLogGroupArn](#amazonec2-ec2_CloudwatchLogGroupArn) <br /> [#amazonec2-ec2_CloudwatchLogStreamArn](#amazonec2-ec2_CloudwatchLogStreamArn) <br /> [#amazonec2-ec2_DirectoryArn](#amazonec2-ec2_DirectoryArn) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SamlProviderArn](#amazonec2-ec2_SamlProviderArn) <br /> [#amazonec2-ec2_ServerCertificateArn](#amazonec2-ec2_ServerCertificateArn)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ImportImage.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ImportImage.html) **
  - **Description:** Grants permission to import single or multi-volume disk images or EBS snapshots into an Amazon Machine Image (AMI)
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-image](#amazonec2-image)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ImageID](#amazonec2-ec2_ImageID) <br /> [#amazonec2-ec2_ImageType](#amazonec2-ec2_ImageType) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_Public](#amazonec2-ec2_Public) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-import-image-task](#amazonec2-import-image-task)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-snapshot](#amazonec2-snapshot)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_ParentVolume](#amazonec2-ec2_ParentVolume) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SnapshotID](#amazonec2-ec2_SnapshotID) <br /> [#amazonec2-ec2_SnapshotTime](#amazonec2-ec2_SnapshotTime) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ImportInstance.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ImportInstance.html) **
  - **Description:** Grants permission to create an import instance task using metadata from a disk image
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-volume](#amazonec2-volume)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_Encrypted](#amazonec2-ec2_Encrypted) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_ParentSnapshot](#amazonec2-ec2_ParentSnapshot) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VolumeID](#amazonec2-ec2_VolumeID) <br /> [#amazonec2-ec2_VolumeIops](#amazonec2-ec2_VolumeIops) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize) <br /> [#amazonec2-ec2_VolumeThroughput](#amazonec2-ec2_VolumeThroughput) <br /> [#amazonec2-ec2_VolumeType](#amazonec2-ec2_VolumeType)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-security-group](#amazonec2-security-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SecurityGroupID](#amazonec2-ec2_SecurityGroupID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-subnet](#amazonec2-subnet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ImportKeyPair.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ImportKeyPair.html) **
  - **Description:** Grants permission to import a public key from an RSA key pair that was created with a third-party tool
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-key-pair](#amazonec2-key-pair)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ImportSnapshot.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ImportSnapshot.html) **
  - **Description:** Grants permission to import a disk into an EBS snapshot
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-import-snapshot-task](#amazonec2-import-snapshot-task)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-snapshot](#amazonec2-snapshot)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_ParentVolume](#amazonec2-ec2_ParentVolume) <br /> [#amazonec2-ec2_SnapshotID](#amazonec2-ec2_SnapshotID) <br /> [#amazonec2-ec2_SnapshotTime](#amazonec2-ec2_SnapshotTime) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ImportVolume.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ImportVolume.html) **
  - **Description:** Grants permission to create an import volume task using metadata from a disk image
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-volume](#amazonec2-volume)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_Encrypted](#amazonec2-ec2_Encrypted) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_ParentSnapshot](#amazonec2-ec2_ParentSnapshot) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VolumeID](#amazonec2-ec2_VolumeID) <br /> [#amazonec2-ec2_VolumeIops](#amazonec2-ec2_VolumeIops) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize) <br /> [#amazonec2-ec2_VolumeThroughput](#amazonec2-ec2_VolumeThroughput) <br /> [#amazonec2-ec2_VolumeType](#amazonec2-ec2_VolumeType)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/fis/latest/userguide/fis-actions-reference.html](https://docs.aws.amazon.com/fis/latest/userguide/fis-actions-reference.html) [permission only]**
  - **Description:** Grants permission to temporarily inject errors for target API requests
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_FisActionId](#amazonec2-ec2_FisActionId) <br /> [#amazonec2-ec2_FisTargetArns](#amazonec2-ec2_FisTargetArns) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/fis/latest/userguide/fis-actions-reference.html#ebs-actions-reference](https://docs.aws.amazon.com/fis/latest/userguide/fis-actions-reference.html#ebs-actions-reference) [permission only]**
  - **Description:** Grants permission to temporarily inject latency to I/O operations for a target Amazon EBS volume
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-volume](#amazonec2-volume)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_Encrypted](#amazonec2-ec2_Encrypted) <br /> [#amazonec2-ec2_ParentSnapshot](#amazonec2-ec2_ParentSnapshot) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VolumeID](#amazonec2-ec2_VolumeID) <br /> [#amazonec2-ec2_VolumeIops](#amazonec2-ec2_VolumeIops) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize) <br /> [#amazonec2-ec2_VolumeThroughput](#amazonec2-ec2_VolumeThroughput) <br /> [#amazonec2-ec2_VolumeType](#amazonec2-ec2_VolumeType)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ListImagesInRecycleBin.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ListImagesInRecycleBin.html) **
  - **Description:** Grants permission to list Amazon Machine Images (AMIs) that are currently in the Recycle Bin
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ListSnapshotsInRecycleBin.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ListSnapshotsInRecycleBin.html) **
  - **Description:** Grants permission to list the Amazon EBS snapshots that are currently in the Recycle Bin
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ListVolumesInRecycleBin.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ListVolumesInRecycleBin.html) **
  - **Description:** Grants permission to list EBS volumes in Recycle Bin
  - **Access level:** List
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_LockSnapshot.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_LockSnapshot.html) **
  - **Description:** Grants permission to lock an Amazon EBS snapshot in either governance or compliance mode to protect it against accidental or malicious deletions
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-snapshot](#amazonec2-snapshot)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Encrypted](#amazonec2-ec2_Encrypted) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_ParentVolume](#amazonec2-ec2_ParentVolume) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SnapshotCoolOffPeriod](#amazonec2-ec2_SnapshotCoolOffPeriod) <br /> [#amazonec2-ec2_SnapshotID](#amazonec2-ec2_SnapshotID) <br /> [#amazonec2-ec2_SnapshotLockDuration](#amazonec2-ec2_SnapshotLockDuration) <br /> [#amazonec2-ec2_SnapshotTime](#amazonec2-ec2_SnapshotTime) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyAddressAttribute.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyAddressAttribute.html) **
  - **Description:** Grants permission to modify an attribute of the specified Elastic IP address
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-elastic-ip](#amazonec2-elastic-ip)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AllocationId](#amazonec2-ec2_AllocationId) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Domain](#amazonec2-ec2_Domain) <br /> [#amazonec2-ec2_PublicIpAddress](#amazonec2-ec2_PublicIpAddress) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyAvailabilityZoneGroup.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyAvailabilityZoneGroup.html) **
  - **Description:** Grants permission to modify the opt-in status of the Local Zone and Wavelength Zone group for your account
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyCapacityReservation.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyCapacityReservation.html) **
  - **Description:** Grants permission to modify a Capacity Reservation's capacity and the conditions under which it is to be released
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-capacity-reservation](#amazonec2-capacity-reservation)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_CapacityReservationFleet](#amazonec2-ec2_CapacityReservationFleet)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyCapacityReservationFleet.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyCapacityReservationFleet.html) **
  - **Description:** Grants permission to modify a Capacity Reservation Fleet
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-capacity-reservation-fleet](#amazonec2-capacity-reservation-fleet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:**  ec2:ModifyCapacityReservation 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyClientVpnEndpoint.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyClientVpnEndpoint.html) **
  - **Description:** Grants permission to modify a Client VPN endpoint
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-client-vpn-endpoint](#amazonec2-client-vpn-endpoint)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ClientRootCertificateChainArn](#amazonec2-ec2_ClientRootCertificateChainArn) <br /> [#amazonec2-ec2_CloudwatchLogGroupArn](#amazonec2-ec2_CloudwatchLogGroupArn) <br /> [#amazonec2-ec2_CloudwatchLogStreamArn](#amazonec2-ec2_CloudwatchLogStreamArn) <br /> [#amazonec2-ec2_DirectoryArn](#amazonec2-ec2_DirectoryArn) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SamlProviderArn](#amazonec2-ec2_SamlProviderArn) <br /> [#amazonec2-ec2_ServerCertificateArn](#amazonec2-ec2_ServerCertificateArn)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-security-group](#amazonec2-security-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SecurityGroupID](#amazonec2-ec2_SecurityGroupID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyDefaultCreditSpecification.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyDefaultCreditSpecification.html) **
  - **Description:** Grants permission to change the account level default credit option for CPU usage of burstable performance instances
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyEbsDefaultKmsKeyId.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyEbsDefaultKmsKeyId.html) **
  - **Description:** Grants permission to change the default customer master key (CMK) for EBS encryption by default for your account
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyFleet.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyFleet.html) **
  - **Description:** Grants permission to modify an EC2 Fleet
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-fleet](#amazonec2-fleet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-image](#amazonec2-image)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ImageID](#amazonec2-ec2_ImageID) <br /> [#amazonec2-ec2_ImageType](#amazonec2-ec2_ImageType) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_Public](#amazonec2-ec2_Public) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-launch-template](#amazonec2-launch-template)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-subnet](#amazonec2-subnet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyFpgaImageAttribute.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyFpgaImageAttribute.html) **
  - **Description:** Grants permission to modify an attribute of an Amazon FPGA Image (AFI)
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-fpga-image](#amazonec2-fpga-image)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_Public](#amazonec2-ec2_Public) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyHosts.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyHosts.html) **
  - **Description:** Grants permission to modify a Dedicated Host
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-dedicated-host](#amazonec2-dedicated-host)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyIdFormat.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyIdFormat.html) **
  - **Description:** Grants permission to modify the ID format for a resource
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyIdentityIdFormat.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyIdentityIdFormat.html) **
  - **Description:** Grants permission to modify the ID format of a resource for a specific principal in your account
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyImageAttribute.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyImageAttribute.html) **
  - **Description:** Grants permission to modify an attribute of an Amazon Machine Image (AMI)
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-image](#amazonec2-image)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ImageID](#amazonec2-ec2_ImageID) <br /> [#amazonec2-ec2_ImageType](#amazonec2-ec2_ImageType) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_Public](#amazonec2-ec2_Public) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyInstanceAttribute.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyInstanceAttribute.html) **
  - **Description:** Grants permission to modify an attribute of an instance
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ProductCode](#amazonec2-ec2_ProductCode) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-security-group](#amazonec2-security-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SecurityGroupID](#amazonec2-ec2_SecurityGroupID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-volume](#amazonec2-volume)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_Encrypted](#amazonec2-ec2_Encrypted) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_ParentSnapshot](#amazonec2-ec2_ParentSnapshot) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VolumeID](#amazonec2-ec2_VolumeID) <br /> [#amazonec2-ec2_VolumeInitializationRate](#amazonec2-ec2_VolumeInitializationRate) <br /> [#amazonec2-ec2_VolumeIops](#amazonec2-ec2_VolumeIops) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize) <br /> [#amazonec2-ec2_VolumeThroughput](#amazonec2-ec2_VolumeThroughput) <br /> [#amazonec2-ec2_VolumeType](#amazonec2-ec2_VolumeType)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyInstanceCapacityReservationAttributes.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyInstanceCapacityReservationAttributes.html) **
  - **Description:** Grants permission to modify the Capacity Reservation settings for a stopped instance
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ProductCode](#amazonec2-ec2_ProductCode) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-capacity-reservation](#amazonec2-capacity-reservation)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyInstanceConnectEndpoint.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyInstanceConnectEndpoint.html) **
  - **Description:** Grants permission to modify an existing EC2 Instance Connect Endpoint
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance-connect-endpoint](#amazonec2-instance-connect-endpoint)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-security-group](#amazonec2-security-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SecurityGroupID](#amazonec2-ec2_SecurityGroupID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyInstanceCpuOptions.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyInstanceCpuOptions.html) **
  - **Description:** Grants permission to modify the CPU options on an instance
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ProductCode](#amazonec2-ec2_ProductCode) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyInstanceCreditSpecification.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyInstanceCreditSpecification.html) **
  - **Description:** Grants permission to modify the credit option for CPU usage on an instance
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ProductCode](#amazonec2-ec2_ProductCode) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyInstanceEventStartTime.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyInstanceEventStartTime.html) **
  - **Description:** Grants permission to modify the start time for a scheduled EC2 instance event
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ProductCode](#amazonec2-ec2_ProductCode) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyInstanceEventWindow.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyInstanceEventWindow.html) **
  - **Description:** Grants permission to modify the specified event window
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance-event-window](#amazonec2-instance-event-window)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyInstanceMaintenanceOptions.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyInstanceMaintenanceOptions.html) **
  - **Description:** Grants permission to modify the recovery behaviour for an instance
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ProductCode](#amazonec2-ec2_ProductCode) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyInstanceMetadataDefaults.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyInstanceMetadataDefaults.html) **
  - **Description:** Grants permission to modify the default instance metadata service (IMDS) settings for your account in the specified Region
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyInstanceMetadataOptions.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyInstanceMetadataOptions.html) **
  - **Description:** Grants permission to modify the metadata options for an instance
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ProductCode](#amazonec2-ec2_ProductCode) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyInstanceNetworkPerformanceOptions.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyInstanceNetworkPerformanceOptions.html) **
  - **Description:** Grants permission to modify the network performance options for an instance
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ProductCode](#amazonec2-ec2_ProductCode) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyInstancePlacement.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyInstancePlacement.html) **
  - **Description:** Grants permission to modify the placement attributes for an instance
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ProductCode](#amazonec2-ec2_ProductCode) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-dedicated-host](#amazonec2-dedicated-host)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-placement-group](#amazonec2-placement-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_PlacementGroupName](#amazonec2-ec2_PlacementGroupName) <br /> [#amazonec2-ec2_PlacementGroupStrategy](#amazonec2-ec2_PlacementGroupStrategy) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyIpam.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyIpam.html) **
  - **Description:** Grants permission to modify the configurations of an Amazon VPC IP Address Manager (IPAM)
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipam](#amazonec2-ipam)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyIpamPolicyAllocationRules.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyIpamPolicyAllocationRules.html) **
  - **Description:** Grants permission to modify the rules that define how Amazon VPC IP Address Manager (IPAM) pools allocate IP addresses to AWS resource types within an IPAM policy
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipam-policy](#amazonec2-ipam-policy)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipam-pool](#amazonec2-ipam-pool)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyIpamPool.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyIpamPool.html) **
  - **Description:** Grants permission to modify the configurations of an Amazon VPC IP Address Manager (IPAM) pool
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipam-pool](#amazonec2-ipam-pool)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyIpamPrefixListResolver.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyIpamPrefixListResolver.html) **
  - **Description:** Grants permission to modify an IPAM prefix list resolver
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipam-prefix-list-resolver](#amazonec2-ipam-prefix-list-resolver)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipam-scope](#amazonec2-ipam-scope)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyIpamPrefixListResolverTarget.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyIpamPrefixListResolverTarget.html) **
  - **Description:** Grants permission to modify an IPAM prefix list resolver target
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipam-prefix-list-resolver-target](#amazonec2-ipam-prefix-list-resolver-target)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyIpamResourceCidr.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyIpamResourceCidr.html) **
  - **Description:** Grants permission to modify the configurations of an Amazon VPC IP Address Manager (IPAM) resource CIDR
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipam-scope](#amazonec2-ipam-scope)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyIpamResourceDiscovery.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyIpamResourceDiscovery.html) **
  - **Description:** Grants permission to modify a resource discovery
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipam-resource-discovery](#amazonec2-ipam-resource-discovery)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyIpamScope.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyIpamScope.html) **
  - **Description:** Grants permission to modify the configurations of an Amazon VPC IP Address Manager (IPAM) scope
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipam-scope](#amazonec2-ipam-scope)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyLaunchTemplate.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyLaunchTemplate.html) **
  - **Description:** Grants permission to modify a launch template
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-launch-template](#amazonec2-launch-template)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyLocalGatewayRoute.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyLocalGatewayRoute.html) **
  - **Description:** Grants permission to modify a local gateway route
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-local-gateway-route-table](#amazonec2-local-gateway-route-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-local-gateway-virtual-interface-group](#amazonec2-local-gateway-virtual-interface-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-network-interface](#amazonec2-network-interface)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AuthorizedUser](#amazonec2-ec2_AuthorizedUser) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_NetworkInterfaceID](#amazonec2-ec2_NetworkInterfaceID) <br /> [#amazonec2-ec2_Permission](#amazonec2-ec2_Permission) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Subnet](#amazonec2-ec2_Subnet) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-prefix-list](#amazonec2-prefix-list)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyManagedPrefixList.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyManagedPrefixList.html) **
  - **Description:** Grants permission to modify a managed prefix list
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-prefix-list](#amazonec2-prefix-list)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_IpamPrefixListResolverTargetId](#amazonec2-ec2_IpamPrefixListResolverTargetId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyNetworkInterfaceAttribute.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyNetworkInterfaceAttribute.html) **
  - **Description:** Grants permission to modify an attribute of a network interface
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-network-interface](#amazonec2-network-interface)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_NetworkInterfaceID](#amazonec2-ec2_NetworkInterfaceID) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Subnet](#amazonec2-ec2_Subnet) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ProductCode](#amazonec2-ec2_ProductCode) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-security-group](#amazonec2-security-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SecurityGroupID](#amazonec2-ec2_SecurityGroupID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-subnet](#amazonec2-subnet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyOdbNetworkPeering.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyOdbNetworkPeering.html) [permission only]**
  - **Description:** Grants permission to allow Oracle Database@AWS to modify the settings of a peering connection between an ODB network and a VPC
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyPrivateDnsNameOptions.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyPrivateDnsNameOptions.html) **
  - **Description:** Grants permission to modify the options for instance hostnames for the specified instance
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_NewInstanceProfile](#amazonec2-ec2_NewInstanceProfile) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ProductCode](#amazonec2-ec2_ProductCode) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyPublicIpDnsNameOptions.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyPublicIpDnsNameOptions.html) **
  - **Description:** Grants permission to modify public hostname options for a network interface
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-network-interface](#amazonec2-network-interface)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Subnet](#amazonec2-ec2_Subnet) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyReservedInstances.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyReservedInstances.html) **
  - **Description:** Grants permission to modify attributes of one or more Reserved Instances
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-reserved-instances](#amazonec2-reserved-instances)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ReservedInstancesOfferingType](#amazonec2-ec2_ReservedInstancesOfferingType) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyRouteServer.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyRouteServer.html) **
  - **Description:** Grants permission to modify a route server
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-route-server](#amazonec2-route-server)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifySecurityGroupRules.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifySecurityGroupRules.html) **
  - **Description:** Grants permission to modify the rules of a security group
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-security-group](#amazonec2-security-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SecurityGroupID](#amazonec2-ec2_SecurityGroupID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-security-group-rule](#amazonec2-security-group-rule)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-prefix-list](#amazonec2-prefix-list)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifySnapshotAttribute.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifySnapshotAttribute.html) **
  - **Description:** Grants permission to add or remove permission settings for a snapshot
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#amazonec2-snapshot](#amazonec2-snapshot)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Add_group](#amazonec2-ec2_Add_group) <br /> [#amazonec2-ec2_Add_userId](#amazonec2-ec2_Add_userId) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_ParentVolume](#amazonec2-ec2_ParentVolume) <br /> [#amazonec2-ec2_Remove_group](#amazonec2-ec2_Remove_group) <br /> [#amazonec2-ec2_Remove_userId](#amazonec2-ec2_Remove_userId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SnapshotID](#amazonec2-ec2_SnapshotID) <br /> [#amazonec2-ec2_SnapshotTime](#amazonec2-ec2_SnapshotTime) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifySnapshotTier.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifySnapshotTier.html) **
  - **Description:** Grants permission to archive Amazon EBS snapshots
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-snapshot](#amazonec2-snapshot)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Encrypted](#amazonec2-ec2_Encrypted) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_ParentVolume](#amazonec2-ec2_ParentVolume) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SnapshotID](#amazonec2-ec2_SnapshotID) <br /> [#amazonec2-ec2_SnapshotTime](#amazonec2-ec2_SnapshotTime) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifySpotFleetRequest.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifySpotFleetRequest.html) **
  - **Description:** Grants permission to modify a Spot Fleet request
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-spot-fleet-request](#amazonec2-spot-fleet-request)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-launch-template](#amazonec2-launch-template)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-subnet](#amazonec2-subnet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifySubnetAttribute.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifySubnetAttribute.html) **
  - **Description:** Grants permission to modify an attribute of a subnet
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-subnet](#amazonec2-subnet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyTrafficMirrorFilterNetworkServices.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyTrafficMirrorFilterNetworkServices.html) **
  - **Description:** Grants permission to allow or restrict mirroring network services
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-traffic-mirror-filter](#amazonec2-traffic-mirror-filter)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyTrafficMirrorFilterRule.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyTrafficMirrorFilterRule.html) **
  - **Description:** Grants permission to modify a traffic mirror rule
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-traffic-mirror-filter](#amazonec2-traffic-mirror-filter)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-traffic-mirror-filter-rule](#amazonec2-traffic-mirror-filter-rule)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyTrafficMirrorSession.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyTrafficMirrorSession.html) **
  - **Description:** Grants permission to modify a traffic mirror session
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-traffic-mirror-session](#amazonec2-traffic-mirror-session)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-traffic-mirror-filter](#amazonec2-traffic-mirror-filter)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-traffic-mirror-target](#amazonec2-traffic-mirror-target)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyTransitGateway.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyTransitGateway.html) **
  - **Description:** Grants permission to modify a transit gateway
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-transit-gateway](#amazonec2-transit-gateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayId](#amazonec2-ec2_transitGatewayId)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-route-table](#amazonec2-transit-gateway-route-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayRouteTableId](#amazonec2-ec2_transitGatewayRouteTableId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyTransitGatewayMeteringPolicy.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyTransitGatewayMeteringPolicy.html) **
  - **Description:** Grants permission to modify a transit gateway metering policy
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-metering-policy](#amazonec2-transit-gateway-metering-policy)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayMeteringPolicyId](#amazonec2-ec2_transitGatewayMeteringPolicyId)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-attachment](#amazonec2-transit-gateway-attachment)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayAttachmentId](#amazonec2-ec2_transitGatewayAttachmentId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyTransitGatewayPrefixListReference.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyTransitGatewayPrefixListReference.html) **
  - **Description:** Grants permission to modify a transit gateway prefix list reference
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-prefix-list](#amazonec2-prefix-list)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-route-table](#amazonec2-transit-gateway-route-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayRouteTableId](#amazonec2-ec2_transitGatewayRouteTableId)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-attachment](#amazonec2-transit-gateway-attachment)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayAttachmentId](#amazonec2-ec2_transitGatewayAttachmentId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyTransitGatewayVpcAttachment.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyTransitGatewayVpcAttachment.html) **
  - **Description:** Grants permission to modify a VPC attachment on a transit gateway
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-attachment](#amazonec2-transit-gateway-attachment)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayAttachmentId](#amazonec2-ec2_transitGatewayAttachmentId)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-subnet](#amazonec2-subnet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVerifiedAccessEndpoint.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVerifiedAccessEndpoint.html) **
  - **Description:** Grants permission to modify the configuration of a Verified Access endpoint
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-verified-access-endpoint](#amazonec2-verified-access-endpoint)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-subnet](#amazonec2-subnet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-verified-access-group](#amazonec2-verified-access-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVerifiedAccessEndpointPolicy.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVerifiedAccessEndpointPolicy.html) **
  - **Description:** Grants permission to modify the specified Verified Access endpoint policy
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-verified-access-endpoint](#amazonec2-verified-access-endpoint)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVerifiedAccessGroup.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVerifiedAccessGroup.html) **
  - **Description:** Grants permission to modify the specified Verified Access Group configuration
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-verified-access-group](#amazonec2-verified-access-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-verified-access-instance](#amazonec2-verified-access-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVerifiedAccessGroupPolicy.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVerifiedAccessGroupPolicy.html) **
  - **Description:** Grants permission to modify the specified Verified Access group policy
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-verified-access-group](#amazonec2-verified-access-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVerifiedAccessInstance.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVerifiedAccessInstance.html) **
  - **Description:** Grants permission to modify the configuration of the specified Verified Access instance
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-verified-access-instance](#amazonec2-verified-access-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVerifiedAccessInstanceLoggingConfiguration.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVerifiedAccessInstanceLoggingConfiguration.html) **
  - **Description:** Grants permission to modify the logging configuration for the specified Verified Access instance
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-verified-access-instance](#amazonec2-verified-access-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVerifiedAccessTrustProvider.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVerifiedAccessTrustProvider.html) **
  - **Description:** Grants permission to modify the configuration of the specified Verified Access trust provider
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-verified-access-trust-provider](#amazonec2-verified-access-trust-provider)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVolume.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVolume.html) **
  - **Description:** Grants permission to modify the parameters of an EBS volume
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-volume](#amazonec2-volume)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_Encrypted](#amazonec2-ec2_Encrypted) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_ParentSnapshot](#amazonec2-ec2_ParentSnapshot) <br /> [#amazonec2-ec2_ParentVolume](#amazonec2-ec2_ParentVolume) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VolumeID](#amazonec2-ec2_VolumeID) <br /> [#amazonec2-ec2_VolumeInitializationRate](#amazonec2-ec2_VolumeInitializationRate) <br /> [#amazonec2-ec2_VolumeIops](#amazonec2-ec2_VolumeIops) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize) <br /> [#amazonec2-ec2_VolumeThroughput](#amazonec2-ec2_VolumeThroughput) <br /> [#amazonec2-ec2_VolumeType](#amazonec2-ec2_VolumeType)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVolumeAttribute.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVolumeAttribute.html) **
  - **Description:** Grants permission to modify an attribute of a volume
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-volume](#amazonec2-volume)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_Encrypted](#amazonec2-ec2_Encrypted) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_ParentSnapshot](#amazonec2-ec2_ParentSnapshot) <br /> [#amazonec2-ec2_ParentVolume](#amazonec2-ec2_ParentVolume) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VolumeID](#amazonec2-ec2_VolumeID) <br /> [#amazonec2-ec2_VolumeInitializationRate](#amazonec2-ec2_VolumeInitializationRate) <br /> [#amazonec2-ec2_VolumeIops](#amazonec2-ec2_VolumeIops) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize) <br /> [#amazonec2-ec2_VolumeThroughput](#amazonec2-ec2_VolumeThroughput) <br /> [#amazonec2-ec2_VolumeType](#amazonec2-ec2_VolumeType)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVpcAttribute.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVpcAttribute.html) **
  - **Description:** Grants permission to modify an attribute of a VPC
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVpcBlockPublicAccessExclusion.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVpcBlockPublicAccessExclusion.html) **
  - **Description:** Grants permission to modify an exclusion list for blocked public access on a VPC
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpc-block-public-access-exclusion](#amazonec2-vpc-block-public-access-exclusion)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVpcBlockPublicAccessOptions.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVpcBlockPublicAccessOptions.html) **
  - **Description:** Grants permission to modify options for blocked public access on a VPC
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVpcEncryptionControl.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVpcEncryptionControl.html) **
  - **Description:** Grants permission to modify an existing VPC Encryption Control
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpc-encryption-control](#amazonec2-vpc-encryption-control)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVpcEndpoint.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVpcEndpoint.html) **
  - **Description:** Grants permission to modify an attribute of a VPC endpoint
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpc-endpoint](#amazonec2-vpc-endpoint)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VpceMultiRegion](#amazonec2-ec2_VpceMultiRegion) <br /> [#amazonec2-ec2_VpceServiceRegion](#amazonec2-ec2_VpceServiceRegion)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-route-table](#amazonec2-route-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RouteTableID](#amazonec2-ec2_RouteTableID)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-security-group](#amazonec2-security-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SecurityGroupID](#amazonec2-ec2_SecurityGroupID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-subnet](#amazonec2-subnet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVpcEndpointConnectionNotification.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVpcEndpointConnectionNotification.html) **
  - **Description:** Grants permission to modify a connection notification for a VPC endpoint or VPC endpoint service
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpc-endpoint](#amazonec2-vpc-endpoint)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpc-endpoint-service](#amazonec2-vpc-endpoint-service)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VpceMultiRegion](#amazonec2-ec2_VpceMultiRegion) <br /> [#amazonec2-ec2_VpceSupportedRegion](#amazonec2-ec2_VpceSupportedRegion)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVpcEndpointServiceConfiguration.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVpcEndpointServiceConfiguration.html) **
  - **Description:** Grants permission to modify the attributes of a VPC endpoint service configuration
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpc-endpoint-service](#amazonec2-vpc-endpoint-service)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VpceMultiRegion](#amazonec2-ec2_VpceMultiRegion) <br /> [#amazonec2-ec2_VpceServicePrivateDnsName](#amazonec2-ec2_VpceServicePrivateDnsName) <br /> [#amazonec2-ec2_VpceSupportedRegion](#amazonec2-ec2_VpceSupportedRegion)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVpcEndpointServicePayerResponsibility.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVpcEndpointServicePayerResponsibility.html) **
  - **Description:** Grants permission to modify the payer responsibility for a VPC endpoint service
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpc-endpoint-service](#amazonec2-vpc-endpoint-service)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VpceMultiRegion](#amazonec2-ec2_VpceMultiRegion) <br /> [#amazonec2-ec2_VpceSupportedRegion](#amazonec2-ec2_VpceSupportedRegion)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVpcEndpointServicePermissions.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVpcEndpointServicePermissions.html) **
  - **Description:** Grants permission to modify the permissions for a VPC endpoint service
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#amazonec2-vpc-endpoint-service](#amazonec2-vpc-endpoint-service)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VpceMultiRegion](#amazonec2-ec2_VpceMultiRegion) <br /> [#amazonec2-ec2_VpceSupportedRegion](#amazonec2-ec2_VpceSupportedRegion)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVpcPeeringConnectionOptions.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVpcPeeringConnectionOptions.html) **
  - **Description:** Grants permission to modify the VPC peering connection options on one side of a VPC peering connection
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpc-peering-connection](#amazonec2-vpc-peering-connection)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AccepterVpc](#amazonec2-ec2_AccepterVpc) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_RequesterVpc](#amazonec2-ec2_RequesterVpc) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VpcPeeringConnectionID](#amazonec2-ec2_VpcPeeringConnectionID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVpcTenancy.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVpcTenancy.html) **
  - **Description:** Grants permission to modify the instance tenancy attribute of a VPC
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpc](#amazonec2-vpc)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVpnConnection.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVpnConnection.html) **
  - **Description:** Grants permission to modify the target gateway of a Site-to-Site VPN connection
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpn-connection](#amazonec2-vpn-connection)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_AuthenticationType](#amazonec2-ec2_AuthenticationType) <br /> [#amazonec2-ec2_DPDTimeoutSeconds](#amazonec2-ec2_DPDTimeoutSeconds) <br /> [#amazonec2-ec2_GatewayType](#amazonec2-ec2_GatewayType) <br /> [#amazonec2-ec2_IKEVersions](#amazonec2-ec2_IKEVersions) <br /> [#amazonec2-ec2_InsideTunnelCidr](#amazonec2-ec2_InsideTunnelCidr) <br /> [#amazonec2-ec2_InsideTunnelIpv6Cidr](#amazonec2-ec2_InsideTunnelIpv6Cidr) <br /> [#amazonec2-ec2_Phase1DHGroup](#amazonec2-ec2_Phase1DHGroup) <br /> [#amazonec2-ec2_Phase1EncryptionAlgorithms](#amazonec2-ec2_Phase1EncryptionAlgorithms) <br /> [#amazonec2-ec2_Phase1IntegrityAlgorithms](#amazonec2-ec2_Phase1IntegrityAlgorithms) <br /> [#amazonec2-ec2_Phase1LifetimeSeconds](#amazonec2-ec2_Phase1LifetimeSeconds) <br /> [#amazonec2-ec2_Phase2DHGroup](#amazonec2-ec2_Phase2DHGroup) <br /> [#amazonec2-ec2_Phase2EncryptionAlgorithms](#amazonec2-ec2_Phase2EncryptionAlgorithms) <br /> [#amazonec2-ec2_Phase2IntegrityAlgorithms](#amazonec2-ec2_Phase2IntegrityAlgorithms) <br /> [#amazonec2-ec2_Phase2LifetimeSeconds](#amazonec2-ec2_Phase2LifetimeSeconds) <br /> [#amazonec2-ec2_RekeyFuzzPercentage](#amazonec2-ec2_RekeyFuzzPercentage) <br /> [#amazonec2-ec2_RekeyMarginTimeSeconds](#amazonec2-ec2_RekeyMarginTimeSeconds) <br /> [#amazonec2-ec2_ReplayWindowSizePackets](#amazonec2-ec2_ReplayWindowSizePackets) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RoutingType](#amazonec2-ec2_RoutingType)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVpnConnectionOptions.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVpnConnectionOptions.html) **
  - **Description:** Grants permission to modify the connection options for your Site-to-Site VPN connection
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpn-connection](#amazonec2-vpn-connection)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVpnTunnelCertificate.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVpnTunnelCertificate.html) **
  - **Description:** Grants permission to modify the certificate for a Site-to-Site VPN connection
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpn-connection](#amazonec2-vpn-connection)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVpnTunnelOptions.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyVpnTunnelOptions.html) **
  - **Description:** Grants permission to modify the options for a Site-to-Site VPN connection
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpn-connection](#amazonec2-vpn-connection)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_AuthenticationType](#amazonec2-ec2_AuthenticationType) <br /> [#amazonec2-ec2_DPDTimeoutSeconds](#amazonec2-ec2_DPDTimeoutSeconds) <br /> [#amazonec2-ec2_GatewayType](#amazonec2-ec2_GatewayType) <br /> [#amazonec2-ec2_IKEVersions](#amazonec2-ec2_IKEVersions) <br /> [#amazonec2-ec2_InsideTunnelCidr](#amazonec2-ec2_InsideTunnelCidr) <br /> [#amazonec2-ec2_InsideTunnelIpv6Cidr](#amazonec2-ec2_InsideTunnelIpv6Cidr) <br /> [#amazonec2-ec2_Phase1DHGroup](#amazonec2-ec2_Phase1DHGroup) <br /> [#amazonec2-ec2_Phase1EncryptionAlgorithms](#amazonec2-ec2_Phase1EncryptionAlgorithms) <br /> [#amazonec2-ec2_Phase1IntegrityAlgorithms](#amazonec2-ec2_Phase1IntegrityAlgorithms) <br /> [#amazonec2-ec2_Phase1LifetimeSeconds](#amazonec2-ec2_Phase1LifetimeSeconds) <br /> [#amazonec2-ec2_Phase2DHGroup](#amazonec2-ec2_Phase2DHGroup) <br /> [#amazonec2-ec2_Phase2EncryptionAlgorithms](#amazonec2-ec2_Phase2EncryptionAlgorithms) <br /> [#amazonec2-ec2_Phase2IntegrityAlgorithms](#amazonec2-ec2_Phase2IntegrityAlgorithms) <br /> [#amazonec2-ec2_Phase2LifetimeSeconds](#amazonec2-ec2_Phase2LifetimeSeconds) <br /> [#amazonec2-ec2_RekeyFuzzPercentage](#amazonec2-ec2_RekeyFuzzPercentage) <br /> [#amazonec2-ec2_RekeyMarginTimeSeconds](#amazonec2-ec2_RekeyMarginTimeSeconds) <br /> [#amazonec2-ec2_ReplayWindowSizePackets](#amazonec2-ec2_ReplayWindowSizePackets) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RoutingType](#amazonec2-ec2_RoutingType)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_MonitorInstances.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_MonitorInstances.html) **
  - **Description:** Grants permission to enable detailed monitoring for a running instance
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ProductCode](#amazonec2-ec2_ProductCode) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_MoveAddressToVpc.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_MoveAddressToVpc.html) **
  - **Description:** Grants permission to move an Elastic IP address from the EC2-Classic platform to the EC2-VPC platform
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_MoveByoipCidrToIpam.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_MoveByoipCidrToIpam.html) **
  - **Description:** Grants permission to move a BYOIP IPv4 CIDR to Amazon VPC IP Address Manager (IPAM) from a public IPv4 pool
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipam-pool](#amazonec2-ipam-pool)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_MoveCapacityReservationInstances.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_MoveCapacityReservationInstances.html) **
  - **Description:** Grants permission to move available capacity from a source Capacity Reservation to a destination Capacity Reservation
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-capacity-reservation](#amazonec2-capacity-reservation)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_CapacityReservationFleet](#amazonec2-ec2_CapacityReservationFleet) <br /> [#amazonec2-ec2_CreateDate](#amazonec2-ec2_CreateDate) <br /> [#amazonec2-ec2_DestinationCapacityReservationId](#amazonec2-ec2_DestinationCapacityReservationId) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_EndDate](#amazonec2-ec2_EndDate) <br /> [#amazonec2-ec2_EndDateType](#amazonec2-ec2_EndDateType) <br /> [#amazonec2-ec2_InstanceCount](#amazonec2-ec2_InstanceCount) <br /> [#amazonec2-ec2_InstanceMatchCriteria](#amazonec2-ec2_InstanceMatchCriteria) <br /> [#amazonec2-ec2_InstancePlatform](#amazonec2-ec2_InstancePlatform) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_OutpostArn](#amazonec2-ec2_OutpostArn) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SourceCapacityReservationId](#amazonec2-ec2_SourceCapacityReservationId) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/fis/latest/userguide/fis-actions-reference.html#ebs-actions-reference](https://docs.aws.amazon.com/fis/latest/userguide/fis-actions-reference.html#ebs-actions-reference) [permission only]**
  - **Description:** Grants permission to temporarily pause I/O operations for a target Amazon EBS volume
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-volume](#amazonec2-volume)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_Encrypted](#amazonec2-ec2_Encrypted) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_ParentSnapshot](#amazonec2-ec2_ParentSnapshot) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VolumeID](#amazonec2-ec2_VolumeID) <br /> [#amazonec2-ec2_VolumeIops](#amazonec2-ec2_VolumeIops) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize) <br /> [#amazonec2-ec2_VolumeThroughput](#amazonec2-ec2_VolumeThroughput) <br /> [#amazonec2-ec2_VolumeType](#amazonec2-ec2_VolumeType)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ProvisionByoipCidr.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ProvisionByoipCidr.html) **
  - **Description:** Grants permission to provision an address range for use in AWS through bring your own IP addresses (BYOIP), and to create a corresponding address pool
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ProvisionIpamByoasn.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ProvisionIpamByoasn.html) **
  - **Description:** Grants permission to provision an Autonomous System Number (ASN) for use in an Amazon Web Services account
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipam](#amazonec2-ipam)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ProvisionIpamPoolCidr.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ProvisionIpamPoolCidr.html) **
  - **Description:** Grants permission to provision a CIDR to an Amazon VPC IP Address Manager (IPAM) pool
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipam-pool](#amazonec2-ipam-pool)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipam-external-resource-verification-token](#amazonec2-ipam-external-resource-verification-token)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ProvisionPublicIpv4PoolCidr.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ProvisionPublicIpv4PoolCidr.html) **
  - **Description:** Grants permission to provision a CIDR to a public IPv4 pool
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipam-pool](#amazonec2-ipam-pool)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipv4pool-ec2](#amazonec2-ipv4pool-ec2)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_PurchaseCapacityBlock.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_PurchaseCapacityBlock.html) **
  - **Description:** Grants permission to purchase a Capacity Block offering
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-capacity-reservation](#amazonec2-capacity-reservation)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_CapacityReservationFleet](#amazonec2-ec2_CapacityReservationFleet)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_PurchaseCapacityBlockExtension.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_PurchaseCapacityBlockExtension.html) **
  - **Description:** Grants permission to purchase a Capacity Block extension
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-capacity-reservation](#amazonec2-capacity-reservation)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_CapacityReservationFleet](#amazonec2-ec2_CapacityReservationFleet)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_PurchaseHostReservation.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_PurchaseHostReservation.html) **
  - **Description:** Grants permission to purchase a reservation with configurations that match those of a Dedicated Host
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-dedicated-host](#amazonec2-dedicated-host)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_PurchaseReservedInstancesOffering.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_PurchaseReservedInstancesOffering.html) **
  - **Description:** Grants permission to purchase a Reserved Instance offering
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_PurchaseScheduledInstances.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_PurchaseScheduledInstances.html) **
  - **Description:** Grants permission to purchase one or more Scheduled Instances with a specified schedule
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/vpc/latest/ipam/share-pool-ipam.html](https://docs.aws.amazon.com/vpc/latest/ipam/share-pool-ipam.html) [permission only]**
  - **Description:** Grants permission to attach an IAM policy that enables cross-account sharing to a resource
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#amazonec2-ipam-pool](#amazonec2-ipam-pool)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-placement-group](#amazonec2-placement-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_PlacementGroupName](#amazonec2-ec2_PlacementGroupName) <br /> [#amazonec2-ec2_PlacementGroupStrategy](#amazonec2-ec2_PlacementGroupStrategy) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-verified-access-group](#amazonec2-verified-access-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RebootInstances.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RebootInstances.html) **
  - **Description:** Grants permission to request a reboot of one or more instances
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ProductCode](#amazonec2-ec2_ProductCode) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RegisterImage.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RegisterImage.html) **
  - **Description:** Grants permission to register an Amazon Machine Image (AMI)
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-image](#amazonec2-image)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ImageID](#amazonec2-ec2_ImageID) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-snapshot](#amazonec2-snapshot)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_OutpostArn](#amazonec2-ec2_OutpostArn) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_ParentVolume](#amazonec2-ec2_ParentVolume) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SnapshotID](#amazonec2-ec2_SnapshotID) <br /> [#amazonec2-ec2_SnapshotTime](#amazonec2-ec2_SnapshotTime) <br /> [#amazonec2-ec2_SourceOutpostArn](#amazonec2-ec2_SourceOutpostArn) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RegisterInstanceEventNotificationAttributes.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RegisterInstanceEventNotificationAttributes.html) **
  - **Description:** Grants permission to add tags to the set of tags to include in notifications about scheduled events for your instances
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RegisterTransitGatewayMulticastGroupMembers.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RegisterTransitGatewayMulticastGroupMembers.html) **
  - **Description:** Grants permission to register one or more network interfaces as a member of a group IP address in a transit gateway multicast domain
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-network-interface](#amazonec2-network-interface)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_NetworkInterfaceID](#amazonec2-ec2_NetworkInterfaceID) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Subnet](#amazonec2-ec2_Subnet) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-multicast-domain](#amazonec2-transit-gateway-multicast-domain)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayMulticastDomainId](#amazonec2-ec2_transitGatewayMulticastDomainId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RegisterTransitGatewayMulticastGroupSources.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RegisterTransitGatewayMulticastGroupSources.html) **
  - **Description:** Grants permission to register one or more network interfaces as a source of a group IP address in a transit gateway multicast domain
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-network-interface](#amazonec2-network-interface)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_NetworkInterfaceID](#amazonec2-ec2_NetworkInterfaceID) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Subnet](#amazonec2-ec2_Subnet) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-multicast-domain](#amazonec2-transit-gateway-multicast-domain)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayMulticastDomainId](#amazonec2-ec2_transitGatewayMulticastDomainId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RejectCapacityReservationBillingOwnership.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RejectCapacityReservationBillingOwnership.html) **
  - **Description:** Grants permission to reject a request to assign billing of the available capacity of a shared Capacity Reservation to your account
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-capacity-reservation](#amazonec2-capacity-reservation)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_CapacityReservationFleet](#amazonec2-ec2_CapacityReservationFleet) <br /> [#amazonec2-ec2_CreateDate](#amazonec2-ec2_CreateDate) <br /> [#amazonec2-ec2_DestinationCapacityReservationId](#amazonec2-ec2_DestinationCapacityReservationId) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_EndDate](#amazonec2-ec2_EndDate) <br /> [#amazonec2-ec2_EndDateType](#amazonec2-ec2_EndDateType) <br /> [#amazonec2-ec2_InstanceCount](#amazonec2-ec2_InstanceCount) <br /> [#amazonec2-ec2_InstanceMatchCriteria](#amazonec2-ec2_InstanceMatchCriteria) <br /> [#amazonec2-ec2_InstancePlatform](#amazonec2-ec2_InstancePlatform) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_OutpostArn](#amazonec2-ec2_OutpostArn) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SourceCapacityReservationId](#amazonec2-ec2_SourceCapacityReservationId) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RejectTransitGatewayMulticastDomainAssociations.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RejectTransitGatewayMulticastDomainAssociations.html) **
  - **Description:** Grants permission to reject requests to associate cross-account subnets with a transit gateway multicast domain
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-attachment](#amazonec2-transit-gateway-attachment)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayAttachmentId](#amazonec2-ec2_transitGatewayAttachmentId)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-multicast-domain](#amazonec2-transit-gateway-multicast-domain)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayMulticastDomainId](#amazonec2-ec2_transitGatewayMulticastDomainId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RejectTransitGatewayPeeringAttachment.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RejectTransitGatewayPeeringAttachment.html) **
  - **Description:** Grants permission to reject a transit gateway peering attachment request
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-attachment](#amazonec2-transit-gateway-attachment)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayAttachmentId](#amazonec2-ec2_transitGatewayAttachmentId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RejectTransitGatewayVpcAttachment.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RejectTransitGatewayVpcAttachment.html) **
  - **Description:** Grants permission to reject a request to attach a VPC to a transit gateway
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-attachment](#amazonec2-transit-gateway-attachment)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayAttachmentId](#amazonec2-ec2_transitGatewayAttachmentId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RejectVpcEndpointConnections.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RejectVpcEndpointConnections.html) **
  - **Description:** Grants permission to reject one or more VPC endpoint connection requests to a VPC endpoint service
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpc-endpoint-service](#amazonec2-vpc-endpoint-service)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VpceMultiRegion](#amazonec2-ec2_VpceMultiRegion) <br /> [#amazonec2-ec2_VpceSupportedRegion](#amazonec2-ec2_VpceSupportedRegion)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RejectVpcPeeringConnection.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RejectVpcPeeringConnection.html) **
  - **Description:** Grants permission to reject a VPC peering connection request
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpc-peering-connection](#amazonec2-vpc-peering-connection)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AccepterVpc](#amazonec2-ec2_AccepterVpc) <br /> [#amazonec2-ec2_RequesterVpc](#amazonec2-ec2_RequesterVpc) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VpcPeeringConnectionID](#amazonec2-ec2_VpcPeeringConnectionID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ReleaseAddress.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ReleaseAddress.html) **
  - **Description:** Grants permission to release an Elastic IP address
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-elastic-ip](#amazonec2-elastic-ip)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AllocationId](#amazonec2-ec2_AllocationId) <br /> [#amazonec2-ec2_Domain](#amazonec2-ec2_Domain) <br /> [#amazonec2-ec2_PublicIpAddress](#amazonec2-ec2_PublicIpAddress) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ReleaseHosts.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ReleaseHosts.html) **
  - **Description:** Grants permission to release one or more On-Demand Dedicated Hosts
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-dedicated-host](#amazonec2-dedicated-host)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ReleaseIpamPoolAllocation.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ReleaseIpamPoolAllocation.html) **
  - **Description:** Grants permission to release an allocation within an Amazon VPC IP Address Manager (IPAM) pool
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-ipam-pool](#amazonec2-ipam-pool)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ReplaceIamInstanceProfileAssociation.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ReplaceIamInstanceProfileAssociation.html) **
  - **Description:** Grants permission to replace an IAM instance profile for an instance
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_NewInstanceProfile](#amazonec2-ec2_NewInstanceProfile) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ProductCode](#amazonec2-ec2_ProductCode) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:**  iam:PassRole 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ReplaceImageCriteriaInAllowedImagesSettings.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ReplaceImageCriteriaInAllowedImagesSettings.html) **
  - **Description:** Grants permission to replace image criteria in allowed images settings
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ReplaceNetworkAclAssociation.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ReplaceNetworkAclAssociation.html) **
  - **Description:** Grants permission to change which network ACL a subnet is associated with
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-network-acl](#amazonec2-network-acl)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_NetworkAclID](#amazonec2-ec2_NetworkAclID) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-subnet](#amazonec2-subnet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ReplaceNetworkAclEntry.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ReplaceNetworkAclEntry.html) **
  - **Description:** Grants permission to replace an entry (rule) in a network ACL
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-network-acl](#amazonec2-network-acl)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_NetworkAclID](#amazonec2-ec2_NetworkAclID) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ReplaceRoute.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ReplaceRoute.html) **
  - **Description:** Grants permission to replace a route within a route table in a VPC
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-route-table](#amazonec2-route-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RouteTableID](#amazonec2-ec2_RouteTableID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ReplaceRouteTableAssociation.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ReplaceRouteTableAssociation.html) **
  - **Description:** Grants permission to change the route table that is associated with a subnet
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-route-table](#amazonec2-route-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RouteTableID](#amazonec2-ec2_RouteTableID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-internet-gateway](#amazonec2-internet-gateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_InternetGatewayID](#amazonec2-ec2_InternetGatewayID) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipv4pool-ec2](#amazonec2-ipv4pool-ec2)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-ipv6pool-ec2](#amazonec2-ipv6pool-ec2)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-subnet](#amazonec2-subnet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-vpn-gateway](#amazonec2-vpn-gateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ReplaceTransitGatewayRoute.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ReplaceTransitGatewayRoute.html) **
  - **Description:** Grants permission to replace a route in a transit gateway route table
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-route-table](#amazonec2-transit-gateway-route-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayRouteTableId](#amazonec2-ec2_transitGatewayRouteTableId)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-attachment](#amazonec2-transit-gateway-attachment)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayAttachmentId](#amazonec2-ec2_transitGatewayAttachmentId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ReplaceVpnTunnel.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ReplaceVpnTunnel.html) **
  - **Description:** Grants permission to replace a VPN tunnel
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpn-connection](#amazonec2-vpn-connection)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ReportInstanceStatus.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ReportInstanceStatus.html) **
  - **Description:** Grants permission to submit feedback about the status of an instance
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RequestSpotFleet.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RequestSpotFleet.html) **
  - **Description:** Grants permission to create a Spot Fleet request
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-spot-fleet-request](#amazonec2-spot-fleet-request)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-image](#amazonec2-image)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ImageID](#amazonec2-ec2_ImageID) <br /> [#amazonec2-ec2_ImageType](#amazonec2-ec2_ImageType) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_Public](#amazonec2-ec2_Public) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-key-pair](#amazonec2-key-pair)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_KeyPairName](#amazonec2-ec2_KeyPairName) <br /> [#amazonec2-ec2_KeyPairType](#amazonec2-ec2_KeyPairType) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-launch-template](#amazonec2-launch-template)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-placement-group](#amazonec2-placement-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_PlacementGroupName](#amazonec2-ec2_PlacementGroupName) <br /> [#amazonec2-ec2_PlacementGroupStrategy](#amazonec2-ec2_PlacementGroupStrategy) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-security-group](#amazonec2-security-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SecurityGroupID](#amazonec2-ec2_SecurityGroupID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-snapshot](#amazonec2-snapshot)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_OutpostArn](#amazonec2-ec2_OutpostArn) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_ParentVolume](#amazonec2-ec2_ParentVolume) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SnapshotID](#amazonec2-ec2_SnapshotID) <br /> [#amazonec2-ec2_SnapshotTime](#amazonec2-ec2_SnapshotTime) <br /> [#amazonec2-ec2_SourceOutpostArn](#amazonec2-ec2_SourceOutpostArn) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-subnet](#amazonec2-subnet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RequestSpotInstances.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RequestSpotInstances.html) **
  - **Description:** Grants permission to create a Spot Instance request
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-spot-instances-request](#amazonec2-spot-instances-request)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:**  ec2:CreateTags <br /> iam:PassRole 
  - **Resource types (\*required):**  [#amazonec2-image](#amazonec2-image)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ImageID](#amazonec2-ec2_ImageID) <br /> [#amazonec2-ec2_ImageType](#amazonec2-ec2_ImageType) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_Public](#amazonec2-ec2_Public) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-key-pair](#amazonec2-key-pair)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_KeyPairName](#amazonec2-ec2_KeyPairName) <br /> [#amazonec2-ec2_KeyPairType](#amazonec2-ec2_KeyPairType) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-network-interface](#amazonec2-network-interface)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AuthorizedUser](#amazonec2-ec2_AuthorizedUser) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_NetworkInterfaceID](#amazonec2-ec2_NetworkInterfaceID) <br /> [#amazonec2-ec2_Permission](#amazonec2-ec2_Permission) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Subnet](#amazonec2-ec2_Subnet) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-placement-group](#amazonec2-placement-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_PlacementGroupName](#amazonec2-ec2_PlacementGroupName) <br /> [#amazonec2-ec2_PlacementGroupStrategy](#amazonec2-ec2_PlacementGroupStrategy) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-security-group](#amazonec2-security-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SecurityGroupID](#amazonec2-ec2_SecurityGroupID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-snapshot](#amazonec2-snapshot)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_OutpostArn](#amazonec2-ec2_OutpostArn) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_ParentVolume](#amazonec2-ec2_ParentVolume) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SnapshotID](#amazonec2-ec2_SnapshotID) <br /> [#amazonec2-ec2_SnapshotTime](#amazonec2-ec2_SnapshotTime) <br /> [#amazonec2-ec2_SourceOutpostArn](#amazonec2-ec2_SourceOutpostArn) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-subnet](#amazonec2-subnet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ResetAddressAttribute.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ResetAddressAttribute.html) **
  - **Description:** Grants permission to reset the attribute of the specified IP address
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-elastic-ip](#amazonec2-elastic-ip)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AllocationId](#amazonec2-ec2_AllocationId) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Domain](#amazonec2-ec2_Domain) <br /> [#amazonec2-ec2_PublicIpAddress](#amazonec2-ec2_PublicIpAddress) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ResetEbsDefaultKmsKeyId.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ResetEbsDefaultKmsKeyId.html) **
  - **Description:** Grants permission to reset the default customer master key (CMK) for EBS encryption for your account to use the AWS-managed CMK for EBS
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ResetFpgaImageAttribute.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ResetFpgaImageAttribute.html) **
  - **Description:** Grants permission to reset an attribute of an Amazon FPGA Image (AFI) to its default value
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-fpga-image](#amazonec2-fpga-image)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_Public](#amazonec2-ec2_Public) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ResetImageAttribute.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ResetImageAttribute.html) **
  - **Description:** Grants permission to reset an attribute of an Amazon Machine Image (AMI) to its default value
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-image](#amazonec2-image)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ImageID](#amazonec2-ec2_ImageID) <br /> [#amazonec2-ec2_ImageType](#amazonec2-ec2_ImageType) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_Public](#amazonec2-ec2_Public) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ResetInstanceAttribute.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ResetInstanceAttribute.html) **
  - **Description:** Grants permission to reset an attribute of an instance to its default value
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_ProductCode](#amazonec2-ec2_ProductCode) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ResetNetworkInterfaceAttribute.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ResetNetworkInterfaceAttribute.html) **
  - **Description:** Grants permission to reset an attribute of a network interface
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-network-interface](#amazonec2-network-interface)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_NetworkInterfaceID](#amazonec2-ec2_NetworkInterfaceID) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Subnet](#amazonec2-ec2_Subnet) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ResetSnapshotAttribute.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ResetSnapshotAttribute.html) **
  - **Description:** Grants permission to reset permission settings for a snapshot
  - **Access level:** Permissions management
  - **Resource types (\*required):**  [#amazonec2-snapshot](#amazonec2-snapshot)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_ParentVolume](#amazonec2-ec2_ParentVolume) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SnapshotID](#amazonec2-ec2_SnapshotID) <br /> [#amazonec2-ec2_SnapshotTime](#amazonec2-ec2_SnapshotTime) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RestoreAddressToClassic.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RestoreAddressToClassic.html) **
  - **Description:** Grants permission to restore an Elastic IP address that was previously moved to the EC2-VPC platform back to the EC2-Classic platform
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RestoreImageFromRecycleBin.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RestoreImageFromRecycleBin.html) **
  - **Description:** Grants permission to restore an Amazon Machine Image (AMI) from the Recycle Bin
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-image](#amazonec2-image)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ImageID](#amazonec2-ec2_ImageID) <br /> [#amazonec2-ec2_ImageType](#amazonec2-ec2_ImageType) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_Public](#amazonec2-ec2_Public) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RestoreManagedPrefixListVersion.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RestoreManagedPrefixListVersion.html) **
  - **Description:** Grants permission to restore the entries from a previous version of a managed prefix list to a new version of the prefix list
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-prefix-list](#amazonec2-prefix-list)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RestoreSnapshotFromRecycleBin.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RestoreSnapshotFromRecycleBin.html) **
  - **Description:** Grants permission to restore an Amazon EBS snapshot from the Recycle Bin
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-snapshot](#amazonec2-snapshot)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Encrypted](#amazonec2-ec2_Encrypted) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_ParentVolume](#amazonec2-ec2_ParentVolume) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SnapshotID](#amazonec2-ec2_SnapshotID) <br /> [#amazonec2-ec2_SnapshotTime](#amazonec2-ec2_SnapshotTime) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RestoreSnapshotTier.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RestoreSnapshotTier.html) **
  - **Description:** Grants permission to restore an archived Amazon EBS snapshot for use temporarily or permanently, or modify the restore period or restore type for a snapshot that was previously temporarily restored
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-snapshot](#amazonec2-snapshot)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Encrypted](#amazonec2-ec2_Encrypted) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_ParentVolume](#amazonec2-ec2_ParentVolume) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SnapshotID](#amazonec2-ec2_SnapshotID) <br /> [#amazonec2-ec2_SnapshotTime](#amazonec2-ec2_SnapshotTime) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RestoreVolumeFromRecycleBin.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RestoreVolumeFromRecycleBin.html) **
  - **Description:** Grants permission to restore an EBS volume from Recycle Bin
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-volume](#amazonec2-volume)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_Encrypted](#amazonec2-ec2_Encrypted) <br /> [#amazonec2-ec2_ParentSnapshot](#amazonec2-ec2_ParentSnapshot) <br /> [#amazonec2-ec2_ParentVolume](#amazonec2-ec2_ParentVolume) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VolumeID](#amazonec2-ec2_VolumeID) <br /> [#amazonec2-ec2_VolumeInitializationRate](#amazonec2-ec2_VolumeInitializationRate) <br /> [#amazonec2-ec2_VolumeIops](#amazonec2-ec2_VolumeIops) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize) <br /> [#amazonec2-ec2_VolumeThroughput](#amazonec2-ec2_VolumeThroughput) <br /> [#amazonec2-ec2_VolumeType](#amazonec2-ec2_VolumeType)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RevokeClientVpnIngress.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RevokeClientVpnIngress.html) **
  - **Description:** Grants permission to remove an inbound authorization rule from a Client VPN endpoint
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-client-vpn-endpoint](#amazonec2-client-vpn-endpoint)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ClientRootCertificateChainArn](#amazonec2-ec2_ClientRootCertificateChainArn) <br /> [#amazonec2-ec2_CloudwatchLogGroupArn](#amazonec2-ec2_CloudwatchLogGroupArn) <br /> [#amazonec2-ec2_CloudwatchLogStreamArn](#amazonec2-ec2_CloudwatchLogStreamArn) <br /> [#amazonec2-ec2_DirectoryArn](#amazonec2-ec2_DirectoryArn) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SamlProviderArn](#amazonec2-ec2_SamlProviderArn) <br /> [#amazonec2-ec2_ServerCertificateArn](#amazonec2-ec2_ServerCertificateArn)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RevokeSecurityGroupEgress.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RevokeSecurityGroupEgress.html) **
  - **Description:** Grants permission to remove one or more outbound rules from a VPC security group
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-security-group](#amazonec2-security-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SecurityGroupID](#amazonec2-ec2_SecurityGroupID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RevokeSecurityGroupIngress.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RevokeSecurityGroupIngress.html) **
  - **Description:** Grants permission to remove one or more inbound rules from a security group
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-security-group](#amazonec2-security-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SecurityGroupID](#amazonec2-ec2_SecurityGroupID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RunInstances.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RunInstances.html) **
  - **Description:** Grants permission to launch one or more instances / **Access level:** Write / **Resource types (\*required):**  [#amazonec2-image](#amazonec2-image)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ImageID](#amazonec2-ec2_ImageID) <br /> [#amazonec2-ec2_ImageType](#amazonec2-ec2_ImageType) <br /> [#amazonec2-ec2_IsLaunchTemplateResource](#amazonec2-ec2_IsLaunchTemplateResource) <br /> [#amazonec2-ec2_LaunchTemplate](#amazonec2-ec2_LaunchTemplate) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_Public](#amazonec2-ec2_Public) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType)  / **Dependent actions:**  ec2:CreateTags <br /> iam:PassRole <br /> ssm:GetParameters 
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_IsLaunchTemplateResource](#amazonec2-ec2_IsLaunchTemplateResource) <br /> [#amazonec2-ec2_LaunchTemplate](#amazonec2-ec2_LaunchTemplate) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ProductCode](#amazonec2-ec2_ProductCode) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-network-interface](#amazonec2-network-interface)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_AssociatePublicIpAddress](#amazonec2-ec2_AssociatePublicIpAddress) <br /> [#amazonec2-ec2_AuthorizedService](#amazonec2-ec2_AuthorizedService) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_IsLaunchTemplateResource](#amazonec2-ec2_IsLaunchTemplateResource) <br /> [#amazonec2-ec2_LaunchTemplate](#amazonec2-ec2_LaunchTemplate) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_NetworkInterfaceID](#amazonec2-ec2_NetworkInterfaceID) <br /> [#amazonec2-ec2_Subnet](#amazonec2-ec2_Subnet) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-security-group](#amazonec2-security-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_IsLaunchTemplateResource](#amazonec2-ec2_IsLaunchTemplateResource) <br /> [#amazonec2-ec2_LaunchTemplate](#amazonec2-ec2_LaunchTemplate) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SecurityGroupID](#amazonec2-ec2_SecurityGroupID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-subnet](#amazonec2-subnet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_IsLaunchTemplateResource](#amazonec2-ec2_IsLaunchTemplateResource) <br /> [#amazonec2-ec2_LaunchTemplate](#amazonec2-ec2_LaunchTemplate) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-capacity-reservation](#amazonec2-capacity-reservation)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_IsLaunchTemplateResource](#amazonec2-ec2_IsLaunchTemplateResource) <br /> [#amazonec2-ec2_LaunchTemplate](#amazonec2-ec2_LaunchTemplate)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-elastic-gpu](#amazonec2-elastic-gpu)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ElasticGpuType](#amazonec2-ec2_ElasticGpuType) <br /> [#amazonec2-ec2_IsLaunchTemplateResource](#amazonec2-ec2_IsLaunchTemplateResource) <br /> [#amazonec2-ec2_LaunchTemplate](#amazonec2-ec2_LaunchTemplate) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-elastic-inference](#amazonec2-elastic-inference)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-group](#amazonec2-group)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-key-pair](#amazonec2-key-pair)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_IsLaunchTemplateResource](#amazonec2-ec2_IsLaunchTemplateResource) <br /> [#amazonec2-ec2_KeyPairName](#amazonec2-ec2_KeyPairName) <br /> [#amazonec2-ec2_KeyPairType](#amazonec2-ec2_KeyPairType) <br /> [#amazonec2-ec2_LaunchTemplate](#amazonec2-ec2_LaunchTemplate) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-launch-template](#amazonec2-launch-template)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_IsLaunchTemplateResource](#amazonec2-ec2_IsLaunchTemplateResource) <br /> [#amazonec2-ec2_LaunchTemplate](#amazonec2-ec2_LaunchTemplate) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-license-configuration](#amazonec2-license-configuration)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-placement-group](#amazonec2-placement-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_IsLaunchTemplateResource](#amazonec2-ec2_IsLaunchTemplateResource) <br /> [#amazonec2-ec2_LaunchTemplate](#amazonec2-ec2_LaunchTemplate) <br /> [#amazonec2-ec2_PlacementGroupName](#amazonec2-ec2_PlacementGroupName) <br /> [#amazonec2-ec2_PlacementGroupStrategy](#amazonec2-ec2_PlacementGroupStrategy) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-secondary-subnet](#amazonec2-secondary-subnet)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-snapshot](#amazonec2-snapshot)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_IsLaunchTemplateResource](#amazonec2-ec2_IsLaunchTemplateResource) <br /> [#amazonec2-ec2_LaunchTemplate](#amazonec2-ec2_LaunchTemplate) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_ParentVolume](#amazonec2-ec2_ParentVolume) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SnapshotID](#amazonec2-ec2_SnapshotID) <br /> [#amazonec2-ec2_SnapshotTime](#amazonec2-ec2_SnapshotTime) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-volume](#amazonec2-volume)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_Encrypted](#amazonec2-ec2_Encrypted) <br /> [#amazonec2-ec2_IsLaunchTemplateResource](#amazonec2-ec2_IsLaunchTemplateResource) <br /> [#amazonec2-ec2_LaunchTemplate](#amazonec2-ec2_LaunchTemplate) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_ParentSnapshot](#amazonec2-ec2_ParentSnapshot) <br /> [#amazonec2-ec2_VolumeID](#amazonec2-ec2_VolumeID) <br /> [#amazonec2-ec2_VolumeInitializationRate](#amazonec2-ec2_VolumeInitializationRate) <br /> [#amazonec2-ec2_VolumeIops](#amazonec2-ec2_VolumeIops) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize) <br /> [#amazonec2-ec2_VolumeThroughput](#amazonec2-ec2_VolumeThroughput) <br /> [#amazonec2-ec2_VolumeType](#amazonec2-ec2_VolumeType)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 
  - **Description:**  **SCENARIO: ** EC2-Classic-EBS  / **Access level:**  / **Resource types (\*required):**  [#amazonec2-image](#amazonec2-image) <br /> [#amazonec2-instance](#amazonec2-instance) <br /> [#amazonec2-security-group](#amazonec2-security-group) <br /> [#amazonec2-volume](#amazonec2-volume) <br /> [#amazonec2-key-pair](#amazonec2-key-pair) <br /> [#amazonec2-placement-group](#amazonec2-placement-group) <br /> [#amazonec2-snapshot](#amazonec2-snapshot)  / **Condition keys:**  / **Dependent actions:** 
  - **Description:**  **SCENARIO: ** EC2-Classic-InstanceStore  / **Access level:**  / **Resource types (\*required):**  [#amazonec2-image](#amazonec2-image) <br /> [#amazonec2-instance](#amazonec2-instance) <br /> [#amazonec2-security-group](#amazonec2-security-group) <br /> [#amazonec2-key-pair](#amazonec2-key-pair) <br /> [#amazonec2-placement-group](#amazonec2-placement-group) <br /> [#amazonec2-snapshot](#amazonec2-snapshot)  / **Condition keys:**  / **Dependent actions:** 
  - **Description:**  **SCENARIO: ** EC2-VPC-EBS  / **Access level:**  / **Resource types (\*required):**  [#amazonec2-image](#amazonec2-image) <br /> [#amazonec2-instance](#amazonec2-instance) <br /> [#amazonec2-network-interface](#amazonec2-network-interface) <br /> [#amazonec2-security-group](#amazonec2-security-group) <br /> [#amazonec2-volume](#amazonec2-volume) <br /> [#amazonec2-key-pair](#amazonec2-key-pair) <br /> [#amazonec2-placement-group](#amazonec2-placement-group) <br /> [#amazonec2-snapshot](#amazonec2-snapshot)  / **Condition keys:**  / **Dependent actions:** 
  - **Description:**  **SCENARIO: ** EC2-VPC-EBS-Subnet  / **Access level:**  / **Resource types (\*required):**  [#amazonec2-image](#amazonec2-image) <br /> [#amazonec2-instance](#amazonec2-instance) <br /> [#amazonec2-network-interface](#amazonec2-network-interface) <br /> [#amazonec2-security-group](#amazonec2-security-group) <br /> [#amazonec2-subnet](#amazonec2-subnet) <br /> [#amazonec2-volume](#amazonec2-volume) <br /> [#amazonec2-key-pair](#amazonec2-key-pair) <br /> [#amazonec2-placement-group](#amazonec2-placement-group) <br /> [#amazonec2-snapshot](#amazonec2-snapshot)  / **Condition keys:**  / **Dependent actions:** 
  - **Description:**  **SCENARIO: ** EC2-VPC-InstanceStore  / **Access level:**  / **Resource types (\*required):**  [#amazonec2-image](#amazonec2-image) <br /> [#amazonec2-instance](#amazonec2-instance) <br /> [#amazonec2-network-interface](#amazonec2-network-interface) <br /> [#amazonec2-security-group](#amazonec2-security-group) <br /> [#amazonec2-key-pair](#amazonec2-key-pair) <br /> [#amazonec2-placement-group](#amazonec2-placement-group) <br /> [#amazonec2-snapshot](#amazonec2-snapshot)  / **Condition keys:**  / **Dependent actions:** 
  - **Description:**  **SCENARIO: ** EC2-VPC-InstanceStore-Subnet  / **Access level:**  / **Resource types (\*required):**  [#amazonec2-image](#amazonec2-image) <br /> [#amazonec2-instance](#amazonec2-instance) <br /> [#amazonec2-network-interface](#amazonec2-network-interface) <br /> [#amazonec2-security-group](#amazonec2-security-group) <br /> [#amazonec2-subnet](#amazonec2-subnet) <br /> [#amazonec2-key-pair](#amazonec2-key-pair) <br /> [#amazonec2-placement-group](#amazonec2-placement-group) <br /> [#amazonec2-snapshot](#amazonec2-snapshot)  / **Condition keys:**  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RunScheduledInstances.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RunScheduledInstances.html) **
  - **Description:** Grants permission to launch one or more Scheduled Instances
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_SearchLocalGatewayRoutes.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_SearchLocalGatewayRoutes.html) **
  - **Description:** Grants permission to search for routes in a local gateway route table
  - **Access level:** List
  - **Resource types (\*required):**  [#amazonec2-local-gateway-route-table](#amazonec2-local-gateway-route-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_SearchTransitGatewayMulticastGroups.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_SearchTransitGatewayMulticastGroups.html) **
  - **Description:** Grants permission to search for groups, sources, and members in a transit gateway multicast domain
  - **Access level:** List
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-multicast-domain](#amazonec2-transit-gateway-multicast-domain)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayMulticastDomainId](#amazonec2-ec2_transitGatewayMulticastDomainId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_SearchTransitGatewayRoutes.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_SearchTransitGatewayRoutes.html) **
  - **Description:** Grants permission to search for routes in a transit gateway route table
  - **Access level:** List
  - **Resource types (\*required):**  [#amazonec2-transit-gateway-route-table](#amazonec2-transit-gateway-route-table)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayRouteTableId](#amazonec2-ec2_transitGatewayRouteTableId)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_SendDiagnosticInterrupt.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_SendDiagnosticInterrupt.html) **
  - **Description:** Grants permission to send a diagnostic interrupt to an Amazon EC2 instance
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/fis/latest/userguide/fis-actions-reference.html#send-spot-instance-interruptions](https://docs.aws.amazon.com/fis/latest/userguide/fis-actions-reference.html#send-spot-instance-interruptions) [permission only]**
  - **Description:** Grants permission to interrupt a Spot Instance
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_StartDeclarativePoliciesReport.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_StartDeclarativePoliciesReport.html) **
  - **Description:** Grants permission to start a declarative policies report
  - **Access level:** Read
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_StartInstances.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_StartInstances.html) **
  - **Description:** Grants permission to start a stopped instance
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  [#amazonec2-license-configuration](#amazonec2-license-configuration)  / **Condition keys:**  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_StartNetworkInsightsAccessScopeAnalysis.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_StartNetworkInsightsAccessScopeAnalysis.html) **
  - **Description:** Grants permission to start a Network Access Scope analysis
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-network-insights-access-scope](#amazonec2-network-insights-access-scope)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-network-insights-access-scope-analysis](#amazonec2-network-insights-access-scope-analysis)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_StartNetworkInsightsAnalysis.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_StartNetworkInsightsAnalysis.html) **
  - **Description:** Grants permission to start analyzing a specified path
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-network-insights-analysis](#amazonec2-network-insights-analysis)  / **Condition keys:**  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys)  / **Dependent actions:**  ec2:CreateTags 
  - **Resource types (\*required):**  [#amazonec2-network-insights-path](#amazonec2-network-insights-path)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_StartVpcEndpointServicePrivateDnsVerification.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_StartVpcEndpointServicePrivateDnsVerification.html) **
  - **Description:** Grants permission to start the private DNS verification process for a VPC endpoint service
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-vpc-endpoint-service](#amazonec2-vpc-endpoint-service)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VpceMultiRegion](#amazonec2-ec2_VpceMultiRegion) <br /> [#amazonec2-ec2_VpceSupportedRegion](#amazonec2-ec2_VpceSupportedRegion)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_StopInstances.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_StopInstances.html) **
  - **Description:** Grants permission to stop an Amazon EBS-backed instance
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_TerminateClientVpnConnections.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_TerminateClientVpnConnections.html) **
  - **Description:** Grants permission to terminate active Client VPN endpoint connections
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-client-vpn-endpoint](#amazonec2-client-vpn-endpoint)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ClientRootCertificateChainArn](#amazonec2-ec2_ClientRootCertificateChainArn) <br /> [#amazonec2-ec2_CloudwatchLogGroupArn](#amazonec2-ec2_CloudwatchLogGroupArn) <br /> [#amazonec2-ec2_CloudwatchLogStreamArn](#amazonec2-ec2_CloudwatchLogStreamArn) <br /> [#amazonec2-ec2_DirectoryArn](#amazonec2-ec2_DirectoryArn) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SamlProviderArn](#amazonec2-ec2_SamlProviderArn) <br /> [#amazonec2-ec2_ServerCertificateArn](#amazonec2-ec2_ServerCertificateArn)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_TerminateInstances.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_TerminateInstances.html) **
  - **Description:** Grants permission to shut down one or more instances
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ProductCode](#amazonec2-ec2_ProductCode) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_UnassignIpv6Addresses.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_UnassignIpv6Addresses.html) **
  - **Description:** Grants permission to unassign one or more IPv6 addresses from a network interface
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-network-interface](#amazonec2-network-interface)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_NetworkInterfaceID](#amazonec2-ec2_NetworkInterfaceID) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Subnet](#amazonec2-ec2_Subnet) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_UnassignPrivateIpAddresses.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_UnassignPrivateIpAddresses.html) **
  - **Description:** Grants permission to unassign one or more secondary private IP addresses from a network interface
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-network-interface](#amazonec2-network-interface)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_NetworkInterfaceID](#amazonec2-ec2_NetworkInterfaceID) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Subnet](#amazonec2-ec2_Subnet) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_UnassignPrivateNatGatewayAddress.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_UnassignPrivateNatGatewayAddress.html) **
  - **Description:** Grants permission to unassign secondary private IPv4 addresses from a private NAT gateway
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-natgateway](#amazonec2-natgateway)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_UnlockSnapshot.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_UnlockSnapshot.html) **
  - **Description:** Grants permission to unlock a snapshot that is locked in governance mode or in compliance mode while still in the cooling-off period
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-snapshot](#amazonec2-snapshot)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Encrypted](#amazonec2-ec2_Encrypted) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_ParentVolume](#amazonec2-ec2_ParentVolume) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SnapshotCoolOffPeriod](#amazonec2-ec2_SnapshotCoolOffPeriod) <br /> [#amazonec2-ec2_SnapshotID](#amazonec2-ec2_SnapshotID) <br /> [#amazonec2-ec2_SnapshotLockDuration](#amazonec2-ec2_SnapshotLockDuration) <br /> [#amazonec2-ec2_SnapshotTime](#amazonec2-ec2_SnapshotTime) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_UnmonitorInstances.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_UnmonitorInstances.html) **
  - **Description:** Grants permission to disable detailed monitoring for a running instance
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-instance](#amazonec2-instance)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ProductCode](#amazonec2-ec2_ProductCode) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_UpdateCapacityManagerOrganizationsAccess.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_UpdateCapacityManagerOrganizationsAccess.html) **
  - **Description:** Grants permission to update the Organizations access setting for EC2 Capacity Manager
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_UpdateInterruptibleCapacityReservationAllocation.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_UpdateInterruptibleCapacityReservationAllocation.html) **
  - **Description:** Grants permission to update the number of instances allocated to an interruptible reservation, allowing you to add more capacity or reclaim capacity to your source Capacity Reservation
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-capacity-reservation](#amazonec2-capacity-reservation)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CreateDate](#amazonec2-ec2_CreateDate) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_EndDate](#amazonec2-ec2_EndDate) <br /> [#amazonec2-ec2_EndDateType](#amazonec2-ec2_EndDateType) <br /> [#amazonec2-ec2_InstanceCount](#amazonec2-ec2_InstanceCount) <br /> [#amazonec2-ec2_InstanceMatchCriteria](#amazonec2-ec2_InstanceMatchCriteria) <br /> [#amazonec2-ec2_InstancePlatform](#amazonec2-ec2_InstancePlatform) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_InterruptibleCapacityReservationId](#amazonec2-ec2_InterruptibleCapacityReservationId) <br /> [#amazonec2-ec2_InterruptionType](#amazonec2-ec2_InterruptionType) <br /> [#amazonec2-ec2_IsInterruptible](#amazonec2-ec2_IsInterruptible) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SourceCapacityReservationId](#amazonec2-ec2_SourceCapacityReservationId) <br /> [#amazonec2-ec2_TargetInstanceCount](#amazonec2-ec2_TargetInstanceCount) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_UpdateSecurityGroupRuleDescriptionsEgress.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_UpdateSecurityGroupRuleDescriptionsEgress.html) **
  - **Description:** Grants permission to update descriptions for one or more outbound rules in a VPC security group
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-security-group](#amazonec2-security-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SecurityGroupID](#amazonec2-ec2_SecurityGroupID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_UpdateSecurityGroupRuleDescriptionsIngress.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_UpdateSecurityGroupRuleDescriptionsIngress.html) **
  - **Description:** Grants permission to update descriptions for one or more inbound rules in a security group
  - **Access level:** Write
  - **Resource types (\*required):**  [#amazonec2-security-group](#amazonec2-security-group)  / **Condition keys:**  [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SecurityGroupID](#amazonec2-ec2_SecurityGroupID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  / **Dependent actions:** 
  - **Resource types (\*required):**  / **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  / **Dependent actions:** 

- **  [https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_WithdrawByoipCidr.html](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_WithdrawByoipCidr.html) **
  - **Description:** Grants permission to stop advertising an address range that was provisioned for use in AWS through bring your own IP addresses (BYOIP)
  - **Access level:** Write
  - **Resource types (\*required):** 
  - **Condition keys:**  [#amazonec2-ec2_Region](#amazonec2-ec2_Region) 
  - **Dependent actions:** 



## Resource types defined by Amazon EC2
<a name="amazonec2-resources-for-iam-policies"></a>

The following resource types are defined by this service and can be used in the `Resource` element of IAM permission policy statements. Each action in the [Actions table](#amazonec2-actions-as-permissions) identifies the resource types that can be specified with that action. A resource type can also define which condition keys you can include in a policy. These keys are displayed in the last column of the table. For details about the columns in the following table, see [Resource types table](reference_policies_actions-resources-contextkeys.html#resources_table).


****  

| Resource types | ARN | Condition keys | 
| --- | --- | --- | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/elastic-ip-addresses-eip.html](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/elastic-ip-addresses-eip.html)  |  arn:${Partition}:ec2:${Region}:${Account}:elastic-ip/${AllocationId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_AllocationId](#amazonec2-ec2_AllocationId) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Domain](#amazonec2-ec2_Domain) <br /> [#amazonec2-ec2_PublicIpAddress](#amazonec2-ec2_PublicIpAddress) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format)  |  arn:${Partition}:ec2:${Region}:${Account}:capacity-block/${CapacityBlockId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format)  |  arn:${Partition}:ec2:${Region}:${Account}:capacity-manager-data-export/${CapacityManagerDataExportId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format)  |  arn:${Partition}:ec2:${Region}:${Account}:capacity-reservation-fleet/${CapacityReservationFleetId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-capacity-reservations.html](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-capacity-reservations.html)  |  arn:${Partition}:ec2:${Region}:${Account}:capacity-reservation/${CapacityReservationId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CapacityReservationFleet](#amazonec2-ec2_CapacityReservationFleet) <br /> [#amazonec2-ec2_CommitmentDuration](#amazonec2-ec2_CommitmentDuration) <br /> [#amazonec2-ec2_CreateDate](#amazonec2-ec2_CreateDate) <br /> [#amazonec2-ec2_DestinationCapacityReservationId](#amazonec2-ec2_DestinationCapacityReservationId) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_EndDate](#amazonec2-ec2_EndDate) <br /> [#amazonec2-ec2_EndDateType](#amazonec2-ec2_EndDateType) <br /> [#amazonec2-ec2_EphemeralStorage](#amazonec2-ec2_EphemeralStorage) <br /> [#amazonec2-ec2_InstanceCount](#amazonec2-ec2_InstanceCount) <br /> [#amazonec2-ec2_InstanceMatchCriteria](#amazonec2-ec2_InstanceMatchCriteria) <br /> [#amazonec2-ec2_InstancePlatform](#amazonec2-ec2_InstancePlatform) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_InterruptibleCapacityReservationId](#amazonec2-ec2_InterruptibleCapacityReservationId) <br /> [#amazonec2-ec2_InterruptionType](#amazonec2-ec2_InterruptionType) <br /> [#amazonec2-ec2_IsInterruptible](#amazonec2-ec2_IsInterruptible) <br /> [#amazonec2-ec2_IsLaunchTemplateResource](#amazonec2-ec2_IsLaunchTemplateResource) <br /> [#amazonec2-ec2_LaunchTemplate](#amazonec2-ec2_LaunchTemplate) <br /> [#amazonec2-ec2_OutpostArn](#amazonec2-ec2_OutpostArn) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SourceCapacityReservationId](#amazonec2-ec2_SourceCapacityReservationId) <br /> [#amazonec2-ec2_TargetInstanceCount](#amazonec2-ec2_TargetInstanceCount) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  | 
|   [https://docs.aws.amazon.com/vpc/latest/userguide/Carrier_Gateway.html](https://docs.aws.amazon.com/vpc/latest/userguide/Carrier_Gateway.html)  |  arn:${Partition}:ec2:${Region}:${Account}:carrier-gateway/${CarrierGatewayId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  | 
|   [https://docs.aws.amazon.com/acm/latest/userguide/authen-overview.html#acm-resources-operations](https://docs.aws.amazon.com/acm/latest/userguide/authen-overview.html#acm-resources-operations)  |  arn:${Partition}:acm:${Region}:${Account}:certificate/${CertificateId}  |  | 
|   [https://docs.aws.amazon.com/vpn/latest/clientvpn-admin/what-is.html](https://docs.aws.amazon.com/vpn/latest/clientvpn-admin/what-is.html)  |  arn:${Partition}:ec2:${Region}:${Account}:client-vpn-endpoint/${ClientVpnEndpointId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ClientRootCertificateChainArn](#amazonec2-ec2_ClientRootCertificateChainArn) <br /> [#amazonec2-ec2_CloudwatchLogGroupArn](#amazonec2-ec2_CloudwatchLogGroupArn) <br /> [#amazonec2-ec2_CloudwatchLogStreamArn](#amazonec2-ec2_CloudwatchLogStreamArn) <br /> [#amazonec2-ec2_DirectoryArn](#amazonec2-ec2_DirectoryArn) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SamlProviderArn](#amazonec2-ec2_SamlProviderArn) <br /> [#amazonec2-ec2_ServerCertificateArn](#amazonec2-ec2_ServerCertificateArn)  | 
|   [https://docs.aws.amazon.com/vpn/latest/s2svpn/VPC_VPN.html](https://docs.aws.amazon.com/vpn/latest/s2svpn/VPC_VPN.html)  |  arn:${Partition}:ec2:${Region}:${Account}:customer-gateway/${CustomerGatewayId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format)  |  arn:${Partition}:ec2:${Region}:${Account}:declarative-policies-report/${DeclarativePoliciesReportId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/dedicated-hosts-overview.html](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/dedicated-hosts-overview.html)  |  arn:${Partition}:ec2:${Region}:${Account}:dedicated-host/${DedicatedHostId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_AutoPlacement](#amazonec2-ec2_AutoPlacement) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_HostRecovery](#amazonec2-ec2_HostRecovery) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_IsLaunchTemplateResource](#amazonec2-ec2_IsLaunchTemplateResource) <br /> [#amazonec2-ec2_LaunchTemplate](#amazonec2-ec2_LaunchTemplate) <br /> [#amazonec2-ec2_Quantity](#amazonec2-ec2_Quantity) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/vpc/latest/userguide/VPC_DHCP_Options.html](https://docs.aws.amazon.com/vpc/latest/userguide/VPC_DHCP_Options.html)  |  arn:${Partition}:ec2:${Region}:${Account}:dhcp-options/${DhcpOptionsId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_DhcpOptionsID](#amazonec2-ec2_DhcpOptionsID) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/vpc/latest/userguide/egress-only-internet-gateway.html](https://docs.aws.amazon.com/vpc/latest/userguide/egress-only-internet-gateway.html)  |  arn:${Partition}:ec2:${Region}:${Account}:egress-only-internet-gateway/${EgressOnlyInternetGatewayId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/WindowsGuide/elastic-gpus.html](https://docs.aws.amazon.com/AWSEC2/latest/WindowsGuide/elastic-gpus.html)  |  arn:${Partition}:ec2:${Region}:${Account}:elastic-gpu/${ElasticGpuId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_ElasticGpuType](#amazonec2-ec2_ElasticGpuType) <br /> [#amazonec2-ec2_IsLaunchTemplateResource](#amazonec2-ec2_IsLaunchTemplateResource) <br /> [#amazonec2-ec2_LaunchTemplate](#amazonec2-ec2_LaunchTemplate) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/elastic-inference/latest/developerguide/what-is-ei.html](https://docs.aws.amazon.com/elastic-inference/latest/developerguide/what-is-ei.html)  |  arn:${Partition}:elastic-inference:${Region}:${Account}:elastic-inference-accelerator/${AcceleratorId}  |  | 
|   [https://docs.aws.amazon.com/vm-import/latest/userguide/vmimport-image-import.html#export-vm-image](https://docs.aws.amazon.com/vm-import/latest/userguide/vmimport-image-import.html#export-vm-image)  |  arn:${Partition}:ec2:${Region}:${Account}:export-image-task/${ExportImageTaskId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/vm-import/latest/userguide/vmexport.html](https://docs.aws.amazon.com/vm-import/latest/userguide/vmexport.html)  |  arn:${Partition}:ec2:${Region}:${Account}:export-instance-task/${ExportTaskId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-fleet.html](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-fleet.html)  |  arn:${Partition}:ec2:${Region}:${Account}:fleet/${FleetId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format)  |  arn:${Partition}:ec2:${Region}:${Account}:fpga-image/${FpgaImageId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_Public](#amazonec2-ec2_Public) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format)  |  arn:${Partition}:ec2:${Region}:${Account}:host-reservation/${HostReservationId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/AMIs.html](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/AMIs.html)  |  arn:${Partition}:ec2:${Region}::image/${ImageId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_ImageID](#amazonec2-ec2_ImageID) <br /> [#amazonec2-ec2_ImageType](#amazonec2-ec2_ImageType) <br /> [#amazonec2-ec2_IsLaunchTemplateResource](#amazonec2-ec2_IsLaunchTemplateResource) <br /> [#amazonec2-ec2_LaunchTemplate](#amazonec2-ec2_LaunchTemplate) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_Public](#amazonec2-ec2_Public) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType)  | 
|   [https://docs.aws.amazon.com/vm-import/latest/userguide/image-usage-report.html](https://docs.aws.amazon.com/vm-import/latest/userguide/image-usage-report.html)  |  arn:${Partition}:ec2:${Region}:${Account}:image-usage-report/${ImageUsageReportId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/vm-import/latest/userguide/vmimport-image-import.html#import-vm-image](https://docs.aws.amazon.com/vm-import/latest/userguide/vmimport-image-import.html#import-vm-image)  |  arn:${Partition}:ec2:${Region}:${Account}:import-image-task/${ImportImageTaskId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/vm-import/latest/userguide/vmimport-import-snapshot.html](https://docs.aws.amazon.com/vm-import/latest/userguide/vmimport-import-snapshot.html)  |  arn:${Partition}:ec2:${Region}:${Account}:import-snapshot-task/${ImportSnapshotTaskId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format)  |  arn:${Partition}:ec2:${Region}:${Account}:instance-connect-endpoint/${InstanceConnectEndpointId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format)  |  arn:${Partition}:ec2:${Region}:${Account}:instance-event-window/${InstanceEventWindowId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Instances.html](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Instances.html)  |  arn:${Partition}:ec2:${Region}:${Account}:instance/${InstanceId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_CpuOptionsAmdSevSnp](#amazonec2-ec2_CpuOptionsAmdSevSnp) <br /> [#amazonec2-ec2_EbsOptimized](#amazonec2-ec2_EbsOptimized) <br /> [#amazonec2-ec2_InstanceAutoRecovery](#amazonec2-ec2_InstanceAutoRecovery) <br /> [#amazonec2-ec2_InstanceBandwidthWeighting](#amazonec2-ec2_InstanceBandwidthWeighting) <br /> [#amazonec2-ec2_InstanceID](#amazonec2-ec2_InstanceID) <br /> [#amazonec2-ec2_InstanceMarketType](#amazonec2-ec2_InstanceMarketType) <br /> [#amazonec2-ec2_InstanceMetadataTags](#amazonec2-ec2_InstanceMetadataTags) <br /> [#amazonec2-ec2_InstanceProfile](#amazonec2-ec2_InstanceProfile) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_IsLaunchTemplateResource](#amazonec2-ec2_IsLaunchTemplateResource) <br /> [#amazonec2-ec2_LaunchTemplate](#amazonec2-ec2_LaunchTemplate) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_MetadataHttpEndpoint](#amazonec2-ec2_MetadataHttpEndpoint) <br /> [#amazonec2-ec2_MetadataHttpPutResponseHopLimit](#amazonec2-ec2_MetadataHttpPutResponseHopLimit) <br /> [#amazonec2-ec2_MetadataHttpTokens](#amazonec2-ec2_MetadataHttpTokens) <br /> [#amazonec2-ec2_NewInstanceProfile](#amazonec2-ec2_NewInstanceProfile) <br /> [#amazonec2-ec2_PlacementGroup](#amazonec2-ec2_PlacementGroup) <br /> [#amazonec2-ec2_ProductCode](#amazonec2-ec2_ProductCode) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RootDeviceType](#amazonec2-ec2_RootDeviceType) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  | 
|   [https://docs.aws.amazon.com/vpc/latest/userguide/VPC_Internet_Gateway.html](https://docs.aws.amazon.com/vpc/latest/userguide/VPC_Internet_Gateway.html)  |  arn:${Partition}:ec2:${Region}:${Account}:internet-gateway/${InternetGatewayId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_InternetGatewayID](#amazonec2-ec2_InternetGatewayID) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format)  |  arn:${Partition}:ec2::${Account}:ipam-external-resource-verification-token/${IpamExternalResourceVerificationTokenId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format)  |  arn:${Partition}:ec2::${Account}:ipam/${IpamId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format)  |  arn:${Partition}:ec2::${Account}:ipam-policy/${IpamPolicyId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format)  |  arn:${Partition}:ec2::${Account}:ipam-pool/${IpamPoolId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format)  |  arn:${Partition}:ec2::${Account}:ipam-prefix-list-resolver/${IpamPrefixListResolverId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format)  |  arn:${Partition}:ec2::${Account}:ipam-prefix-list-resolver-target/${IpamPrefixListResolverTargetId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format)  |  arn:${Partition}:ec2::${Account}:ipam-resource-discovery-association/${IpamResourceDiscoveryAssociationId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format)  |  arn:${Partition}:ec2::${Account}:ipam-resource-discovery/${IpamResourceDiscoveryId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format)  |  arn:${Partition}:ec2::${Account}:ipam-scope/${IpamScopeId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format)  |  arn:${Partition}:ec2:${Region}:${Account}:coip-pool/${Ipv4PoolCoipId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-instance-addressing.html#ip-addressing-eips](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-instance-addressing.html#ip-addressing-eips)  |  arn:${Partition}:ec2:${Region}:${Account}:ipv4pool-ec2/${Ipv4PoolEc2Id}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-instance-addressing.html#ipv6-addressing](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-instance-addressing.html#ipv6-addressing)  |  arn:${Partition}:ec2:${Region}:${Account}:ipv6pool-ec2/${Ipv6PoolEc2Id}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-key-pairs.html](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-key-pairs.html)  |  arn:${Partition}:ec2:${Region}:${Account}:key-pair/${KeyPairName}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_IsLaunchTemplateResource](#amazonec2-ec2_IsLaunchTemplateResource) <br /> [#amazonec2-ec2_KeyPairName](#amazonec2-ec2_KeyPairName) <br /> [#amazonec2-ec2_KeyPairType](#amazonec2-ec2_KeyPairType) <br /> [#amazonec2-ec2_LaunchTemplate](#amazonec2-ec2_LaunchTemplate) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-launch-templates.html](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-launch-templates.html)  |  arn:${Partition}:ec2:${Region}:${Account}:launch-template/${LaunchTemplateId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_IsLaunchTemplateResource](#amazonec2-ec2_IsLaunchTemplateResource) <br /> [#amazonec2-ec2_LaunchTemplate](#amazonec2-ec2_LaunchTemplate) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/license-manager/latest/userguide/create-license-configuration.html](https://docs.aws.amazon.com/license-manager/latest/userguide/create-license-configuration.html)  |  arn:${Partition}:license-manager:${Region}:${Account}:license-configuration:${LicenseConfigurationId}  |  | 
|   [https://docs.aws.amazon.com/outposts/latest/userguide/outposts-local-gateways.html#lgw](https://docs.aws.amazon.com/outposts/latest/userguide/outposts-local-gateways.html#lgw)  |  arn:${Partition}:ec2:${Region}:${Account}:local-gateway/${LocalGatewayId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/outposts/latest/userguide/outposts-local-gateways.html](https://docs.aws.amazon.com/outposts/latest/userguide/outposts-local-gateways.html)  |  arn:${Partition}:ec2:${Region}:${Account}:local-gateway-route-table-virtual-interface-group-association/${LocalGatewayRouteTableVirtualInterfaceGroupAssociationId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/outposts/latest/userguide/outposts-local-gateways.html#vpc-associations](https://docs.aws.amazon.com/outposts/latest/userguide/outposts-local-gateways.html#vpc-associations)  |  arn:${Partition}:ec2:${Region}:${Account}:local-gateway-route-table-vpc-association/${LocalGatewayRouteTableVpcAssociationId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/outposts/latest/userguide/outposts-local-gateways.html#route-tables](https://docs.aws.amazon.com/outposts/latest/userguide/outposts-local-gateways.html#route-tables)  |  arn:${Partition}:ec2:${Region}:${Account}:local-gateway-route-table/${LocalGatewayRoutetableId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/outposts/latest/userguide/outposts-local-gateways.html](https://docs.aws.amazon.com/outposts/latest/userguide/outposts-local-gateways.html)  |  arn:${Partition}:ec2:${Region}:${Account}:local-gateway-virtual-interface-group/${LocalGatewayVirtualInterfaceGroupId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/outposts/latest/userguide/outposts-local-gateways.html](https://docs.aws.amazon.com/outposts/latest/userguide/outposts-local-gateways.html)  |  arn:${Partition}:ec2:${Region}:${Account}:local-gateway-virtual-interface/${LocalGatewayVirtualInterfaceId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/mac-modification-task.html](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/mac-modification-task.html)  |  arn:${Partition}:ec2:${Region}:${Account}:mac-modification-task/${MacModificationTaskId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/vpc/latest/userguide/vpc-nat-gateway.html](https://docs.aws.amazon.com/vpc/latest/userguide/vpc-nat-gateway.html)  |  arn:${Partition}:ec2:${Region}:${Account}:natgateway/${NatGatewayId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  | 
|   [https://docs.aws.amazon.com/vpc/latest/userguide/vpc-network-acls.html](https://docs.aws.amazon.com/vpc/latest/userguide/vpc-network-acls.html)  |  arn:${Partition}:ec2:${Region}:${Account}:network-acl/${NaclId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_NetworkAclID](#amazonec2-ec2_NetworkAclID) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format)  |  arn:${Partition}:ec2:${Region}:${Account}:network-insights-access-scope-analysis/${NetworkInsightsAccessScopeAnalysisId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format)  |  arn:${Partition}:ec2:${Region}:${Account}:network-insights-access-scope/${NetworkInsightsAccessScopeId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format)  |  arn:${Partition}:ec2:${Region}:${Account}:network-insights-analysis/${NetworkInsightsAnalysisId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format)  |  arn:${Partition}:ec2:${Region}:${Account}:network-insights-path/${NetworkInsightsPathId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-eni.html](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-eni.html)  |  arn:${Partition}:ec2:${Region}:${Account}:network-interface/${NetworkInterfaceId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_AssociatePublicIpAddress](#amazonec2-ec2_AssociatePublicIpAddress) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_AuthorizedService](#amazonec2-ec2_AuthorizedService) <br /> [#amazonec2-ec2_AuthorizedUser](#amazonec2-ec2_AuthorizedUser) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_IsLaunchTemplateResource](#amazonec2-ec2_IsLaunchTemplateResource) <br /> [#amazonec2-ec2_LaunchTemplate](#amazonec2-ec2_LaunchTemplate) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_NetworkInterfaceID](#amazonec2-ec2_NetworkInterfaceID) <br /> [#amazonec2-ec2_Permission](#amazonec2-ec2_Permission) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Subnet](#amazonec2-ec2_Subnet) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  | 
|   [outposts-lag.html#outpostlag](outposts-lag.html#outpostlag)  |  arn:${Partition}:ec2:${Region}:${Account}:outpost-lag/${OutpostLagId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/placement-groups.html](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/placement-groups.html)  |  arn:${Partition}:ec2:${Region}:${Account}:placement-group/${PlacementGroupName}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_IsLaunchTemplateResource](#amazonec2-ec2_IsLaunchTemplateResource) <br /> [#amazonec2-ec2_LaunchTemplate](#amazonec2-ec2_LaunchTemplate) <br /> [#amazonec2-ec2_PlacementGroupName](#amazonec2-ec2_PlacementGroupName) <br /> [#amazonec2-ec2_PlacementGroupStrategy](#amazonec2-ec2_PlacementGroupStrategy) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/vpc/latest/userguide/managed-prefix-lists.html](https://docs.aws.amazon.com/vpc/latest/userguide/managed-prefix-lists.html)  |  arn:${Partition}:ec2:${Region}:${Account}:prefix-list/${PrefixListId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_IpamPrefixListResolverTargetId](#amazonec2-ec2_IpamPrefixListResolverTargetId) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/replace-root.html](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/replace-root.html)  |  arn:${Partition}:ec2:${Region}:${Account}:replace-root-volume-task/${ReplaceRootVolumeTaskId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-reserved-instances.html](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-reserved-instances.html)  |  arn:${Partition}:ec2:${Region}:${Account}:reserved-instances/${ReservationId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_InstanceType](#amazonec2-ec2_InstanceType) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ReservedInstancesOfferingType](#amazonec2-ec2_ReservedInstancesOfferingType) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy)  | 
|   [https://docs.aws.amazon.com/ARG/latest/userguide/resource-groups.html](https://docs.aws.amazon.com/ARG/latest/userguide/resource-groups.html)  |  arn:${Partition}:resource-groups:${Region}:${Account}:group/${GroupName}  |  | 
|   [https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles.html](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles.html)  |  arn:${Partition}:iam::${Account}:role/${RoleNameWithPath}  |  | 
|   [https://docs.aws.amazon.com/vpc/latest/userguide/route-server-terms.html](https://docs.aws.amazon.com/vpc/latest/userguide/route-server-terms.html)  |  arn:${Partition}:ec2:${Region}:${Account}:route-server-endpoint/${RouteServerEndpointId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/vpc/latest/userguide/route-server-terms.html](https://docs.aws.amazon.com/vpc/latest/userguide/route-server-terms.html)  |  arn:${Partition}:ec2:${Region}:${Account}:route-server/${RouteServerId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/vpc/latest/userguide/route-server-terms.html](https://docs.aws.amazon.com/vpc/latest/userguide/route-server-terms.html)  |  arn:${Partition}:ec2:${Region}:${Account}:route-server-peer/${RouteServerPeerId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/vpc/latest/userguide/VPC_Route_Tables.html](https://docs.aws.amazon.com/vpc/latest/userguide/VPC_Route_Tables.html)  |  arn:${Partition}:ec2:${Region}:${Account}:route-table/${RouteTableId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RouteTableID](#amazonec2-ec2_RouteTableID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format)  |  arn:${Partition}:ec2:${Region}:${Account}:secondary-interface/${SecondaryInterfaceId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_IsLaunchTemplateResource](#amazonec2-ec2_IsLaunchTemplateResource) <br /> [#amazonec2-ec2_LaunchTemplate](#amazonec2-ec2_LaunchTemplate) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format)  |  arn:${Partition}:ec2:${Region}:${Account}:secondary-network/${SecondaryNetworkId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format)  |  arn:${Partition}:ec2:${Region}:${Account}:secondary-subnet/${SecondarySubnetId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-security-groups.html](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-security-groups.html)  |  arn:${Partition}:ec2:${Region}:${Account}:security-group/${SecurityGroupId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_IsLaunchTemplateResource](#amazonec2-ec2_IsLaunchTemplateResource) <br /> [#amazonec2-ec2_LaunchTemplate](#amazonec2-ec2_LaunchTemplate) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SecurityGroupID](#amazonec2-ec2_SecurityGroupID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format)  |  arn:${Partition}:ec2:${Region}:${Account}:security-group-rule/${SecurityGroupRuleId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/ebs/latest/userguide/ebs-snapshots.html](https://docs.aws.amazon.com/ebs/latest/userguide/ebs-snapshots.html)  |  arn:${Partition}:ec2:${Region}::snapshot/${SnapshotId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Add_group](#amazonec2-ec2_Add_group) <br /> [#amazonec2-ec2_Add_userId](#amazonec2-ec2_Add_userId) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_Encrypted](#amazonec2-ec2_Encrypted) <br /> [#amazonec2-ec2_IsLaunchTemplateResource](#amazonec2-ec2_IsLaunchTemplateResource) <br /> [#amazonec2-ec2_LaunchTemplate](#amazonec2-ec2_LaunchTemplate) <br /> [#amazonec2-ec2_Location](#amazonec2-ec2_Location) <br /> [#amazonec2-ec2_OutpostArn](#amazonec2-ec2_OutpostArn) <br /> [#amazonec2-ec2_Owner](#amazonec2-ec2_Owner) <br /> [#amazonec2-ec2_ParentSnapshot](#amazonec2-ec2_ParentSnapshot) <br /> [#amazonec2-ec2_ParentVolume](#amazonec2-ec2_ParentVolume) <br /> [#amazonec2-ec2_ProductCode](#amazonec2-ec2_ProductCode) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_Remove_group](#amazonec2-ec2_Remove_group) <br /> [#amazonec2-ec2_Remove_userId](#amazonec2-ec2_Remove_userId) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SnapshotCoolOffPeriod](#amazonec2-ec2_SnapshotCoolOffPeriod) <br /> [#amazonec2-ec2_SnapshotID](#amazonec2-ec2_SnapshotID) <br /> [#amazonec2-ec2_SnapshotLockDuration](#amazonec2-ec2_SnapshotLockDuration) <br /> [#amazonec2-ec2_SnapshotTime](#amazonec2-ec2_SnapshotTime) <br /> [#amazonec2-ec2_SourceAvailabilityZone](#amazonec2-ec2_SourceAvailabilityZone) <br /> [#amazonec2-ec2_SourceOutpostArn](#amazonec2-ec2_SourceOutpostArn) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format)  |  arn:${Partition}:ec2:${Region}:${Account}:spot-fleet-request/${SpotFleetRequestId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-spot-instances.html](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-spot-instances.html)  |  arn:${Partition}:ec2:${Region}:${Account}:spot-instances-request/${SpotInstanceRequestId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/vpc/latest/userguide/subnet-cidr-reservation.html](https://docs.aws.amazon.com/vpc/latest/userguide/subnet-cidr-reservation.html)  |  arn:${Partition}:ec2:${Region}:${Account}:subnet-cidr-reservation/${SubnetCidrReservationId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/vpc/latest/userguide/VPC_Subnets.html](https://docs.aws.amazon.com/vpc/latest/userguide/VPC_Subnets.html)  |  arn:${Partition}:ec2:${Region}:${Account}:subnet/${SubnetId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_Ipv4IpamPoolId](#amazonec2-ec2_Ipv4IpamPoolId) <br /> [#amazonec2-ec2_Ipv6IpamPoolId](#amazonec2-ec2_Ipv6IpamPoolId) <br /> [#amazonec2-ec2_IsLaunchTemplateResource](#amazonec2-ec2_IsLaunchTemplateResource) <br /> [#amazonec2-ec2_LaunchTemplate](#amazonec2-ec2_LaunchTemplate) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_SubnetID](#amazonec2-ec2_SubnetID) <br /> [#amazonec2-ec2_Vpc](#amazonec2-ec2_Vpc)  | 
|   [https://docs.aws.amazon.com/vpc/latest/mirroring/traffic-mirroring-filter.html](https://docs.aws.amazon.com/vpc/latest/mirroring/traffic-mirroring-filter.html)  |  arn:${Partition}:ec2:${Region}:${Account}:traffic-mirror-filter/${TrafficMirrorFilterId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/vpc/latest/mirroring/traffic-mirroring-filter.html](https://docs.aws.amazon.com/vpc/latest/mirroring/traffic-mirroring-filter.html)  |  arn:${Partition}:ec2:${Region}:${Account}:traffic-mirror-filter-rule/${TrafficMirrorFilterRuleId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/vpc/latest/mirroring/traffic-mirroring-session.html](https://docs.aws.amazon.com/vpc/latest/mirroring/traffic-mirroring-session.html)  |  arn:${Partition}:ec2:${Region}:${Account}:traffic-mirror-session/${TrafficMirrorSessionId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/vpc/latest/mirroring/traffic-mirroring-target.html](https://docs.aws.amazon.com/vpc/latest/mirroring/traffic-mirroring-target.html)  |  arn:${Partition}:ec2:${Region}:${Account}:traffic-mirror-target/${TrafficMirrorTargetId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/vpc/latest/tgw/how-transit-gateways-work.html](https://docs.aws.amazon.com/vpc/latest/tgw/how-transit-gateways-work.html)  |  arn:${Partition}:ec2:${Region}:${Account}:transit-gateway-attachment/${TransitGatewayAttachmentId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayAttachmentId](#amazonec2-ec2_transitGatewayAttachmentId)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format)  |  arn:${Partition}:ec2:${Region}:${Account}:transit-gateway-connect-peer/${TransitGatewayConnectPeerId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayConnectPeerId](#amazonec2-ec2_transitGatewayConnectPeerId)  | 
|   [https://docs.aws.amazon.com/vpc/latest/tgw/how-transit-gateways-work.html](https://docs.aws.amazon.com/vpc/latest/tgw/how-transit-gateways-work.html)  |  arn:${Partition}:ec2:${Region}:${Account}:transit-gateway/${TransitGatewayId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayId](#amazonec2-ec2_transitGatewayId)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format)  |  arn:${Partition}:ec2:${Region}:${Account}:transit-gateway-metering-policy/${TransitGatewayMeteringPolicyId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayMeteringPolicyId](#amazonec2-ec2_transitGatewayMeteringPolicyId)  | 
|   [https://docs.aws.amazon.com/vpc/latest/tgw/tgw-multicast-overview.html](https://docs.aws.amazon.com/vpc/latest/tgw/tgw-multicast-overview.html)  |  arn:${Partition}:ec2:${Region}:${Account}:transit-gateway-multicast-domain/${TransitGatewayMulticastDomainId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayMulticastDomainId](#amazonec2-ec2_transitGatewayMulticastDomainId)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format)  |  arn:${Partition}:ec2:${Region}:${Account}:transit-gateway-policy-table/${TransitGatewayPolicyTableId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayPolicyTableId](#amazonec2-ec2_transitGatewayPolicyTableId)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format)  |  arn:${Partition}:ec2:${Region}:${Account}:transit-gateway-route-table-announcement/${TransitGatewayRouteTableAnnouncementId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayRouteTableAnnouncementId](#amazonec2-ec2_transitGatewayRouteTableAnnouncementId)  | 
|   [https://docs.aws.amazon.com/vpc/latest/tgw/how-transit-gateways-work.html](https://docs.aws.amazon.com/vpc/latest/tgw/how-transit-gateways-work.html)  |  arn:${Partition}:ec2:${Region}:${Account}:transit-gateway-route-table/${TransitGatewayRouteTableId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_transitGatewayRouteTableId](#amazonec2-ec2_transitGatewayRouteTableId)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format)  |  arn:${Partition}:ec2:${Region}:${Account}:verified-access-endpoint/${VerifiedAccessEndpointId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format)  |  arn:${Partition}:ec2:${Region}:${Account}:verified-access-endpoint-target/${VerifiedAccessEndpointTargetId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format)  |  arn:${Partition}:ec2:${Region}:${Account}:verified-access-group/${VerifiedAccessGroupId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format)  |  arn:${Partition}:ec2:${Region}:${Account}:verified-access-instance/${VerifiedAccessInstanceId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format)  |  arn:${Partition}:ec2:${Region}:${Account}:verified-access-policy/${VerifiedAccessPolicyId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#EC2_ARN_Format)  |  arn:${Partition}:ec2:${Region}:${Account}:verified-access-trust-provider/${VerifiedAccessTrustProviderId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/ebs/latest/userguide/ebs-volumes.html](https://docs.aws.amazon.com/ebs/latest/userguide/ebs-volumes.html)  |  arn:${Partition}:ec2:${Region}:${Account}:volume/${VolumeId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_AvailabilityZone](#amazonec2-ec2_AvailabilityZone) <br /> [#amazonec2-ec2_AvailabilityZoneId](#amazonec2-ec2_AvailabilityZoneId) <br /> [#amazonec2-ec2_Encrypted](#amazonec2-ec2_Encrypted) <br /> [#amazonec2-ec2_IsLaunchTemplateResource](#amazonec2-ec2_IsLaunchTemplateResource) <br /> [#amazonec2-ec2_KmsKeyId](#amazonec2-ec2_KmsKeyId) <br /> [#amazonec2-ec2_LaunchTemplate](#amazonec2-ec2_LaunchTemplate) <br /> [#amazonec2-ec2_ManagedResourceOperator](#amazonec2-ec2_ManagedResourceOperator) <br /> [#amazonec2-ec2_ParentSnapshot](#amazonec2-ec2_ParentSnapshot) <br /> [#amazonec2-ec2_ParentVolume](#amazonec2-ec2_ParentVolume) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VolumeID](#amazonec2-ec2_VolumeID) <br /> [#amazonec2-ec2_VolumeInitializationRate](#amazonec2-ec2_VolumeInitializationRate) <br /> [#amazonec2-ec2_VolumeIops](#amazonec2-ec2_VolumeIops) <br /> [#amazonec2-ec2_VolumeSize](#amazonec2-ec2_VolumeSize) <br /> [#amazonec2-ec2_VolumeThroughput](#amazonec2-ec2_VolumeThroughput) <br /> [#amazonec2-ec2_VolumeType](#amazonec2-ec2_VolumeType)  | 
|   [https://docs.aws.amazon.com/vpc/latest/userguide/vpc-block-public-access.html](https://docs.aws.amazon.com/vpc/latest/userguide/vpc-block-public-access.html)  |  arn:${Partition}:ec2:${Region}:${Account}:vpc-block-public-access-exclusion/${VpcBlockPublicAccessExclusionId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/vpc/latest/userguide/vpc-encryption-control.html](https://docs.aws.amazon.com/vpc/latest/userguide/vpc-encryption-control.html)  |  arn:${Partition}:ec2:${Region}:${Account}:vpc-encryption-control/${VpcEncryptionControlId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/vpc/latest/userguide/endpoint-services-overview.html](https://docs.aws.amazon.com/vpc/latest/userguide/endpoint-services-overview.html)  |  arn:${Partition}:ec2:${Region}:${Account}:vpc-endpoint-connection/${VpcEndpointConnectionId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/vpc/latest/userguide/endpoint-services-overview.html](https://docs.aws.amazon.com/vpc/latest/userguide/endpoint-services-overview.html)  |  arn:${Partition}:ec2:${Region}:${Account}:vpc-endpoint/${VpcEndpointId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VpceMultiRegion](#amazonec2-ec2_VpceMultiRegion) <br /> [#amazonec2-ec2_VpcePrivateDnsPreference](#amazonec2-ec2_VpcePrivateDnsPreference) <br /> [#amazonec2-ec2_VpcePrivateDnsSpecifiedDomains](#amazonec2-ec2_VpcePrivateDnsSpecifiedDomains) <br /> [#amazonec2-ec2_VpceServiceName](#amazonec2-ec2_VpceServiceName) <br /> [#amazonec2-ec2_VpceServiceOwner](#amazonec2-ec2_VpceServiceOwner) <br /> [#amazonec2-ec2_VpceServiceRegion](#amazonec2-ec2_VpceServiceRegion)  | 
|   [https://docs.aws.amazon.com/vpc/latest/userguide/endpoint-services-overview.html](https://docs.aws.amazon.com/vpc/latest/userguide/endpoint-services-overview.html)  |  arn:${Partition}:ec2:${Region}:${Account}:vpc-endpoint-service/${VpcEndpointServiceId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VpceMultiRegion](#amazonec2-ec2_VpceMultiRegion) <br /> [#amazonec2-ec2_VpceServicePrivateDnsName](#amazonec2-ec2_VpceServicePrivateDnsName) <br /> [#amazonec2-ec2_VpceServiceRegion](#amazonec2-ec2_VpceServiceRegion) <br /> [#amazonec2-ec2_VpceSupportedRegion](#amazonec2-ec2_VpceSupportedRegion)  | 
|   [https://docs.aws.amazon.com/vpc/latest/privatelink/vpc-endpoints-access.html#vpc-endpoint-policies](https://docs.aws.amazon.com/vpc/latest/privatelink/vpc-endpoints-access.html#vpc-endpoint-policies)  |  arn:${Partition}:ec2:${Region}:${Account}:vpc-endpoint-service-permission/${VpcEndpointServicePermissionId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/vpc/latest/userguide/flow-logs.html](https://docs.aws.amazon.com/vpc/latest/userguide/flow-logs.html)  |  arn:${Partition}:ec2:${Region}:${Account}:vpc-flow-log/${VpcFlowLogId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/vpc/latest/userguide/VPC_Subnets.html](https://docs.aws.amazon.com/vpc/latest/userguide/VPC_Subnets.html)  |  arn:${Partition}:ec2:${Region}:${Account}:vpc/${VpcId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Ipv4IpamPoolId](#amazonec2-ec2_Ipv4IpamPoolId) <br /> [#amazonec2-ec2_Ipv6IpamPoolId](#amazonec2-ec2_Ipv6IpamPoolId) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_Tenancy](#amazonec2-ec2_Tenancy) <br /> [#amazonec2-ec2_VpcID](#amazonec2-ec2_VpcID)  | 
|   [https://docs.aws.amazon.com/vpc/latest/peering/what-is-vpc-peering.html](https://docs.aws.amazon.com/vpc/latest/peering/what-is-vpc-peering.html)  |  arn:${Partition}:ec2:${Region}:${Account}:vpc-peering-connection/${VpcPeeringConnectionId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_AccepterVpc](#amazonec2-ec2_AccepterVpc) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_RequesterVpc](#amazonec2-ec2_RequesterVpc) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_VpcPeeringConnectionID](#amazonec2-ec2_VpcPeeringConnectionID)  | 
|   [https://docs.aws.amazon.com/vpn/latest/s2svpn/VPC_VPN.html](https://docs.aws.amazon.com/vpn/latest/s2svpn/VPC_VPN.html)  |  arn:${Partition}:ec2:${Region}:${Account}:vpn-concentrator/${VpnConcentratorId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/vpn/latest/s2svpn/VPC_VPN.html](https://docs.aws.amazon.com/vpn/latest/s2svpn/VPC_VPN.html)  |  arn:${Partition}:ec2:${Region}:${Account}:vpn-connection-device-type/${VpnConnectionDeviceTypeId}  |  [#amazonec2-ec2_Region](#amazonec2-ec2_Region)  | 
|   [https://docs.aws.amazon.com/vpn/latest/s2svpn/VPC_VPN.html](https://docs.aws.amazon.com/vpn/latest/s2svpn/VPC_VPN.html)  |  arn:${Partition}:ec2:${Region}:${Account}:vpn-connection/${VpnConnectionId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Attribute](#amazonec2-ec2_Attribute) <br /> [#amazonec2-ec2_Attribute___AttributeName_](#amazonec2-ec2_Attribute___AttributeName_) <br /> [#amazonec2-ec2_AuthenticationType](#amazonec2-ec2_AuthenticationType) <br /> [#amazonec2-ec2_DPDTimeoutSeconds](#amazonec2-ec2_DPDTimeoutSeconds) <br /> [#amazonec2-ec2_GatewayType](#amazonec2-ec2_GatewayType) <br /> [#amazonec2-ec2_IKEVersions](#amazonec2-ec2_IKEVersions) <br /> [#amazonec2-ec2_InsideTunnelCidr](#amazonec2-ec2_InsideTunnelCidr) <br /> [#amazonec2-ec2_InsideTunnelIpv6Cidr](#amazonec2-ec2_InsideTunnelIpv6Cidr) <br /> [#amazonec2-ec2_Phase1DHGroup](#amazonec2-ec2_Phase1DHGroup) <br /> [#amazonec2-ec2_Phase1EncryptionAlgorithms](#amazonec2-ec2_Phase1EncryptionAlgorithms) <br /> [#amazonec2-ec2_Phase1IntegrityAlgorithms](#amazonec2-ec2_Phase1IntegrityAlgorithms) <br /> [#amazonec2-ec2_Phase1LifetimeSeconds](#amazonec2-ec2_Phase1LifetimeSeconds) <br /> [#amazonec2-ec2_Phase2DHGroup](#amazonec2-ec2_Phase2DHGroup) <br /> [#amazonec2-ec2_Phase2EncryptionAlgorithms](#amazonec2-ec2_Phase2EncryptionAlgorithms) <br /> [#amazonec2-ec2_Phase2IntegrityAlgorithms](#amazonec2-ec2_Phase2IntegrityAlgorithms) <br /> [#amazonec2-ec2_Phase2LifetimeSeconds](#amazonec2-ec2_Phase2LifetimeSeconds) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_RekeyFuzzPercentage](#amazonec2-ec2_RekeyFuzzPercentage) <br /> [#amazonec2-ec2_RekeyMarginTimeSeconds](#amazonec2-ec2_RekeyMarginTimeSeconds) <br /> [#amazonec2-ec2_ReplayWindowSizePackets](#amazonec2-ec2_ReplayWindowSizePackets) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_) <br /> [#amazonec2-ec2_RoutingType](#amazonec2-ec2_RoutingType)  | 
|   [https://docs.aws.amazon.com/vpn/latest/s2svpn/VPC_VPN.html](https://docs.aws.amazon.com/vpn/latest/s2svpn/VPC_VPN.html)  |  arn:${Partition}:ec2:${Region}:${Account}:vpn-gateway/${VpnGatewayId}  |  [#amazonec2-aws_RequestTag___TagKey_](#amazonec2-aws_RequestTag___TagKey_) <br /> [#amazonec2-aws_ResourceTag___TagKey_](#amazonec2-aws_ResourceTag___TagKey_) <br /> [#amazonec2-aws_TagKeys](#amazonec2-aws_TagKeys) <br /> [#amazonec2-ec2_Region](#amazonec2-ec2_Region) <br /> [#amazonec2-ec2_ResourceTag___TagKey_](#amazonec2-ec2_ResourceTag___TagKey_)  | 

## Condition keys for Amazon EC2
<a name="amazonec2-policy-keys"></a>

Amazon EC2 defines the following condition keys that can be used in the `Condition` element of an IAM policy. You can use these keys to further refine the conditions under which the policy statement applies. For details about the columns in the following table, see [Condition keys table](reference_policies_actions-resources-contextkeys.html#context_keys_table).

To view the global condition keys that are available to all services, see [AWS global condition context keys](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_condition-keys.html).


****  

| Condition keys | Description | Type | 
| --- | --- | --- | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/supported-iam-actions-tagging.html#control-tagging](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/supported-iam-actions-tagging.html#control-tagging)  | Filters access by a tag key and value pair that is allowed in the request | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/control-access-with-tags.html](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/control-access-with-tags.html)  | Filters access by a tag key and value pair of a resource | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/supported-iam-actions-tagging.html#control-tagging](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/supported-iam-actions-tagging.html#control-tagging)  | Filters access by a list of tag keys that are allowed in the request | ArrayOfString | 
|   [https://docs.aws.amazon.com/vpc/latest/peering/security-iam.html](https://docs.aws.amazon.com/vpc/latest/peering/security-iam.html)  | Filters access by the ARN of an accepter VPC in a VPC peering connection | ARN | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the group being added to a snapshot | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the account id being added to a snapshot | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the allocation ID of the Elastic IP address | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by whether the user wants to associate a public IP address with the instance | Bool | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#attribute-key](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#attribute-key)  | Filters access by an attribute of a resource | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#attribute-key](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#attribute-key)  | Filters access by an attribute being set on a resource | String | 
|   [https://docs.aws.amazon.com/vpn/latest/s2svpn/vpn-authentication-access-control.html](https://docs.aws.amazon.com/vpn/latest/s2svpn/vpn-authentication-access-control.html)  | Filters access by the authentication type for the VPN tunnel endpoints | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the AWS service that has permission to use a resource | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by an IAM principal that has permission to use a resource | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the Auto Placement properties of a Dedicated Host | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the name of an Availability Zone in an AWS Region | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the ID of an Availability Zone in an AWS Region | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the ARN of the Capacity Reservation Fleet | ARN | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the ARN of the client root certificate chain | ARN | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the ARN of the CloudWatch Logs log group | ARN | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the ARN of the CloudWatch Logs log stream | ARN | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by commitment duration of the Capacity Reservation | Numeric | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/sev-snp.html](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/sev-snp.html)  | Filters access by the state of AMD SEV-SNP CPU Options. Currently, only US East (Ohio) and Europe (Ireland) are supported | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/supported-iam-actions-tagging.html](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/supported-iam-actions-tagging.html)  | Filters access by the name of a resource-creating API action | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the date and time at which the Capacity Reservation was created | Date | 
|   [https://docs.aws.amazon.com/vpn/latest/s2svpn/vpn-authentication-access-control.html](https://docs.aws.amazon.com/vpn/latest/s2svpn/vpn-authentication-access-control.html)  | Filters access by the duration after which DPD timeout occurs on a VPN tunnel | Numeric | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the ID of the Capacity Reservation that you want to move capacity into | ARN | 
|   [iam-policies-for-amazon-ec2.html#imageId-key](iam-policies-for-amazon-ec2.html#imageId-key)  | Filters access by the ID of a dynamic host configuration protocol (DHCP) options set | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the ARN of the directory | ARN | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the domain of the Elastic IP address | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by whether the instance is enabled for EBS optimization | Bool | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the type of Elastic Graphics accelerator | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by whether the EBS volume is encrypted | Bool | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the date and time at which the Capacity Reservation ends | Date | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the way in which the Capacity Reservation ends | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by whether the instance is enabled for ephemeral storage | Bool | 
|   [https://docs.aws.amazon.com/fis/latest/userguide/fis-actions-reference.html](https://docs.aws.amazon.com/fis/latest/userguide/fis-actions-reference.html)  | Filters access by the ID of an AWS FIS action | String | 
|   [https://docs.aws.amazon.com/fis/latest/userguide/fis-actions-reference.html](https://docs.aws.amazon.com/fis/latest/userguide/fis-actions-reference.html)  | Filters access by the ARN of an AWS FIS target | ArrayOfARN | 
|   [https://docs.aws.amazon.com/vpn/latest/s2svpn/vpn-authentication-access-control.html](https://docs.aws.amazon.com/vpn/latest/s2svpn/vpn-authentication-access-control.html)  | Filters access by the gateway type for a VPN endpoint on the AWS side of a VPN connection | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by whether host recovery is enabled for a Dedicated Host | String | 
|   [https://docs.aws.amazon.com/vpn/latest/s2svpn/vpn-authentication-access-control.html](https://docs.aws.amazon.com/vpn/latest/s2svpn/vpn-authentication-access-control.html)  | Filters access by the internet key exchange (IKE) versions that are permitted for a VPN tunnel | ArrayOfString | 
|   [iam-policies-for-amazon-ec2.html#imageId-key](iam-policies-for-amazon-ec2.html#imageId-key)  | Filters access by the ID of an image | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the type of image (machine, aki, or ari) | String | 
|   [https://docs.aws.amazon.com/vpn/latest/s2svpn/vpn-authentication-access-control.html](https://docs.aws.amazon.com/vpn/latest/s2svpn/vpn-authentication-access-control.html)  | Filters access by the range of inside IP addresses for a VPN tunnel | String | 
|   [https://docs.aws.amazon.com/vpn/latest/s2svpn/vpn-authentication-access-control.html](https://docs.aws.amazon.com/vpn/latest/s2svpn/vpn-authentication-access-control.html)  | Filters access by a range of inside IPv6 addresses for a VPN tunnel | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by whether the instance type supports auto recovery | String | 
|   [iam-policies-for-amazon-ec2.html#imageId-key](iam-policies-for-amazon-ec2.html#imageId-key)  | Filters access by the bandwidth weighting of an instance | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the number of instances | Numeric | 
|   [iam-policies-for-amazon-ec2.html#imageId-key](iam-policies-for-amazon-ec2.html#imageId-key)  | Filters access by the ID of an instance | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the market or purchasing option of an instance (capacity-block, on-demand, or spot) | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the type of instance launches that the Capacity Reservation accepts | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by whether the instance allows access to instance tags from the instance metadata | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the type of operating system for which the Capacity Reservation reserves capacity | ARN | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the ARN of an instance profile | ARN | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the type of instance | String | 
|   [iam-policies-for-amazon-ec2.html#imageId-key](iam-policies-for-amazon-ec2.html#imageId-key)  | Filters access by the ID of an internet gateway | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the ID of an interruptible Capacity Reservation | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the type of interruption | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the IPAM prefix list resolver target ID that is syncing CIDRs to a managed prefix list | String | 
|   [iam-policies-for-amazon-ec2.html#amazon-ec2-keys](iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the ID of an IPAM pool provided for IPv4 CIDR block allocation | String | 
|   [iam-policies-for-amazon-ec2.html#amazon-ec2-keys](iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the ID of an IPAM pool provided for IPv6 CIDR block allocation | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by whether Capacity Reservations are interruptible | Bool | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by whether users are able to override resources that are specified in the launch template | Bool | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the name of a key pair | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the type of a key pair | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the ID of an AWS KMS key provided in the request | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the ARN of a launch template | ARN | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the destination for the snapshot copy | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the presence of an EC2 operator provisioning a managed resource | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by whether the HTTP endpoint is enabled for the instance metadata service | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the allowed number of hops when calling the instance metadata service | Numeric | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by whether tokens are required when calling the instance metadata service (optional or required) | String | 
|   [iam-policies-for-amazon-ec2.html#imageId-key](iam-policies-for-amazon-ec2.html#imageId-key)  | Filters access by the ID of a network access control list (ACL) | String | 
|   [iam-policies-for-amazon-ec2.html#imageId-key](iam-policies-for-amazon-ec2.html#imageId-key)  | Filters access by the ID of an elastic network interface | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the ARN of the instance profile being attached | ARN | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the ARN of the Outpost | ARN | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the owner of the resource (amazon, aws-marketplace, or an AWS account ID) | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the ARN of the parent snapshot | ARN | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the ARN of the parent volume from which the snapshot was created | ARN | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the type of permission for a resource (INSTANCE-ATTACH or EIP-ASSOCIATE) | String | 
|   [https://docs.aws.amazon.com/vpn/latest/s2svpn/vpn-authentication-access-control.html](https://docs.aws.amazon.com/vpn/latest/s2svpn/vpn-authentication-access-control.html)  | Filters access by the Diffie-Hellman group numbers that are permitted for a VPN tunnel for the phase 1 IKE negotiations | ArrayOfString | 
|   [https://docs.aws.amazon.com/vpn/latest/s2svpn/vpn-authentication-access-control.html](https://docs.aws.amazon.com/vpn/latest/s2svpn/vpn-authentication-access-control.html)  | Filters access by the encryption algorithms that are permitted for a VPN tunnel for the phase 1 IKE negotiations | ArrayOfString | 
|   [https://docs.aws.amazon.com/vpn/latest/s2svpn/vpn-authentication-access-control.html](https://docs.aws.amazon.com/vpn/latest/s2svpn/vpn-authentication-access-control.html)  | Filters access by the integrity algorithms that are permitted for a VPN tunnel for the phase 1 IKE negotiations | ArrayOfString | 
|   [https://docs.aws.amazon.com/vpn/latest/s2svpn/vpn-authentication-access-control.html](https://docs.aws.amazon.com/vpn/latest/s2svpn/vpn-authentication-access-control.html)  | Filters access by the lifetime in seconds for phase 1 of the IKE negotiations for a VPN tunnel | Numeric | 
|   [https://docs.aws.amazon.com/vpn/latest/s2svpn/vpn-authentication-access-control.html](https://docs.aws.amazon.com/vpn/latest/s2svpn/vpn-authentication-access-control.html)  | Filters access by the Diffie-Hellman group numbers that are permitted for a VPN tunnel for the phase 2 IKE negotiations | ArrayOfString | 
|   [https://docs.aws.amazon.com/vpn/latest/s2svpn/vpn-authentication-access-control.html](https://docs.aws.amazon.com/vpn/latest/s2svpn/vpn-authentication-access-control.html)  | Filters access by the encryption algorithms that are permitted for a VPN tunnel for the phase 2 IKE negotiations | ArrayOfString | 
|   [https://docs.aws.amazon.com/vpn/latest/s2svpn/vpn-authentication-access-control.html](https://docs.aws.amazon.com/vpn/latest/s2svpn/vpn-authentication-access-control.html)  | Filters access by the integrity algorithms that are permitted for a VPN tunnel for the phase 2 IKE negotiations | ArrayOfString | 
|   [https://docs.aws.amazon.com/vpn/latest/s2svpn/vpn-authentication-access-control.html](https://docs.aws.amazon.com/vpn/latest/s2svpn/vpn-authentication-access-control.html)  | Filters access by the lifetime in seconds for phase 2 of the IKE negotiations for a VPN tunnel | Numeric | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the ARN of the placement group | ARN | 
|   [iam-policies-for-amazon-ec2.html#imageId-key](iam-policies-for-amazon-ec2.html#imageId-key)  | Filters access by the name of a placement group | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the instance placement strategy used by the placement group (cluster, spread, or partition) | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the product code that is associated with the AMI | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by whether the image has public launch permissions | Bool | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by a public IP address | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the number of Dedicated Hosts in a request | Numeric | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the name of the AWS Region | String | 
|   [https://docs.aws.amazon.com/vpn/latest/s2svpn/vpn-authentication-access-control.html](https://docs.aws.amazon.com/vpn/latest/s2svpn/vpn-authentication-access-control.html)  | Filters access by the percentage of increase of the rekey window (determined by the rekey margin time) within which the rekey time is randomly selected for a VPN tunnel | Numeric | 
|   [https://docs.aws.amazon.com/vpn/latest/s2svpn/vpn-authentication-access-control.html](https://docs.aws.amazon.com/vpn/latest/s2svpn/vpn-authentication-access-control.html)  | Filters access by the margin time before the phase 2 lifetime expires for a VPN tunnel | Numeric | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the group being removed from a snapshot | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the account id being removed from a snapshot | String | 
|   [iam-policies-for-amazon-ec2.html#amazon-ec2-keys](iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the number of packets in an IKE replay window | String | 
|   [https://docs.aws.amazon.com/vpc/latest/peering/security-iam.html](https://docs.aws.amazon.com/vpc/latest/peering/security-iam.html)  | Filters access by the ARN of a requester VPC in a VPC peering connection | ARN | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-reserved-instances.html#ri-payment-options](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-reserved-instances.html#ri-payment-options)  | Filters access by the payment option of the Reserved Instance offering (No Upfront, Partial Upfront, or All Upfront) | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/control-access-with-tags.html](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/control-access-with-tags.html)  | Filters access by a tag key and value pair of a resource | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the version of the instance metadata service for retrieving IAM role credentials for EC2 | Numeric | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the root device type of the instance (ebs or instance-store) | String | 
|   [iam-policies-for-amazon-ec2.html#imageId-key](iam-policies-for-amazon-ec2.html#imageId-key)  | Filters access by the ID of a route table | String | 
|   [https://docs.aws.amazon.com/vpn/latest/s2svpn/vpn-authentication-access-control.html](https://docs.aws.amazon.com/vpn/latest/s2svpn/vpn-authentication-access-control.html)  | Filters access by the routing type for the VPN connection | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the ARN of the IAM SAML identity provider | ARN | 
|   [iam-policies-for-amazon-ec2.html#imageId-key](iam-policies-for-amazon-ec2.html#imageId-key)  | Filters access by the ID of a security group | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the ARN of the server certificate | ARN | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the compliance mode cooling-off period | Numeric | 
|   [iam-policies-for-amazon-ec2.html#imageId-key](iam-policies-for-amazon-ec2.html#imageId-key)  | Filters access by the ID of a snapshot | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the snapshot lock duration | Numeric | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the initiation time of a snapshot | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the name of the Availability Zone from which the request originated | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the ID of the Capacity Reservation from which you want to move capacity | ARN | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the ARN of the instance from which the request originated | ARN | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the ARN of the Outpost from which the request originated | ARN | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the ARN of the subnet | ARN | 
|   [iam-policies-for-amazon-ec2.html#imageId-key](iam-policies-for-amazon-ec2.html#imageId-key)  | Filters access by the ID of a subnet | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the number of instances the interruptible Capacity Reservation is assigned | Numeric | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the tenancy of the VPC or instance (default, dedicated, or host) | String | 
|   [iam-policies-for-amazon-ec2.html#imageId-key](iam-policies-for-amazon-ec2.html#imageId-key)  | Filters access by the ID of a volume | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the initialization rate of the volume, in MiBps | Numeric | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the the number of input/output operations per second (IOPS) provisioned for the volume | Numeric | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the size of the volume, in GiB | Numeric | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the throughput of the volume, in MiBps | Numeric | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the type of volume (gp2, gp3, io1, io2, st1, sc1, or standard) | String | 
|   [https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-policies-for-amazon-ec2.html#amazon-ec2-keys)  | Filters access by the ARN of the VPC | ARN | 
|   [iam-policies-for-amazon-ec2.html#imageId-key](iam-policies-for-amazon-ec2.html#imageId-key)  | Filters access by the ID of a virtual private cloud (VPC) | String | 
|   [iam-policies-for-amazon-ec2.html#imageId-key](iam-policies-for-amazon-ec2.html#imageId-key)  | Filters access by the ID of a VPC peering connection | String | 
|   [https://docs.aws.amazon.com/vpc/latest/userguide/vpc-endpoints-iam.html](https://docs.aws.amazon.com/vpc/latest/userguide/vpc-endpoints-iam.html)  | Filters access by multi region of the VPC endpoint service | String | 
|   [https://docs.aws.amazon.com/vpc/latest/userguide/vpc-endpoints-iam.html](https://docs.aws.amazon.com/vpc/latest/userguide/vpc-endpoints-iam.html)  | Filters access by the private DNS preference | String | 
|   [https://docs.aws.amazon.com/vpc/latest/userguide/vpc-endpoints-iam.html](https://docs.aws.amazon.com/vpc/latest/userguide/vpc-endpoints-iam.html)  | Filters access by the private DNS domains | ArrayOfString | 
|   [https://docs.aws.amazon.com/vpc/latest/userguide/vpc-endpoints-iam.html](https://docs.aws.amazon.com/vpc/latest/userguide/vpc-endpoints-iam.html)  | Filters access by the name of the VPC endpoint service | String | 
|   [https://docs.aws.amazon.com/vpc/latest/userguide/vpc-endpoints-iam.html](https://docs.aws.amazon.com/vpc/latest/userguide/vpc-endpoints-iam.html)  | Filters access by the service owner of the VPC endpoint service (amazon, aws-marketplace, or an AWS account ID) | String | 
|   [https://docs.aws.amazon.com/vpc/latest/userguide/vpc-endpoints-iam.html](https://docs.aws.amazon.com/vpc/latest/userguide/vpc-endpoints-iam.html)  | Filters access by the private DNS name of the VPC endpoint service | String | 
|   [https://docs.aws.amazon.com/vpc/latest/userguide/vpc-endpoints-iam.html](https://docs.aws.amazon.com/vpc/latest/userguide/vpc-endpoints-iam.html)  | Filters access by the region of the VPC endpoint service | String | 
|   [https://docs.aws.amazon.com/vpc/latest/userguide/vpc-endpoints-iam.html](https://docs.aws.amazon.com/vpc/latest/userguide/vpc-endpoints-iam.html)  | Filters access by the supported region of the VPC endpoint service | String | 
|   [iam-policies-for-amazon-ec2.html#imageId-key](iam-policies-for-amazon-ec2.html#imageId-key)  | Filters access by the ID of a transit gateway attachment | String | 
|   [iam-policies-for-amazon-ec2.html#imageId-key](iam-policies-for-amazon-ec2.html#imageId-key)  | Filters access by the ID of a transit gateway connect peer | String | 
|   [iam-policies-for-amazon-ec2.html#imageId-key](iam-policies-for-amazon-ec2.html#imageId-key)  | Filters access by the ID of a transit gateway | String | 
|   [iam-policies-for-amazon-ec2.html#imageId-key](iam-policies-for-amazon-ec2.html#imageId-key)  | Filters access by the ID of a metering policy id | String | 
|   [iam-policies-for-amazon-ec2.html#imageId-key](iam-policies-for-amazon-ec2.html#imageId-key)  | Filters access by the ID of a transit gateway multicast domain | String | 
|   [iam-policies-for-amazon-ec2.html#imageId-key](iam-policies-for-amazon-ec2.html#imageId-key)  | Filters access by the ID of a transit gateway policy table | String | 
|   [iam-policies-for-amazon-ec2.html#imageId-key](iam-policies-for-amazon-ec2.html#imageId-key)  | Filters access by the ID of a transit gateway route table announcement | String | 
|   [iam-policies-for-amazon-ec2.html#imageId-key](iam-policies-for-amazon-ec2.html#imageId-key)  | Filters access by the ID of a transit gateway route table | String | 