

本文属于机器翻译版本。若本译文内容与英语原文存在差异，则一律以英文原文为准。

# Amazon EC2 Image Builder 的操作、资源和条件键
<a name="list_amazonec2imagebuilder"></a>

Amazon EC2 Image Builder（服务前缀：`imagebuilder`）提供以下服务特定的资源、操作和条件上下文键以在 IAM 权限策略中使用。

参考：
+ 了解如何[配置该服务](https://docs.aws.amazon.com/imagebuilder/latest/userguide/)。
+ 查看[适用于该服务的 API 操作列表](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/)。
+ 了解如何[使用 IAM](https://docs.aws.amazon.com/imagebuilder/latest/userguide/security-iam.html) 权限策略保护该服务及其资源。

**Topics**
+ [Amazon EC2 Image Builder 定义的操作](#amazonec2imagebuilder-actions-as-permissions)
+ [Amazon EC2 Image Builder 定义的资源类型](#amazonec2imagebuilder-resources-for-iam-policies)
+ [Amazon EC2 Image Builder 的条件键](#amazonec2imagebuilder-policy-keys)

## Amazon EC2 Image Builder 定义的操作
<a name="amazonec2imagebuilder-actions-as-permissions"></a>

您可以在 IAM 策略语句的 `Action` 元素中指定以下操作。可以使用策略授予在 AWS中执行操作的权限。您在策略中使用一项操作时，通常使用相同的名称允许或拒绝对 API 操作或 CLI 命令的访问。但在某些情况下，单一动作可控制对多项操作的访问。还有某些操作需要多种不同的动作。

操作表的**访问级别**列描述如何对操作进行分类（列出、读取、权限管理或标记）。此分类可以帮助您了解当您在策略中使用操作时，相应操作授予的访问级别。有关访问级别的更多信息，请参阅[策略摘要中的访问级别](https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_understand-policy-summary-access-level-summaries.html)。

操作表的**资源类型**列指示每项操作是否支持资源级权限。如果该列没有任何值，您必须在策略语句的 `Resource` 元素中指定策略应用的所有资源（“\*”）。通过在 IAM policy 中使用条件来筛选访问权限，以控制是否可以在资源或请求中使用特定标签键。如果操作具有一个或多个必需资源，则调用方必须具有使用这些资源来使用该操作的权限。必需资源在表中以星号 (\*) 表示。如果您在 IAM policy 中使用 `Resource` 元素限制资源访问权限，则必须为每种必需的资源类型添加 ARN 或模式。某些操作支持多种资源类型。如果资源类型是可选的（未指示为必需），则可以选择使用一种可选资源类型。

操作表的**条件键**列包括可以在策略语句的 `Condition` 元素中指定的键。有关与服务资源关联的条件键的更多信息，请参阅资源类型表的**条件键**列。

操作表的**依赖操作**列显示成功调用操作可能需要的其他权限。除了操作本身的权限以外，可能还需要这些权限。若某个操作指定依赖操作，则这些依赖关系可能适用于为该操作定义的其他资源，而不仅仅是表中列出的第一个资源。

**注意**  
资源条件键在[资源类型](#amazonec2imagebuilder-resources-for-iam-policies)表中列出。您可以在操作表的**资源类型（\* 为必需）**列中找到应用于某项操作的资源类型的链接。资源类型表中的资源类型包括**条件密钥**列，这是应用于操作表中操作的资源条件键。

有关下表中各列的详细信息，请参阅[操作表](reference_policies_actions-resources-contextkeys.html#actions_table)。


****  


- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_CancelImageCreation.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_CancelImageCreation.html) **
  - **描述:** 授予权限以取消映像创建
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-image](#amazonec2imagebuilder-image) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_CancelLifecycleExecution.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_CancelLifecycleExecution.html) **
  - **描述:** 授予取消生命周期执行的权限
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-lifecycleExecution](#amazonec2imagebuilder-lifecycleExecution) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_CreateComponent.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_CreateComponent.html) **
  - **描述:** 授予权限以创建新组件
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-component](#amazonec2imagebuilder-component)  / **条件键:**  / **相关操作:**  imagebuilder:TagResource <br /> kms:Encrypt <br /> kms:GenerateDataKey <br /> kms:GenerateDataKeyWithoutPlaintext <br /> s3:GetObject <br /> s3:ListBucket 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#amazonec2imagebuilder-aws_RequestTag___TagKey_](#amazonec2imagebuilder-aws_RequestTag___TagKey_) <br /> [#amazonec2imagebuilder-aws_TagKeys](#amazonec2imagebuilder-aws_TagKeys)  / **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_CreateContainerRecipe.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_CreateContainerRecipe.html) **
  - **描述:** 授予权限以创建新的容器配方
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-containerRecipe](#amazonec2imagebuilder-containerRecipe)  / **条件键:**  / **相关操作:**  ec2:DescribeImages <br /> ecr:DescribeImages <br /> ecr:DescribeRepositories <br /> imagebuilder:GetComponent <br /> imagebuilder:GetImage <br /> imagebuilder:TagResource <br /> kms:Encrypt <br /> kms:GenerateDataKey <br /> kms:GenerateDataKeyWithoutPlaintext <br /> s3:GetObject <br /> s3:ListBucket <br /> ssm:GetParameter 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#amazonec2imagebuilder-aws_RequestTag___TagKey_](#amazonec2imagebuilder-aws_RequestTag___TagKey_) <br /> [#amazonec2imagebuilder-aws_TagKeys](#amazonec2imagebuilder-aws_TagKeys)  / **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_CreateDistributionConfiguration.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_CreateDistributionConfiguration.html) **
  - **描述:** 授予权限以创建新的分配配置
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-distributionConfiguration](#amazonec2imagebuilder-distributionConfiguration)  / **条件键:**  / **相关操作:**  ec2:CreateLaunchTemplateVersion <br /> ec2:DescribeLaunchTemplates <br /> ec2:ModifyLaunchTemplate <br /> imagebuilder:TagResource <br /> s3:ListBucket <br /> ssm:GetParameter 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#amazonec2imagebuilder-aws_RequestTag___TagKey_](#amazonec2imagebuilder-aws_RequestTag___TagKey_) <br /> [#amazonec2imagebuilder-aws_TagKeys](#amazonec2imagebuilder-aws_TagKeys)  / **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_CreateImage.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_CreateImage.html) **
  - **描述:** 授予权限以创建新的映像
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-image](#amazonec2imagebuilder-image)  / **条件键:**  / **相关操作:**  ecr:BatchGetRepositoryScanningConfiguration <br /> ecr:DescribeRepositories <br /> iam:CreateServiceLinkedRole <br /> iam:PassRole <br /> imagebuilder:GetContainerRecipe <br /> imagebuilder:GetDistributionConfiguration <br /> imagebuilder:GetImageRecipe <br /> imagebuilder:GetInfrastructureConfiguration <br /> imagebuilder:GetWorkflow <br /> imagebuilder:TagResource <br /> inspector2:BatchGetAccountStatus 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#amazonec2imagebuilder-aws_RequestTag___TagKey_](#amazonec2imagebuilder-aws_RequestTag___TagKey_) <br /> [#amazonec2imagebuilder-aws_TagKeys](#amazonec2imagebuilder-aws_TagKeys)  / **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_CreateImagePipeline.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_CreateImagePipeline.html) **
  - **描述:** 授予权限以创建新的映像管道
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-imagePipeline](#amazonec2imagebuilder-imagePipeline)  / **条件键:**  / **相关操作:**  ecr:BatchGetRepositoryScanningConfiguration <br /> ecr:DescribeRepositories <br /> iam:CreateServiceLinkedRole <br /> iam:PassRole <br /> imagebuilder:GetContainerRecipe <br /> imagebuilder:GetDistributionConfiguration <br /> imagebuilder:GetImageRecipe <br /> imagebuilder:GetInfrastructureConfiguration <br /> imagebuilder:GetWorkflow <br /> imagebuilder:TagResource <br /> inspector2:BatchGetAccountStatus 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#amazonec2imagebuilder-aws_RequestTag___TagKey_](#amazonec2imagebuilder-aws_RequestTag___TagKey_) <br /> [#amazonec2imagebuilder-aws_TagKeys](#amazonec2imagebuilder-aws_TagKeys)  / **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_CreateImageRecipe.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_CreateImageRecipe.html) **
  - **描述:** 授予权限以创建新的映像配方
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-imageRecipe](#amazonec2imagebuilder-imageRecipe)  / **条件键:**  / **相关操作:**  ec2:DescribeImages <br /> imagebuilder:GetComponent <br /> imagebuilder:GetImage <br /> imagebuilder:TagResource <br /> ssm:GetParameter 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#amazonec2imagebuilder-aws_RequestTag___TagKey_](#amazonec2imagebuilder-aws_RequestTag___TagKey_) <br /> [#amazonec2imagebuilder-aws_TagKeys](#amazonec2imagebuilder-aws_TagKeys)  / **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_CreateInfrastructureConfiguration.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_CreateInfrastructureConfiguration.html) **
  - **描述:** 授予权限以创建新的基础设施配置
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-infrastructureConfiguration](#amazonec2imagebuilder-infrastructureConfiguration)  / **条件键:**  / **相关操作:**  ec2:DescribeAvailabilityZones <br /> ec2:DescribeHosts <br /> iam:PassRole <br /> imagebuilder:TagResource <br /> resource-groups:GetGroup <br /> sns:Publish 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#amazonec2imagebuilder-aws_RequestTag___TagKey_](#amazonec2imagebuilder-aws_RequestTag___TagKey_) <br /> [#amazonec2imagebuilder-aws_TagKeys](#amazonec2imagebuilder-aws_TagKeys) <br /> [#amazonec2imagebuilder-imagebuilder_CreatedResourceTagKeys](#amazonec2imagebuilder-imagebuilder_CreatedResourceTagKeys) <br /> [#amazonec2imagebuilder-imagebuilder_CreatedResourceTag___TagKey_](#amazonec2imagebuilder-imagebuilder_CreatedResourceTag___TagKey_) <br /> [#amazonec2imagebuilder-imagebuilder_Ec2MetadataHttpTokens](#amazonec2imagebuilder-imagebuilder_Ec2MetadataHttpTokens) <br /> [#amazonec2imagebuilder-imagebuilder_StatusTopicArn](#amazonec2imagebuilder-imagebuilder_StatusTopicArn)  / **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_CreateLifecyclePolicy.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_CreateLifecyclePolicy.html) **
  - **描述:** 授予创建新生命周期策略的权限
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-lifecyclePolicy](#amazonec2imagebuilder-lifecyclePolicy)  / **条件键:**  / **相关操作:**  iam:PassRole <br /> imagebuilder:TagResource 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#amazonec2imagebuilder-aws_RequestTag___TagKey_](#amazonec2imagebuilder-aws_RequestTag___TagKey_) <br /> [#amazonec2imagebuilder-aws_TagKeys](#amazonec2imagebuilder-aws_TagKeys) <br /> [#amazonec2imagebuilder-imagebuilder_LifecyclePolicyResourceType](#amazonec2imagebuilder-imagebuilder_LifecyclePolicyResourceType)  / **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_CreateWorkflow.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_CreateWorkflow.html) **
  - **描述:** 授予创建新工作流的权限
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-workflow](#amazonec2imagebuilder-workflow)  / **条件键:**  / **相关操作:**  imagebuilder:TagResource <br /> kms:Encrypt <br /> kms:GenerateDataKey <br /> kms:GenerateDataKeyWithoutPlaintext <br /> s3:GetObject <br /> s3:ListBucket 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#amazonec2imagebuilder-aws_RequestTag___TagKey_](#amazonec2imagebuilder-aws_RequestTag___TagKey_) <br /> [#amazonec2imagebuilder-aws_TagKeys](#amazonec2imagebuilder-aws_TagKeys)  / **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_DeleteComponent.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_DeleteComponent.html) **
  - **描述:** 授予删除组件的权限
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-component](#amazonec2imagebuilder-component) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_DeleteContainerRecipe.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_DeleteContainerRecipe.html) **
  - **描述:** 授予删除容器配方的权限
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-containerRecipe](#amazonec2imagebuilder-containerRecipe) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_DeleteDistributionConfiguration.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_DeleteDistributionConfiguration.html) **
  - **描述:** 授予权限以删除分配配置
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-distributionConfiguration](#amazonec2imagebuilder-distributionConfiguration) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_DeleteImage.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_DeleteImage.html) **
  - **描述:** 授予权限以删除映像
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-image](#amazonec2imagebuilder-image) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_DeleteImagePipeline.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_DeleteImagePipeline.html) **
  - **描述:** 授予权限以删除映像管道
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-imagePipeline](#amazonec2imagebuilder-imagePipeline) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_DeleteImageRecipe.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_DeleteImageRecipe.html) **
  - **描述:** 授予权限以删除映像配方
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-imageRecipe](#amazonec2imagebuilder-imageRecipe) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_DeleteInfrastructureConfiguration.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_DeleteInfrastructureConfiguration.html) **
  - **描述:** 授予权限以删除基础设施配置
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-infrastructureConfiguration](#amazonec2imagebuilder-infrastructureConfiguration) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_DeleteLifecyclePolicy.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_DeleteLifecyclePolicy.html) **
  - **描述:** 授予删除生命周期策略的权限
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-lifecyclePolicy](#amazonec2imagebuilder-lifecyclePolicy) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_DeleteWorkflow.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_DeleteWorkflow.html) **
  - **描述:** 授予权限以删除工作流程
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-workflow](#amazonec2imagebuilder-workflow) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_DistributeImage.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_DistributeImage.html) **
  - **描述:** 授予分发图像的权限
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-image](#amazonec2imagebuilder-image)  / **条件键:**  / **相关操作:**  ec2:DescribeImages <br /> iam:PassRole <br /> imagebuilder:GetDistributionConfiguration <br /> imagebuilder:GetImage <br /> imagebuilder:TagResource <br /> ssm:GetParameter 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#amazonec2imagebuilder-aws_RequestTag___TagKey_](#amazonec2imagebuilder-aws_RequestTag___TagKey_) <br /> [#amazonec2imagebuilder-aws_TagKeys](#amazonec2imagebuilder-aws_TagKeys)  / **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_GetComponent.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_GetComponent.html) **
  - **描述:** 授予权限以查看有关组件的详细信息
  - **访问级别:** Read
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-component](#amazonec2imagebuilder-component) 
  - **条件键:** 
  - **相关操作:**  kms:Decrypt 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_GetComponentPolicy.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_GetComponentPolicy.html) **
  - **描述:** 授予权限以查看与组件关联的资源策略
  - **访问级别:** Read
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-component](#amazonec2imagebuilder-component) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_GetContainerRecipe.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_GetContainerRecipe.html) **
  - **描述:** 授予权限以查看有关容器配方的详细信息
  - **访问级别:** Read
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-containerRecipe](#amazonec2imagebuilder-containerRecipe) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_GetContainerRecipePolicy.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_GetContainerRecipePolicy.html) **
  - **描述:** 授予权限以查看与容器配方关联的资源策略
  - **访问级别:** Read
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-containerRecipe](#amazonec2imagebuilder-containerRecipe) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_GetDistributionConfiguration.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_GetDistributionConfiguration.html) **
  - **描述:** 授予权限以查看有关分配配置的详细信息
  - **访问级别:** Read
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-distributionConfiguration](#amazonec2imagebuilder-distributionConfiguration) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_GetImage.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_GetImage.html) **
  - **描述:** 授予权限以查看有关映像的详细信息
  - **访问级别:** Read
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-image](#amazonec2imagebuilder-image) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_GetImagePipeline.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_GetImagePipeline.html) **
  - **描述:** 授予权限以查看有关映像管道的详细信息
  - **访问级别:** Read
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-imagePipeline](#amazonec2imagebuilder-imagePipeline) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_GetImagePolicy.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_GetImagePolicy.html) **
  - **描述:** 授予权限以查看与映像关联的资源策略
  - **访问级别:** Read
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-image](#amazonec2imagebuilder-image) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_GetImageRecipe.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_GetImageRecipe.html) **
  - **描述:** 授予权限以查看有关映像配方的详细信息
  - **访问级别:** Read
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-imageRecipe](#amazonec2imagebuilder-imageRecipe) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_GetImageRecipePolicy.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_GetImageRecipePolicy.html) **
  - **描述:** 授予权限以查看与映像配方关联的资源策略
  - **访问级别:** Read
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-imageRecipe](#amazonec2imagebuilder-imageRecipe) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_GetInfrastructureConfiguration.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_GetInfrastructureConfiguration.html) **
  - **描述:** 授予权限以查看有关基础设施配置的详细信息
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-infrastructureConfiguration](#amazonec2imagebuilder-infrastructureConfiguration) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_GetLifecycleExecution.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_GetLifecycleExecution.html) **
  - **描述:** 授予查看生命周期执行详细信息的权限
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-lifecycleExecution](#amazonec2imagebuilder-lifecycleExecution) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_GetLifecyclePolicy.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_GetLifecyclePolicy.html) **
  - **描述:** 授予查看生命周期策略详细信息的权限
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-lifecyclePolicy](#amazonec2imagebuilder-lifecyclePolicy) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_GetMarketplaceResource.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_GetMarketplaceResource.html) **
  - **描述:** 授予权限以检索 Marketpace 提供的资源
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-component](#amazonec2imagebuilder-component) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_GetWorkflow.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_GetWorkflow.html) **
  - **描述:** 授予查看工作流详细信息的权限
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-workflow](#amazonec2imagebuilder-workflow) 
  - **条件键:** 
  - **相关操作:**  kms:Decrypt 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_GetWorkflowExecution.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_GetWorkflowExecution.html) **
  - **描述:** 授予查看工作流程执行详细信息的权限
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-workflowExecution](#amazonec2imagebuilder-workflowExecution) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_GetWorkflowStepExecution.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_GetWorkflowStepExecution.html) **
  - **描述:** 授予查看工作流程步骤执行详细信息的权限
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-workflowStepExecution](#amazonec2imagebuilder-workflowStepExecution) 
  - **条件键:** 
  - **相关操作:**  kms:Decrypt 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ImportComponent.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ImportComponent.html) **
  - **描述:** 授予权限以导入新组件
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-component](#amazonec2imagebuilder-component)  / **条件键:**  / **相关操作:**  imagebuilder:TagResource <br /> kms:Encrypt <br /> kms:GenerateDataKey <br /> kms:GenerateDataKeyWithoutPlaintext <br /> s3:GetObject <br /> s3:ListBucket 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#amazonec2imagebuilder-aws_RequestTag___TagKey_](#amazonec2imagebuilder-aws_RequestTag___TagKey_) <br /> [#amazonec2imagebuilder-aws_TagKeys](#amazonec2imagebuilder-aws_TagKeys)  / **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ImportDiskImage.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ImportDiskImage.html) **
  - **描述:** 授予权限以导入磁盘映像
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-imageVersion](#amazonec2imagebuilder-imageVersion)  / **条件键:**  / **相关操作:**  iam:CreateServiceLinkedRole <br /> iam:PassRole <br /> imagebuilder:GetInfrastructureConfiguration <br /> imagebuilder:GetWorkflow <br /> imagebuilder:TagResource <br /> s3:GetObject <br /> s3:ListBucket 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#amazonec2imagebuilder-aws_RequestTag___TagKey_](#amazonec2imagebuilder-aws_RequestTag___TagKey_) <br /> [#amazonec2imagebuilder-aws_TagKeys](#amazonec2imagebuilder-aws_TagKeys)  / **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ImportVmImage.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ImportVmImage.html) **
  - **描述:** 授予导入镜像的权限
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-imageVersion](#amazonec2imagebuilder-imageVersion)  / **条件键:**  / **相关操作:**  ec2:DescribeImages <br /> ec2:DescribeImportImageTasks <br /> iam:CreateServiceLinkedRole <br /> imagebuilder:TagResource 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#amazonec2imagebuilder-aws_RequestTag___TagKey_](#amazonec2imagebuilder-aws_RequestTag___TagKey_) <br /> [#amazonec2imagebuilder-aws_TagKeys](#amazonec2imagebuilder-aws_TagKeys)  / **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListComponentBuildVersions.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListComponentBuildVersions.html) **
  - **描述:** 授予权限以列出您账户中的组件内部版本
  - **访问级别:** List
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-allComponentBuildVersions](#amazonec2imagebuilder-allComponentBuildVersions) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListComponents.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListComponents.html) **
  - **描述:** 授予权限以列出您的账户拥有或与之共享的组件版本
  - **访问级别:** List
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListContainerRecipes.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListContainerRecipes.html) **
  - **描述:** 授予权限以列出您账户拥有或与之共享的容器配方
  - **访问级别:** List
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListDistributionConfigurations.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListDistributionConfigurations.html) **
  - **描述:** 授予权限以列出您账户中的分配配置
  - **访问级别:** List
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListImageBuildVersions.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListImageBuildVersions.html) **
  - **描述:** 授予权限以列出您账户中的映像内部版本
  - **访问级别:** 列表
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-allImageBuildVersions](#amazonec2imagebuilder-allImageBuildVersions) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListImagePackages.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListImagePackages.html) **
  - **描述:** 授予权限以返回指定映像上安装的软件包列表
  - **访问级别:** 列表
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-image](#amazonec2imagebuilder-image) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListImagePipelineImages.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListImagePipelineImages.html) **
  - **描述:** 授予权限以返回由指定管道创建的映像的列表
  - **访问级别:** 列表
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-imagePipeline](#amazonec2imagebuilder-imagePipeline) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListImagePipelines.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListImagePipelines.html) **
  - **描述:** 授予权限以列出您账户中的映像管道
  - **访问级别:** List
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListImageRecipes.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListImageRecipes.html) **
  - **描述:** 授予权限以列出您账户拥有或与之共享的映像配方
  - **访问级别:** 列表
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListImageScanFindingAggregations.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListImageScanFindingAggregations.html) **
  - **描述:** 授予权限以列出您账户中的映像扫描结果的聚合
  - **访问级别:** 列表
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-image](#amazonec2imagebuilder-image)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-imagePipeline](#amazonec2imagebuilder-imagePipeline)  / **条件键:**  / **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListImageScanFindings.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListImageScanFindings.html) **
  - **描述:** 授予权限以列出您账户中的映像的扫描结果
  - **访问级别:** 列表
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-image](#amazonec2imagebuilder-image)  / **条件键:**  / **相关操作:**  inspector2:ListFindings 
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-imagePipeline](#amazonec2imagebuilder-imagePipeline)  / **条件键:**  / **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListImages.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListImages.html) **
  - **描述:** 授予权限以列出您账户拥有或与之共享的映像版本
  - **访问级别:** List
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListInfrastructureConfigurations.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListInfrastructureConfigurations.html) **
  - **描述:** 授予权限以列出您账户中的基础设施配置
  - **访问级别:** 列表
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListLifecycleExecutionResources.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListLifecycleExecutionResources.html) **
  - **描述:** 授予列出指定生命周期执行的资源的权限
  - **访问级别:** 列表
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-lifecycleExecution](#amazonec2imagebuilder-lifecycleExecution) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListLifecycleExecutions.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListLifecycleExecutions.html) **
  - **描述:** 授予列出指定资源的生命周期执行的权限
  - **访问级别:** 列表
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-image](#amazonec2imagebuilder-image)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-lifecyclePolicy](#amazonec2imagebuilder-lifecyclePolicy)  / **条件键:**  / **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListLifecyclePolicies.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListLifecyclePolicies.html) **
  - **描述:** 授予列出您账户中的生命周期策略的权限
  - **访问级别:** 列表
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListTagsForResource.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListTagsForResource.html) **
  - **描述:** 授予权限以列出 Image Builder 资源的标签
  - **访问级别:** 读取
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-component](#amazonec2imagebuilder-component)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-containerRecipe](#amazonec2imagebuilder-containerRecipe)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-distributionConfiguration](#amazonec2imagebuilder-distributionConfiguration)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-image](#amazonec2imagebuilder-image)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-imagePipeline](#amazonec2imagebuilder-imagePipeline)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-imageRecipe](#amazonec2imagebuilder-imageRecipe)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-infrastructureConfiguration](#amazonec2imagebuilder-infrastructureConfiguration)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-lifecyclePolicy](#amazonec2imagebuilder-lifecyclePolicy)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-workflow](#amazonec2imagebuilder-workflow)  / **条件键:**  / **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListWaitingWorkflowSteps.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListWaitingWorkflowSteps.html) **
  - **描述:** 授予列出调用方账户的等待工作流步骤的权限
  - **访问级别:** 列表
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListWorkflowBuildVersions.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListWorkflowBuildVersions.html) **
  - **描述:** 授予列出您账户中的工作流内部版本的权限
  - **访问级别:** 列表
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-allWorkflowBuildVersions](#amazonec2imagebuilder-allWorkflowBuildVersions) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListWorkflowExecutions.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListWorkflowExecutions.html) **
  - **描述:** 授予权限以列出指定映像的工作流程执行情况
  - **访问级别:** 列表
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-image](#amazonec2imagebuilder-image) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListWorkflowStepExecutions.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListWorkflowStepExecutions.html) **
  - **描述:** 授予权限以列出指定工作流程的步骤执行情况
  - **访问级别:** 列表
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-workflowExecution](#amazonec2imagebuilder-workflowExecution) 
  - **条件键:** 
  - **相关操作:**  kms:Decrypt 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListWorkflows.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ListWorkflows.html) **
  - **描述:** 授予列出您账户拥有或与之共享的工作流版本的权限
  - **访问级别:** 列表
  - **资源类型（\* 为必需）:** 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_PutComponentPolicy.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_PutComponentPolicy.html) **
  - **描述:** 授予权限以设置与组件关联的资源策略
  - **访问级别:** Permissions management
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-component](#amazonec2imagebuilder-component) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_PutContainerRecipePolicy.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_PutContainerRecipePolicy.html) **
  - **描述:** 授予权限以设置与容器配方关联的资源策略
  - **访问级别:** Permissions management
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-containerRecipe](#amazonec2imagebuilder-containerRecipe) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_PutImagePolicy.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_PutImagePolicy.html) **
  - **描述:** 授予权限以设置与映像关联的资源策略
  - **访问级别:** Permissions management
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-image](#amazonec2imagebuilder-image) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_PutImageRecipePolicy.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_PutImageRecipePolicy.html) **
  - **描述:** 授予权限以设置与映像配方关联的资源策略
  - **访问级别:** 权限管理
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-imageRecipe](#amazonec2imagebuilder-imageRecipe) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_RetryImage.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_RetryImage.html) **
  - **描述:** 授予重试创建图像的权限
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-image](#amazonec2imagebuilder-image) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_SendWorkflowStepAction.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_SendWorkflowStepAction.html) **
  - **描述:** 授予将操作发送到工作流步骤的权限
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-image](#amazonec2imagebuilder-image)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-workflowStepExecution](#amazonec2imagebuilder-workflowStepExecution)  / **条件键:**  / **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_StartImagePipelineExecution.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_StartImagePipelineExecution.html) **
  - **描述:** 授予权限以从管道创建新的映像
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-imagePipeline](#amazonec2imagebuilder-imagePipeline)  / **条件键:**  / **相关操作:**  iam:CreateServiceLinkedRole <br /> imagebuilder:GetImagePipeline <br /> imagebuilder:TagResource 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#amazonec2imagebuilder-aws_RequestTag___TagKey_](#amazonec2imagebuilder-aws_RequestTag___TagKey_) <br /> [#amazonec2imagebuilder-aws_TagKeys](#amazonec2imagebuilder-aws_TagKeys)  / **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_StartResourceStateUpdate.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_StartResourceStateUpdate.html) **
  - **描述:** 授予启动指定资源的状态更新的权限
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-image](#amazonec2imagebuilder-image) 
  - **条件键:** 
  - **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_TagResource.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_TagResource.html) **
  - **描述:** 授予权限以标记 Image Builder 资源
  - **访问级别:** Tagging
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-component](#amazonec2imagebuilder-component)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-containerRecipe](#amazonec2imagebuilder-containerRecipe)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-distributionConfiguration](#amazonec2imagebuilder-distributionConfiguration)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-image](#amazonec2imagebuilder-image)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-imagePipeline](#amazonec2imagebuilder-imagePipeline)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-imageRecipe](#amazonec2imagebuilder-imageRecipe)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-infrastructureConfiguration](#amazonec2imagebuilder-infrastructureConfiguration)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-lifecyclePolicy](#amazonec2imagebuilder-lifecyclePolicy)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-workflow](#amazonec2imagebuilder-workflow)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#amazonec2imagebuilder-aws_TagKeys](#amazonec2imagebuilder-aws_TagKeys) <br /> [#amazonec2imagebuilder-aws_RequestTag___TagKey_](#amazonec2imagebuilder-aws_RequestTag___TagKey_)  / **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_UntagResource.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_UntagResource.html) **
  - **描述:** 授予权限以取消标记 Image Builder 资源
  - **访问级别:** Tagging
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-component](#amazonec2imagebuilder-component)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-containerRecipe](#amazonec2imagebuilder-containerRecipe)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-distributionConfiguration](#amazonec2imagebuilder-distributionConfiguration)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-image](#amazonec2imagebuilder-image)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-imagePipeline](#amazonec2imagebuilder-imagePipeline)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-imageRecipe](#amazonec2imagebuilder-imageRecipe)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-infrastructureConfiguration](#amazonec2imagebuilder-infrastructureConfiguration)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-lifecyclePolicy](#amazonec2imagebuilder-lifecyclePolicy)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-workflow](#amazonec2imagebuilder-workflow)  / **条件键:**  / **相关操作:** 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#amazonec2imagebuilder-aws_TagKeys](#amazonec2imagebuilder-aws_TagKeys)  / **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_UpdateDistributionConfiguration.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_UpdateDistributionConfiguration.html) **
  - **描述:** 授予权限以更新现有分配配置
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-distributionConfiguration](#amazonec2imagebuilder-distributionConfiguration) 
  - **条件键:** 
  - **相关操作:**  ec2:CreateLaunchTemplateVersion <br /> ec2:DescribeLaunchTemplates <br /> ec2:ModifyLaunchTemplate <br /> s3:ListBucket <br /> ssm:GetParameter 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_UpdateImagePipeline.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_UpdateImagePipeline.html) **
  - **描述:** 授予权限以更新现有映像管道
  - **访问级别:** Write
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-imagePipeline](#amazonec2imagebuilder-imagePipeline) 
  - **条件键:** 
  - **相关操作:**  ecr:BatchGetRepositoryScanningConfiguration <br /> ecr:DescribeRepositories <br /> iam:CreateServiceLinkedRole <br /> iam:PassRole <br /> imagebuilder:GetContainerRecipe <br /> imagebuilder:GetDistributionConfiguration <br /> imagebuilder:GetImageRecipe <br /> imagebuilder:GetInfrastructureConfiguration <br /> imagebuilder:GetWorkflow <br /> inspector2:BatchGetAccountStatus 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_UpdateInfrastructureConfiguration.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_UpdateInfrastructureConfiguration.html) **
  - **描述:** 授予权限以更新现有基础设施配置
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-infrastructureConfiguration](#amazonec2imagebuilder-infrastructureConfiguration)  / **条件键:**  / **相关操作:**  ec2:DescribeAvailabilityZones <br /> ec2:DescribeHosts <br /> iam:PassRole <br /> resource-groups:GetGroup <br /> sns:Publish 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#amazonec2imagebuilder-imagebuilder_CreatedResourceTagKeys](#amazonec2imagebuilder-imagebuilder_CreatedResourceTagKeys) <br /> [#amazonec2imagebuilder-imagebuilder_CreatedResourceTag___TagKey_](#amazonec2imagebuilder-imagebuilder_CreatedResourceTag___TagKey_) <br /> [#amazonec2imagebuilder-imagebuilder_Ec2MetadataHttpTokens](#amazonec2imagebuilder-imagebuilder_Ec2MetadataHttpTokens) <br /> [#amazonec2imagebuilder-imagebuilder_StatusTopicArn](#amazonec2imagebuilder-imagebuilder_StatusTopicArn)  / **相关操作:** 

- **  [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_UpdateLifecyclePolicy.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_UpdateLifecyclePolicy.html) **
  - **描述:** 授予更新现有生命周期策略的权限
  - **访问级别:** 写入
  - **资源类型（\* 为必需）:**  [#amazonec2imagebuilder-lifecyclePolicy](#amazonec2imagebuilder-lifecyclePolicy)  / **条件键:**  / **相关操作:**  iam:PassRole 
  - **资源类型（\* 为必需）:**  / **条件键:**  [#amazonec2imagebuilder-imagebuilder_LifecyclePolicyResourceType](#amazonec2imagebuilder-imagebuilder_LifecyclePolicyResourceType)  / **相关操作:** 



## Amazon EC2 Image Builder 定义的资源类型
<a name="amazonec2imagebuilder-resources-for-iam-policies"></a>

以下资源类型是由该服务定义的，可以在 IAM 权限策略语句的 `Resource` 元素中使用这些资源类型。[操作表](#amazonec2imagebuilder-actions-as-permissions)中的每个操作指定了可以使用该操作指定的资源类型。您也可以在策略中包含条件键，从而定义资源类型。这些键显示在资源类型表的最后一列。有关下表中各列的详细信息，请参阅[资源类型表](reference_policies_actions-resources-contextkeys.html#resources_table)。


****  

| 资源类型 | ARN | 条件键 | 
| --- | --- | --- | 
|   [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_Component.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_Component.html)  |  arn:${Partition}:imagebuilder:${Region}:${Account}:component/${ComponentName}/${ComponentVersion}/${ComponentBuildVersion}  |  [#amazonec2imagebuilder-aws_ResourceTag___TagKey_](#amazonec2imagebuilder-aws_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_DistributionConfiguration.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_DistributionConfiguration.html)  |  arn:${Partition}:imagebuilder:${Region}:${Account}:distribution-configuration/${DistributionConfigurationName}  |  [#amazonec2imagebuilder-aws_ResourceTag___TagKey_](#amazonec2imagebuilder-aws_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_Image.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_Image.html)  |  arn:${Partition}:imagebuilder:${Region}:${Account}:image/${ImageName}/${ImageVersion}/${ImageBuildVersion}  |  [#amazonec2imagebuilder-aws_ResourceTag___TagKey_](#amazonec2imagebuilder-aws_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ImageVersion.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ImageVersion.html)  |  arn:${Partition}:imagebuilder:${Region}:${Account}:image/${ImageName}/${ImageVersion}  |  [#amazonec2imagebuilder-aws_ResourceTag___TagKey_](#amazonec2imagebuilder-aws_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ImageRecipe.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ImageRecipe.html)  |  arn:${Partition}:imagebuilder:${Region}:${Account}:image-recipe/${ImageRecipeName}/${ImageRecipeVersion}  |  [#amazonec2imagebuilder-aws_ResourceTag___TagKey_](#amazonec2imagebuilder-aws_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ContainerRecipe.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ContainerRecipe.html)  |  arn:${Partition}:imagebuilder:${Region}:${Account}:container-recipe/${ContainerRecipeName}/${ContainerRecipeVersion}  |  [#amazonec2imagebuilder-aws_ResourceTag___TagKey_](#amazonec2imagebuilder-aws_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ImagePipeline.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_ImagePipeline.html)  |  arn:${Partition}:imagebuilder:${Region}:${Account}:image-pipeline/${ImagePipelineName}  |  [#amazonec2imagebuilder-aws_ResourceTag___TagKey_](#amazonec2imagebuilder-aws_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_InfrastructureConfiguration.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_InfrastructureConfiguration.html)  |  arn:${Partition}:imagebuilder:${Region}:${Account}:infrastructure-configuration/${ResourceId}  |  [#amazonec2imagebuilder-aws_ResourceTag___TagKey_](#amazonec2imagebuilder-aws_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_LifecycleExecution.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_LifecycleExecution.html)  |  arn:${Partition}:imagebuilder:${Region}:${Account}:lifecycle-execution/${LifecycleExecutionId}  |  | 
|   [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_LifecyclePolicy.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_LifecyclePolicy.html)  |  arn:${Partition}:imagebuilder:${Region}:${Account}:lifecycle-policy/${LifecyclePolicyName}  |  [#amazonec2imagebuilder-aws_ResourceTag___TagKey_](#amazonec2imagebuilder-aws_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_Workflow.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_Workflow.html)  |  arn:${Partition}:imagebuilder:${Region}:${Account}:workflow/${WorkflowType}/${WorkflowName}/${WorkflowVersion}/${WorkflowBuildVersion}  |  [#amazonec2imagebuilder-aws_ResourceTag___TagKey_](#amazonec2imagebuilder-aws_ResourceTag___TagKey_)  | 
|   [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_WorkflowExecutionMetadata.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_WorkflowExecutionMetadata.html)  |  arn:${Partition}:imagebuilder:${Region}:${Account}:workflow-execution/${WorkflowExecutionId}  |  | 
|   [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_WorkflowStepMetadata.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_WorkflowStepMetadata.html)  |  arn:${Partition}:imagebuilder:${Region}:${Account}:workflow-step-execution/${WorkflowStepExecutionId}  |  | 
|   [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_Component.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_Component.html)  |  arn:${Partition}:imagebuilder:${Region}:${Account}:component/${ComponentName}/${ComponentVersion}/\*  |  | 
|   [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_Image.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_Image.html)  |  arn:${Partition}:imagebuilder:${Region}:${Account}:image/${ImageName}/${ImageVersion}/\*  |  | 
|   [https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_Workflow.html](https://docs.aws.amazon.com/imagebuilder/latest/APIReference/API_Workflow.html)  |  arn:${Partition}:imagebuilder:${Region}:${Account}:workflow/${WorkflowType}/${WorkflowName}/${WorkflowVersion}/\*  |  | 

## Amazon EC2 Image Builder 的条件键
<a name="amazonec2imagebuilder-policy-keys"></a>

Amazon EC2 Image Builder 定义以下可以在 IAM policy 的 `Condition` 元素中使用的条件键。您可以使用这些键进一步细化应用策略语句的条件。有关下表中各列的详细信息，请参阅[条件键表](reference_policies_actions-resources-contextkeys.html#context_keys_table)。

要查看适用于所有服务的全局条件键，请参阅 [AWS 全局条件上下文键](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_condition-keys.html)。


****  

| 条件键 | 描述 | Type | 
| --- | --- | --- | 
|   [https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_condition-keys.html#condition-keys-requesttag](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_condition-keys.html#condition-keys-requesttag)  | 根据在请求中是否具有标签键值对来筛选访问权限 | 字符串 | 
|   [https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_condition-keys.html#condition-keys-resourcetag](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_condition-keys.html#condition-keys-resourcetag)  | 按附加到资源的标签键值对筛选操作 | 字符串 | 
|   [https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_condition-keys.html#condition-keys-tagkeys](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_condition-keys.html#condition-keys-tagkeys)  | 根据在请求中是否具有标签键来筛选访问 | ArrayOfString | 
|   [https://docs.aws.amazon.com/imagebuilder/latest/userguide/security_iam_service-with-iam.html#image-builder-security-createdresourcetag](https://docs.aws.amazon.com/imagebuilder/latest/userguide/security_iam_service-with-iam.html#image-builder-security-createdresourcetag)  | 根据附加到 Image Builder 所创建的资源的标签键值对来筛选访问 | 字符串 | 
|   [https://docs.aws.amazon.com/imagebuilder/latest/userguide/security_iam_service-with-iam.html#image-builder-security-createdresourcetagkeys](https://docs.aws.amazon.com/imagebuilder/latest/userguide/security_iam_service-with-iam.html#image-builder-security-createdresourcetagkeys)  | 根据在请求中是否具有标签键来筛选访问 | ArrayOfString | 
|   [https://docs.aws.amazon.com/imagebuilder/latest/userguide/security_iam_service-with-iam.html#image-builder-security-ec2metadatatokens](https://docs.aws.amazon.com/imagebuilder/latest/userguide/security_iam_service-with-iam.html#image-builder-security-ec2metadatatokens)  | 按请求中指定的 EC2 实例元数据 HTTP Token Requirement 筛选访问权限 | 字符串 | 
|   [https://docs.aws.amazon.com/imagebuilder/latest/userguide/security_iam_service-with-iam.html#image-builder-security-lifecyclepolicyresourcetype](https://docs.aws.amazon.com/imagebuilder/latest/userguide/security_iam_service-with-iam.html#image-builder-security-lifecyclepolicyresourcetype)  | 按请求中指定的生命周期策略资源类型筛选访问权限 | 字符串 | 
|   [https://docs.aws.amazon.com/imagebuilder/latest/userguide/security_iam_service-with-iam.html#image-builder-security-statustopicarn](https://docs.aws.amazon.com/imagebuilder/latest/userguide/security_iam_service-with-iam.html#image-builder-security-statustopicarn)  | 按将发送终端状态通知的请求中的 SNS Topic Arn 筛选访问权限 | 进行筛选 | 