帳戶型應用程式上架的 IAM 角色許可 - Amazon CloudWatch

本文為英文版的機器翻譯版本,如內容有任何歧義或不一致之處,概以英文版為準。

帳戶型應用程式上架的 IAM 角色許可

如果想要將帳戶中的所有資源上架,而且選擇不使用 Application Insights 受管政策完整存取 Application Insights 功能,則您必須將下列許可連接至 IAM 角色,以便 Application Insights 能夠探索您帳戶中的所有資源:

"ec2:DescribeInstances" "ec2:DescribeNatGateways" "ec2:DescribeVolumes" "ec2:DescribeVPCs" "rds:DescribeDBInstances" "rds:DescribeDBClusters" "sqs:ListQueues" "elasticloadbalancing:DescribeLoadBalancers" "autoscaling:DescribeAutoScalingGroups" "lambda:ListFunctions" "dynamodb:ListTables" "s3:ListAllMyBuckets" "sns:ListTopics" "states:ListStateMachines" "apigateway:GET" "ecs:ListClusters" "ecs:DescribeTaskDefinition" "ecs:ListServices" "ecs:ListTasks" "eks:ListClusters" "eks:ListNodegroups" "fsx:DescribeFileSystems" "route53:ListHealthChecks" "route53:ListHostedZones" "route53:ListQueryLoggingConfigs" "route53resolver:ListFirewallRuleGroups" "route53resolver:ListFirewallRuleGroupAssociations" "route53resolver:ListResolverEndpoints" "route53resolver:ListResolverQueryLogConfigs" "route53resolver:ListResolverQueryLogConfigAssociations" "logs:DescribeLogGroups" "resource-explorer:ListResources"