本文為英文版的機器翻譯版本,如內容有任何歧義或不一致之處,概以英文版為準。
AWSSystemsManagerJustInTimeNodeAccessRolePropagationPolicy
描述:此政策允許 Systems Manager 共用拒絕存取政策,以便從委派管理員帳戶just-in-time存取節點至成員帳戶,並將政策複寫至多個區域。
AWSSystemsManagerJustInTimeNodeAccessRolePropagationPolicy
是 AWS 受管政策。
使用此政策
您可以AWSSystemsManagerJustInTimeNodeAccessRolePropagationPolicy
連接到您的使用者、群組和角色。
政策詳細資訊
-
Type: AWS 受管政策
-
建立時間:2025 年 4 月 21 日,UTC 20:52
-
編輯時間:2025 年 4 月 23 日,UTC 21:07
-
ARN:
arn:aws:iam::aws:policy/AWSSystemsManagerJustInTimeNodeAccessRolePropagationPolicy
政策版本
政策版本: v2 (預設)
政策的預設版本是定義政策許可的版本。當具有 政策的使用者或角色提出存取 AWS 資源的請求時, 會 AWS 檢查政策的預設版本,以決定是否允許請求。
JSON 政策文件
{ "Version" : "2012-10-17", "Statement" : [ { "Sid" : "QuickSetupPermissions", "Effect" : "Allow", "Action" : [ "ssm-quicksetup:ListConfigurationManagers", "ssm-quicksetup:GetConfigurationManager", "cloudformation:ListStackSets" ], "Resource" : "*" }, { "Sid" : "QuickSetupOrganizationsPermissions", "Effect" : "Allow", "Action" : [ "organizations:ListDelegatedAdministrators" ], "Resource" : "*", "Condition" : { "StringEquals" : { "organizations:ServicePrincipal" : "ssm-quicksetup.amazonaws.com" } } }, { "Sid" : "QuickSetupSLRPermissions", "Effect" : "Allow", "Action" : [ "iam:GetRole" ], "Resource" : [ "arn:aws:iam::*:role/aws-service-role/ssm-quicksetup.amazonaws.com/AWSServiceRoleForSSMQuickSetup" ] }, { "Sid" : "OrganizationsPermissions", "Effect" : "Allow", "Action" : [ "organizations:DescribeOrganization", "organizations:DescribeOrganizationalUnit" ], "Resource" : "*" }, { "Sid" : "SSMDocumentPermissions", "Effect" : "Allow", "Action" : [ "ssm:GetDocument", "ssm:DescribeDocument", "ssm:ListTagsForResource", "ssm:PutResourcePolicy", "ssm:DeleteResourcePolicy", "ssm:GetResourcePolicies" ], "Resource" : "arn:aws:ssm:*:*:document/SSM-JustInTimeAccessDenyAccessOrgPolicy", "Condition" : { "StringEquals" : { "ssm:DocumentType" : "AutoApprovalPolicy" } } }, { "Sid" : "SSMDocumentCreateReplicaPermissions", "Effect" : "Allow", "Action" : [ "ssm:CreateDocument" ], "Resource" : "arn:aws:ssm:*:*:document/SSM-JustInTimeAccessDenyAccessOrgPolicy", "Condition" : { "StringEquals" : { "ssm:DocumentType" : "AutoApprovalPolicy", "aws:RequestTag/SystemsManagerJustInTimeNodeAccessManaged" : "true" }, "ForAllValues:StringEquals" : { "aws:TagKeys" : [ "SystemsManagerJustInTimeNodeAccessManaged" ] } } }, { "Sid" : "SSMDocumentUpdateReplicaPermissions", "Effect" : "Allow", "Action" : [ "ssm:UpdateDocument", "ssm:UpdateDocumentDefaultVersion", "ssm:UpdateDocumentMetadata", "ssm:DeleteDocument", "ssm:AddTagsToResource", "ssm:RemoveTagsFromResource" ], "Resource" : "arn:aws:ssm:*:*:document/SSM-JustInTimeAccessDenyAccessOrgPolicy", "Condition" : { "StringEquals" : { "ssm:DocumentType" : "AutoApprovalPolicy", "aws:ResourceTag/SystemsManagerJustInTimeNodeAccessManaged" : "true" } } }, { "Sid" : "RAMReadPermissions", "Effect" : "Allow", "Action" : [ "ram:GetResourceShares", "ram:GetResourceShareAssociations" ], "Resource" : "*" }, { "Sid" : "RAMCreatePermissions", "Effect" : "Allow", "Action" : [ "ram:CreateResourceShare" ], "Resource" : "arn:aws:ram:*:*:resource-share/*", "Condition" : { "StringEquals" : { "aws:RequestTag/SystemsManagerJustInTimeNodeAccessManaged" : "true" }, "ForAllValues:StringEquals" : { "aws:TagKeys" : [ "SystemsManagerJustInTimeNodeAccessManaged" ] }, "StringEqualsIfExists" : { "ram:RequestedResourceType" : "ssm:Document" }, "ArnLikeIfExists" : { "ram:ResourceArn" : "arn:aws:ssm:*:*:document/SSM-JustInTimeAccessDenyAccessOrgPolicy" } } }, { "Sid" : "RAMTaggingPermissions", "Effect" : "Allow", "Action" : "ram:TagResource", "Resource" : "arn:aws:ram:*:*:resource-share/*", "Condition" : { "StringEquals" : { "aws:RequestTag/SystemsManagerJustInTimeNodeAccessManaged" : "true" }, "ForAllValues:StringEquals" : { "aws:TagKeys" : [ "SystemsManagerJustInTimeNodeAccessManaged" ] } } }, { "Sid" : "RAMModificationPermissions", "Effect" : "Allow", "Action" : [ "ram:AssociateResourceShare", "ram:DisassociateResourceShare" ], "Resource" : "*", "Condition" : { "StringEquals" : { "ram:ResourceShareName" : "SSMJustInTimeNodeAccessManagedResourceShare", "aws:ResourceTag/SystemsManagerJustInTimeNodeAccessManaged" : "true" }, "StringEqualsIfExists" : { "ram:RequestedResourceType" : "ssm:Document" }, "ArnLikeIfExists" : { "ram:ResourceArn" : "arn:aws:ssm:*:*:document/SSM-JustInTimeAccessDenyAccessOrgPolicy" } } } ] }