Condition keys for resource metrics configuration access
This topic explains how the cloudwatch:ResourceArn condition key
works and how to use it to limit the resources that a principal can enable or disable
detailed monitoring for.
The resource metrics configuration operations are not authorized against a
CloudWatch resource type. These operations are
CreateResourceMetricsConfiguration,
UpdateResourceMetricsConfiguration,
GetResourceMetricsConfiguration, and
DeleteResourceMetricsConfiguration. Instead, they are authorized at the
action level, and the AWS resource that the request targets is supplied to IAM in
the cloudwatch:ResourceArn condition key. For links to the API reference
for these operations, see Amazon CloudWatch permissions reference.
Important
Because these operations are authorized at the action level, specifying the target
resource ARN in the Resource element of a policy statement does not
restrict them. Use "Resource": "*" together with a
Condition block on cloudwatch:ResourceArn to control which
resources a principal can configure. A statement that omits the condition allows the
principal to configure detailed monitoring for any resource in the account.
The value of cloudwatch:ResourceArn is the Amazon Resource Name (ARN)
that the caller passes in the ResourceArn request parameter. Each of these
operations targets exactly one resource per request.
For example, to allow a principal to manage detailed monitoring for only one
resource, grant the resource metrics configuration actions on
"Resource": "*" and add a StringEquals condition on
cloudwatch:ResourceArn with the full ARN of that resource. A request that
targets any other resource is denied.
cloudwatch:ResourceArn is evaluated as a string. Use
StringEquals for an exact match, or StringLike with
wildcards to match a set of resources. For example, you can use
arn:aws:service:*:123456789012:resource-type/*. The ARN condition operators, such
as ArnEquals and ArnLike, do not apply to this key.
The following policy uses StringLike with wildcards to allow the
principal to manage detailed monitoring for any resource of one type in the
account:
For more information about the Condition element in IAM policies, see
IAM JSON
policy elements: Condition.