Die vorliegende Übersetzung wurde maschinell erstellt. Im Falle eines Konflikts oder eines Widerspruchs zwischen dieser übersetzten Fassung und der englischen Fassung (einschließlich infolge von Verzögerungen bei der Übersetzung) ist die englische Fassung maßgeblich.
Verwaltete Richtlinien für Ihr Unternehmen
Warnung
Wir stellen unser neues Erlebnis derzeit einer begrenzten Anzahl von Kunden zur Verfügung. Möglicherweise können Sie noch nicht auf dieses Erlebnis zugreifen.
Wenn Sie unsere neue AWS Erfahrung nutzen, AWS verwaltet es die Verwaltungsrichtlinien der Organisation, einschließlich der Resource Control Policies (RCPs) und der Service Control Policies (SCPs). Diese Schutzmaßnahmen verhindern, dass ein Projekteigentümer oder ein Teammitglied Aktionen durchführt, die die vorkonfigurierten Standardeinstellungen verhindern würden, die Sie für AWS eine schnelle Entwicklung und Entwicklung definiert haben.
Richtlinien zur Servicesteuerung für Projekte
Die folgende Dienststeuerungsrichtlinie gilt für alle Benutzer in einem Projekt und kann nicht geändert werden:
{ "Version" : "2012-10-17", "Statement" : [ { "Sid" : "BlockOrgEscape", "Effect" : "Deny", "Action" : [ "account:CloseAccount", "organizations:AcceptHandshake", "organizations:LeaveOrganization", "sso:CreateInstance" ], "Resource" : "*" }, { "Sid" : "ProtectManagedRoles", "Effect" : "Deny", "Action" : [ "iam:AttachRolePolicy", "iam:CreateRole", "iam:DeleteRole", "iam:DeleteRolePermissionsBoundary", "iam:DeleteRolePolicy", "iam:DetachRolePolicy", "iam:PutRolePermissionsBoundary", "iam:PutRolePolicy", "iam:TagRole", "iam:UntagRole", "iam:UpdateAssumeRolePolicy", "iam:UpdateRole" ], "Resource" : "arn:*:iam::*:role/managed/*", "Condition" : { "StringNotLike" : { "aws:PrincipalArn" : "arn:*:iam::*:role/managed/AWSManagedAccountManagementAccessRole" } } } ] }
Diese Richtlinie wird nicht entfernt, wenn Sie erweiterte Funktionen aktivieren. Weitere Informationen finden Sie unter Erweitert aktivieren AWS features.
Darüber hinaus wenden wir die folgende Dienststeuerungsrichtlinie für alle Benutzer in einem Projekt an, um bestimmte Änderungen an Ihrem Projekt einzuschränken, die entweder nicht unterstützt werden oder in den AWS Einstellungen vorgenommen werden müssen:
{ "Version" : "2012-10-17", "Statement" : [ { "Sid" : "BlockAccountManagementAPIs", "Effect" : "Deny", "Action" : [ "account:AcceptPrimaryEmailUpdate", "account:DeleteAlternateContact", "account:DisableRegion", "account:EnableRegion", "account:GetAlternateContact", "account:GetContactInformation", "account:GetGovCloudAccountInformation", "account:GetRegionOptStatus", "account:PutAccountName", "account:PutAlternateContact", "account:PutContactInformation", "account:StartPrimaryEmailUpdate" ], "Resource" : "*" }, { "Sid" : "DenyBillingOperations", "Effect" : "Deny", "Action" : "billing:*", "Resource" : "*" }, { "Sid" : "DenyNotificationContactsOperations", "Effect" : "Deny", "Action" : "notifications-contacts:*", "Resource" : "*" }, { "Sid" : "DenyRestrictedNotificationOperations", "Effect" : "Deny", "Action" : [ "notifications:AssociateChannel", "notifications:AssociateManagedNotificationAccountContact", "notifications:AssociateManagedNotificationAdditionalChannel", "notifications:AssociateOrganizationalUnit", "notifications:CreateEventRule", "notifications:CreateNotificationConfiguration", "notifications:DeleteEventRule", "notifications:DeleteNotificationConfiguration", "notifications:DeregisterNotificationHub", "notifications:DisableNotificationsAccessForOrganization", "notifications:DisassociateChannel", "notifications:DisassociateManagedNotificationAccountContact", "notifications:DisassociateManagedNotificationAdditionalChannel", "notifications:DisassociateOrganizationalUnit", "notifications:EnableNotificationsAccessForOrganization", "notifications:GetEventRule", "notifications:GetFeatureOptInStatus", "notifications:GetNotificationConfiguration", "notifications:GetNotificationEvent", "notifications:GetNotificationsAccessForOrganization", "notifications:ListChannels", "notifications:ListEventRules", "notifications:ListManagedNotificationChannelAssociations", "notifications:ListMemberAccounts", "notifications:ListNotificationConfigurations", "notifications:ListNotificationEvents", "notifications:ListNotificationHubs", "notifications:ListOrganizationalUnits", "notifications:ListTagsForResource", "notifications:PutFeatureOptInStatus", "notifications:RegisterNotificationHub", "notifications:TagResource", "notifications:UntagResource", "notifications:UpdateEventRule", "notifications:UpdateNotificationConfiguration" ], "Resource" : "*" }, { "Sid" : "DenyRoleManagerDisablement", "Effect" : "Deny", "Action" : "iam:PutAccountProperties", "Resource" : "*", "Condition" : { "ForAnyValue:StringEquals" : { "iam:AccountPropertyNamespaces" : "RoleManager" } } } ] }
Diese Richtlinie wird entfernt, wenn Sie erweiterte Funktionen aktivieren. Weitere Informationen finden Sie unter Erweitert aktivieren AWS features.
Darüber hinaus wenden wir die folgende Richtlinie zur Dienstkontrolle auf alle Benutzer in einem Projekt an, um die Unterstützung partitionaler Dienste einzuschränken AWS-Regionen , je nach Ihren selected-region Anforderungen:
{ "Version" : "2012-10-17", "Statement" : [ { "Sid" : "UsEast1Partitional", "Effect" : "Deny", "NotAction" : [ "account:*", "acm:AddTagsToCertificate", "acm:DeleteCertificate", "acm:DescribeCertificate", "acm:GetCertificate", "acm:ListCertificates", "acm:ListTagsForCertificate", "acm:RemoveTagsFromCertificate", "acm:RequestCertificate", "acm:ResendValidationEmail", "activate:*", "appfabric:*", "artifact:*", "aws-marketplace:*", "bedrock-mantle:CallWithBearerToken", "bedrock-mantle:CreateInference", "bedrock-mantle:GetInference", "bedrock-mantle:GetModel", "bedrock-mantle:ListModels", "bedrock:ApplyGuardrail", "bedrock:CountTokens", "bedrock:GetFoundationModel", "bedrock:GetFoundationModelAvailability", "bedrock:GetInferenceProfile", "bedrock:InvokeModel", "bedrock:InvokeModelWithResponseStream", "bedrock:ListFoundationModels", "bedrock:ListInferenceProfiles", "budgets:*", "ce:*", "chatbot:*", "cloudfront-keyvaluestore:*", "cloudfront:*", "cloudshell:*", "cloudtrail:LookupEvents", "consoleapp:*", "cost-optimization-hub:*", "ec2:DescribeRegions", "ecr-public:*", "freetier:*", "health:*", "iam:*", "identitystore-auth:*", "identitystore:*", "invoicing:*", "kms:CreateGrant", "kms:Decrypt", "kms:DescribeKey", "kms:ListAliases", "machinelearning:*", "managedblockchain-query:*", "managedblockchain:*", "mapcredits:*", "notifications:GetManagedNotificationConfiguration", "notifications:GetManagedNotificationEvent", "notifications:ListManagedNotificationChildEvents", "notifications:ListManagedNotificationConfigurations", "notifications:ListManagedNotificationEvents", "organizations:*", "q:*", "route53:*", "route53domains:*", "route53globalresolver:*", "s3:GetBucketLocation", "s3:ListAllMyBuckets", "signin:*", "sso-directory:*", "sso-oauth:*", "sso:*", "sts:*", "support:*", "tax:*", "trustedadvisor:*", "uxc:*", "waf:*" ], "Resource" : "*", "Condition" : { "StringEquals" : { "aws:RequestedRegion" : "us-east-1" } } }, { "Sid" : "DenyUsEast1AcmPrivateCaRequests", "Effect" : "Deny", "Action" : "acm:RequestCertificate", "Resource" : "*", "Condition" : { "Null" : { "acm:CertificateAuthority" : "false" }, "StringEquals" : { "aws:RequestedRegion" : "us-east-1" } } }, { "Sid" : "UsWest2Partitional", "Effect" : "Deny", "NotAction" : [ "bedrock-mantle:CallWithBearerToken", "bedrock-mantle:CreateInference", "bedrock-mantle:GetInference", "bedrock-mantle:GetModel", "bedrock-mantle:ListModels", "bedrock:ApplyGuardrail", "bedrock:CountTokens", "bedrock:GetFoundationModel", "bedrock:GetFoundationModelAvailability", "bedrock:GetInferenceProfile", "bedrock:InvokeModel", "bedrock:InvokeModelWithResponseStream", "bedrock:ListFoundationModels", "bedrock:ListInferenceProfiles", "cloudshell:*", "cloudtrail:LookupEvents", "health:*", "identitystore-auth:*", "identitystore:*", "kms:Decrypt", "kms:DescribeKey", "kms:ListAliases", "networkmanager-chat:*", "networkmanager:*", "route53-recovery-cluster:*", "route53-recovery-control-config:*", "route53-recovery-readiness:*", "sso-directory:*", "sso-oauth:*", "sso:*", "support:*", "trustedadvisor:*", "uxc:*" ], "Resource" : "*", "Condition" : { "StringEquals" : { "aws:RequestedRegion" : "us-west-2" } } }, { "Sid" : "RegionFloor", "Effect" : "Deny", "NotAction" : [ "bedrock-mantle:CallWithBearerToken", "bedrock-mantle:CreateInference", "bedrock-mantle:GetInference", "bedrock-mantle:GetModel", "bedrock-mantle:ListModels", "bedrock:ApplyGuardrail", "bedrock:CountTokens", "bedrock:GetFoundationModel", "bedrock:GetFoundationModelAvailability", "bedrock:GetInferenceProfile", "bedrock:InvokeModel", "bedrock:InvokeModelWithResponseStream", "bedrock:ListFoundationModels", "bedrock:ListInferenceProfiles" ], "Resource" : "*", "Condition" : { "StringNotEquals" : { "aws:RequestedRegion" : [ "unspecified", "us-east-1", "selected-region", "us-west-2" ] } } } ] }
Nachdem Sie die erweiterten Funktionen aktiviert haben, wird die folgende Dienststeuerungsrichtlinie auf Ihr Konto angewendet:
{ "Version" : "2012-10-17", "Statement" : [ { "Sid" : "UsEast1Partitional", "Effect" : "Deny", "NotAction" : [ "a4b:*", "access-analyzer:*", "account-access:*", "account:*", "acm:*", "activate:*", "appfabric:*", "artifact:*", "aws-marketplace-management:*", "aws-marketplace:*", "aws-portal:*", "bedrock-mantle:CallWithBearerToken", "bedrock-mantle:CreateInference", "bedrock-mantle:GetInference", "bedrock-mantle:GetModel", "bedrock-mantle:ListModels", "bedrock:ApplyGuardrail", "bedrock:CountTokens", "bedrock:GetFoundationModel", "bedrock:GetFoundationModelAvailability", "bedrock:GetInferenceProfile", "bedrock:InvokeModel", "bedrock:InvokeModelWithResponseStream", "bedrock:ListFoundationModels", "bedrock:ListInferenceProfiles", "billing:*", "billingconductor:*", "budgets:*", "builderid:*", "ce:*", "chatbot:*", "chime:*", "cloudfront-keyvaluestore:*", "cloudfront:*", "cloudshell:*", "cloudtrail:LookupEvents", "compute-optimizer:*", "config:*", "consoleapp:*", "consolidatedbilling:*", "cost-optimization-hub:*", "cur:*", "datapipeline:GetAccountLimits", "devicefarm:*", "directconnect:*", "ec2:DescribeRegions", "ec2:DescribeTransitGateways", "ec2:DescribeVpnGateways", "ecr-public:*", "fms:*", "freetier:*", "globalaccelerator:*", "health:*", "iam:*", "identitystore-auth:*", "identitystore:*", "importexport:*", "invoicing:*", "iq:*", "kms:*", "license-manager:ListReceivedLicenses", "lightsail:Get*", "machinelearning:*", "managedblockchain-query:*", "managedblockchain:*", "mapcredits:*", "mobileanalytics:*", "networkmanager:*", "notifications-contacts:*", "notifications:*", "organizations:*", "payments:*", "pricing:*", "q:*", "quicksight:DescribeAccountSubscription", "resource-explorer-2:*", "route53-recovery-cluster:*", "route53-recovery-control-config:*", "route53-recovery-readiness:*", "route53:*", "route53domains:*", "route53globalresolver:*", "s3:CreateMultiRegionAccessPoint", "s3:DeleteMultiRegionAccessPoint", "s3:DescribeMultiRegionAccessPointOperation", "s3:GetAccountPublicAccessBlock", "s3:GetBucketLocation", "s3:GetBucketPolicyStatus", "s3:GetBucketPublicAccessBlock", "s3:GetMultiRegionAccessPoint", "s3:GetMultiRegionAccessPointPolicy", "s3:GetMultiRegionAccessPointPolicyStatus", "s3:GetStorageLensConfiguration", "s3:GetStorageLensDashboard", "s3:ListAllMyBuckets", "s3:ListMultiRegionAccessPoints", "s3:ListStorageLensConfigurations", "s3:PutAccountPublicAccessBlock", "s3:PutMultiRegionAccessPointPolicy", "savingsplans:*", "shield:*", "signin:*", "sso-directory:*", "sso-oauth:*", "sso:*", "sts:*", "support:*", "supportapp:*", "supportplans:*", "sustainability:*", "tag:GetResources", "tax:*", "trustedadvisor:*", "uxc:*", "vendor-insights:ListEntitledSecurityProfiles", "waf-regional:*", "waf:*", "wafv2:*" ], "Resource" : "*", "Condition" : { "StringEquals" : { "aws:RequestedRegion" : "us-east-1" } } }, { "Sid" : "UsWest2Partitional", "Effect" : "Deny", "NotAction" : [ "bedrock-mantle:CallWithBearerToken", "bedrock-mantle:CreateInference", "bedrock-mantle:GetInference", "bedrock-mantle:GetModel", "bedrock-mantle:ListModels", "bedrock:ApplyGuardrail", "bedrock:CountTokens", "bedrock:GetFoundationModel", "bedrock:GetFoundationModelAvailability", "bedrock:GetInferenceProfile", "bedrock:InvokeModel", "bedrock:InvokeModelWithResponseStream", "bedrock:ListFoundationModels", "bedrock:ListInferenceProfiles", "cloudshell:*", "cloudtrail:LookupEvents", "health:*", "identitystore-auth:*", "identitystore:*", "kms:Decrypt", "kms:DescribeKey", "kms:ListAliases", "networkmanager-chat:*", "networkmanager:*", "route53-recovery-cluster:*", "route53-recovery-control-config:*", "route53-recovery-readiness:*", "sso-directory:*", "sso-oauth:*", "sso:*", "support:*", "trustedadvisor:*", "uxc:*" ], "Resource" : "*", "Condition" : { "StringEquals" : { "aws:RequestedRegion" : "us-west-2" } } }, { "Sid" : "RegionFloor", "Effect" : "Deny", "NotAction" : [ "bedrock-mantle:CallWithBearerToken", "bedrock-mantle:CreateInference", "bedrock-mantle:GetInference", "bedrock-mantle:GetModel", "bedrock-mantle:ListModels", "bedrock:ApplyGuardrail", "bedrock:CountTokens", "bedrock:GetFoundationModel", "bedrock:GetFoundationModelAvailability", "bedrock:GetInferenceProfile", "bedrock:InvokeModel", "bedrock:InvokeModelWithResponseStream", "bedrock:ListFoundationModels", "bedrock:ListInferenceProfiles" ], "Resource" : "*", "Condition" : { "StringNotEquals" : { "aws:RequestedRegion" : [ "unspecified", "us-east-1", "selected-region", "us-west-2" ] } } } ] }
Richtlinien zur Servicekontrollen für Ausgabenlimits
Wenn Sie ein Ausgabenlimit verwenden, werden die folgenden Richtlinien zur Servicesteuerung auf Ihr Projekt angewendet, sobald es sich dem Ausgabenlimit nähert. Weitere Informationen zu Ausgabenlimits finden Sie unterErstellen Sie ein Ausgabenlimit in AWS Einstellungen.
{ "Version": "2012-10-17", "Statement": { "Sid": "DenyBedrockUsage", "Effect": "Deny", "Action": [ "bedrock:ApplyGuardrail", "bedrock:CallWithBearerToken", "bedrock:InvokeAgent", "bedrock:InvokeAutomatedReasoningPolicy", "bedrock:InvokeDataAutomation", "bedrock:InvokeDataAutomationAsync", "bedrock:InvokeFlow", "bedrock:InvokeInlineAgent", "bedrock:InvokeModel", "bedrock:InvokeModelWithResponseStream", "bedrock:InvokeTool", "bedrock:OptimizePrompt", "bedrock:Retrieve", "bedrock:RetrieveAndGenerate", "bedrock:StartFlowExecution", "bedrock-mantle:CallWithBearerToken", "bedrock-mantle:CreateInference" ], "Resource": "*" } }
{ "Version": "2012-10-17", "Statement": { "Sid": "DenyLambdaUsage", "Effect": "Deny", "Action": [ "lambda:DeleteFunctionConcurrency", "lambda:InvokeAsync", "lambda:InvokeFunction", "lambda:InvokeFunctionUrl", "lambda:PutFunctionConcurrency" ], "Resource": "*" } }
{ "Version": "2012-10-17", "Statement": { "Sid": "DenySageMakerInference", "Effect": "Deny", "Action": [ "sagemaker:InvokeEndpoint", "sagemaker:InvokeEndpointAsync", "sagemaker:InvokeEndpointWithResponseStream" ], "Resource": "*" } }
{ "Version": "2012-10-17", "Statement": [ { "Sid": "DenyCompute", "Effect": "Deny", "Action": [ "ec2:CreateNatGateway", "ec2:CreateVolume", "ec2:CreateVpnConnection", "ec2:RunInstances", "ec2:StartInstances", "elasticloadbalancing:CreateLoadBalancer", "autoscaling:CreateAutoScalingGroup", "ecs:CreateService", "eks:CreateCluster", "eks:CreateNodegroup", "eks:CreateFargateProfile", "elasticbeanstalk:CreateEnvironment", "apprunner:CreateService", "apprunner:ResumeService", "batch:CreateComputeEnvironment", "elasticmapreduce:RunJobFlow", "appstream:CreateFleet" ], "Resource": "*" }, { "Sid": "DenyLambda", "Effect": "Deny", "Action": "lambda:CreateFunction", "Resource": "*" }, { "Sid": "DenyDatabase", "Effect": "Deny", "Action": [ "rds:CreateDBCluster", "rds:CreateDBInstance", "rds:RestoreDBClusterFromS3", "rds:RestoreDBClusterFromSnapshot", "rds:RestoreDBClusterToPointInTime", "rds:RestoreDBInstanceFromDBSnapshot", "rds:RestoreDBInstanceFromS3", "rds:RestoreDBInstanceToPointInTime", "rds:StartDBCluster", "rds:StartDBInstance", "dynamodb:CreateTable", "dynamodb:CreateGlobalTable", "elasticache:CreateCacheCluster", "elasticache:CreateReplicationGroup", "timestream:CreateDatabase", "timestream:CreateTable", "memorydb:CreateCluster", "es:CreateDomain", "aoss:CreateCollection", "redshift:CreateCluster", "redshift:ResumeCluster", "redshift-serverless:CreateWorkgroup", "dsql:CreateCluster" ], "Resource": "*" }, { "Sid": "DenyStorage", "Effect": "Deny", "Action": [ "elasticfilesystem:CreateFileSystem", "datasync:CreateTask", "storagegateway:ActivateGateway", "glacier:CreateVault" ], "Resource": "*" }, { "Sid": "DenySageMaker", "Effect": "Deny", "Action": [ "sagemaker:CreateApp", "sagemaker:CreateEndpoint", "sagemaker:CreateNotebookInstance", "sagemaker:CreateProcessingJob", "sagemaker:CreateTrainingJob", "sagemaker:CreateTransformJob", "sagemaker:StartNotebookInstance" ], "Resource": "*" }, { "Sid": "DenyBedrock", "Effect": "Deny", "Action": [ "bedrock:CreateCustomModelDeployment", "bedrock:CreateDataAutomationProject", "bedrock:CreateEvaluationJob", "bedrock:CreateMarketplaceModelEndpoint", "bedrock:CreateModelCustomizationJob", "bedrock:CreateModelImportJob", "bedrock:CreateModelInvocationJob", "bedrock:CreateProvisionedModelThroughput", "bedrock-mantle:CreateCustomizedModel", "bedrock-mantle:CreateFineTuningJob", "bedrock-mantle:CreateReservation" ], "Resource": "*" }, { "Sid": "DenyAIML", "Effect": "Deny", "Action": [ "kendra:CreateIndex", "personalize:CreateSolution", "personalize:CreateCampaign", "forecast:CreatePredictor", "forecast:CreateForecast", "rekognition:CreateProject", "lex:CreateBot" ], "Resource": "*" }, { "Sid": "DenyNetworking", "Effect": "Deny", "Action": [ "cloudfront:CreateDistribution", "route53:CreateHostedZone", "appmesh:CreateMesh" ], "Resource": "*" }, { "Sid": "DenyApiGatewayCreate", "Effect": "Deny", "Action": "apigateway:POST", "Resource": [ "arn:aws:apigateway:*::/restapis", "arn:aws:apigateway:*::/apis" ] }, { "Sid": "DenyMessaging", "Effect": "Deny", "Action": [ "mq:CreateBroker", "kafka:CreateCluster", "kafka:CreateVpcConnection", "kinesis:CreateStream", "firehose:CreateDeliveryStream", "kinesisanalytics:CreateApplication", "kinesisvideo:CreateStream", "sns:CreateTopic", "sqs:CreateQueue", "events:CreateEventBus", "pipes:CreatePipe", "scheduler:CreateSchedule" ], "Resource": "*" }, { "Sid": "DenyAnalytics", "Effect": "Deny", "Action": [ "states:CreateStateMachine", "glue:CreateJob", "glue:CreateCrawler", "athena:CreateWorkGroup", "appsync:CreateGraphqlApi", "appflow:CreateFlow", "datazone:CreateDomain", "datazone:CreateProject", "entityresolution:CreateMatchingWorkflow", "datapipeline:CreatePipeline", "dataexchange:CreateDataSet" ], "Resource": "*" }, { "Sid": "DenyDevTools", "Effect": "Deny", "Action": [ "amplify:CreateApp", "amplify:CreateBranch", "cloud9:CreateEnvironmentEC2", "codebuild:CreateProject", "codepipeline:CreatePipeline", "codedeploy:CreateApplication", "cloudformation:CreateStack", "cloudformation:CreateStackSet", "codeartifact:CreateRepository", "codeartifact:CreateDomain" ], "Resource": "*" }, { "Sid": "DenySecurity", "Effect": "Deny", "Action": [ "kms:CreateKey", "wafv2:CreateWebACL", "cloudhsm:CreateCluster", "network-firewall:CreateFirewall", "secretsmanager:CreateSecret", "acm-pca:CreateCertificateAuthority", "cognito-idp:CreateUserPool", "cognito-identity:CreateIdentityPool", "ds:CreateDirectory", "ds:CreateMicrosoftAD", "fms:PutPolicy", "payment-cryptography:CreateKey" ], "Resource": "*" }, { "Sid": "DenyMedia", "Effect": "Deny", "Action": [ "medialive:CreateChannel", "mediapackage:CreateChannel", "mediaconnect:CreateFlow", "mediatailor:CreateChannel" ], "Resource": "*" }, { "Sid": "DenyIoT", "Effect": "Deny", "Action": [ "iot:CreateThing", "iot:CreateTopicRule", "iotevents:CreateDetectorModel", "iottwinmaker:CreateWorkspace", "iotsitewise:CreateAssetModel", "iotsitewise:CreatePortal", "iotfleetwise:CreateCampaign" ], "Resource": "*" }, { "Sid": "DenyMisc", "Effect": "Deny", "Action": [ "ses:CreateConfigurationSet", "ecr:CreateRepository", "aps:CreateWorkspace", "healthlake:CreateFHIRDatastore", "transfer:CreateServer", "managedblockchain:CreateNetwork", "managedblockchain:CreateMember", "route53-recovery-control-config:CreateCluster", "fis:CreateExperimentTemplate", "appfabric:CreateAppBundle", "appfabric:CreateIngestion", "b2bi:CreateProfile", "b2bi:CreateTransformer", "geo:CreateMap", "geo:CreatePlaceIndex", "geo:CreateTracker", "geo:CreateGeofenceCollection", "geo:CreateRouteCalculator" ], "Resource": "*" } ] }
Richtlinien zur Ressourcenkontrolle für Projekte
Im Folgenden finden Sie die Richtlinien zur Ressourcenkontrolle für die Ressourcen im Projekt. Diese Richtlinie kann nicht geändert werden:
{ "Version" : "2012-10-17", "Statement" : [ { "Sid" : "DenyAnyoneOutsideMyOrgAndAWS", "Effect" : "Deny", "Principal" : "*", "Action" : [ "aoss:*", "appconfig:*", "appstream:*", "autoscaling:*", "codebuild:*", "codecommit:*", "cognito-identity:*", "cognito-idp:*", "comprehend:*", "comprehendmedical:*", "dax:*", "dynamodb:*", "ecr:*", "health:*", "kinesisvideo:*", "kms:*", "logs:*", "s3:*", "secretsmanager:*", "sqs:*", "sts:*", "support:*", "textract:*", "transcribe:*", "translate:*" ], "Resource" : "*", "Condition" : { "BoolIfExists" : { "aws:PrincipalIsAWSService" : "false" }, "Null" : { "aws:PrincipalARN" : "false" }, "StringNotEqualsIfExists" : { "aws:PrincipalOrgID" : "${aws:ResourceOrgID}" } } }, { "Sid" : "DenyAWSWhenItsNotMyOrgsSourceAccount", "Effect" : "Deny", "Principal" : "*", "Action" : [ "aoss:*", "appconfig:*", "appstream:*", "autoscaling:*", "codebuild:*", "codecommit:*", "cognito-identity:*", "cognito-idp:*", "comprehend:*", "comprehendmedical:*", "dax:*", "dynamodb:*", "ecr:*", "health:*", "kinesisvideo:*", "kms:*", "logs:*", "s3:*", "secretsmanager:*", "sqs:*", "sts:*", "support:*", "textract:*", "transcribe:*", "translate:*" ], "Resource" : "*", "Condition" : { "Null" : { "aws:SourceAccount" : "false" }, "StringNotEquals" : { "aws:SourceOrgID" : "${aws:ResourceOrgID}" } } } ] }