Les traductions sont fournies par des outils de traduction automatique. En cas de conflit entre le contenu d'une traduction et celui de la version originale en anglais, la version anglaise prévaudra.
AWS politique gérée : AmazonDataZoneRedshiftManageAccessRolePolicy
Cette politique autorise Amazon DataZone à publier les données Amazon Redshift dans le catalogue. Cela donne également à Amazon l' DataZone autorisation d'accorder ou de révoquer l'accès aux ressources publiées par Amazon Redshift ou Amazon Redshift Serverless dans le catalogue.
{ "Version": "2012-10-17", "Statement": [ { "Sid": "redshiftDataScopeDownPermissions", "Effect": "Allow", "Action": [ "redshift-data:BatchExecuteStatement", "redshift-data:DescribeTable", "redshift-data:ExecuteStatement", "redshift-data:ListTables", "redshift-data:ListSchemas", "redshift-data:ListDatabases" ], "Resource": [ "arn:aws:redshift-serverless:*:*:workgroup/*", "arn:aws:redshift:*:*:cluster:*" ], "Condition": { "StringEquals": { "aws:ResourceAccount": "${aws:PrincipalAccount}" } } }, { "Sid": "listSecretsPermission", "Effect": "Allow", "Action": "secretsmanager:ListSecrets", "Resource": "*" }, { "Sid": "getWorkgroupPermission", "Effect": "Allow", "Action": "redshift-serverless:GetWorkgroup", "Resource": [ "arn:aws:redshift-serverless:*:*:workgroup/*" ], "Condition": { "StringEquals": { "aws:ResourceAccount": "${aws:PrincipalAccount}" } } }, { "Sid": "getNamespacePermission", "Effect": "Allow", "Action": "redshift-serverless:GetNamespace", "Resource": [ "arn:aws:redshift-serverless:*:*:namespace/*" ], "Condition": { "StringEquals": { "aws:ResourceAccount": "${aws:PrincipalAccount}" } } }, { "Sid": "redshiftDataPermissions", "Effect": "Allow", "Action": [ "redshift-data:DescribeStatement", "redshift-data:GetStatementResult", "redshift:DescribeClusters" ], "Resource": "*" }, { "Sid": "dataSharesPermissions", "Effect": "Allow", "Action": [ "redshift:AuthorizeDataShare", "redshift:DescribeDataShares" ], "Resource": [ "arn:aws:redshift:*:*:datashare:*/datazone*" ], "Condition": { "StringEquals": { "aws:ResourceAccount": "${aws:PrincipalAccount}" } } }, { "Sid": "associateDataShareConsumerPermission", "Effect": "Allow", "Action": "redshift:AssociateDataShareConsumer", "Resource": "arn:aws:redshift:*:*:datashare:*/datazone*" } ] }