View a markdown version of this page

Actions, resources, and condition keys for AWS AppConfig - Service Authorization Reference

Actions, resources, and condition keys for AWS AppConfig

AWS AppConfig (service prefix: appconfig) provides the following service-specific operations, resources, actions, and condition keys for use in IAM permission policies.

References:

API operations defined by AWS AppConfig

The following table maps API operations to the IAM actions they authorize. Only condition keys that have static values for the given API and action are listed; for the full set of condition keys supported by each action, see the Actions table.

Operation SDK client IAM action Condition key Possible value(s) Access level

CreateApplication

appconfig

appconfig:CreateApplication

Write

appconfig:TagResource

Tagging, Write

CreateConfigurationProfile

appconfig

appconfig:CreateConfigurationProfile

Write

appconfig:TagResource

Tagging, Write

iam:PassRole

iam:PassedToService

appconfig.amazonaws.com

Write

CreateDeploymentStrategy

appconfig

appconfig:CreateDeploymentStrategy

Write

appconfig:TagResource

Tagging, Write

CreateEnvironment

appconfig

appconfig:CreateEnvironment

Write

appconfig:TagResource

Tagging, Write

iam:PassRole

iam:PassedToService

appconfig.amazonaws.com

Write

CreateExperimentDefinition

appconfig

appconfig:CreateExperimentDefinition

Write

appconfig:TagResource

Tagging, Write

CreateExtension

appconfig

appconfig:CreateExtension

Write

appconfig:TagResource

Tagging, Write

iam:PassRole

iam:PassedToService

appconfig.amazonaws.com

Write

CreateExtensionAssociation

appconfig

appconfig:CreateExtensionAssociation

Write

appconfig:TagResource

Tagging, Write

CreateHostedConfigurationVersion

appconfig

appconfig:CreateHostedConfigurationVersion

Write

DeleteApplication

appconfig

appconfig:DeleteApplication

Write

DeleteConfigurationProfile

appconfig

appconfig:DeleteConfigurationProfile

Write

DeleteDeploymentStrategy

appconfig

appconfig:DeleteDeploymentStrategy

Write

DeleteEnvironment

appconfig

appconfig:DeleteEnvironment

Write

DeleteExperimentDefinition

appconfig

appconfig:DeleteExperimentDefinition

Write

DeleteExtension

appconfig

appconfig:DeleteExtension

Write

DeleteExtensionAssociation

appconfig

appconfig:DeleteExtensionAssociation

Write

DeleteHostedConfigurationVersion

appconfig

appconfig:DeleteHostedConfigurationVersion

Write

GetAccountSettings

appconfig

appconfig:GetAccountSettings

Read

GetApplication

appconfig

appconfig:GetApplication

Read

GetConfiguration

appconfig

appconfig:GetConfiguration

Read

GetConfigurationProfile

appconfig

appconfig:GetConfigurationProfile

Read

GetDeployment

appconfig

appconfig:GetDeployment

Read

GetDeploymentStrategy

appconfig

appconfig:GetDeploymentStrategy

Read

GetEnvironment

appconfig

appconfig:GetEnvironment

Read

GetExperimentDefinition

appconfig

appconfig:GetExperimentDefinition

Read

GetExperimentRun

appconfig

appconfig:GetExperimentRun

Read

GetExtension

appconfig

appconfig:GetExtension

Read

GetExtensionAssociation

appconfig

appconfig:GetExtensionAssociation

Read

GetHostedConfigurationVersion

appconfig

appconfig:GetHostedConfigurationVersion

Read

ListApplications

appconfig

appconfig:ListApplications

List

ListConfigurationProfiles

appconfig

appconfig:ListConfigurationProfiles

List

ListDeploymentStrategies

appconfig

appconfig:ListDeploymentStrategies

List

ListDeployments

appconfig

appconfig:ListDeployments

List

ListEnvironments

appconfig

appconfig:ListEnvironments

List

ListExperimentDefinitions

appconfig

appconfig:ListExperimentDefinitions

List

ListExperimentRunEvents

appconfig

appconfig:ListExperimentRunEvents

List

ListExperimentRuns

appconfig

appconfig:ListExperimentRuns

List

ListExtensionAssociations

appconfig

appconfig:ListExtensionAssociations

List

ListExtensions

appconfig

appconfig:ListExtensions

List

ListHostedConfigurationVersions

appconfig

appconfig:ListHostedConfigurationVersions

List

ListTagsForResource

appconfig

appconfig:ListTagsForResource

Read

StartDeployment

appconfig

appconfig:StartDeployment

Write

appconfig:TagResource

Tagging, Write

StartExperimentRun

appconfig

appconfig:StartExperimentRun

Write

appconfig:TagResource

Tagging, Write

StopDeployment

appconfig

appconfig:StopDeployment

Write

StopExperimentRun

appconfig

appconfig:StopExperimentRun

Write

TagResource

appconfig

appconfig:TagResource

Tagging, Write

UntagResource

appconfig

appconfig:UntagResource

Tagging, Write

UpdateAccountSettings

appconfig

appconfig:UpdateAccountSettings

Write

UpdateApplication

appconfig

appconfig:UpdateApplication

Write

UpdateConfigurationProfile

appconfig

appconfig:UpdateConfigurationProfile

Write

iam:PassRole

iam:PassedToService

appconfig.amazonaws.com

Write

UpdateDeploymentStrategy

appconfig

appconfig:UpdateDeploymentStrategy

Write

UpdateEnvironment

appconfig

appconfig:UpdateEnvironment

Write

iam:PassRole

iam:PassedToService

appconfig.amazonaws.com

Write

UpdateExperimentDefinition

appconfig

appconfig:UpdateExperimentDefinition

Write

UpdateExperimentRun

appconfig

appconfig:UpdateExperimentRun

Write

UpdateExtension

appconfig

appconfig:UpdateExtension

Write

iam:PassRole

iam:PassedToService

appconfig.amazonaws.com

Write

UpdateExtensionAssociation

appconfig

appconfig:UpdateExtensionAssociation

Write

ValidateConfiguration

appconfig

appconfig:ValidateConfiguration

Write

GetLatestConfiguration

appconfigdata

appconfig:GetLatestConfiguration

Read

StartConfigurationSession

appconfigdata

appconfig:StartConfigurationSession

Write

Actions defined by AWS AppConfig

You can specify the following actions in the Action element of an IAM policy statement. Use policies to grant permissions to perform an operation in AWS. When you use an action in a policy, you usually allow or deny access to the API operation or CLI command with the same name. However, in some cases, a single action controls access to more than one operation. Alternatively, some operations require several different actions.

Actions Description Resource types (*required) Condition keys Access level

CreateApplication

Grants permission to create an application

aws:RequestTag/${TagKey}

aws:TagKeys

Write

CreateConfigurationProfile

Grants permission to create a configuration profile

application*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

CreateDeploymentStrategy

Grants permission to create a deployment strategy

aws:RequestTag/${TagKey}

aws:TagKeys

Write

CreateEnvironment

Grants permission to create an environment

application*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

CreateExperimentDefinition

Grants permission to create an experiment definition

application*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

CreateExtension

Grants permission to create an extension

aws:RequestTag/${TagKey}

aws:TagKeys

Write

CreateExtensionAssociation

Grants permission to create an extension association

aws:RequestTag/${TagKey}

aws:TagKeys

Write

CreateHostedConfigurationVersion

Grants permission to create a hosted configuration version

application*

aws:ResourceTag/${TagKey}

Write

configurationprofile*

aws:ResourceTag/${TagKey}

DeleteApplication

Grants permission to delete an application

application*

aws:ResourceTag/${TagKey}

Write

DeleteConfigurationProfile

Grants permission to delete a configuration profile

application*

aws:ResourceTag/${TagKey}

Write

configurationprofile*

aws:ResourceTag/${TagKey}

DeleteDeploymentStrategy

Grants permission to delete a deployment strategy

deploymentstrategy*

aws:ResourceTag/${TagKey}

Write

DeleteEnvironment

Grants permission to delete an environment

application*

aws:ResourceTag/${TagKey}

Write

environment*

aws:ResourceTag/${TagKey}

DeleteExperimentDefinition

Grants permission to delete an experiment definition

application*

aws:ResourceTag/${TagKey}

Write

experimentdefinition*

aws:ResourceTag/${TagKey}

DeleteExtension

Grants permission to delete an extension

extension*

aws:ResourceTag/${TagKey}

Write

DeleteExtensionAssociation

Grants permission to delete an extension association

extensionassociation*

aws:ResourceTag/${TagKey}

Write

DeleteHostedConfigurationVersion

Grants permission to delete a hosted configuration version

application*

aws:ResourceTag/${TagKey}

Write

configurationprofile*

aws:ResourceTag/${TagKey}

hostedconfigurationversion*

GetAccountSettings

Grants permission to view account-wide AppConfig settings

Read

GetApplication

Grants permission to view details about an application

application*

aws:ResourceTag/${TagKey}

Read

GetConfiguration

Grants permission to view details about a configuration

application*

aws:ResourceTag/${TagKey}

Read

configurationprofile*

aws:ResourceTag/${TagKey}

environment*

aws:ResourceTag/${TagKey}

GetConfigurationProfile

Grants permission to view details about a configuration profile

application*

aws:ResourceTag/${TagKey}

Read

configurationprofile*

aws:ResourceTag/${TagKey}

GetDeployment

Grants permission to view details about a deployment

application*

aws:ResourceTag/${TagKey}

Read

deployment*

aws:ResourceTag/${TagKey}

environment*

aws:ResourceTag/${TagKey}

GetDeploymentStrategy

Grants permission to view details about a deployment strategy

deploymentstrategy*

aws:ResourceTag/${TagKey}

Read

GetEnvironment

Grants permission to view details about an environment

application*

aws:ResourceTag/${TagKey}

Read

environment*

aws:ResourceTag/${TagKey}

GetExperimentDefinition

Grants permission to view details about an experiment definition

application*

aws:ResourceTag/${TagKey}

Read

experimentdefinition*

aws:ResourceTag/${TagKey}

GetExperimentRun

Grants permission to view details about an experiment run

application*

aws:ResourceTag/${TagKey}

Read

experimentdefinition*

aws:ResourceTag/${TagKey}

experimentrun*

aws:ResourceTag/${TagKey}

GetExtension

Grants permission to view details about an extension

extension*

aws:ResourceTag/${TagKey}

Read

GetExtensionAssociation

Grants permission to view details about an extension association

extensionassociation*

aws:ResourceTag/${TagKey}

Read

GetHostedConfigurationVersion

Grants permission to view details about a hosted configuration version

application*

aws:ResourceTag/${TagKey}

Read

configurationprofile*

aws:ResourceTag/${TagKey}

hostedconfigurationversion*

GetLatestConfiguration

Grants permission to retrieve a deployed configuration

configuration*

aws:ResourceTag/${TagKey}

Read

ListApplications

Grants permission to list the applications in your account

List

ListConfigurationProfiles

Grants permission to list the configuration profiles for an application

application*

aws:ResourceTag/${TagKey}

List

ListDeploymentStrategies

Grants permission to list the deployment strategies for your account

List

ListDeployments

Grants permission to list the deployments for an environment

application*

aws:ResourceTag/${TagKey}

List

environment*

aws:ResourceTag/${TagKey}

ListEnvironments

Grants permission to list the environments for an application

application*

aws:ResourceTag/${TagKey}

List

ListExperimentDefinitions

Grants permission to list the experiment definitions in your account

List

ListExperimentRunEvents

Grants permission to list the events for an experiment run

application*

aws:ResourceTag/${TagKey}

List

experimentdefinition*

aws:ResourceTag/${TagKey}

experimentrun*

aws:ResourceTag/${TagKey}

ListExperimentRuns

Grants permission to list the experiment runs for an experiment definition

application*

aws:ResourceTag/${TagKey}

List

experimentdefinition*

aws:ResourceTag/${TagKey}

ListExtensionAssociations

Grants permission to list the extension associations in your account

List

ListExtensions

Grants permission to list the extensions in your account

List

ListHostedConfigurationVersions

Grants permission to list the hosted configuration versions for a configuration profile

application*

aws:ResourceTag/${TagKey}

List

configurationprofile*

aws:ResourceTag/${TagKey}

ListTagsForResource

Grants permission to view a list of resource tags for a specified resource

application

aws:ResourceTag/${TagKey}

Read

configurationprofile

aws:ResourceTag/${TagKey}

deployment

aws:ResourceTag/${TagKey}

deploymentstrategy

aws:ResourceTag/${TagKey}

environment

aws:ResourceTag/${TagKey}

experimentdefinition

aws:ResourceTag/${TagKey}

experimentrun

aws:ResourceTag/${TagKey}

extension

aws:ResourceTag/${TagKey}

extensionassociation

aws:ResourceTag/${TagKey}

StartConfigurationSession

Grants permission to start a configuration session

configuration*

aws:ResourceTag/${TagKey}

Write

StartDeployment

Grants permission to initiate a deployment

application*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

configurationprofile*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

deploymentstrategy*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

environment*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

StartExperimentRun

Grants permission to start an experiment run

application*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

experimentdefinition*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

StopDeployment

Grants permission to stop a deployment

application*

aws:ResourceTag/${TagKey}

Write

deployment*

aws:ResourceTag/${TagKey}

environment*

aws:ResourceTag/${TagKey}

StopExperimentRun

Grants permission to stop an experiment run

application*

aws:ResourceTag/${TagKey}

Write

experimentdefinition*

aws:ResourceTag/${TagKey}

experimentrun*

aws:ResourceTag/${TagKey}

TagResource

Grants permission to tag an appconfig resource

application

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Tagging, Write

configuration

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

configurationprofile

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

deployment

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

deploymentstrategy

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

environment

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

experimentdefinition

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

experimentrun

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

extension

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

extensionassociation

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

UntagResource

Grants permission to untag an appconfig resource

application

aws:ResourceTag/${TagKey}

aws:TagKeys

Tagging, Write

configuration

aws:ResourceTag/${TagKey}

aws:TagKeys

configurationprofile

aws:ResourceTag/${TagKey}

aws:TagKeys

deployment

aws:ResourceTag/${TagKey}

aws:TagKeys

deploymentstrategy

aws:ResourceTag/${TagKey}

aws:TagKeys

environment

aws:ResourceTag/${TagKey}

aws:TagKeys

experimentdefinition

aws:ResourceTag/${TagKey}

aws:TagKeys

experimentrun

aws:ResourceTag/${TagKey}

aws:TagKeys

extension

aws:ResourceTag/${TagKey}

aws:TagKeys

extensionassociation

aws:ResourceTag/${TagKey}

aws:TagKeys

UpdateAccountSettings

Grants permission to modify account-wide AppConfig settings

Write

UpdateApplication

Grants permission to modify an application

application*

aws:ResourceTag/${TagKey}

Write

UpdateConfigurationProfile

Grants permission to modify a configuration profile

application*

aws:ResourceTag/${TagKey}

Write

configurationprofile*

aws:ResourceTag/${TagKey}

UpdateDeploymentStrategy

Grants permission to modify a deployment strategy

deploymentstrategy*

aws:ResourceTag/${TagKey}

Write

UpdateEnvironment

Grants permission to modify an environment

application*

aws:ResourceTag/${TagKey}

Write

environment*

aws:ResourceTag/${TagKey}

UpdateExperimentDefinition

Grants permission to modify an experiment definition

application*

aws:ResourceTag/${TagKey}

Write

experimentdefinition*

aws:ResourceTag/${TagKey}

UpdateExperimentRun

Grants permission to modify an experiment run

application*

aws:ResourceTag/${TagKey}

Write

experimentdefinition*

aws:ResourceTag/${TagKey}

experimentrun*

aws:ResourceTag/${TagKey}

UpdateExtension

Grants permission to modify an extension

extension*

aws:ResourceTag/${TagKey}

Write

UpdateExtensionAssociation

Grants permission to modify an extension association

extensionassociation*

aws:ResourceTag/${TagKey}

Write

ValidateConfiguration

Grants permission to validate a configuration

application*

aws:ResourceTag/${TagKey}

Write

configurationprofile*

aws:ResourceTag/${TagKey}

Resource types defined by AWS AppConfig

The following resource types are defined by this service and can be used in the Resource element of IAM permission policy statements.

Resource types ARN Condition keys

application

arn:${Partition}:appconfig:${Region}:${Account}:application/${ApplicationId}

aws:ResourceTag/${TagKey}

configuration

arn:${Partition}:appconfig:${Region}:${Account}:application/${ApplicationId}/environment/${EnvironmentId}/configuration/${ConfigurationProfileId}

aws:ResourceTag/${TagKey}

configurationprofile

arn:${Partition}:appconfig:${Region}:${Account}:application/${ApplicationId}/configurationprofile/${ConfigurationProfileId}

aws:ResourceTag/${TagKey}

deployment

arn:${Partition}:appconfig:${Region}:${Account}:application/${ApplicationId}/environment/${EnvironmentId}/deployment/${DeploymentNumber}

aws:ResourceTag/${TagKey}

deploymentstrategy

arn:${Partition}:appconfig:${Region}:${Account}:deploymentstrategy/${DeploymentStrategyId}

aws:ResourceTag/${TagKey}

environment

arn:${Partition}:appconfig:${Region}:${Account}:application/${ApplicationId}/environment/${EnvironmentId}

aws:ResourceTag/${TagKey}

experimentdefinition

arn:${Partition}:appconfig:${Region}:${Account}:application/${ApplicationId}/experimentdefinition/${ExperimentDefinitionId}

aws:ResourceTag/${TagKey}

experimentrun

arn:${Partition}:appconfig:${Region}:${Account}:application/${ApplicationId}/experimentdefinition/${ExperimentDefinitionId}/experimentrun/${ExperimentRunNumber}

aws:ResourceTag/${TagKey}

extension

arn:${Partition}:appconfig:${Region}:${Account}:extension/${ExtensionId}/${ExtensionVersionNumber}

aws:ResourceTag/${TagKey}

extensionassociation

arn:${Partition}:appconfig:${Region}:${Account}:extensionassociation/${ExtensionAssociationId}

aws:ResourceTag/${TagKey}

hostedconfigurationversion

arn:${Partition}:appconfig:${Region}:${Account}:application/${ApplicationId}/configurationprofile/${ConfigurationProfileId}

Condition keys for AWS AppConfig

AWS AppConfig defines the following condition keys that can be used in the Condition element of an IAM policy.

Condition keys Description Type

aws:RequestTag/${TagKey}

Filters access by the allowed set of values for a specified tag

String

aws:ResourceTag/${TagKey}

Filters access by a tag key-value pair assigned to the AWS resource

String

aws:TagKeys

Filters access by a list of tag keys that are allowed in the request

ArrayOfString