View a markdown version of this page

Izin API Lattice Amazon VPC - Amazon VPC Lattice

Terjemahan disediakan oleh mesin penerjemah. Jika konten terjemahan yang diberikan bertentangan dengan versi bahasa Inggris aslinya, utamakan versi bahasa Inggris.

Izin API Lattice Amazon VPC

Anda harus memberikan identitas IAM (seperti pengguna atau peran) izin untuk memanggil tindakan API VPC Lattice yang mereka butuhkan, seperti yang dijelaskan dalam. Tindakan kebijakan untuk VPC Lattice Selain itu, untuk beberapa tindakan VPC Lattice, Anda harus memberikan izin identitas IAM untuk memanggil tindakan tertentu dari API lain AWS .

Izin yang diperlukan untuk API

Saat memanggil tindakan berikut dari API, Anda harus memberikan izin kepada pengguna IAM untuk memanggil tindakan yang ditentukan.

CreateResourceConfiguration
  • vpc-lattice:CreateResourceConfiguration

  • ec2:DescribeSubnets

  • rds:DescribeDBInstances

  • rds:DescribeDBClusters

CreateResourceGateway
  • vpc-lattice:CreateResourceGateway

  • ec2:AssignPrivateIpAddresses

  • ec2:AssignIpv6Addresses

  • ec2:CreateNetworkInterface

  • ec2:CreateNetworkInterfacePermission

  • ec2:DeleteNetworkInterface

  • ec2:DescribeNetworkInterfaces

  • ec2:DescribeSecurityGroups

  • ec2:DescribeSubnets

DeleteResourceGateway
  • vpc-lattice:DeleteResourceGateway

  • ec2:DeleteNetworkInterface

UpdateResourceGateway
  • vpc-lattice:UpdateResourceGateway

  • ec2:AssignPrivateIpAddresses

  • ec2:AssignIpv6Addresses

  • ec2:UnassignPrivateIpAddresses

  • ec2:CreateNetworkInterface

  • ec2:CreateNetworkInterfacePermission

  • ec2:DeleteNetworkInterface

  • ec2:DescribeNetworkInterfaces

  • ec2:DescribeSecurityGroups

  • ec2:DescribeSubnets

  • ec2:ModifyNetworkInterfaceAttribute

CreateServiceNetworkResourceAssociation
  • vpc-lattice:CreateServiceNetworkResourceAssociation

  • ec2:AssignIpv6Addresses

  • ec2:CreateNetworkInterface

  • ec2:CreateNetworkInterfacePermission

  • ec2:DescribeNetworkInterfaces

CreateServiceNetworkVpcAssociation
  • vpc-lattice:CreateServiceNetworkVpcAssociation

  • ec2:DescribeVpcs

  • ec2:DescribeSecurityGroups(Hanya diperlukan ketika grup keamanan disediakan)

UpdateServiceNetworkVpcAssociation
  • vpc-lattice:UpdateServiceNetworkVpcAssociation

  • ec2:DescribeSecurityGroups(Hanya diperlukan ketika grup keamanan disediakan)

CreateTargetGroup
  • vpc-lattice:CreateTargetGroup

  • ec2:DescribeVpcs

RegisterTargets
  • vpc-lattice:RegisterTargets

  • ec2:DescribeInstances(Hanya INSTANCE diperlukan kapan tipe kelompok sasaran)

  • ec2:DescribeVpcs(Hanya diperlukan ketika INSTANCE atau IP merupakan tipe kelompok sasaran)

  • ec2:DescribeSubnets(Hanya diperlukan ketika INSTANCE atau IP merupakan tipe kelompok sasaran)

  • lambda:GetFunction(Hanya LAMBDA diperlukan kapan tipe kelompok sasaran)

  • lambda:AddPermission(Hanya diperlukan jika kelompok target belum memiliki izin untuk memanggil fungsi Lambda yang ditentukan)

DeregisterTargets
  • vpc-lattice:DeregisterTargets

CreateAccessLogSubscription
  • vpc-lattice:CreateAccessLogSubscription

  • logs:GetLogDelivery

  • logs:CreateLogDelivery

DeleteAccessLogSubscription
  • vpc-lattice:DeleteAccessLogSubscription

  • logs:DeleteLogDelivery

UpdateAccessLogSubscription
  • vpc-lattice:UpdateAccessLogSubscription

  • logs:UpdateLogDelivery