AWSMigrationHubStrategyCollector - AWS 托管策略

本文属于机器翻译版本。若本译文内容与英语原文存在差异,则一律以英文原文为准。

AWSMigrationHubStrategyCollector

描述:授予权限以允许与 Migration Hub 策略建议服务进行通信、对与该 AWS 服务相关的 S3 存储桶进行读/写访问权限、向其上传日志和指标的 Amazon API Gateway、S AWS ecrets Manager 获取证书的访问权限以及任何相关服务。 AWS

AWSMigrationHubStrategyCollector是一个AWS 托管策略

使用此策略

您可以将 AWSMigrationHubStrategyCollector 附加到您的用户、组和角色。

策略详细信息

  • 类型: AWS 托管策略

  • 创建时间:2021 年 10 月 19 日 20:15 UTC

  • 编辑时间:世界标准时间 2024 年 4 月 1 日 16:21

  • ARN: arn:aws:iam::aws:policy/AWSMigrationHubStrategyCollector

策略版本

策略版本:v6(默认)

此策略的默认版本是定义策略权限的版本。当使用该策略的用户或角色请求访问 AWS 资源时, AWS 会检查策略的默认版本以确定是否允许该请求。

JSON 策略文档

{ "Version" : "2012-10-17", "Statement" : [ { "Sid" : "MHSRAllowS3Resources", "Effect" : "Allow", "Action" : [ "s3:GetObject", "s3:PutObject", "s3:GetBucketAcl", "s3:CreateBucket", "s3:PutEncryptionConfiguration", "s3:PutBucketPublicAccessBlock", "s3:PutBucketVersioning", "s3:PutLifecycleConfiguration", "s3:ListBucket", "s3:GetBucketLocation" ], "Resource" : "arn:aws:s3:::migrationhub-strategy-*", "Condition" : { "StringEquals" : { "aws:ResourceAccount" : "${aws:PrincipalAccount}" } } }, { "Sid" : "MHSRAllowS3ListBucket", "Effect" : "Allow", "Action" : [ "s3:ListAllMyBuckets" ], "Resource" : "arn:aws:s3:::*", "Condition" : { "StringEquals" : { "aws:ResourceAccount" : "${aws:PrincipalAccount}" } } }, { "Sid" : "MHSRAllowMetricsAndLogs", "Effect" : "Allow", "Action" : [ "application-transformation:PutMetricData", "application-transformation:PutLogData", "application-transformation:StartPortingCompatibilityAssessment", "application-transformation:GetPortingCompatibilityAssessment", "application-transformation:StartPortingRecommendationAssessment", "application-transformation:GetPortingRecommendationAssessment" ], "Resource" : "*" }, { "Sid" : "MHSRAllowExecuteAPI", "Effect" : "Allow", "Action" : [ "execute-api:Invoke", "execute-api:ManageConnections" ], "Resource" : [ "arn:aws:execute-api:*:*:*/prod/*/put-log-data", "arn:aws:execute-api:*:*:*/prod/*/put-metric-data" ] }, { "Sid" : "MHSRAllowCollectorAPI", "Effect" : "Allow", "Action" : [ "migrationhub-strategy:RegisterCollector", "migrationhub-strategy:GetAntiPattern", "migrationhub-strategy:GetMessage", "migrationhub-strategy:SendMessage", "migrationhub-strategy:ListAntiPatterns", "migrationhub-strategy:ListJarArtifacts", "migrationhub-strategy:UpdateCollectorConfiguration", "migrationhub-strategy:PutLogData", "migrationhub-strategy:PutMetricData" ], "Resource" : "arn:aws:migrationhub-strategy:*:*:*" }, { "Sid" : "MHSRAllowSecretsManager", "Effect" : "Allow", "Action" : [ "secretsmanager:GetSecretValue" ], "Resource" : "arn:aws:secretsmanager:*:*:secret:migrationhub-strategy-*", "Condition" : { "StringEquals" : { "aws:ResourceAccount" : "${aws:PrincipalAccount}" } } } ] }

了解更多信息