本文属于机器翻译版本。若本译文内容与英语原文存在差异,则一律以英文原文为准。
AWSThinkboxDeadlineResourceTrackerAccessPolicy
描述:授予运行 AWS Thinkbox 的截止日期资源跟踪器所需的权限。这包括对某些 EC2 操作的完全访问权限,包括 DeleteFleets 和 CancelSpotFleetRequests。
AWSThinkboxDeadlineResourceTrackerAccessPolicy
是一项 AWS 托管式策略。
使用此策略
您可以将 AWSThinkboxDeadlineResourceTrackerAccessPolicy
附加到您的用户、组和角色。
策略详细信息
-
类型: AWS 托管策略
-
创建时间:2020 年 5 月 27 日 19:25 UTC
-
编辑时间:2020 年 5 月 27 日 19:25 UTC
-
ARN:
arn:aws:iam::aws:policy/AWSThinkboxDeadlineResourceTrackerAccessPolicy
策略版本
策略版本:v1 (默认值)
此策略的默认版本是定义策略权限的版本。当使用该策略的用户或角色请求访问 AWS 资源时, AWS 会检查策略的默认版本以确定是否允许该请求。
JSON 策略文档
{
"Version" : "2012-10-17",
"Statement" : [
{
"Effect" : "Allow",
"Action" : [
"dynamodb:ListStreams"
],
"Resource" : [
"*"
]
},
{
"Effect" : "Allow",
"Action" : [
"dynamodb:BatchWriteItem",
"dynamodb:DeleteItem",
"dynamodb:DescribeStream",
"dynamodb:DescribeTable",
"dynamodb:GetItem",
"dynamodb:GetRecords",
"dynamodb:GetShardIterator",
"dynamodb:PutItem",
"dynamodb:Scan",
"dynamodb:UpdateItem",
"dynamodb:UpdateTable"
],
"Resource" : [
"arn:aws:dynamodb:*:*:table/DeadlineEC2ComputeNodeHealth*",
"arn:aws:dynamodb:*:*:table/DeadlineEC2ComputeNodeInfo*",
"arn:aws:dynamodb:*:*:table/DeadlineFleetHealth*"
]
},
{
"Effect" : "Allow",
"Action" : [
"ec2:CancelSpotFleetRequests",
"ec2:DeleteFleets",
"ec2:DescribeFleetInstances",
"ec2:DescribeFleets",
"ec2:DescribeInstances",
"ec2:DescribeSpotFleetInstances",
"ec2:DescribeSpotFleetRequests"
],
"Resource" : [
"*"
]
},
{
"Effect" : "Allow",
"Action" : [
"ec2:RebootInstances",
"ec2:TerminateInstances"
],
"Resource" : [
"arn:aws:ec2:*:*:instance/*"
],
"Condition" : {
"StringLike" : {
"ec2:ResourceTag/DeadlineTrackedAWSResource" : "*"
}
}
},
{
"Effect" : "Allow",
"Action" : [
"events:PutEvents"
],
"Resource" : [
"arn:aws:events:*:*:event-bus/default"
]
},
{
"Effect" : "Allow",
"Action" : [
"lambda:InvokeFunction"
],
"Resource" : [
"arn:aws:lambda:*:*:function:DeadlineResourceTracker*"
]
},
{
"Effect" : "Allow",
"Action" : [
"logs:CreateLogGroup"
],
"Resource" : [
"*"
]
},
{
"Effect" : "Allow",
"Action" : [
"logs:CreateLogStream",
"logs:PutLogEvents"
],
"Resource" : [
"arn:aws:logs:*:*:log-group:/aws/lambda/DeadlineResourceTracker*"
]
},
{
"Effect" : "Allow",
"Action" : [
"sqs:DeleteMessage",
"sqs:GetQueueAttributes",
"sqs:ReceiveMessage"
],
"Resource" : [
"arn:aws:sqs:*:*:DeadlineAWSComputeNodeStateMessageQueue*"
]
}
]
}