View a markdown version of this page

AWSTransformLandingZoneAgentPolicy - AWS 托管策略

本文属于机器翻译版本。若本译文内容与英语原文存在差异,则一律以英文原文为准。

AWSTransformLandingZoneAgentPolicy

描述:授予T AWS ransform设置 AWS 登录区域的权限,包括账户配置、组织治理和控制塔配置

AWSTransformLandingZoneAgentPolicy 是一项 AWS 托管式策略。

使用此策略

您可以将 AWSTransformLandingZoneAgentPolicy 附加到您的用户、组和角色。

策略详细信息

  • 类型: AWS 托管策略

  • 创建时间:UTC 时间 2026 年 8 月 6 日 15:12

  • 编辑时间:世界标准时间 2026 年 9 月 1 日 10:27

  • ARN: arn:aws:iam::aws:policy/AWSTransformLandingZoneAgentPolicy

策略版本

策略版本:v2(默认)

此策略的默认版本是定义策略权限的版本。当具有该策略的用户或角色请求访问 AWS 资源时, AWS 会检查策略的默认版本以确定是否允许该请求。

JSON 策略文档

{ "Version" : "2012-10-17", "Statement" : [ { "Sid" : "S3LandingZoneBucketAndObjectOperations", "Effect" : "Allow", "Action" : [ "s3:AbortMultipartUpload", "s3:CreateBucket", "s3:DeleteObject", "s3:GetBucketLocation", "s3:GetBucketPublicAccessBlock", "s3:GetBucketTagging", "s3:GetObject", "s3:GetObjectAttributes", "s3:GetObjectVersion", "s3:ListBucket", "s3:ListBucketMultipartUploads", "s3:ListMultipartUploadParts", "s3:PutBucketPolicy", "s3:PutBucketTagging", "s3:PutEncryptionConfiguration", "s3:PutObject" ], "Resource" : "arn:aws:s3:::transform-vmware-landing-zone-*", "Condition" : { "StringEquals" : { "aws:ResourceAccount" : "${aws:PrincipalAccount}" } } }, { "Sid" : "CfnLandingZoneStackCreate", "Effect" : "Allow", "Action" : [ "cloudformation:CreateStack", "cloudformation:TagResource" ], "Resource" : "arn:aws:cloudformation:*:*:stack/AtxLz*", "Condition" : { "StringEquals" : { "aws:RequestTag/CreatedBy" : "AWSTransform", "aws:RequestedRegion" : "${aws:PrincipalTag/TargetRegion}", "aws:ResourceAccount" : "${aws:PrincipalAccount}" } } }, { "Sid" : "CfnLandingZoneStackUpdate", "Effect" : "Allow", "Action" : [ "cloudformation:UpdateStack" ], "Resource" : "arn:aws:cloudformation:*:*:stack/AtxLz*", "Condition" : { "StringEquals" : { "aws:RequestTag/CreatedBy" : "AWSTransform", "aws:RequestedRegion" : "${aws:PrincipalTag/TargetRegion}", "aws:ResourceTag/CreatedBy" : "AWSTransform", "aws:ResourceAccount" : "${aws:PrincipalAccount}" } } }, { "Sid" : "CfnLandingZoneStackOperationsAndChangeSets", "Effect" : "Allow", "Action" : [ "cloudformation:CreateChangeSet", "cloudformation:DescribeChangeSet", "cloudformation:DescribeStackEvents", "cloudformation:DescribeStacks", "cloudformation:ExecuteChangeSet", "cloudformation:GetTemplate", "cloudformation:ListChangeSets" ], "Resource" : "arn:aws:cloudformation:*:*:stack/AtxLz*", "Condition" : { "StringEquals" : { "aws:RequestedRegion" : "${aws:PrincipalTag/TargetRegion}", "aws:ResourceAccount" : "${aws:PrincipalAccount}" } } }, { "Sid" : "ControlTowerAndOrganizationsOperationsReadOnly", "Effect" : "Allow", "Action" : [ "controltower:GetBaselineOperation", "controltower:GetControlOperation", "controltower:ListBaselines", "controltower:ListEnabledBaselines", "controltower:ListEnabledControls", "controltower:ListLandingZones", "organizations:DescribeCreateAccountStatus", "organizations:DescribeOrganization", "organizations:ListPolicies", "organizations:ListRoots" ], "Resource" : "*" }, { "Sid" : "ControlTowerResourceOperationsReadOnly", "Effect" : "Allow", "Action" : [ "controltower:GetEnabledBaseline", "controltower:GetEnabledControl", "controltower:GetLandingZone", "controltower:ListTagsForResource" ], "Resource" : [ "arn:aws:controltower:*:*:enabledbaseline/*", "arn:aws:controltower:*:*:enabledcontrol/*", "arn:aws:controltower:*:*:landingzone/*" ], "Condition" : { "StringEquals" : { "aws:RequestedRegion" : "${aws:PrincipalTag/TargetRegion}", "aws:ResourceAccount" : "${aws:PrincipalAccount}" } } }, { "Sid" : "ControlTowerBaselineOperationsReadOnly", "Effect" : "Allow", "Action" : [ "controltower:GetBaseline" ], "Resource" : "arn:aws:controltower:*::baseline/*", "Condition" : { "StringEquals" : { "aws:RequestedRegion" : "${aws:PrincipalTag/TargetRegion}" } } }, { "Sid" : "ControlTowerEnableControlWithRequestTag", "Effect" : "Allow", "Action" : [ "controltower:EnableControl" ], "Resource" : "arn:aws:controltower:*:*:enabledcontrol/*", "Condition" : { "StringEquals" : { "aws:RequestTag/ATWorkspace" : "${aws:PrincipalTag/WorkspaceId}", "aws:RequestTag/CreatedBy" : "AWSTransform", "aws:RequestedRegion" : "${aws:PrincipalTag/TargetRegion}", "aws:ResourceAccount" : "${aws:PrincipalAccount}" } } }, { "Sid" : "ControlTowerEnableBaselineAndOrganizationsAccountCreate", "Effect" : "Allow", "Action" : [ "controltower:EnableBaseline", "controltower:TagResource", "organizations:CreateAccount" ], "Resource" : "*", "Condition" : { "StringEquals" : { "aws:RequestTag/ATWorkspace" : "${aws:PrincipalTag/WorkspaceId}", "aws:RequestTag/CreatedBy" : "AWSTransform" } } }, { "Sid" : "OrganizationsTagAndCreateOrganizationalUnit", "Effect" : "Allow", "Action" : [ "organizations:CreateOrganizationalUnit", "organizations:TagResource" ], "Resource" : [ "arn:aws:organizations::*:account/o-*/*", "arn:aws:organizations::*:ou/o-*/*", "arn:aws:organizations::*:policy/o-*/*", "arn:aws:organizations::*:root/o-*/*" ], "Condition" : { "StringEquals" : { "aws:RequestTag/ATWorkspace" : "${aws:PrincipalTag/WorkspaceId}", "aws:RequestTag/CreatedBy" : "AWSTransform", "aws:ResourceAccount" : "${aws:PrincipalAccount}" } } }, { "Sid" : "OrganizationsResourceDescribeReadOnly", "Effect" : "Allow", "Action" : [ "organizations:DescribeAccount", "organizations:DescribeOrganizationalUnit", "organizations:DescribePolicy" ], "Resource" : [ "arn:aws:organizations::*:account/*", "arn:aws:organizations::*:ou/*", "arn:aws:organizations::*:policy/*" ], "Condition" : { "StringEquals" : { "aws:ResourceAccount" : "${aws:PrincipalAccount}" } } }, { "Sid" : "OrganizationsPolicyUpdateViaControlTower", "Effect" : "Allow", "Action" : [ "organizations:UpdatePolicy" ], "Resource" : "arn:aws:organizations::*:policy/*", "Condition" : { "ForAnyValue:StringEquals" : { "aws:CalledVia" : "controltower.amazonaws.com" }, "StringEquals" : { "organizations:PolicyType" : "SERVICE_CONTROL_POLICY", "aws:ResourceAccount" : "${aws:PrincipalAccount}" } } }, { "Sid" : "OrganizationsHierarchyOperationsReadOnly", "Effect" : "Allow", "Action" : [ "organizations:ListAccountsForParent", "organizations:ListOrganizationalUnitsForParent", "organizations:ListParents" ], "Resource" : [ "arn:aws:organizations::*:account/*", "arn:aws:organizations::*:ou/*", "arn:aws:organizations::*:root/*" ], "Condition" : { "StringEquals" : { "aws:ResourceAccount" : "${aws:PrincipalAccount}" } } }, { "Sid" : "OrganizationsMoveAccountWithResourceTag", "Effect" : "Allow", "Action" : [ "organizations:MoveAccount" ], "Resource" : [ "arn:aws:organizations::*:account/*", "arn:aws:organizations::*:ou/*", "arn:aws:organizations::*:root/*" ], "Condition" : { "StringEquals" : { "aws:ResourceTag/ATWorkspace" : "${aws:PrincipalTag/WorkspaceId}", "aws:ResourceTag/CreatedBy" : "AWSTransform", "aws:ResourceAccount" : "${aws:PrincipalAccount}" } } }, { "Sid" : "OrganizationsListTagsForResource", "Effect" : "Allow", "Action" : [ "organizations:ListTagsForResource" ], "Resource" : [ "arn:aws:organizations::*:account/o-*/*", "arn:aws:organizations::*:ou/o-*/*", "arn:aws:organizations::*:policy/o-*/*", "arn:aws:organizations::*:root/o-*/*" ], "Condition" : { "StringEquals" : { "aws:ResourceAccount" : "${aws:PrincipalAccount}" } } }, { "Sid" : "OrganizationsServiceControlPolicyCreateViaControlTower", "Effect" : "Allow", "Action" : [ "organizations:CreatePolicy" ], "Resource" : "*", "Condition" : { "ForAnyValue:StringEquals" : { "aws:CalledVia" : "controltower.amazonaws.com" }, "StringEquals" : { "organizations:PolicyType" : "SERVICE_CONTROL_POLICY" } } }, { "Sid" : "OrganizationsServiceControlPolicyAttachViaControlTower", "Effect" : "Allow", "Action" : [ "organizations:AttachPolicy" ], "Resource" : [ "arn:aws:organizations::*:account/o-*/*", "arn:aws:organizations::*:ou/o-*/*", "arn:aws:organizations::*:policy/o-*/*", "arn:aws:organizations::*:root/o-*/*" ], "Condition" : { "ForAnyValue:StringEquals" : { "aws:CalledVia" : "controltower.amazonaws.com" }, "StringEquals" : { "organizations:PolicyType" : "SERVICE_CONTROL_POLICY", "aws:ResourceAccount" : "${aws:PrincipalAccount}" } } }, { "Sid" : "ServiceCatalogProvisioningArtifactOperations", "Effect" : "Allow", "Action" : [ "servicecatalog:CreateProvisioningArtifact", "servicecatalog:DeleteProvisioningArtifact", "servicecatalog:ListProvisioningArtifacts", "servicecatalog:UpdateProvisioningArtifact" ], "Resource" : "arn:aws:catalog:*:*:product/*", "Condition" : { "StringEquals" : { "aws:RequestedRegion" : "${aws:PrincipalTag/TargetRegion}", "aws:ResourceAccount" : "${aws:PrincipalAccount}" } } } ] }

了解详情