本文属于机器翻译版本。若本译文内容与英语原文存在差异,则一律以英文原文为准。
AmazonDataZoneSageMakerProvisioningRolePolicy
描述:该 AmazonDataZoneSageMakerProvisioningRolePolicy 政策授予亚马逊 DataZone 与亚马逊 SageMaker互操作所需的权限。
AmazonDataZoneSageMakerProvisioningRolePolicy
是一项 AWS 托管式策略。
使用此策略
您可以将 AmazonDataZoneSageMakerProvisioningRolePolicy
附加到您的用户、组和角色。
策略详细信息
-
类型: AWS 托管策略
-
创建时间:2024 年 4 月 23 日 23:32 UTC
-
编辑时间:世界标准时间 2025 年 1 月 9 日 20:52
-
ARN:
arn:aws:iam::aws:policy/AmazonDataZoneSageMakerProvisioningRolePolicy
策略版本
策略版本:v2 (默认值)
此策略的默认版本是定义策略权限的版本。当使用该策略的用户或角色请求访问 AWS 资源时, AWS 会检查策略的默认版本以确定是否允许该请求。
JSON 策略文档
{
"Version" : "2012-10-17",
"Statement" : [
{
"Sid" : "CreateSageMakerStudio",
"Effect" : "Allow",
"Action" : [
"sagemaker:CreateDomain"
],
"Resource" : [
"*"
],
"Condition" : {
"StringEquals" : {
"aws:CalledViaFirst" : [
"cloudformation.amazonaws.com"
]
},
"ForAnyValue:StringEquals" : {
"aws:TagKeys" : [
"AmazonDataZoneEnvironment"
]
},
"Null" : {
"aws:TagKeys" : "false",
"aws:ResourceTag/AmazonDataZoneEnvironment" : "false",
"aws:RequestTag/AmazonDataZoneEnvironment" : "false"
}
}
},
{
"Sid" : "DeleteSageMakerStudio",
"Effect" : "Allow",
"Action" : [
"sagemaker:DeleteDomain"
],
"Resource" : [
"*"
],
"Condition" : {
"StringEquals" : {
"aws:CalledViaFirst" : [
"cloudformation.amazonaws.com"
]
},
"ForAnyValue:StringLike" : {
"aws:TagKeys" : [
"AmazonDataZoneEnvironment"
]
},
"Null" : {
"aws:TagKeys" : "false",
"aws:ResourceTag/AmazonDataZoneEnvironment" : "false"
}
}
},
{
"Sid" : "AmazonDataZoneEnvironmentSageMakerDescribePermissions",
"Effect" : "Allow",
"Action" : [
"sagemaker:DescribeDomain"
],
"Resource" : "*",
"Condition" : {
"StringEquals" : {
"aws:CalledViaFirst" : [
"cloudformation.amazonaws.com"
]
}
}
},
{
"Sid" : "IamPassRolePermissions",
"Effect" : "Allow",
"Action" : [
"iam:PassRole"
],
"Resource" : [
"arn:aws:iam::*:role/sm-provisioning/datazone_usr*"
],
"Condition" : {
"StringEquals" : {
"iam:PassedToService" : [
"glue.amazonaws.com",
"lakeformation.amazonaws.com",
"sagemaker.amazonaws.com"
],
"aws:CalledViaFirst" : [
"cloudformation.amazonaws.com"
]
}
}
},
{
"Sid" : "AmazonDataZonePermissionsToCreateEnvironmentRole",
"Effect" : "Allow",
"Action" : [
"iam:CreateRole",
"iam:DetachRolePolicy",
"iam:DeleteRolePolicy",
"iam:AttachRolePolicy",
"iam:PutRolePolicy"
],
"Resource" : [
"arn:aws:iam::*:role/sm-provisioning/datazone_usr*"
],
"Condition" : {
"StringEquals" : {
"aws:CalledViaFirst" : [
"cloudformation.amazonaws.com"
],
"iam:PermissionsBoundary" : "arn:aws:iam::aws:policy/AmazonDataZoneSageMakerEnvironmentRolePermissionsBoundary"
}
}
},
{
"Sid" : "AmazonDataZonePermissionsToManageEnvironmentRole",
"Effect" : "Allow",
"Action" : [
"iam:GetRole",
"iam:GetRolePolicy",
"iam:DeleteRole"
],
"Resource" : [
"arn:aws:iam::*:role/sm-provisioning/datazone_usr*"
],
"Condition" : {
"StringEquals" : {
"aws:CalledViaFirst" : [
"cloudformation.amazonaws.com"
]
}
}
},
{
"Sid" : "AmazonDataZonePermissionsToCreateSageMakerServiceRole",
"Effect" : "Allow",
"Action" : [
"iam:CreateServiceLinkedRole"
],
"Resource" : [
"arn:aws:iam::*:role/aws-service-role/sagemaker.amazonaws.com/AWSServiceRoleForAmazonSageMakerNotebooks"
],
"Condition" : {
"StringEquals" : {
"aws:CalledViaFirst" : [
"cloudformation.amazonaws.com"
]
}
}
},
{
"Sid" : "AmazonDataZoneEnvironmentParameterValidation",
"Effect" : "Allow",
"Action" : [
"ec2:DescribeVpcs",
"ec2:DescribeSubnets",
"sagemaker:ListDomains"
],
"Resource" : "*"
},
{
"Sid" : "AmazonDataZoneEnvironmentKMSKeyValidation",
"Effect" : "Allow",
"Action" : [
"kms:DescribeKey"
],
"Resource" : "arn:aws:kms:*:*:key/*",
"Condition" : {
"Null" : {
"aws:ResourceTag/AmazonDataZoneEnvironment" : "false"
}
}
},
{
"Sid" : "AmazonDataZoneEnvironmentGluePermissions",
"Effect" : "Allow",
"Action" : [
"glue:CreateConnection",
"glue:DeleteConnection",
"glue:GetConnection"
],
"Resource" : [
"arn:aws:glue:*:*:connection/dz-sm-athena-glue-connection-*",
"arn:aws:glue:*:*:connection/dz-sm-redshift-cluster-connection-*",
"arn:aws:glue:*:*:connection/dz-sm-redshift-serverless-connection-*",
"arn:aws:glue:*:*:catalog"
],
"Condition" : {
"StringEquals" : {
"aws:CalledViaFirst" : [
"cloudformation.amazonaws.com"
]
}
}
}
]
}