AWS 存取 AppStream 2.0 資源所需的受管原則 - Amazon AppStream 2.0

本文為英文版的機器翻譯版本,如內容有任何歧義或不一致之處,概以英文版為準。

AWS 存取 AppStream 2.0 資源所需的受管原則

若要提供 AppStream 2.0 的完整管理或唯讀存取權限,您必須將下列其中一個 AWS 受管政策附加到需要這些許可的 IAM 使用者或群組。「AWS 受管政策」為獨立的政策,由 AWS建立並管理。如需詳細資訊,請參閱《IAM 使用者指南》中的 AWS 受管政策

AmazonAppStreamFull存取

此受管理原則可提供 AppStream 2.0 資源的完整管理存取權。若要透過 AWS 命令列介面 (AWS CLI)、 AWS SDK 或 AWS 管理主控台管理 AppStream 2.0 資源並執行 API 動作,您必須擁有此原則中定義的權限。

如果您以 IAM 使用者身分登入 AppStream 2.0 主控台,則必須將此政策附加到您的 AWS 帳戶. 如果您是透過主控台聯合登入,則必須將此政策連接至用於聯合的 IAM 角色。

{ "Version": "2012-10-17", "Statement": [ { "Action": [ "appstream:" ], "Effect": "Allow", "Resource": "" }, { "Action": [ "application-autoscaling:DeleteScalingPolicy", "application-autoscaling:DescribeScalableTargets", "application-autoscaling:DescribeScalingPolicies", "application-autoscaling:PutScalingPolicy", "application-autoscaling:RegisterScalableTarget", "application-autoscaling:DescribeScheduledActions", "application-autoscaling:PutScheduledAction", "application-autoscaling:DeleteScheduledAction" ], "Effect": "Allow", "Resource": "" }, { "Action": [ "cloudwatch:DeleteAlarms", "cloudwatch:DescribeAlarms", "cloudwatch:GetMetricStatistics", "cloudwatch:PutMetricAlarm" ], "Effect": "Allow", "Resource": "" }, { "Action": [ "ec2:DescribeRouteTables", "ec2:DescribeSecurityGroups", "ec2:DescribeSubnets", "ec2:DescribeVpcs", "ec2:DescribeVpcEndpoints" ], "Effect": "Allow", "Resource": "" }, { "Action": "iam:ListRoles", "Effect": "Allow", "Resource": "" }, { "Action": "iam:PassRole", "Effect": "Allow", "Resource": "arn:aws:iam:::role/service-role/ApplicationAutoScalingForAmazonAppStreamAccess", "Condition": { "StringLike": { "iam:PassedToService": "application-autoscaling.amazonaws.com" } } }, { "Action": "iam:CreateServiceLinkedRole", "Effect": "Allow", "Resource": "arn:aws:iam:::role/aws-service-role/appstream.application-autoscaling.amazonaws.com/AWSServiceRoleForApplicationAutoScaling_AppStreamFleet (http://appstream.application-autoscaling.amazonaws.com/AWSServiceRoleForApplicationAutoScaling_AppStreamFleet)", "Condition": { "StringLike": { "iam:AWSServiceName": "appstream.application-autoscaling.amazonaws.com" } } } ] }
AmazonAppStreamReadOnlyAccess

此受管理原則可提供 AppStream 2.0 資源的唯讀存取權。

{ "Version": "2012-10-17", "Statement": [ { "Action": [ "appstream:Get*", "appstream:List*", "appstream:Describe*" ], "Effect": "Allow", "Resource": "*" } ] }

AppStream 2.0 主控台使用兩個額外的動作,這些動作提供了 AWS CLI 或 AWS SDK 無法使用的功能。AmazonAppStreamFull存取AmazonAppStreamReadOnlyAccess原則都提供這些動作的權限。

動作 描述 存取層級
GetImageBuilders 如果提供了映像建置器名稱,則會准許擷取說明一或多個指定的映像建置器清單。否則,帳戶中的所有映像建置器都會予以說明。 讀取
GetParametersForThemeAssetUpload 授予可上傳自訂品牌主題資產的許可。如需詳細資訊,請參閱 將您的自訂品牌新增至 Amazon AppStream 2.0 寫入
AmazonApp流浪卡

此受管理原則可提供您 AWS 帳戶中 Certificate Manager Private CA 資源的完整管理存取權,以進行 AWS 憑證型驗證。

{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "acm-pca:IssueCertificate", "acm-pca:GetCertificate", "acm-pca:DescribeCertificateAuthority" ], "Resource": "arn:*:acm-pca:*:*:*", "Condition": { "StringLike": { "aws:ResourceTag/euc-private-ca": "*" } } } ] }
AmazonAppStreamService存取

此受管理原則是 AppStream 2.0 服務角色的預設原則。

{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "ec2:DescribeVpcs", "ec2:DescribeSubnets", "ec2:DescribeAvailabilityZones", "ec2:CreateNetworkInterface", "ec2:DescribeNetworkInterfaces", "ec2:DeleteNetworkInterface", "ec2:DescribeSubnets", "ec2:AssociateAddress", "ec2:DisassociateAddress", "ec2:DescribeRouteTables", "ec2:DescribeSecurityGroups", "ec2:DescribeVpcEndpoints", "s3:ListAllMyBuckets", "ds:DescribeDirectories" ], "Resource": "*" }, { "Effect": "Allow", "Action": [ "s3:CreateBucket", "s3:ListBucket", "s3:GetObject", "s3:PutObject", "s3:DeleteObject", "s3:GetObjectVersion", "s3:DeleteObjectVersion", "s3:GetBucketPolicy", "s3:PutBucketPolicy", "s3:PutEncryptionConfiguration" ], "Resource": [ "arn:aws:s3:::appstream2-36fb080bb8-*", "arn:aws:s3:::appstream-app-settings-*", "arn:aws:s3:::appstream-logs-*" ] } ] }
ApplicationAutoScalingForAmazonAppStreamAccess

此受管原則可讓應用程式自動調度資源達 AppStream 2.0 版。

{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "appstream:UpdateFleet", "appstream:DescribeFleets" ], "Resource": [ "*" ] }, { "Effect": "Allow", "Action": [ "cloudwatch:DescribeAlarms" ], "Resource": [ "*" ] } ] }
AWSApplicationAutoscalingAppStreamFleetPolicy

此受管原則會授與「應用程式自動擴展」存取 AppStream 2.0 和 CloudWatch .

{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "appstream:UpdateFleet", "appstream:DescribeFleets", "cloudwatch:PutMetricAlarm", "cloudwatch:DescribeAlarms", "cloudwatch:DeleteAlarms" ], "Resource": [ "*" ] } ] }

AppStream 2.0 更新 AWS 受管理策略

檢視有關 AppStream 2.0 AWS 受管政策更新的詳細資料,因為此服務開始追蹤這些變更。如需有關此頁面變更的自動提醒,請訂閱 Amazon AppStream 2.0 的文檔歷史記錄 頁面的 RSS 摘要。

變更 描述 日期

AppStream 2.0 開始追蹤變更

AppStream 2.0 開始追蹤其 AWS 受管政策的變更

2022 年 10 月 31 日