本文為英文版的機器翻譯版本,如內容有任何歧義或不一致之處,概以英文版為準。
AmazonAppFlowFullAccess
說明:提供對 Amazon 的完整存取權,以 AppFlow 及存取作為流程來源或目標 (S3 和 Redshift) 支援的 AWS 服務。還提供對 KMS 進行加密的訪問
AmazonAppFlowFullAccess
是AWS 受管理的策略。
使用此政策
您可以附加AmazonAppFlowFullAccess
至您的使用者、群組和角色。
政策詳情
-
類型: AWS 受管理的策略
-
創建時間:2020 年 6 月 2 日, 世界標準時間 23:30
-
編輯時間:世界標準時間 2022 年 2 月 28 日 23:11
-
ARN:
arn:aws:iam::aws:policy/AmazonAppFlowFullAccess
政策版本
策略版本:v3(預設值)
原則的預設版本是定義原則權限的版本。當具有策略的使用者或角色發出要求以存取 AWS 資源時,請 AWS 檢查原則的預設版本,以決定是否允許該要求。
政策文件
{
"Version" : "2012-10-17",
"Statement" : [
{
"Effect" : "Allow",
"Action" : "appflow:*",
"Resource" : "*"
},
{
"Sid" : "ListRolesForRedshift",
"Effect" : "Allow",
"Action" : "iam:ListRoles",
"Resource" : "*"
},
{
"Sid" : "KMSListAccess",
"Effect" : "Allow",
"Action" : [
"kms:ListKeys",
"kms:DescribeKey",
"kms:ListAliases"
],
"Resource" : "*"
},
{
"Sid" : "KMSGrantAccess",
"Effect" : "Allow",
"Action" : [
"kms:CreateGrant"
],
"Resource" : "*",
"Condition" : {
"StringLike" : {
"kms:ViaService" : "appflow.*.amazonaws.com"
},
"Bool" : {
"kms:GrantIsForAWSResource" : "true"
}
}
},
{
"Sid" : "KMSListGrantAccess",
"Effect" : "Allow",
"Action" : [
"kms:ListGrants"
],
"Resource" : "*",
"Condition" : {
"StringLike" : {
"kms:ViaService" : "appflow.*.amazonaws.com"
}
}
},
{
"Sid" : "S3ReadAccess",
"Effect" : "Allow",
"Action" : [
"s3:ListAllMyBuckets",
"s3:ListBucket",
"s3:GetBucketLocation",
"s3:GetBucketPolicy"
],
"Resource" : "*"
},
{
"Sid" : "S3PutBucketPolicyAccess",
"Effect" : "Allow",
"Action" : [
"s3:PutBucketPolicy"
],
"Resource" : "arn:aws:s3:::appflow-*"
},
{
"Sid" : "SecretsManagerCreateSecretAccess",
"Effect" : "Allow",
"Action" : "secretsmanager:CreateSecret",
"Resource" : "*",
"Condition" : {
"StringLike" : {
"secretsmanager:Name" : "appflow!*"
},
"ForAnyValue:StringEquals" : {
"aws:CalledVia" : [
"appflow.amazonaws.com"
]
}
}
},
{
"Sid" : "SecretsManagerPutResourcePolicyAccess",
"Effect" : "Allow",
"Action" : [
"secretsmanager:PutResourcePolicy"
],
"Resource" : "*",
"Condition" : {
"ForAnyValue:StringEquals" : {
"aws:CalledVia" : [
"appflow.amazonaws.com"
]
},
"StringEqualsIgnoreCase" : {
"secretsmanager:ResourceTag/aws:secretsmanager:owningService" : "appflow"
}
}
},
{
"Sid" : "LambdaListFunctions",
"Effect" : "Allow",
"Action" : [
"lambda:ListFunctions"
],
"Resource" : "*"
}
]
}