本文為英文版的機器翻譯版本,如內容有任何歧義或不一致之處,概以英文版為準。
DevOps Agent IAM 許可
AWS DevOps Agent 使用服務特定的 AWS Identity and Access Management (IAM) 動作來控制對其功能和功能的存取。這些動作決定使用者可以在 AWS DevOps Agent 主控台和 Operator Web App 中執行的動作。這與代理程式本身用來調查 資源 AWS 的服務 API 許可不同。
如需限制代理程式存取的詳細資訊,請參閱 限制 AWS 帳戶中的客服人員存取。
若要讓代理程式在您的 AWS 帳戶中執行導向動作,請在帳戶關聯上註冊提升的 IAM 角色。例如,您可以在操作員核准後,使用提升的角色來修復問題。如需導向動作和註冊提升 IAM 角色的詳細資訊,請參閱 使用導向動作。
客服人員空間管理動作
這些動作控制對 Agent Space 組態和管理的存取:
aidevops:GetAgentSpace – 允許使用者檢視客服人員空間的詳細資訊,包括其組態、狀態和相關聯的帳戶。使用者需要此許可才能在 AWS 管理主控台中存取 代理程式空間。
aidevops:GetAssociation – 允許使用者檢視特定帳戶關聯的詳細資訊,包括 IAM 角色組態和連線狀態。
aidevops:ListAssociations – 允許使用者列出為客服人員空間設定的所有 AWS 帳戶關聯,包括主要和次要帳戶。
aidevops:AssociateService – 允許使用者將 AWS 帳戶或第三方工具等服務關聯新增至 代理程式空間。
aidevops:UpdateAssociation – 允許使用者變更現有關聯的組態,例如其 IAM 角色或登入資料。
aidevops:DisassociateService – 允許使用者從代理程式空間移除關聯。
aidevops:ValidateAwsAssociations – 允許使用者檢查客服人員空間 AWS 的帳戶關聯是否正確設定。
aidevops:ListWebhooks – 允許使用者列出屬於 關聯的 Webhook。
關聯動作的資源層級許可
關聯動作會針對代理程式空間進行授權,有些也會針對關聯本身進行授權。使用 請求來判斷動作檢查的資源:
以請求中的關聯 ID (例如 GetAssociation) 識別的一個關聯為目標的動作會針對兩個資源授權:關聯 ARN
arn:aws:aidevops:region:account-id:agentspace/agent-space-id/association/association-id、 和客服人員空間 ARN。允許此類動作的陳述式必須涵蓋這兩個 ARNs。將 Agent Space 的關聯設為群組的 動作,在請求中沒有關聯 ID (例如 ListAssociations),會針對 Agent Space ARN 授權
arn:aws:aidevops:region:account-id:agentspace/agent-space-id。
在 上授予 動作可arn:aws:aidevops:region:account-id:agentspace/*涵蓋這兩種情況,因為 模式符合 Agent Space ARN 及其下的關聯 ARNs。僅範圍為關聯 ARN 的陳述式不會授予以一個關聯為目標之動作的存取權,因為它不涵蓋客服人員空間 ARN。
標籤條件適用於代理程式空間,因為關聯不會承載標籤。
若要依 Agent Space 標籤限制關聯動作,請使用兩個陳述式:
一個沒有條件的陳述式,範圍為關聯 ARN。
一個具有標籤條件的陳述式,範圍為 Agent Space ARN。
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "aidevops:GetAssociation", "aidevops:UpdateAssociation", "aidevops:DisassociateService", "aidevops:ListWebhooks" ], "Resource": "arn:aws:aidevops:us-east-1:111122223333:agentspace/*/association/*" }, { "Effect": "Allow", "Action": [ "aidevops:GetAssociation", "aidevops:UpdateAssociation", "aidevops:DisassociateService", "aidevops:ListWebhooks" ], "Resource": "arn:aws:aidevops:us-east-1:111122223333:agentspace/*", "Condition": { "StringEquals": { "aws:ResourceTag/team": "platform" } } } ] }
調查和執行動作
這些動作控制對事件調查功能的存取:
aidevops:ListExecutions – 可讓您檢視執行中繼資料,包括 ID、狀態等,以進行與任務相關聯的調查、緩解、評估和聊天對話。
aidevops:ListJournalRecords – 允許使用者存取詳細日誌,其中顯示客服人員在調查、緩解、評估和聊天對話期間所諮詢的推理步驟、採取的動作和資料來源。這有助於了解客服人員如何得出結論。
聊天管理動作
聊天需要下列 IAM 許可才能運作:
aidevops:ListChats – 允許使用者列出和存取聊天對話歷史記錄。
aidevops:CreateChat – 允許使用者建立新的聊天對話。
aidevops:SendMessage – 允許使用者提交查詢並接收串流回應。
拓撲和探索動作
這些動作控制對應用程式資源映射功能的存取:
aidevops:DiscoverTopology – 允許使用者觸發代理程式空間的拓撲探索和映射。此動作會啟動掃描 AWS 帳戶和建置應用程式資源拓撲的程序。
預防和建議動作
這些動作控制對預防功能的存取:
aidevops:ListGoals – 允許使用者根據最近的事件模式,檢視客服人員正在努力的預防目標。
aidevops:ListRecommendations – 允許使用者檢視預防功能產生的所有建議,包括其優先順序和類別。
aidevops:GetRecommendation – 允許使用者檢視特定建議的詳細資訊,包括其會阻止的事件和實作指引。
待處理項目任務管理動作
這些動作可控制將建議管理為待處理任務的能力:
aidevops:CreateBacklogTask – 允許使用者建立事件調查或預防評估任務。
aidevops:UpdateBacklogTask – 允許使用者核准緩解計劃或取消主動調查或評估。
aidevops:GetBacklogTask – 允許使用者擷取特定任務的詳細資訊。
aidevops:ListBacklogTasks – 允許使用者列出代理程式空間的任務,依任務類型、狀態、優先順序或建立時間篩選。
資產管理動作
這些動作可控制在 代理程式空間中新增和管理資產的功能,包括技能、AGENTS.md 檔案、附件、自訂代理程式、測試設定檔和意見回饋。如需資產 API 的詳細資訊,請參閱管理資產。
aidevops:CreateAsset – 允許使用者在客服人員空間中建立新的資產,包括技能、AGENTS.md 檔案、附件、自訂客服人員、測試設定檔和意見回饋。
aidevops:GetAsset – 允許使用者擷取資產的中繼資料和版本資訊。
aidevops:UpdateAsset – 允許使用者更新現有資產的中繼資料或內容。
aidevops:DeleteAsset – 允許使用者從代理程式空間刪除資產及其所有檔案。
aidevops:ListAssets – 允許使用者列出客服人員空間中的資產,並依資產類型進行選用篩選。
aidevops:ListAssetVersions – 允許使用者列出資產的歷史版本。
aidevops:GetAssetContent – 允許使用者將資產的完整內容下載為壓縮套件。
aidevops:CreateAssetFile – 允許使用者將新檔案新增至現有資產。
aidevops:GetAssetFile – 允許使用者依其路徑從資產擷取單一檔案。
aidevops:UpdateAssetFile – 允許使用者取代資產中現有檔案的內容或中繼資料。
aidevops:DeleteAssetFile – 允許使用者從資產移除單一檔案。
aidevops:ListAssetFiles – 允許使用者列出資產中的檔案。
aidevops:ListAssetTypes – 允許使用者列出 AWS DevOps Agent 支援的資產類型。此動作的範圍不限於特定的客服人員空間,且需要
Resource: "*"。
AWS 支援整合動作
這些動作會控制與 AWS Support 案例的整合:
aidevops:InitiateChatForCase – 允許使用者直接從調查中使用 AWS Support 啟動聊天工作階段,並自動提供有關事件的內容。
aidevops:EndChatForCase – 允許使用者結束作用中的 AWS 支援案例聊天工作階段。
aidevops:DescribeSupportLevel – 允許使用者檢查帳戶的 AWS 支援計劃層級,以判斷可用的支援選項。
存取字符管理動作
這些動作會控制存取權杖操作以進行遠端 MCP 和 A2A 伺服器身分驗證:
aidevops:CreateAccessToken – 允許使用者建立客服人員空間的存取權杖。
aidevops:GetAccessToken – 允許使用者檢視存取權杖詳細資訊。
aidevops:ListAccessTokens – 允許使用者列出客服人員空間中的存取權杖。
aidevops:RotateAccessToken – 允許使用者輪換存取字符,在保留組態的同時產生新值。
aidevops:RevokeAccessToken – 允許使用者撤銷存取字符,並永久停用它。
用量和監控動作
這些動作控制對用量資訊的存取:
aidevops:GetAccountUsage – 允許使用者檢視調查時數、預防評估時數和聊天請求,以及當月用量的 AWS DevOps 代理程式每月配額。
常見的 IAM 政策範例
管理員政策
此政策授予 all AWS DevOps Agent 功能的完整存取權:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "aidevops:*", "Resource": "*" } ] }
運算子政策
此政策授予沒有管理功能的調查和預防功能的存取權:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "aidevops:GetAgentSpace", "aidevops:InvokeAgent", "aidevops:ListExecutions", "aidevops:ListJournalRecords", "aidevops:ListAssociations", "aidevops:GetAssociation", "aidevops:DiscoverTopology", "aidevops:ListRecommendations", "aidevops:GetRecommendation", "aidevops:CreateBacklogTask", "aidevops:UpdateBacklogTask", "aidevops:GetBacklogTask", "aidevops:ListBacklogTasks", "aidevops:ListAssets", "aidevops:ListAssetVersions", "aidevops:ListAssetFiles", "aidevops:ListAssetTypes", "aidevops:GetAsset", "aidevops:GetAssetContent", "aidevops:GetAssetFile", "aidevops:InitiateChatForCase", "aidevops:EndChatForCase", "aidevops:ListChats", "aidevops:CreateChat", "aidevops:SendMessage", "aidevops:ListGoals", "aidevops:CreateAsset", "aidevops:CreateAssetFile", "aidevops:UpdateAsset", "aidevops:UpdateAssetFile", "aidevops:DescribeSupportLevel", "aidevops:ListPendingMessages" ], "Resource": "*" } ] }
唯讀政策
此政策授予僅檢視的調查和建議存取權:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "aidevops:GetAgentSpace", "aidevops:ListAssociations", "aidevops:GetAssociation", "aidevops:ListExecutions", "aidevops:ListJournalRecords", "aidevops:ListRecommendations", "aidevops:GetRecommendation", "aidevops:ListBacklogTasks", "aidevops:GetBacklogTask", "aidevops:ListAssets", "aidevops:ListAssetVersions", "aidevops:ListAssetFiles", "aidevops:ListAssetTypes", "aidevops:GetAsset", "aidevops:GetAssetContent", "aidevops:GetAssetFile", "aidevops:GetAccountUsage" ], "Resource": "*" } ] }
使用適用於 AWS DevOps Agent 的服務連結角色
AWS DevOps 代理程式使用 AWS Identity and Access Management (IAM) 服務連結角色。服務連結角色是直接連結至 AWS DevOps 代理程式的唯一 IAM 角色類型。服務連結角色由 AWS DevOps Agent 預先定義,並包含該服務代表您呼叫其他 AWS 服務所需的所有許可。
服務連結角色許可
AWSServiceRoleForAIDevOps 服務連結角色信任 aidevops.amazonaws.com 服務委託人來擔任角色。
此角色使用AWSServiceRoleForAIDevOpsPolicy具有下列許可的 受管政策:
cloudwatch:PutMetricData– 將用量指標發佈至AWS/AIDevOpsCloudWatch 命名空間。受cloudwatch:namespace條件限制,只允許AWS/AIDevOps命名空間。vpc-lattice:CreateResourceGateway– 建立私有連線的 VPC Lattice 資源閘道。受aws:RequestTag/AWSAIDevOpsManaged條件限制,因此服務只能建立帶有AWSAIDevOpsManaged標籤的資源閘道。vpc-lattice:TagResource– 標記 VPC Lattice 資源閘道。由aws:RequestTag/AWSAIDevOpsManaged條件範圍。vpc-lattice:DeleteResourceGateway– 刪除 VPC Lattice 資源閘道。受aws:ResourceTag/AWSAIDevOpsManaged條件限制,因此服務只能刪除其建立的資源閘道。vpc-lattice:GetResourceGateway– 擷取 VPC Lattice 資源閘道的相關資訊。受aws:ResourceTag/AWSAIDevOpsManaged條件限制,因此服務只能讀取其建立的資源閘道。ec2:DescribeVpcs、ec2:DescribeSubnetsec2:DescribeSecurityGroups- 擷取設定資源閘道所需的 VPC 聯網資源相關資訊。這些唯讀動作適用於所有 VPC 資源,因為 EC2 API 不支援描述呼叫的資源層級許可。iam:CreateServiceLinkedRole– 建立資源閘道操作所需的 VPC Lattice 服務連結角色。此許可僅限於vpc-lattice.amazonaws.com服務主體,不能用於為任何其他服務建立服務連結角色。
建立 服務連結角色
您不需要手動建立 AWSServiceRoleForAIDevOps 服務連結角色。當您開始使用 AWS DevOps Agent 時,服務會為您建立服務連結角色。
若要允許服務代表您建立角色,您必須擁有 iam:CreateServiceLinkedRole許可。我們建議您使用 iam:AWSServiceName條件來限定此許可aidevops.amazonaws.com,以遵循最低權限原則。如需更多資訊,請參閱服務連結角色許可權限。
編輯 服務連結角色
您不能編輯 AWSServiceRoleForAIDevOps 服務連結角色。建立角色之後,您無法變更角色的名稱,因為各種實體可能會依名稱參考角色。然而,您可使用 IAM 來編輯角色描述。如需詳細資訊,請參閱編輯服務連結角色。
刪除 服務連結角色
如果您不再需要使用 AWS DevOps Agent,我們建議您刪除AWSServiceRoleForAIDevOps服務連結角色。您必須先移除在客服人員空間中設定的任何私有連線,才能刪除角色。刪除服務連結角色不會自動移除先前由服務建立AWSAIDevOpsManaged、以 標記的 VPC Lattice 資源閘道。如果不再需要這些資源閘道,您應該手動將其刪除。如需詳細資訊,請參閱刪除服務連結角色。
AWS 適用於 AWS DevOps 代理程式的受管政策
AWS 提供由 建立和管理的獨立 IAM 政策,以解決許多常見的使用案例 AWS。這些 AWS 受管政策會授予常見使用案例的必要許可,讓您不必調查需要哪些許可。如需詳細資訊,請參閱《_IAM 使用者指南》中的 AWS 受管政策。
下列 AWS 受管政策是 AWS DevOps 代理程式特有的,您可以連接到您帳戶中的使用者。
AIDevOpsAgentReadOnlyAccess
透過 AWS 管理主控台提供 Amazon DevOps 代理程式的唯讀存取權
{ "Version": "2012-10-17", "Statement": [ { "Sid": "AIDevOpsAgentReadOnlyAccess", "Effect": "Allow", "Action": [ "aidevops:DescribePrivateConnection", "aidevops:DescribeServices", "aidevops:Get*", "aidevops:List*", "aidevops:SearchServiceAccessibleResource" ], "Resource": "*" } ] }
AIDevOpsAgentFullAccess
透過 AWS 管理主控台提供 Amazon DevOps 代理程式的完整存取權
{ "Version": "2012-10-17", "Statement": [ { "Sid": "AIDevOpsAgentAccess", "Effect": "Allow", "Action": [ "aidevops:AllowVendedLogDeliveryForResource", "aidevops:AssociateService", "aidevops:CreateAccessToken", "aidevops:CreateAgentSpace", "aidevops:CreateAsset", "aidevops:CreateAssetFile", "aidevops:CreateBacklogTask", "aidevops:CreateChat", "aidevops:CreateKnowledgeItem", "aidevops:CreateOneTimeLoginSession", "aidevops:CreatePrivateConnection", "aidevops:CreateTrigger", "aidevops:DeleteAgentSpace", "aidevops:DeleteAsset", "aidevops:DeleteAssetFile", "aidevops:DeleteKnowledgeItem", "aidevops:DeletePrivateConnection", "aidevops:DeleteTrigger", "aidevops:DeregisterService", "aidevops:DescribePrivateConnection", "aidevops:DescribeServices", "aidevops:DescribeSupportLevel", "aidevops:DisableOperatorApp", "aidevops:DisassociateService", "aidevops:DiscoverTopology", "aidevops:EnableOperatorApp", "aidevops:EndChatForCase", "aidevops:GetAccessToken", "aidevops:GetAccountUsage", "aidevops:GetAgentSpace", "aidevops:GetAsset", "aidevops:GetAssetContent", "aidevops:GetAssetFile", "aidevops:GetAssociation", "aidevops:GetBacklogTask", "aidevops:GetKnowledgeItem", "aidevops:GetOperatorApp", "aidevops:GetRecommendation", "aidevops:GetService", "aidevops:GetTrigger", "aidevops:InitiateChatForCase", "aidevops:ListAccessTokens", "aidevops:ListAgentSpaces", "aidevops:ListAssetFiles", "aidevops:ListAssets", "aidevops:ListAssetTypes", "aidevops:ListAssetVersions", "aidevops:ListAssociations", "aidevops:ListBacklogTasks", "aidevops:ListChats", "aidevops:ListExecutions", "aidevops:ListGoals", "aidevops:ListJournalRecords", "aidevops:ListKnowledgeItems", "aidevops:ListKnowledgeItemVersions", "aidevops:ListPendingMessages", "aidevops:ListPrivateConnections", "aidevops:ListRecommendations", "aidevops:ListServices", "aidevops:ListTagsForResource", "aidevops:ListTriggers", "aidevops:ListWebhooks", "aidevops:RegisterService", "aidevops:RevokeAccessToken", "aidevops:RotateAccessToken", "aidevops:SearchServiceAccessibleResource", "aidevops:SendMessage", "aidevops:TagResource", "aidevops:UntagResource", "aidevops:UpdateAgentSpace", "aidevops:UpdateApprovalAction", "aidevops:UpdateAsset", "aidevops:UpdateAssetFile", "aidevops:UpdateAssociation", "aidevops:UpdateBacklogTask", "aidevops:UpdateGoal", "aidevops:UpdateKnowledgeItem", "aidevops:UpdateOperatorAppIdpConfig", "aidevops:UpdatePrivateConnectionCertificate", "aidevops:UpdateRecommendation", "aidevops:UpdateTrigger", "aidevops:ValidateAwsAssociations" ], "Resource": "*" } ] }
AIDevOpsOperatorAppAccessPolicy
提供對 代理程式空間使用 AWS DevOps 運算子 Web 應用程式的存取權。
{ "Version": "2012-10-17", "Statement": [ { "Sid": "AllowOperatorAgentSpaceActions", "Effect": "Allow", "Action": [ "aidevops:CreateAccessToken", "aidevops:CreateAsset", "aidevops:CreateAssetFile", "aidevops:CreateBacklogTask", "aidevops:CreateChat", "aidevops:CreateKnowledgeItem", "aidevops:CreateTrigger", "aidevops:DeleteAsset", "aidevops:DeleteAssetFile", "aidevops:DeleteKnowledgeItem", "aidevops:DeleteTrigger", "aidevops:DescribeServices", "aidevops:DescribeSupportLevel", "aidevops:DiscoverTopology", "aidevops:EndChatForCase", "aidevops:GetAccessToken", "aidevops:GetAgentSpace", "aidevops:GetAsset", "aidevops:GetAssetContent", "aidevops:GetAssetFile", "aidevops:GetAssociation", "aidevops:GetBacklogTask", "aidevops:GetKnowledgeItem", "aidevops:GetRecommendation", "aidevops:GetTrigger", "aidevops:InitiateChatForCase", "aidevops:ListAccessTokens", "aidevops:ListAssetFiles", "aidevops:ListAssets", "aidevops:ListAssetTypes", "aidevops:ListAssetVersions", "aidevops:ListAssociations", "aidevops:ListBacklogTasks", "aidevops:ListChats", "aidevops:ListExecutions", "aidevops:ListGoals", "aidevops:ListJournalRecords", "aidevops:ListKnowledgeItems", "aidevops:ListKnowledgeItemVersions", "aidevops:ListPendingMessages", "aidevops:ListRecommendations", "aidevops:ListTriggers", "aidevops:RevokeAccessToken", "aidevops:RotateAccessToken", "aidevops:SendMessage", "aidevops:UpdateApprovalAction", "aidevops:UpdateAsset", "aidevops:UpdateAssetFile", "aidevops:UpdateBacklogTask", "aidevops:UpdateGoal", "aidevops:UpdateKnowledgeItem", "aidevops:UpdateRecommendation", "aidevops:UpdateTrigger" ], "Resource": "arn:aws:aidevops:*:*:agentspace/${aws:PrincipalTag/AgentSpaceId}", "Condition": { "StringEquals": { "aws:ResourceAccount": "${aws:PrincipalAccount}" } } }, { "Sid": "AllowOperatorAccountActions", "Effect": "Allow", "Action": ["aidevops:GetAccountUsage"], "Resource": "*", "Condition": { "StringEquals": { "aws:ResourceAccount": "${aws:PrincipalAccount}" } } }, { "Sid": "AllowSupportOperatorActions", "Effect": "Allow", "Action": [ "support:DescribeCases", "support:DescribeServices", "support:InitiateChatForCase", "support:DescribeSupportLevel" ], "Resource": "*", "Condition": { "StringEquals": { "aws:ResourceAccount": "${aws:PrincipalAccount}" } } }, { "Sid": "AllowSecretsManagerOperatorActions", "Effect": "Allow", "Action": ["secretsmanager:CreateSecret", "secretsmanager:ListSecrets"], "Resource": "*", "Condition": { "StringEquals": { "aws:ResourceAccount": "${aws:PrincipalAccount}" } } }, { "Sid": "AllowTranscribeOperatorActions", "Effect": "Allow", "Action": ["transcribe:StartStreamTranscriptionWebSocket"], "Resource": "*", "Condition": { "StringEquals": { "aws:ResourceAccount": "${aws:PrincipalAccount}" } } } ] }
AIDevOpsAgentAccessPolicy
提供 AWS DevOps 代理程式執行調查和分析客戶 AWS 資源所需的許可。
{ "Version": "2012-10-17", "Statement": [ { "Sid": "AIOPSServiceWriteAccess", "Effect": "Allow", "Action": ["cloudtrail:StartQuery", "support:CreateCase"], "Resource": "*" }, { "Sid": "AIOPSServiceAccess", "Effect": "Allow", "Action": [ "access-analyzer:GetAnalyzer", "access-analyzer:List*", "acm-pca:Describe*", "acm-pca:GetCertificate", "acm-pca:GetCertificateAuthorityCertificate", "acm-pca:GetCertificateAuthorityCsr", "acm-pca:List*", "acm:DescribeCertificate", "acm:GetAccountConfiguration", "acm:GetCertificate", "acm:ListCertificates", "aidevops:GetAsset", "aidevops:GetAssetContent", "aidevops:GetAssetFile", "aidevops:GetKnowledgeItem", "aidevops:ListAssetFiles", "aidevops:ListAssets", "aidevops:ListAssetTypes", "aidevops:ListAssetVersions", "aidevops:ListKnowledgeItems", "airflow:List*", "amplify:GetApp", "amplify:GetBranch", "amplify:GetDomainAssociation", "amplify:List*", "aoss:BatchGetCollection", "aoss:BatchGetLifecyclePolicy", "aoss:BatchGetVpcEndpoint", "aoss:GetAccessPolicy", "aoss:GetSecurityConfig", "aoss:GetSecurityPolicy", "aoss:List*", "appconfig:GetApplication", "appconfig:GetConfigurationProfile", "appconfig:GetEnvironment", "appconfig:GetHostedConfigurationVersion", "appconfig:List*", "appflow:Describe*", "appflow:List*", "application-autoscaling:Describe*", "application-signals:BatchGetServiceLevelObjectiveBudgetReport", "application-signals:GetService", "application-signals:GetServiceLevelObjective", "application-signals:List*", "applicationinsights:Describe*", "applicationinsights:List*", "apprunner:Describe*", "apprunner:List*", "appstream:Describe*", "appstream:List*", "appsync:GetApiAssociation", "appsync:GetDataSource", "appsync:GetDomainName", "appsync:GetFunction", "appsync:GetGraphqlApi", "appsync:GetGraphqlApiEnvironmentVariables", "appsync:GetIntrospectionSchema", "appsync:GetResolver", "appsync:GetSourceApiAssociation", "appsync:List*", "aps:Describe*", "aps:List*", "arc-zonal-shift:GetManagedResource", "arc-zonal-shift:List*", "athena:GetCapacityAssignmentConfiguration", "athena:GetCapacityReservation", "athena:GetDataCatalog", "athena:GetNamedQuery", "athena:GetPreparedStatement", "athena:GetWorkGroup", "athena:List*", "auditmanager:GetAssessment", "auditmanager:List*", "autoscaling:Describe*", "backup-gateway:GetHypervisor", "backup-gateway:List*", "backup:Describe*", "backup:GetBackupPlan", "backup:GetBackupSelection", "backup:GetBackupVaultAccessPolicy", "backup:GetBackupVaultNotifications", "backup:GetRestoreTestingPlan", "backup:GetRestoreTestingSelection", "backup:List*", "batch:DescribeComputeEnvironments", "batch:DescribeJobQueues", "batch:DescribeSchedulingPolicies", "batch:List*", "bcm-data-exports:Get*", "bcm-data-exports:List*", "bedrock:GetAgent", "bedrock:GetAgentActionGroup", "bedrock:GetAgentAlias", "bedrock:GetAgentKnowledgeBase", "bedrock:GetCustomModel", "bedrock:GetDataSource", "bedrock:GetFoundationModel", "bedrock:GetGuardrail", "bedrock:GetInferenceProfile", "bedrock:GetKnowledgeBase", "bedrock:GetModelInvocationLoggingConfiguration", "bedrock:GetProvisionedModelThroughput", "bedrock:List*", "budgets:Describe*", "budgets:List*", "budgets:ViewBudget", "ce:Describe*", "ce:Get*", "ce:List*", "chatbot:Describe*", "chatbot:GetMicrosoftTeamsChannelConfiguration", "chatbot:List*", "cleanrooms-ml:GetTrainingDataset", "cleanrooms-ml:List*", "cleanrooms:GetAnalysisTemplate", "cleanrooms:GetCollaboration", "cleanrooms:GetConfiguredTable", "cleanrooms:GetConfiguredTableAnalysisRule", "cleanrooms:GetConfiguredTableAssociation", "cleanrooms:GetMembership", "cleanrooms:List*", "cloudformation:Describe*", "cloudformation:GetResource", "cloudformation:GetStackPolicy", "cloudformation:GetTemplate", "cloudformation:List*", "cloudfront:Describe*", "cloudfront:GetCachePolicy", "cloudfront:GetCloudFrontOriginAccessIdentity", "cloudfront:GetContinuousDeploymentPolicy", "cloudfront:GetDistribution", "cloudfront:GetDistributionConfig", "cloudfront:GetFunction", "cloudfront:GetKeyGroup", "cloudfront:GetMonitoringSubscription", "cloudfront:GetOriginAccessControl", "cloudfront:GetOriginRequestPolicy", "cloudfront:GetPublicKey", "cloudfront:GetRealtimeLogConfig", "cloudfront:GetResponseHeadersPolicy", "cloudfront:List*", "cloudtrail:Describe*", "cloudtrail:GetChannel", "cloudtrail:GetEventConfiguration", "cloudtrail:GetEventDataStore", "cloudtrail:GetEventSelectors", "cloudtrail:GetInsightSelectors", "cloudtrail:GetQueryResults", "cloudtrail:GetResourcePolicy", "cloudtrail:GetTrail", "cloudtrail:GetTrailStatus", "cloudtrail:List*", "cloudtrail:LookupEvents", "cloudwatch:Describe*", "cloudwatch:GenerateQuery", "cloudwatch:GetDashboard", "cloudwatch:GetInsightRuleReport", "cloudwatch:GetMetricData", "cloudwatch:GetMetricStatistics", "cloudwatch:GetMetricStream", "cloudwatch:GetService", "cloudwatch:GetServiceLevelObjective", "cloudwatch:List*", "codeartifact:Describe*", "codeartifact:GetDomainPermissionsPolicy", "codeartifact:GetRepositoryPermissionsPolicy", "codeartifact:List*", "codebuild:BatchGetFleets", "codebuild:List*", "codecommit:GetRepository", "codecommit:GetRepositoryTriggers", "codedeploy:BatchGetDeployments", "codedeploy:BatchGetDeploymentTargets", "codedeploy:GetApplication", "codedeploy:GetDeploymentConfig", "codedeploy:GetDeploymentTarget", "codedeploy:List*", "codeguru-profiler:Describe*", "codeguru-profiler:GetNotificationConfiguration", "codeguru-profiler:GetPolicy", "codeguru-profiler:List*", "codeguru-reviewer:Describe*", "codeguru-reviewer:List*", "codepipeline:GetPipeline", "codepipeline:GetPipelineState", "codepipeline:List*", "codestar-connections:GetConnection", "codestar-connections:GetRepositoryLink", "codestar-connections:GetSyncConfiguration", "codestar-connections:List*", "codestar-notifications:Describe*", "codestar-notifications:List*", "cognito-identity:DescribeIdentityPool", "cognito-identity:GetIdentityPoolRoles", "cognito-identity:ListIdentityPools", "cognito-identity:ListTagsForResource", "cognito-idp:AdminListGroupsForUser", "cognito-idp:DescribeIdentityProvider", "cognito-idp:DescribeResourceServer", "cognito-idp:DescribeRiskConfiguration", "cognito-idp:DescribeUserImportJob", "cognito-idp:DescribeUserPool", "cognito-idp:DescribeUserPoolDomain", "cognito-idp:GetGroup", "cognito-idp:GetLogDeliveryConfiguration", "cognito-idp:GetUICustomization", "cognito-idp:GetUserPoolMfaConfig", "cognito-idp:GetWebACLForResource", "cognito-idp:ListGroups", "cognito-idp:ListIdentityProviders", "cognito-idp:ListResourceServers", "cognito-idp:ListUserPoolClients", "cognito-idp:ListUserPools", "cognito-idp:ListTagsForResource", "comprehend:Describe*", "comprehend:List*", "config:Describe*", "config:GetStoredQuery", "config:List*", "connect:Describe*", "connect:GetTaskTemplate", "connect:List*", "cur:Describe*", "cur:Get*", "databrew:Describe*", "databrew:List*", "datapipeline:Describe*", "datapipeline:GetPipelineDefinition", "datapipeline:List*", "datasync:Describe*", "datasync:List*", "deadline:GetFarm", "deadline:GetFleet", "deadline:GetLicenseEndpoint", "deadline:GetMonitor", "deadline:GetQueue", "deadline:GetQueueEnvironment", "deadline:GetQueueFleetAssociation", "deadline:GetStorageProfile", "deadline:List*", "detective:GetMembers", "detective:List*", "devicefarm:GetDevicePool", "devicefarm:GetInstanceProfile", "devicefarm:GetNetworkProfile", "devicefarm:GetProject", "devicefarm:GetTestGridProject", "devicefarm:GetVPCEConfiguration", "devicefarm:List*", "devops-guru:Describe*", "devops-guru:GetResourceCollection", "devops-guru:List*", "directconnect:DescribeConnections", "directconnect:DescribeDirectConnectGatewayAssociations", "directconnect:DescribeDirectConnectGatewayAttachments", "directconnect:DescribeDirectConnectGateways", "directconnect:DescribeHostedConnections", "directconnect:DescribeInterconnects", "directconnect:DescribeLags", "directconnect:DescribeTags", "directconnect:DescribeVirtualInterfaces", "dms:Describe*", "dms:List*", "ds:Describe*", "dynamodb:Describe*", "dynamodb:GetResourcePolicy", "dynamodb:List*", "ec2:Describe*", "ec2:GetAssociatedEnclaveCertificateIamRoles", "ec2:GetCapacityManagerAttributes", "ec2:GetCapacityManagerMetricData", "ec2:GetCapacityManagerMonitoredTagKeys", "ec2:GetIpamPoolAllocations", "ec2:GetIpamPoolCidrs", "ec2:GetManagedPrefixListEntries", "ec2:GetNetworkInsightsAccessScopeContent", "ec2:GetSnapshotBlockPublicAccessState", "ec2:GetTransitGatewayMulticastDomainAssociations", "ec2:GetTransitGatewayRouteTableAssociations", "ec2:GetTransitGatewayRouteTablePropagations", "ec2:GetVerifiedAccessEndpointPolicy", "ec2:GetVerifiedAccessGroupPolicy", "ec2:GetVerifiedAccessInstanceWebAcl", "ec2:SearchLocalGatewayRoutes", "ec2:SearchTransitGatewayRoutes", "ecr:Describe*", "ecr:GetLifecyclePolicy", "ecr:GetRegistryPolicy", "ecr:GetRepositoryPolicy", "ecr:List*", "ecs:Describe*", "ecs:List*", "eks:AccessKubernetesApi", "eks:Describe*", "eks:List*", "elasticache:Describe*", "elasticache:List*", "elasticbeanstalk:Describe*", "elasticbeanstalk:List*", "elasticfilesystem:Describe*", "elasticloadbalancing:GetResourcePolicy", "elasticloadbalancing:GetTrustStoreCaCertificatesBundle", "elasticloadbalancing:GetTrustStoreRevocationContent", "elasticloadbalancing:Describe*", "elasticmapreduce:Describe*", "elasticmapreduce:List*", "emr-containers:Describe*", "emr-containers:List*", "emr-serverless:GetApplication", "emr-serverless:List*", "es:Describe*", "es:List*", "events:Describe*", "events:List*", "evidently:GetExperiment", "evidently:GetFeature", "evidently:GetLaunch", "evidently:GetProject", "evidently:GetSegment", "evidently:List*", "firehose:Describe*", "firehose:List*", "fis:GetExperimentTemplate", "fis:GetTargetAccountConfiguration", "fis:List*", "fms:GetNotificationChannel", "fms:GetPolicy", "fms:List*", "forecast:Describe*", "forecast:List*", "frauddetector:BatchGetVariable", "frauddetector:Describe*", "frauddetector:GetDetectors", "frauddetector:GetDetectorVersion", "frauddetector:GetEntityTypes", "frauddetector:GetEventTypes", "frauddetector:GetExternalModels", "frauddetector:GetLabels", "frauddetector:GetListElements", "frauddetector:GetListsMetadata", "frauddetector:GetModelVersion", "frauddetector:GetOutcomes", "frauddetector:GetRules", "frauddetector:GetVariables", "frauddetector:List*", "fsx:Describe*", "gamelift:Describe*", "gamelift:List*", "globalaccelerator:Describe*", "globalaccelerator:List*", "glue:BatchGetJobs", "glue:GetClassifier", "glue:GetClassifiers", "glue:GetCrawler", "glue:GetCrawlerMetrics", "glue:GetCrawlers", "glue:GetDatabase", "glue:GetDatabases", "glue:GetDataCatalogEncryptionSettings", "glue:GetJob", "glue:GetJobBookmark", "glue:GetJobRun", "glue:GetJobRuns", "glue:GetPartitions", "glue:GetRegistry", "glue:GetResourcePolicy", "glue:GetSchema", "glue:GetSchemaVersion", "glue:GetTable", "glue:GetTables", "glue:GetTags", "glue:GetTrigger", "glue:GetSecurityConfiguration", "glue:GetSecurityConfigurations", "glue:GetWorkflow", "glue:GetWorkflowRun", "glue:List*", "glue:querySchemaVersionMetadata", "grafana:Describe*", "grafana:List*", "greengrass:Describe*", "greengrass:GetDeployment", "greengrass:List*", "groundstation:GetConfig", "groundstation:GetDataflowEndpointGroup", "groundstation:GetMissionProfile", "groundstation:List*", "guardduty:GetDetector", "guardduty:GetFilter", "guardduty:GetFindings", "guardduty:GetIPSet", "guardduty:GetMalwareProtectionPlan", "guardduty:GetMasterAccount", "guardduty:GetMembers", "guardduty:GetThreatIntelSet", "guardduty:List*", "health:Describe*", "healthlake:Describe*", "healthlake:List*", "iam:GetGroup", "iam:GetGroupPolicy", "iam:GetInstanceProfile", "iam:GetLoginProfile", "iam:GetOpenIDConnectProvider", "iam:GetPolicy", "iam:GetPolicyVersion", "iam:GetRole", "iam:GetRolePolicy", "iam:GetSAMLProvider", "iam:GetServerCertificate", "iam:GetServiceLinkedRoleDeletionStatus", "iam:GetUser", "iam:GetUserPolicy", "iam:ListAccountAliases", "iam:ListAttachedRolePolicies", "iam:ListOpenIDConnectProviders", "iam:ListRolePolicies", "iam:ListRoles", "iam:ListServerCertificates", "iam:ListUsers", "iam:ListVirtualMFADevices", "identitystore:DescribeGroup", "identitystore:DescribeGroupMembership", "identitystore:ListGroupMemberships", "identitystore:ListGroups", "imagebuilder:GetComponent", "imagebuilder:GetContainerRecipe", "imagebuilder:GetDistributionConfiguration", "imagebuilder:GetImage", "imagebuilder:GetImagePipeline", "imagebuilder:GetImageRecipe", "imagebuilder:GetInfrastructureConfiguration", "imagebuilder:GetLifecyclePolicy", "imagebuilder:GetWorkflow", "imagebuilder:List*", "inspector2:List*", "inspector2:SearchVulnerabilities", "inspector:Describe*", "inspector:List*", "internetmonitor:GetMonitor", "internetmonitor:List*", "iot:Describe*", "iot:GetPackage", "iot:GetPackageVersion", "iot:GetPolicy", "iot:GetThingShadow", "iot:GetTopicRule", "iot:GetTopicRuleDestination", "iot:GetV2LoggingOptions", "iot:List*", "iotanalytics:Describe*", "iotanalytics:List*", "iotevents:Describe*", "iotevents:List*", "iotsitewise:Describe*", "iotsitewise:List*", "iotwireless:GetDestination", "iotwireless:GetDeviceProfile", "iotwireless:GetFuotaTask", "iotwireless:GetMulticastGroup", "iotwireless:GetNetworkAnalyzerConfiguration", "iotwireless:GetServiceProfile", "iotwireless:GetWirelessDevice", "iotwireless:GetWirelessGateway", "iotwireless:GetWirelessGatewayTaskDefinition", "iotwireless:List*", "ivs:GetChannel", "ivs:GetEncoderConfiguration", "ivs:GetPlaybackRestrictionPolicy", "ivs:GetRecordingConfiguration", "ivs:GetStage", "ivs:List*", "ivschat:GetLoggingConfiguration", "ivschat:GetRoom", "ivschat:List*", "kafka:Describe*", "kafka:GetClusterPolicy", "kafka:List*", "kafkaconnect:Describe*", "kafkaconnect:List*", "kendra:Describe*", "kendra:List*", "kinesis:Describe*", "kinesis:GetResourcePolicy", "kinesis:List*", "kinesisanalytics:Describe*", "kinesisanalytics:List*", "kinesisvideo:Describe*", "kms:DescribeKey", "kms:ListResourceTags", "kms:ListKeys", "kms:GetKeyPolicy", "kms:GetKeyRotationStatus", "kms:ListAliases", "kms:ListKeyRotations", "lakeformation:Describe*", "lakeformation:GetLFTag", "lakeformation:GetResourceLFTags", "lakeformation:List*", "lambda:GetAlias", "lambda:GetCodeSigningConfig", "lambda:GetEventSourceMapping", "lambda:GetFunctionCodeSigningConfig", "lambda:GetFunctionConfiguration", "lambda:GetFunctionEventInvokeConfig", "lambda:GetFunctionRecursionConfig", "lambda:GetFunctionUrlConfig", "lambda:GetLayerVersion", "lambda:GetLayerVersionPolicy", "lambda:GetPolicy", "lambda:GetProvisionedConcurrencyConfig", "lambda:GetRuntimeManagementConfig", "lambda:List*", "launchwizard:GetDeployment", "launchwizard:List*", "license-manager:GetLicense", "license-manager:List*", "lightsail:GetAlarms", "lightsail:GetBuckets", "lightsail:GetCertificates", "lightsail:GetContainerServices", "lightsail:GetDisk", "lightsail:GetDisks", "lightsail:GetInstance", "lightsail:GetInstances", "lightsail:GetLoadBalancer", "lightsail:GetLoadBalancers", "lightsail:GetLoadBalancerTlsCertificates", "lightsail:GetStaticIp", "lightsail:GetStaticIps", "logs:Describe*", "logs:FilterLogEvents", "logs:GetDataProtectionPolicy", "logs:GetDelivery", "logs:GetDeliveryDestination", "logs:GetDeliveryDestinationPolicy", "logs:GetDeliverySource", "logs:GetLogAnomalyDetector", "logs:GetLogDelivery", "logs:GetLogEvents", "logs:GetLogGroupFields", "logs:GetQueryResults", "logs:List*", "logs:StartQuery", "logs:StopLiveTail", "logs:StopQuery", "logs:TestMetricFilter", "m2:GetApplication", "m2:GetEnvironment", "m2:List*", "macie2:GetAllowList", "macie2:GetCustomDataIdentifier", "macie2:GetFindingsFilter", "macie2:GetMacieSession", "macie2:List*", "mediaconnect:Describe*", "mediaconnect:List*", "medialive:Describe*", "medialive:GetCloudWatchAlarmTemplate", "medialive:GetCloudWatchAlarmTemplateGroup", "medialive:GetEventBridgeRuleTemplate", "medialive:GetEventBridgeRuleTemplateGroup", "medialive:GetSignalMap", "medialive:List*", "mediapackage-vod:Describe*", "mediapackage-vod:List*", "mediapackage:Describe*", "mediapackage:List*", "mediapackagev2:GetChannel", "mediapackagev2:GetChannelGroup", "mediapackagev2:GetChannelPolicy", "mediapackagev2:GetOriginEndpoint", "mediapackagev2:GetOriginEndpointPolicy", "mediapackagev2:List*", "memorydb:Describe*", "memorydb:List*", "mobiletargeting:GetInAppTemplate", "mobiletargeting:List*", "mq:Describe*", "mq:List*", "network-firewall:Describe*", "network-firewall:List*", "networkmanager:Describe*", "networkmanager:GetConnectAttachment", "networkmanager:GetConnectPeer", "networkmanager:GetCoreNetwork", "networkmanager:GetCoreNetworkPolicy", "networkmanager:GetCustomerGatewayAssociations", "networkmanager:GetDevices", "networkmanager:GetLinkAssociations", "networkmanager:GetLinks", "networkmanager:GetSites", "networkmanager:GetSiteToSiteVpnAttachment", "networkmanager:GetTransitGatewayPeering", "networkmanager:GetTransitGatewayRegistrations", "networkmanager:GetTransitGatewayRouteTableAttachment", "networkmanager:GetVpcAttachment", "networkmanager:List*", "oam:GetLink", "oam:GetSink", "oam:GetSinkPolicy", "oam:List*", "omics:GetAnnotationStore", "omics:GetReferenceStore", "omics:GetRunGroup", "omics:GetSequenceStore", "omics:GetVariantStore", "omics:GetWorkflow", "omics:List*", "organizations:Describe*", "organizations:List*", "osis:GetPipeline", "osis:List*", "payment-cryptography:GetAlias", "payment-cryptography:GetKey", "payment-cryptography:List*", "pca-connector-ad:GetConnector", "pca-connector-ad:GetDirectoryRegistration", "pca-connector-ad:GetServicePrincipalName", "pca-connector-ad:GetTemplate", "pca-connector-ad:GetTemplateGroupAccessControlEntry", "pca-connector-ad:List*", "pca-connector-scep:GetChallengeMetadata", "pca-connector-scep:GetConnector", "pca-connector-scep:List*", "personalize:Describe*", "personalize:List*", "pi:Describe*", "pi:Get*", "pi:List*", "pipes:Describe*", "pipes:List*", "proton:GetEnvironmentTemplate", "proton:GetServiceTemplate", "proton:List*", "qbusiness:GetApplication", "qbusiness:GetDataSource", "qbusiness:GetIndex", "qbusiness:GetPlugin", "qbusiness:GetRetriever", "qbusiness:GetWebExperience", "qbusiness:List*", "ram:GetPermission", "ram:GetResourceShares", "ram:List*", "rds:Describe*", "rds:List*", "redshift-serverless:GetNamespace", "redshift-serverless:GetWorkgroup", "redshift-serverless:List*", "redshift:Describe*", "refactor-spaces:GetApplication", "refactor-spaces:GetEnvironment", "refactor-spaces:GetRoute", "refactor-spaces:List*", "rekognition:Describe*", "rekognition:List*", "resiliencehub:Describe*", "resiliencehub:Get*", "resiliencehub:List*", "resource-explorer-2:GetDefaultView", "resource-explorer-2:GetIndex", "resource-explorer-2:GetView", "resource-explorer-2:List*", "resource-explorer-2:Search", "resource-groups:GetGroup", "resource-groups:GetGroupConfiguration", "resource-groups:GetGroupQuery", "resource-groups:GetTags", "resource-groups:List*", "route53-recovery-control-config:Describe*", "route53-recovery-control-config:List*", "route53-recovery-readiness:GetCell", "route53-recovery-readiness:GetReadinessCheck", "route53-recovery-readiness:GetRecoveryGroup", "route53-recovery-readiness:GetResourceSet", "route53-recovery-readiness:List*", "route53:GetDNSSEC", "route53:GetHealthCheck", "route53:GetHealthCheckStatus", "route53:GetHostedZone", "route53:List*", "route53profiles:GetProfile", "route53profiles:GetProfileAssociation", "route53profiles:GetProfileResourceAssociation", "route53profiles:List*", "route53resolver:GetFirewallDomainList", "route53resolver:GetFirewallRuleGroup", "route53resolver:GetFirewallRuleGroupAssociation", "route53resolver:GetOutpostResolver", "route53resolver:GetResolverConfig", "route53resolver:GetResolverQueryLogConfig", "route53resolver:GetResolverQueryLogConfigAssociation", "route53resolver:GetResolverRule", "route53resolver:GetResolverRuleAssociation", "route53resolver:List*", "rum:GetAppMonitor", "rum:List*", "s3-outposts:ListEndpoints", "s3-outposts:ListOutpostsWithS3", "s3:GetAccessGrant", "s3:GetAccessGrantsInstance", "s3:GetAccessGrantsLocation", "s3:GetAccessPoint", "s3:GetAccessPointConfigurationForObjectLambda", "s3:GetAccessPointForObjectLambda", "s3:GetAccessPointPolicy", "s3:GetAccessPointPolicyForObjectLambda", "s3:GetAccessPointPolicyStatusForObjectLambda", "s3:GetBucketAbac", "s3:GetBucketAcl", "s3:GetBucketCORS", "s3:GetBucketLocation", "s3:GetBucketLogging", "s3:GetBucketMetadataTableConfiguration", "s3:GetBucketNotification", "s3:GetBucketObjectLockConfiguration", "s3:GetBucketOwnershipControls", "s3:GetBucketPolicy", "s3:GetBucketPublicAccessBlock", "s3:GetBucketTagging", "s3:GetBucketVersioning", "s3:GetEncryptionConfiguration", "s3:GetIntelligentTieringConfiguration", "s3:GetInventoryConfiguration", "s3:GetLifecycleConfiguration", "s3:GetMultiRegionAccessPoint", "s3:GetMultiRegionAccessPointPolicy", "s3:GetMultiRegionAccessPointPolicyStatus", "s3:GetReplicationConfiguration", "s3:GetStorageLensConfiguration", "s3:GetStorageLensConfigurationTagging", "s3:GetStorageLensGroup", "s3:ListAllMyBuckets", "sagemaker:Describe*", "sagemaker:List*", "scheduler:GetSchedule", "scheduler:GetScheduleGroup", "scheduler:List*", "schemas:Describe*", "schemas:GetResourcePolicy", "schemas:List*", "secretsmanager:Describe*", "secretsmanager:GetResourcePolicy", "secretsmanager:List*", "securityhub:BatchGetAutomationRules", "securityhub:BatchGetSecurityControls", "securityhub:Describe*", "securityhub:GetConfigurationPolicy", "securityhub:GetConfigurationPolicyAssociation", "securityhub:GetEnabledStandards", "securityhub:GetFindingAggregator", "securityhub:GetFindings", "securityhub:GetInsights", "securityhub:List*", "securitylake:GetSubscriber", "securitylake:List*", "servicecatalog:Describe*", "servicecatalog:GetApplication", "servicecatalog:GetAttributeGroup", "servicecatalog:List*", "servicequotas:Get*", "servicequotas:List*", "ses:Describe*", "ses:GetAccount", "ses:GetAddonInstance", "ses:GetAddonSubscription", "ses:GetArchive", "ses:GetConfigurationSet", "ses:GetConfigurationSetEventDestinations", "ses:GetContactList", "ses:GetDedicatedIpPool", "ses:GetDedicatedIps", "ses:GetEmailIdentity", "ses:GetEmailTemplate", "ses:GetIngressPoint", "ses:GetRelay", "ses:GetRuleSet", "ses:GetTemplate", "ses:GetTrafficPolicy", "ses:List*", "shield:Describe*", "shield:List*", "signer:GetSigningProfile", "signer:List*", "sns:GetDataProtectionPolicy", "sns:GetSubscriptionAttributes", "sns:GetTopicAttributes", "sns:List*", "sqs:GetQueueAttributes", "sqs:GetQueueUrl", "sqs:List*", "ssm-contacts:GetContact", "ssm-contacts:GetContactChannel", "ssm-contacts:List*", "ssm-incidents:GetReplicationSet", "ssm-incidents:GetResponsePlan", "ssm-incidents:List*", "ssm-sap:GetApplication", "ssm-sap:List*", "ssm:Describe*", "ssm:GetCommandInvocation", "ssm:GetDefaultPatchBaseline", "ssm:GetDocument", "ssm:GetParameters", "ssm:GetPatchBaseline", "ssm:GetResourcePolicies", "ssm:List*", "sso:DescribeAccountAssignmentCreationStatus", "sso:DescribePermissionSet", "sso:GetInlinePolicyForPermissionSet", "sso:GetManagedApplicationInstance", "sso:GetPermissionsBoundaryForPermissionSet", "sso:GetSharedSsoConfiguration", "sso:ListAccountAssignments", "sso:ListApplicationAssignments", "sso:ListApplications", "sso:ListCustomerManagedPolicyReferencesInPermissionSet", "sso:ListInstances", "sso:ListManagedPoliciesInPermissionSet", "sso:ListPermissionSets", "sso:ListTagsForResource", "states:GetExecutionHistory", "states:Describe*", "states:List*", "support:DescribeCases", "synthetics:Describe*", "synthetics:GetCanary", "synthetics:GetCanaryRuns", "synthetics:GetGroup", "synthetics:List*", "tag:GetResources", "timestream:Describe*", "timestream:List*", "transfer:Describe*", "transfer:List*", "verifiedpermissions:GetIdentitySource", "verifiedpermissions:GetPolicy", "verifiedpermissions:GetPolicyStore", "verifiedpermissions:GetPolicyTemplate", "verifiedpermissions:GetSchema", "verifiedpermissions:List*", "vpc-lattice:GetAccessLogSubscription", "vpc-lattice:GetAuthPolicy", "vpc-lattice:GetListener", "vpc-lattice:GetResourcePolicy", "vpc-lattice:GetRule", "vpc-lattice:GetService", "vpc-lattice:GetServiceNetwork", "vpc-lattice:GetServiceNetworkServiceAssociation", "vpc-lattice:GetServiceNetworkVpcAssociation", "vpc-lattice:GetTargetGroup", "vpc-lattice:List*", "wafv2:GetIPSet", "wafv2:GetLoggingConfiguration", "wafv2:GetRegexPatternSet", "wafv2:GetRuleGroup", "wafv2:GetWebACL", "wafv2:GetWebACLForResource", "wafv2:List*", "workspaces-web:GetBrowserSettings", "workspaces-web:GetIdentityProvider", "workspaces-web:GetNetworkSettings", "workspaces-web:GetPortal", "workspaces-web:GetPortalServiceProviderMetadata", "workspaces-web:GetTrustStore", "workspaces-web:GetUserAccessLoggingSettings", "workspaces-web:GetUserSettings", "workspaces-web:List*", "workspaces:Describe*", "xray:BatchGetTraces", "xray:GetGroup", "xray:GetGroups", "xray:GetSamplingRules", "xray:GetServiceGraph", "xray:GetTraceSummaries", "xray:List*" ], "Resource": "*" }, { "Sid": "AIOPSAPIGatewayAccess", "Effect": "Allow", "Action": ["apigateway:GET"], "Resource": [ "arn:aws:apigateway:*::/restapis", "arn:aws:apigateway:*::/restapis/*", "arn:aws:apigateway:*::/restapis/*/deployments", "arn:aws:apigateway:*::/restapis/*/deployments/*", "arn:aws:apigateway:*::/restapis/*/resources/*/methods/*/integrations", "arn:aws:apigateway:*::/restapis/*/resources/*/methods/*/integrations/*", "arn:aws:apigateway:*::/restapis/*/stages", "arn:aws:apigateway:*::/restapis/*/stages/*", "arn:aws:apigateway:*::/apis", "arn:aws:apigateway:*::/apis/*", "arn:aws:apigateway:*::/apis/*/deployments", "arn:aws:apigateway:*::/apis/*/deployments/*", "arn:aws:apigateway:*::/apis/*/integrations", "arn:aws:apigateway:*::/apis/*/integrations/*", "arn:aws:apigateway:*::/apis/*/stages", "arn:aws:apigateway:*::/apis/*/stages/*", "arn:aws:apigateway:*::/domainnames", "arn:aws:apigateway:*::/domainnames/*" ] } ] }