Amazon SageMaker API 許可:動作、許可和資源參考 - Amazon SageMaker

本文為英文版的機器翻譯版本,如內容有任何歧義或不一致之處,概以英文版為準。

Amazon SageMaker API 許可:動作、許可和資源參考

當您設定存取控制,並撰寫可連接至 IAM 身分的許可政策 (身分型政策) 時,請使用以下資料表做為參考。此表格列出每個 Amazon SageMaker API 作業、您可以授與執行動作權限的對應動作,以及您可以授與權限的 AWS 資源。您在政策的 Action 欄位中指定動作,然後在政策的 Resource 欄位中指定資源值。

注意

除了 ListTags API 外,資源層級限制在 List- 呼叫上無法使用。任何呼叫 List- API 的使用者將會看到帳戶中該類型的所有資源。

若要表示 Amazon SageMaker 政策中的條件,您可以使用 AWS寬條件金鑰。如需完 AWS整金鑰清單,請參閱 IAM 使用者指南中的可用金鑰

警告

某些 SageMaker API 動作仍可透過Search API. 例如,如果使用者的 IAM 政策拒絕特定 SageMaker 資源Describe呼叫的許可,該使用者仍然可以透過 Search API 存取說明資訊。若要完全限制使用者存取 Describe 呼叫,您還必須限制對 Search API 的存取。如需可透過搜尋 API 存取的 SageMaker 資源清單,請參閱SageMaker 搜尋 AWS CLI 命令參考

使用捲軸查看資料表的其餘部分。

Amazon SageMaker API 操作和動作所需的許可
Amazon SageMaker API 操作 所需許可 (API 動作) 資源

DeleteEarthObservationJob

sagemaker-geospatial:DeleteEarthObservationJob

arn:aws:sagemaker-geospatial:region:account-id:earth-observation-job/id

DeleteVectorEnrichmentJob

sagemaker-geospatial:DeleteVectorEnrichmentJob

arn:aws:sagemaker-geospatial:region:account-id:vector-enrichment-job/id

ExportEarthObservationJob

sagemaker-geospatial:ExportEarthObservationJob

arn:aws:sagemaker-geospatial:region:account-id:earth-observation-job/id

ExportVectorEnrichmentJob

sagemaker-geospatial:ExportVectorEnrichmentJob

arn:aws:sagemaker-geospatial:region:account-id:vector-enrichment-job/id

GetEarthObservationJob

sagemaker-geospatial:GetEarthObservationJob

arn:aws:sagemaker-geospatial:region:account-id:earth-observation-job/id

GetRasterDataCollection

sagemaker-geospatial:GetRasterDataCollection

arn:aws:sagemaker-geospatial:region:account-id:raster-data-collection/public/id

GetTile

sagemaker-geospatial:GetTile

arn:aws:sagemaker-geospatial:region:account-id:earth-observation-job/id

GetVectorEnrichmentJob

sagemaker-geospatial:GetVectorEnrichmentJob

arn:aws:sagemaker-geospatial:region:account-id:vector-enrichment-job/id

ListEarthObservationJobs

sagemaker-geospatial:ListEarthObservationJobs

*

ListRasterDataCollections

sagemaker-geospatial:ListRasterDataCollections

*

ListTagsForResource

sagemaker-geospatial:ListTagsForResource

arn:aws:sagemaker-geospatial:region:account-id:earth-observation-job/id

arn:aws:sagemaker-geospatial:region:account-id:vector-enrichment-job/id

ListVectorEnrichmentJobs

sagemaker-geospatial:ListVectorEnrichmentJobs

*

SearchRasterDataCollection

sagemaker-geospatial:SearchRasterDataCollection

arn:aws:sagemaker-geospatial:region:account-id:raster-data-collection/public/id

StartEarthObservationJob

sagemaker-geospatial:StartEarthObservationJob

arn:aws:sagemaker-geospatial:region:account-id:earth-observation-job/id

StartVectorEnrichmentJob

sagemaker-geospatial:StartVectorEnrichmentJob

arn:aws:sagemaker-geospatial:region:account-id:vector-enrichment-job/id

StopEarthObservationJob

sagemaker-geospatial:StopEarthObservationJob

arn:aws:sagemaker-geospatial:region:account-id:earth-observation-job/id

StopVectorEnrichmentJob

sagemaker-geospatial:StopVectorEnrichmentJob

arn:aws:sagemaker-geospatial:region:account-id:vector-enrichment-job/id

TagResource

sagemaker-geospatial:TagResource

arn:aws:sagemaker-geospatial:region:account-id:earth-observation-job/id

arn:aws:sagemaker-geospatial:region:account-id:vector-enrichment-job/id

UntagResource

sagemaker-geospatial:UntagResource

arn:aws:sagemaker-geospatial:region:account-id:earth-observation-job/id

arn:aws:sagemaker-geospatial:region:account-id:vector-enrichment-job/id

AddTags

sagemaker:AddTags

arn:aws:sagemaker:region:account-id:*

CreateApp

sagemaker:CreateApp

arn:aws:sagemaker:region:account-id:app/domain-id/user-profile-name/app-type/appName

CreateAppImageConfig

sagemaker:CreateAppImageConfig

arn:aws:sagemaker:region:account-id:app-image-config/appImageConfigName

CreateAutoMLJob

sagemaker:CreateAutoMLJob

iam:PassRole

下列許可只在相關的 ResourceConfig 有指定的 VolumeKmsKeyId 並且關聯的角色沒有允許此動作的政策時才需要:

kms:CreateGrant

arn:aws:sagemaker:region:account-id:automl-job/autoMLJobName

CreateAutoMLJobV2

sagemaker:CreateAutoMLJobV2

iam:PassRole

下列許可只在相關的 ResourceConfig 有指定的 VolumeKmsKeyId 並且關聯的角色沒有允許此動作的政策時才需要:

kms:CreateGrant

arn:aws:sagemaker:region:account-id:automl-job/autoMLJobName

CreateDomain

sagemaker:CreateDomain

iam:CreateServiceLinkedRole

iam:PassRole

如果針對 KmsKeyId 指定 KMS 客戶受管金鑰則需要:

elasticfilesystem:CreateFileSystem

kms:CreateGrant

kms:Decrypt

kms:DescribeKey

kms:GenerateDataKeyWithoutPlainText

建立支援 RStudio 的網域時則需要:

sagemaker:CreateApp

arn:aws:sagemaker:region:account-id:domain/domain-id

CreateEndpoint

sagemaker:CreateEndpoint

kms:CreateGrant (只在相關的 EndPointConfig 有指定的 KmsKeyId 時需要)

arn:aws:sagemaker:region:account-id:endpoint/endpointName

arn:aws:sagemaker:region:account-id:endpoint-config/endpointConfigName

CreateEndpointConfig

sagemaker:CreateEndpointConfig

arn:aws:sagemaker:region:account-id:endpoint-config/endpointConfigName

CreateFlowDefinition

sagemaker:CreateFlowDefinition

iam:PassRole

arn:aws:sagemaker:region:account-id:flow-definition/flowDefinitionName

CreateHumanTaskUi

sagemaker:CreateHumanTaskUi

arn:aws:sagemaker:region:account-id:human-task-ui/humanTaskUiName

CreateInferenceRecommendationsJob

sagemaker:CreateInferenceRecommendationsJob

iam:PassRole

只有在您指定加密金鑰時才需要以下許可:

kms:CreateGrant

kms:Decrypt

kms:DescribeKey

kms:GenerateDataKey

arn:aws:sagemaker:region:account-id:inference-recommendations-job/inferenceRecommendationsJobName

CreateHyperParameterTuningJob

sagemaker:CreateHyperParameterTuningJob

iam:PassRole

下列許可只在相關的 ResourceConfig 有指定的 VolumeKmsKeyId 並且關聯的角色沒有允許此動作的政策時才需要:

kms:CreateGrant

arn:aws:sagemaker:region:account-id:hyper-parameter-tuning-job/hyperParameterTuningJobName

CreateImage

sagemaker:CreateImage

iam:PassRole

arn:aws:sagemaker:region:account-id:image/*

CreateImageVersion

sagemaker:CreateImageVersion

arn:aws:sagemaker:region:account-id:image-version/imageName/*

CreateLabelingJob

Job 者:CreateLabeling工作

IAM:PassRole

arn:aws:sagemaker:region:account-id:labeling-job/labelingJobName

CreateModel

sagemaker:CreateModel

iam:PassRole

arn:aws:sagemaker:region:account-id:model/modelName

CreateModelPackage

sagemaker:CreateModelPackage

arn:aws:sagemaker:region:account-id:model-package/modelPackageName

CreateModelPackageGroup

sagemaker:CreateModelPackageGroup

arn:aws:sagemaker:region:account-id:model-package-group/modelPackageGroupName

CreateNotebookInstance

sagemaker:CreateNotebookInstance

iam:PassRole

只有在您針對筆記本執行個體指定 VPC 時,才需要以下許可:

ec2:CreateNetworkInterface

ec2:DescribeSecurityGroups

ec2:DescribeSubnets

ec2:DescribeVpcs

只有在您針對筆記本執行個體指定 VPC 和 Elastic Inference Accelerator 時,才需要以下許可:

ec2:DescribeVpcEndpoints

只有在您指定加密金鑰時才需要以下許可:

kms:DescribeKey

kms:CreateGrant

只有在您指定 AWS Secrets Manager 機密存取私有 Git 儲存器時,才需要以下許可:

secretsmanager:GetSecretValue

arn:aws:sagemaker:region:account-id:notebook-instance/notebookInstanceName

CreatePipeline

sagemaker:CreatePipeline

iam:PassRole

arn:aws-partition:sagemaker:region:account-id:pipeline/pipeline-name

arn:aws-partition:iam::account-id:role/role-name

CreatePresignedDomainUrl

sagemaker:CreatePresignedDomainUrl

arn:aws:sagemaker:region:account-id:app/domain-id/userProfileName/*

CreatePresignedNotebookInstanceUrl

sagemaker:CreatePresignedNotebookInstanceUrl

arn:aws:sagemaker:region:account-id:notebook-instance/notebookInstanceName

CreateProcessingJob

sagemaker:CreateProcessingJob

iam:PassRole

kms:CreateGrant (只在相關的 ProcessingResources 有指定的 VolumeKmsKeyId 並且關聯的角色沒有允許此動作的政策時才需要)

ec2:CreateNetworkInterface(僅當您指定 VPC 時才需要)

arn:aws:sagemaker:region:account-id:processing-job/processingJobName

CreateSpace

sagemaker:CreateSpace

arn:aws:sagemaker:region:account-id:space/domain-id/spaceName

CreateStudioLifecycleConfig

sagemaker:CreateStudioLifecycleConfig

arn:aws:sagemaker:region:account-id:studio-lifecycle-config/.*

CreateTrainingJob

sagemaker:CreateTrainingJob

iam:PassRole

kms:CreateGrant (只在相關的 ResourceConfig 有指定的 VolumeKmsKeyId 並且關聯的角色沒有允許此動作的政策時才需要)

arn:aws:sagemaker:region:account-id:training-job/trainingJobName

CreateTransformJob

sagemaker:CreateTransformJob

kms:CreateGrant (只在相關的 TransformResources 有指定的 VolumeKmsKeyId 並且關聯的角色沒有允許此動作的政策時才需要)

arn:aws:sagemaker:region:account-id:transform-job/transformJobName

CreateUserProfile

sagemaker:CreateUserProfile

iam:PassRole

arn:aws:sagemaker:region:account-id:user-profile/domain-id/userProfileName

CreateWorkforce

sagemaker:CreateWorkforce

cognito-idp:DescribeUserPoolClient

cognito-idp:UpdateUserPool

cognito-idp:DescribeUserPool

cognito-idp:UpdateUserPoolClient

arn:aws:sagemaker:region:account-id:workforce/*

CreateWorkteam

sagemaker:CreateWorkteam

cognito-idp:DescribeUserPoolClient

cognito-idp:UpdateUserPool

cognito-idp:DescribeUserPool

cognito-idp:UpdateUserPoolClient

arn:aws:sagemaker:region:account-id:workteam/private-crowd/work team name

DeleteApp

sagemaker:DeleteApp

arn:aws:sagemaker:region:account-id:app/domain-id/user-profile-name/app-type/appName

DeleteAppImageConfig

sagemaker:DeleteAppImageConfig

arn:aws:sagemaker:region:account-id:app-image-config/appImageConfigName

DeleteDomain

sagemaker:DeleteDomain

arn:aws:sagemaker:region:account-id:domain/domainId

DeleteEndpoint

sagemaker:DeleteEndpoint

arn:aws:sagemaker:region:account-id:endpoint/endpointName

DeleteEndpointConfig

sagemaker:DeleteEndpointConfig

arn:aws:sagemaker:region:account-id:endpoint-config/endpointConfigName

DeleteFlowDefinition

sagemaker:DeleteFlowDefinition

arn:aws:sagemaker:region:account-id:flow-definition/flowDefinitionName

DeleteHumanLoop

sagemaker:DeleteHumanLoop

arn:aws:sagemaker:region:account-id:human-loop/humanLoopName

DeleteImage

sagemaker:DeleteImage

arn:aws:sagemaker:region:account-id:image/imageName

DeleteImageVersion

sagemaker:DeleteImageVersion

arn:aws:sagemaker:region:account-id:image-version/imageName/versionNumber

DeleteModel

sagemaker:DeleteModel

arn:aws:sagemaker:region:account-id:model/modelName

DeleteModelPackage

sagemaker:DeleteModelPackage

arn:aws:sagemaker:region:account-id:model-package/modelPackageName

DeleteModelPackageGroup

sagemaker:DeleteModelPackageGroup

arn:aws:sagemaker:region:account-id:model-package-group/modelPackageGroupName

DeleteModelPackageGroupPolicy

sagemaker:DeleteModelPackageGroupPolicy

arn:aws:sagemaker:region:account-id:model-package-group/modelPackageGroupName

DeleteNotebookInstance

sagemaker:DeleteNotebookInstance

只有在您針對筆記本執行個體指定 VPC 後,才需要以下許可:

ec2:DeleteNetworkInterface

只有在您於建立筆記本執行個體時指定加密金鑰後,才需要以下許可:

kms:DescribeKey

arn:aws:sagemaker:region:account-id:notebook-instance/notebookInstanceName

DeletePipeline

sagemaker:DeletePipeline

arn:aws-partition:sagemaker:region:account-id:pipeline/pipeline-name

DeleteSpace

sagemaker:DeleteSpace

arn:aws:sagemaker:region:account-id:space/domain-id/spaceName

DeleteTags

sagemaker:DeleteTags

arn:aws:sagemaker:region:account-id:*

DeleteUserProfile

sagemaker:DeleteUserProfile

arn:aws:sagemaker:region:account-id:user-profile/domain-id/userProfileName

DeleteWorkforce

sagemaker:DeleteWorkforce

arn:aws:sagemaker:region:account-id:workforce/*

DeleteWorkteam

sagemaker:DeleteWorkteam

arn:aws:sagemaker:region:account-id:workteam/private-crowd/*

DescribeApp

sagemaker:DescribeApp

arn:aws:sagemaker:region:account-id:app/domain-id/user-profile-name/app-type/appName

DescribeAppImageConfig

sagemaker:DescribeAppImageConfig

arn:aws:sagemaker:region:account-id:app-image-config/appImageConfigName

DescribeAutoMLJob

sagemaker:DescribeAutoMLJob

arn:aws:sagemaker:region:account-id:automl-job/autoMLJobName

DescribeAutoMLJobV2

sagemaker:DescribeAutoMLJobV2

arn:aws:sagemaker:region:account-id:automl-job/autoMLJobName

DescribeDomain

sagemaker:DescribeDomain

arn:aws:sagemaker:region:account-id:domain/domainId

DescribeEndpoint

sagemaker:DescribeEndpoint

arn:aws:sagemaker:region:account-id:endpoint/endpointName

DescribeEndpointConfig

sagemaker:DescribeEndpointConfig

arn:aws:sagemaker:region:account-id:endpoint-config/endpointConfigName

DescribeFlowDefinition

sagemaker:DescribeFlowDefinition

arn:aws:sagemaker:region:account-id:flow-definition/flowDefinitionName

DescribeHumanLoop

sagemaker:DescribeHumanLoop

arn:aws:sagemaker:region:account-id:human-loop/humanLoopName

DescribeHumanTaskUi

sagemaker:DescribeHumanTaskUi

arn:aws:sagemaker:region:account-id:human-task-ui/humanTaskUiName

DescribeHyperParameterTuningJob

sagemaker:DescribeHyperParameterTuningJob

arn:aws:sagemaker:region:account-id:hyper-parameter-tuning-job/hyperParameterTuningJob

DescribeImage

sagemaker:DescribeImage

arn:aws:sagemaker:region:account-id:image/imageName

DescribeImageVersion

sagemaker:DescribeImageVersion

arn:aws:sagemaker:region:account-id:image-version/imageName/versionNumber

DescribeLabelingJob

sagemaker:DescribeLabelingJob

arn:aws:sagemaker:region:account-id:labeling-job/labelingJobName

DescribeModel

sagemaker:DescribeModel

arn:aws:sagemaker:region:account-id:model/modelName

DescribeModelPackage

sagemaker:DescribeModelPackage

arn:aws:sagemaker:region:account-id:model-package/modelPackageName

DescribeModelPackageGroup

sagemaker:DescribeModelPackageGroup

arn:aws:sagemaker:region:account-id:model-package-group/modelPackageGroupName

DescribeNotebookInstance

sagemaker:DescribeNotebookInstance

arn:aws:sagemaker:region:account-id:notebook-instance/notebookInstanceName

DescribePipeline

sagemaker:DescribePipeline

arn:aws-partition:sagemaker:region:account-id:pipeline/pipeline-name

DescribePipelineDefinitionForExecution

sagemaker:DescribePipelineDefinitionForExecution

arn:aws-partition:sagemaker:region:account-id:pipeline/pipeline-name/execution/execution-id

DescribePipelineExecution

sagemaker:DescribePipelineExecution

arn:aws-partition:sagemaker:region:account-id:pipeline/pipeline-name/execution/execution-id

DescribeProcessingJob

sagemaker:DescribeProcessingJob

arn:aws:sagemaker:region:account-id:processing-job/processingjobname

DescribeSpace

sagemaker:DescribeSpace

arn:aws:sagemaker:region:account-id:space/domain-id/spaceName

DescribeSubscribedWorkteam

sagemaker:DescribeSubscribedWorkteam

aws-marketplace:ViewSubscriptions

arn:aws:sagemaker:region:account-id:workteam/vendor-crowd/*

DescribeTrainingJob

sagemaker:DescribeTrainingJob

arn:aws:sagemaker:region:account-id:training-job/trainingjobname

DescribeTransformJob

sagemaker:DescribeTransformJob

arn:aws:sagemaker:region:account-id:transform-job/transformjobname

DescribeUserProfile

sagemaker:DescribeUserProfile

arn:aws:sagemaker:region:account-id:user-profile/domain-id/userProfileName

DescribeWorkforce

sagemaker:DescribeWorkforce

arn:aws:sagemaker:region:account-id:workforce/*

DescribeWorkteam

sagemaker:DescribeWorkteam

arn:aws:sagemaker:region:account-id:workteam/private-crowd/*

GetModelPackageGroupPolicy

sagemaker:GetModelPackageGroupPolicy

arn:aws:sagemaker:region:account-id:model-package-group/modelPackageGroupName

InvokeEndpoint

sagemaker:InvokeEndpoint

arn:aws:sagemaker:region:account-id:endpoint/endpointName

ListAppImageConfigs

sagemaker:ListAppImageConfigs

arn:aws:sagemaker:region:account-id:app-image-config/*

ListApps

sagemaker:ListApps

arn:aws:sagemaker:region:account-id:app/domain-id/user-profile-name/*

ListDomains

sagemaker:ListDomains

arn:aws:sagemaker:region:account-id:domain/*

ListEndpointConfigs

sagemaker:ListEndpointConfigs

*

ListEndpoints

sagemaker:ListEndpoints

*

ListFlowDefinitions

sagemaker:ListFlowDefinitions

*

ListHumanLoops

sagemaker:ListHumanLoops

*

ListHumanTaskUis

sagemaker:ListHumanTaskUis

*

ListHyperParameterTuningJobs

sagemaker:ListHyperParameterTuningJobs

arn:aws:sagemaker:region:account-id:hyper-parameter-tuning-job/hyperParameterTuningJob

ListImages

sagemaker:ListImages

*

ListImageVersions

sagemaker:ListImageVersions

arn:aws:sagemaker:region:account-id:image/*

ListLabelingJobs

sagemaker:ListLabelingJobs

*

ListLabelingJobsForWorkteam

sagemaker:ListLabelingJobForWorkteam

*

ListModelPackageGroups

sagemaker:ListModelPackageGroups

arn:aws:sagemaker:region:account-id :model-package-group/ModelPackageGroupName

ListModelPackages

sagemaker:ListModelPackages

arn:aws:sagemaker:region:account-id :model-package/ModelPackageName

ListModels

sagemaker:ListModels

*

ListNotebookInstances

sagemaker:ListNotebookInstances

*

ListPipelineExecutions

sagemaker:ListPipelineExecutions

arn:aws-partition:sagemaker:region:account-id:pipeline/pipeline-name

ListPipelineExecutionSteps

sagemaker:ListPipelineExecutionSteps

arn:aws-partition:sagemaker:region:account-id:pipeline/pipeline-name/execution/execution-id

ListPipelineParametersForExecution

sagemaker:ListPipelineParametersForExecution

arn:aws-partition:sagemaker:region:account-id:pipeline/pipeline-name/execution/execution-id

ListPipelines

sagemaker:ListPipelines

*

ListProcessingJobs

sagemaker:ListProcessingJobs

*

ListSpaces

sagemaker:ListSpaces

arn:aws:sagemaker:region:account-id:space/domain-id/*

ListSubscribedWorkteams

sagemaker:ListSubscribedWorkteams

aws-marketplace:ViewSubscriptions

*

ListTags

sagemaker:ListTags

arn:aws:sagemaker:region:account-id:*

ListTrainingJobs

sagemaker:ListTrainingJobs

*

ListTrainingJobsForHyperParameterTuningJob

sagemaker:ListTrainingJobsForHyperParameterTuningJob

arn:aws:sagemaker:region:account-id:hyper-parameter-tuning-job/hyperParameterTuningJob

ListTransformJobs

sagemaker:ListTransformJobs

*

ListUserProfiles

sagemaker:ListUserProfiles

arn:aws:sagemaker:region:account-id:user-profile/domain-id/*

ListWorkforces

sagemaker:ListWorkforces

*

ListWorkteams

sagemaker:ListWorkteams

*

PutModelPackageGroupPolicy

sagemaker:PutModelPackageGroupPolicy

arn:aws:sagemaker:region:account-id:model-package-group/modelPackageGroupName

RetryPipelineExecution

sagemaker:RetryPipelineExecution

arn:aws-partition:sagemaker:region:account-id:pipeline/pipeline-name/execution/execution-id

Search

sagemaker:Search

*

SendPipelineExecutionStepFailure

sagemaker:SendPipelineExecutionStepFailure

*

SendPipelineExecutionStepSuccess

sagemaker:SendPipelineExecutionStepSuccess

*

StartHumanLoop

sagemaker:StartHumanLoop

arn:aws:sagemaker:region:account-id:human-loop/humanLoopName

StartNotebookInstance

sagemaker:StartNotebookInstance

只有在您於建立筆記本執行個體時指定 VPC 後,才需要以下許可:

ec2:CreateNetworkInterface

ec2:DescribeNetworkInterfaces

ec2:DescribeSecurityGroups

ec2:DescribeSubnets

ec2:DescribeVpcs

只有在您針對筆記本執行個體指定 VPC 和 Elastic Inference Accelerator 時,才需要以下許可:

ec2:DescribeVpcEndpoints

只有在您於建立筆記本執行個體時指定加密金鑰後,才需要以下許可:

kms:DescribeKey

kms:CreateGrant

只有在您於建立筆記本執行個體時,指定 AWS Secrets Manager 機密存取私有 Git 儲存庫後,才需要以下許可:

secretsmanager:GetSecretValue

arn:aws:sagemaker:region:account-id:notebook-instance/notebookInstanceName

StartPipelineExecution

sagemaker:StartPipelineExecution

arn:aws-partition:sagemaker:region:account-id:pipeline/pipeline-name

StopHumanLoop

sagemaker:StopHumanLoop

arn:aws:sagemaker:region:account-id:human-loop/humanLoopName

StopHyperParameterTuningJob

sagemaker:StopHyperParameterTuningJob

arn:aws:sagemaker:region:account-id:hyper-parameter-tuning-job/hyperParameterTuningJob

StopLabelingJob

sagemaker:StopLabelingJob

arn:aws:sagemaker:region:account-id:labeling-job/labelingJobName

StopNotebookInstance

sagemaker:StopNotebookInstance

arn:aws:sagemaker:region:account-id:notebook-instance/notebookInstanceName

StopPipelineExecution

sagemaker:StopPipelineExecution

arn:aws-partition:sagemaker:region:account-id:pipeline/pipeline-name/execution/execution-id

StopProcessingJob

sagemaker:StopProcessingJob

arn:aws:sagemaker:region:account-id:processing-job/processingJobName

StopTrainingJob

sagemaker:StopTrainingJob

arn:aws:sagemaker:region:account-id:training-job/trainingJobName

StopTransformJob

sagemaker:StopTransformJob

arn:aws:sagemaker:region:account-id:transform-job/transformJobName

UpdateAppImageConfig

sagemaker:UpdateAppImageConfig

arn:aws:sagemaker:region:account-id:app-image-config/appImageConfigName

UpdateDomain

sagemaker:UpdateDomain

arn:aws:sagemaker:region:account-id:domain/domainId

UpdateEndpoint

sagemaker:UpdateEndpoint

arn:aws:sagemaker:region:account-id:endpoint/endpointName

UpdateEndpointWeightsAndCapacities

sagemaker:UpdateEndpointWeightsAndCapacities

arn:aws:sagemaker:region:account-id:endpoint/endpointName

UpdateImage

sagemaker:UpdateImage

iam:PassRole

arn:aws:sagemaker:region:account-id:image/imageName

UpdateModelPackage

sagemaker:UpdateModelPackage

arn:aws:sagemaker:region:account-id:model-package/modelPackageName

UpdateNotebookInstance

sagemaker:UpdateNotebookInstance

iam:PassRole

arn:aws:sagemaker:region:account-id:notebook-instance/notebookInstanceName

UpdatePipeline

sagemaker:UpdatePipeline

iam:PassRole

arn:aws-partition:sagemaker:region:account-id:pipeline/pipeline-name

arn:aws-partition:iam::account-id:role/role-name

UpdatePipelineExecution

sagemaker:UpdatePipelineExecution

arn:aws-partition:sagemaker:region:account-id:pipeline/pipeline-name/execution/execution-id

UpdateSpace

sagemaker:UpdateSpace

arn:aws:sagemaker:region:account-id:space/domain-id/spaceName

UpdateUserProfile

sagemaker:UpdateUserProfile

arn:aws:sagemaker:region:account-id:user-profile/domain-id/userProfileName

UpdateWorkforce

sagemaker:UpdateWorkforce

arn:aws:sagemaker:region:account-id:workforce/*

UpdateWorkteam

sagemaker:UpdateWorkteam

arn:aws:sagemaker:region:account-id:workteam/private-crowd/*