Amazon 的動作、資源和條件索引鍵 EC2 - 服務授權參考

本文為英文版的機器翻譯版本,如內容有任何歧義或不一致之處,概以英文版為準。

Amazon 的動作、資源和條件索引鍵 EC2

Amazon EC2(服務字首:ec2) 提供下列服務特定的資源、動作和條件內容索引鍵,可用於 IAM 許可政策。

參考資料:

Amazon 定義的動作 EC2

您可在 IAM 政策陳述式的 Action 元素中指定以下動作。使用政策來授予在 AWS中執行操作的許可。當您在政策中使用 動作時,通常會允許或拒絕存取具有相同名稱API的操作或CLI命令。不過,在某些情況下,單一動作可控制對多個操作的存取。或者,某些操作需要多種不同的動作。

「動作」資料表的資源類型欄會指出每個動作是否支援資源層級的許可。如果此欄沒有值,您必須在政策陳述式的 Resource 元素中指定政策適用的所有資源 ("*")。如果資料欄包含資源類型,則您可以在具有該動作ARN的陳述式中指定該類型的 。如果動作具有一或多個必要資源,呼叫者必須具有對這些資源使用動作的許可。表格中的必要資源會以星號 (*) 表示。如果您在 IAM 政策中限制使用 Resource元素存取資源,您必須為每個必要的資源類型包含 ARN或 模式。某些動作支援多種資源類型。如果資源類型是選用 (未顯示為必要),則您可以選擇使用其中一種選用資源類型。

「動作」資料表的條件索引鍵欄包含您可以在政策陳述式的 Condition 元素中指定的索引鍵。如需有關與服務資源相關聯之條件索引鍵的詳細資訊,請參閱「資源類型」資料表的條件索引鍵欄。

注意

資源條件索引鍵會列在資源類型資料表中。您可以在「動作」資料表的資源類型 (*必填) 欄中找到適用於動作的資源類型連結。「資源類型」資料表中的資源類型包括條件索引鍵欄,其中包含套用至「動作」資料表中動作的資源條件索引鍵。

如需下表各欄的詳細資訊,請參閱動作資料表

動作 描述 存取層級 資源類型 (*必填項目) 條件索引鍵 相依動作
AcceptAddressTransfer 准許接受彈性 IP 地址轉移 寫入

elastic-ip*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:AllocationId

ec2:Domain

ec2:PublicIpAddress

ec2:CreateTags

ec2:Region

AcceptCapacityReservationBillingOwnership 准許接受將共用容量預留可用容量的帳單指派給呼叫帳戶 寫入

capacity-reservation*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CapacityReservationFleet

ec2:CreateDate

ec2:DestinationCapacityReservationId

ec2:EbsOptimized

ec2:EndDate

ec2:EndDateType

ec2:InstanceCount

ec2:InstanceMatchCriteria

ec2:InstancePlatform

ec2:InstanceType

ec2:OutpostArn

ec2:PlacementGroup

ec2:ResourceTag/${TagKey}

ec2:SourceCapacityReservationId

ec2:Tenancy

ec2:Region

AcceptReservedInstancesExchangeQuote 准許接受可轉換預留執行個體的交換報價 寫入

ec2:Region

AcceptTransitGatewayMulticastDomainAssociations 准許接受關聯子網路與傳輸閘道多點傳送網域的要求 寫入

transit-gateway-attachment

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

transit-gateway-multicast-domain

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayMulticastDomainId

ec2:Region

AcceptTransitGatewayPeeringAttachment 准許接受傳輸閘道對等附件請求 寫入

transit-gateway-attachment*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

ec2:Region

AcceptTransitGatewayVpcAttachment 准許接受將 VPC 連接至傳輸閘道的請求 寫入

transit-gateway-attachment*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

ec2:Region

AcceptVpcEndpointConnections 准許接受與VPC端點服務的一或多個介面VPC端點連線 寫入

vpc-endpoint-service*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:vpceMultiRegion

ec2:vpceSupportedRegion

ec2:Region

AcceptVpcPeeringConnection 准許接受VPC對等互連連線請求 寫入

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

vpc-peering-connection*

aws:ResourceTag/${TagKey}

ec2:AccepterVpc

ec2:RequesterVpc

ec2:ResourceTag/${TagKey}

ec2:VpcPeeringConnectionID

ec2:Region

AdvertiseByoipCidr 准許公告已佈建用於 的 IP 地址範圍, AWS 方法是攜帶您自己的 IP 地址 (BYOIP) 寫入

ec2:Region

AllocateAddress 准許將彈性 IP 地址 (EIP) 配置到您的帳戶 寫入

elastic-ip*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

ipam-pool

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ipv4pool-ec2

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

AllocateHosts 准許將專用主機配置給您的帳戶 寫入

dedicated-host*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:AutoPlacement

ec2:AvailabilityZone

ec2:HostRecovery

ec2:InstanceType

ec2:Quantity

ec2:CreateTags

ec2:Region

AllocateIpamPoolCidr 准許CIDR從 Amazon VPC IP Address Manager (IPAM) 集區配置 寫入

ipam-pool*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

ApplySecurityGroupsToClientVpnTargetNetwork 准許將安全群組套用至用戶端VPN端點與目標網路之間的關聯 寫入

client-vpn-endpoint*

aws:ResourceTag/${TagKey}

ec2:ClientRootCertificateChainArn

ec2:CloudwatchLogGroupArn

ec2:CloudwatchLogStreamArn

ec2:DirectoryArn

ec2:ResourceTag/${TagKey}

ec2:SamlProviderArn

ec2:ServerCertificateArn

security-group*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

AssignIpv6Addresses 准許將一或多個IPv6地址指派給網路介面 寫入

network-interface*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

ec2:Region

AssignPrivateIpAddresses 准許將一或多個次要私有 IP 地址指派給網路界面 寫入

network-interface*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

ec2:Region

AssignPrivateNatGatewayAddress 准許將一或多個次要私有 IP 地址指派給私有NAT閘道 寫入

natgateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

AssociateAddress 准許將彈性 IP 地址 (EIP) 與執行個體或網路介面建立關聯 寫入

elastic-ip

aws:ResourceTag/${TagKey}

ec2:AllocationId

ec2:Domain

ec2:PublicIpAddress

ec2:ResourceTag/${TagKey}

instance

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

network-interface

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

ec2:Region

AssociateCapacityReservationBillingOwner 准許將共用容量預留未使用容量的帳單指派給取用者帳戶 寫入

capacity-reservation*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CapacityReservationFleet

ec2:CreateDate

ec2:DestinationCapacityReservationId

ec2:EbsOptimized

ec2:EndDate

ec2:EndDateType

ec2:InstanceCount

ec2:InstanceMatchCriteria

ec2:InstancePlatform

ec2:InstanceType

ec2:OutpostArn

ec2:PlacementGroup

ec2:ResourceTag/${TagKey}

ec2:SourceCapacityReservationId

ec2:Tenancy

ec2:Region

AssociateClientVpnTargetNetwork 准許將目標網路與用戶端VPN端點建立關聯 寫入

client-vpn-endpoint*

aws:ResourceTag/${TagKey}

ec2:ClientRootCertificateChainArn

ec2:CloudwatchLogGroupArn

ec2:CloudwatchLogStreamArn

ec2:DirectoryArn

ec2:ResourceTag/${TagKey}

ec2:SamlProviderArn

ec2:ServerCertificateArn

subnet*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Region

AssociateDhcpOptions 准許將一組DHCP選項與 建立關聯或取消關聯 VPC 寫入

dhcp-options*

aws:ResourceTag/${TagKey}

ec2:DhcpOptionsID

ec2:ResourceTag/${TagKey}

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

AssociateEnclaveCertificateIamRole 准許將ACM憑證與要在 EC2 Enclave 中使用的IAM角色建立關聯 寫入

certificate*

role*

ec2:Region

AssociateIamInstanceProfile 准許將IAM執行個體描述檔與執行中或已停止的執行個體建立關聯 寫入

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:NewInstanceProfile

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

iam:PassRole

ec2:Region

AssociateInstanceEventWindow 准許將一或多個目標與事件時段相關聯 寫入

instance-event-window*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

AssociateIpamByoasn 准許將自治系統編號 (ASN) 與 BYOIP CIDR 寫入

ec2:Region

AssociateIpamResourceDiscovery 准許將IPAM資源探索與 Amazon 建立關聯 VPC IPAM 寫入

ipam*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:CreateTags

ipam-resource-discovery*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ipam-resource-discovery-association*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:Region

AssociateNatGatewayAddress 准許將彈性 IP 地址和私有 IP 地址與公有 NAT 閘道建立關聯 寫入

elastic-ip*

aws:ResourceTag/${TagKey}

ec2:AllocationId

ec2:Domain

ec2:PublicIpAddress

ec2:ResourceTag/${TagKey}

natgateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

AssociateRouteTable 准許將子網路或閘道與路由表建立關聯 寫入

route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:RouteTableID

ec2:Vpc

internet-gateway

aws:ResourceTag/${TagKey}

ec2:InternetGatewayID

ec2:ResourceTag/${TagKey}

subnet

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

vpn-gateway

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

AssociateSecurityGroupVpc 准許將安全群組與VPC相同區域中的另一個群組建立關聯 寫入

security-group*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

vpc*

aws:ResourceTag/${TagKey}

ec2:Ipv4IpamPoolId

ec2:Ipv6IpamPoolId

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

AssociateSubnetCidrBlock 准許將CIDR區塊與子網路建立關聯 寫入

subnet*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

ipam-pool

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

AssociateTransitGatewayMulticastDomain 准許將附件和子網路清單與傳輸閘道多點傳送網域建立關聯 寫入

subnet*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

transit-gateway-attachment*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

transit-gateway-multicast-domain*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayMulticastDomainId

ec2:Region

AssociateTransitGatewayPolicyTable 准許將政策資料表與傳輸閘道連接相關聯 寫入

transit-gateway-attachment*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

transit-gateway-policy-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayPolicyTableId

ec2:Region

AssociateTransitGatewayRouteTable 准許將附件與傳輸閘道路由表建立關聯 寫入

transit-gateway-attachment*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

transit-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableId

ec2:Region

AssociateTrunkInterface 准許將分支網路界面與幹線網路界面相關聯 寫入

ec2:Region

AssociateVerifiedAccessInstanceWebAcl [僅限許可] 准許將 AWS Web Application Firewall (WAF) Web 存取控制清單 (ACL) 與 Verified Access 執行個體建立關聯 寫入

verified-access-instance*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

AssociateVpcCidrBlock 准許將CIDR區塊與 建立關聯 VPC 寫入

vpc*

aws:ResourceTag/${TagKey}

ec2:Ipv4IpamPoolId

ec2:Ipv6IpamPoolId

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ipam-pool

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ipv6pool-ec2

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

AttachClassicLinkVpc 准許VPC透過一或多個 的安全群組,將 EC2-Classic 執行個體連結至 ClassicLink已啟用VPC的 寫入

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

security-group*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

AttachInternetGateway 准許將網際網路閘道連接至 VPC 寫入

internet-gateway*

aws:ResourceTag/${TagKey}

ec2:InternetGatewayID

ec2:ResourceTag/${TagKey}

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

AttachNetworkInterface 准許將網路界面連接至執行個體 寫入

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

network-interface*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

ec2:Region

AttachVerifiedAccessTrustProvider 准許將受信任提供者連接至 Verified Access 執行個體 寫入

verified-access-instance*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

verified-access-trust-provider*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

AttachVolume 准許將EBS磁碟區連接至執行中或已停止的執行個體,並使用指定的裝置名稱將其公開至執行個體 寫入

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

volume*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:Encrypted

ec2:ManagedResourceOperator

ec2:ParentSnapshot

ec2:ResourceTag/${TagKey}

ec2:VolumeID

ec2:VolumeIops

ec2:VolumeSize

ec2:VolumeThroughput

ec2:VolumeType

ec2:Region

AttachVpnGateway 准許將虛擬私有閘道連接至 VPC 寫入

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

vpn-gateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

AuthorizeClientVpnIngress 准許將傳入授權規則新增至用戶端VPN端點 寫入

client-vpn-endpoint*

aws:ResourceTag/${TagKey}

ec2:ClientRootCertificateChainArn

ec2:CloudwatchLogGroupArn

ec2:CloudwatchLogStreamArn

ec2:DirectoryArn

ec2:ResourceTag/${TagKey}

ec2:SamlProviderArn

ec2:ServerCertificateArn

ec2:Region

AuthorizeSecurityGroupEgress 准許將一或多個傳出規則新增至VPC安全群組。只有在API請求包含 時, security-group-rule才會強制執行使用資源層級許可的政策 TagSpecifications 寫入

security-group*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

ec2:CreateTags

security-group-rule

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:Region

AuthorizeSecurityGroupIngress 准許將一或多個傳入規則新增至VPC安全群組。只有在API請求包含 時, security-group-rule才會強制執行使用資源層級許可的政策 TagSpecifications 寫入

security-group*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

ec2:CreateTags

security-group-rule

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:Region

BundleInstance 准許綁定執行個體存放區支援的 Windows 執行個體 寫入

ec2:Region

CancelBundleTask 准許取消綁定操作 寫入

ec2:Region

CancelCapacityReservation 准許取消容量保留並釋出預留容量 寫入

capacity-reservation*

aws:ResourceTag/${TagKey}

ec2:CapacityReservationFleet

ec2:Region

CancelCapacityReservationFleets 准許取消一或多個容量保留機群 寫入

capacity-reservation-fleet*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:CancelCapacityReservation

ec2:Region

CancelConversionTask 准許取消作用中的轉換任務 寫入

ec2:Region

CancelDeclarativePoliciesReport 准許取消宣告政策報告 寫入

declarative-policies-report*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

CancelExportTask 准許取消作用中的匯出任務 寫入

export-image-task

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

export-instance-task

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

CancelImageLaunchPermission 准許 AWS 帳戶 從指定 的啟動許可中移除您的 AMI 寫入

image*

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Region

CancelImportTask 准許取消進行中的匯入虛擬機器或匯入快照任務 寫入

import-image-task

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

import-snapshot-task

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

CancelReservedInstancesListing 准許取消預留執行個體 Marketplace 上的預留執行個體清單 寫入

ec2:Region

CancelSpotFleetRequests 准許取消一或多個 Spot 機群請求 寫入

spot-fleet-request*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

CancelSpotInstanceRequests 准許取消一或多個 Spot 執行個體請求 寫入

spot-instances-request*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

ConfirmProductInstance 准許決定擁有的產品代碼是否與執行個體相關聯 寫入

ec2:Region

CopyFpgaImage 准許將來源 Amazon FPGA映像 (AFI) 複製到目前區域。此動作指定的資源層級許可AFI僅適用於新的 。它們不適用於來源 AFI 寫入

fpga-image*

ec2:Owner

ec2:Region

CopyImage 准許將 Amazon Machine Image (AMI) 從來源區域複製到目前區域 寫入

image*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:ImageID

ec2:Owner

ec2:CreateTags

snapshot*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:Region

CopySnapshot 准許複製 point-in-timeEBS磁碟區的快照,並將其存放在 Amazon S3 中。為此動作指定的資源層級許可僅適用於新快照。它們不適用於來源快照 寫入

snapshot*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:OutpostArn

ec2:SnapshotID

ec2:CreateTags

ec2:Region

CreateCapacityReservation 准許建立容量保留 寫入

capacity-reservation*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CapacityReservationFleet

ec2:CreateTags

ec2:Region

CreateCapacityReservationBySplitting 准許分割來源容量預留的可用容量,以建立新的容量預留 寫入

capacity-reservation*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CapacityReservationFleet

ec2:CreateDate

ec2:DestinationCapacityReservationId

ec2:EbsOptimized

ec2:EndDate

ec2:EndDateType

ec2:InstanceCount

ec2:InstanceMatchCriteria

ec2:InstancePlatform

ec2:InstanceType

ec2:OutpostArn

ec2:PlacementGroup

ec2:ResourceTag/${TagKey}

ec2:SourceCapacityReservationId

ec2:Tenancy

ec2:CreateTags

ec2:Region

CreateCapacityReservationFleet 准許建立容量保留機群 寫入

capacity-reservation-fleet*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateCapacityReservation

ec2:CreateTags

ec2:DescribeCapacityReservations

ec2:DescribeInstances

ec2:Region

CreateCarrierGateway 准許建立電信業者閘道,並為客戶提供CSP連線 VPC 寫入

carrier-gateway*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

CreateClientVpnEndpoint 准許建立用戶端VPN端點 寫入

client-vpn-endpoint*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:ClientRootCertificateChainArn

ec2:CloudwatchLogGroupArn

ec2:CloudwatchLogStreamArn

ec2:DirectoryArn

ec2:SamlProviderArn

ec2:ServerCertificateArn

ec2:CreateTags

security-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

vpc

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:VpcID

ec2:Region

CreateClientVpnRoute 准許將網路路由新增至用戶端VPN端點的路由表 寫入

client-vpn-endpoint*

aws:ResourceTag/${TagKey}

ec2:ClientRootCertificateChainArn

ec2:CloudwatchLogGroupArn

ec2:CloudwatchLogStreamArn

ec2:DirectoryArn

ec2:ResourceTag/${TagKey}

ec2:SamlProviderArn

ec2:ServerCertificateArn

subnet*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Region

CreateCoipCidr 准許建立客戶擁有的 IP (CoIP) 地址範圍 寫入

coip-pool*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

CreateCoipPool 准許建立客戶擁有的 IP (CoIP) 地址集區 寫入

coip-pool*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

local-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

CreateCoipPoolPermission [僅限許可] 准許允許服務存取客戶擁有的 IP (CoIP) 集區 寫入

coip-pool*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

CreateCustomerGateway 准許建立客戶閘道,提供 AWS 客戶閘道裝置的相關資訊給 寫入

customer-gateway*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

ec2:Region

CreateDefaultSubnet 准許在預設的指定可用區域中建立預設子網路 VPC 寫入

ec2:Region

CreateDefaultVpc 准許在每個可用區域中建立VPC預設子網路 寫入

ec2:Region

CreateDhcpOptions 准許為 建立一組DHCP選項 VPC 寫入

dhcp-options*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:DhcpOptionsID

ec2:CreateTags

ec2:Region

CreateEgressOnlyInternetGateway 准許為 建立輸出限定網際網路閘道 VPC 寫入

egress-only-internet-gateway*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

CreateFleet 准許啟動EC2機群。此動作的資源層級許可不包括啟動範本中指定的資源。若要為啟動範本中指定的資源指定資源層級許可,您必須在 RunInstances 動作陳述式中包含資源 寫入

fleet*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

instance*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceID

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:PlacementGroup

ec2:RootDeviceType

ec2:Tenancy

image

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

launch-template

aws:ResourceTag/${TagKey}

ec2:ManagedResourceOperator

ec2:ResourceTag/${TagKey}

placement-group

aws:ResourceTag/${TagKey}

ec2:PlacementGroupName

ec2:PlacementGroupStrategy

ec2:ResourceTag/${TagKey}

subnet

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

volume

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:AvailabilityZone

ec2:Encrypted

ec2:KmsKeyId

ec2:ManagedResourceOperator

ec2:ParentSnapshot

ec2:VolumeID

ec2:VolumeIops

ec2:VolumeSize

ec2:VolumeThroughput

ec2:VolumeType

ec2:Region

CreateFlowLogs 准許建立一或多個流程日誌,以擷取網路界面的 IP 流量 寫入

vpc-flow-log*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

ecs:ListClusters

ecs:ListContainerInstances

ecs:ListServices

ecs:ListTaskDefinitions

ecs:ListTasks

iam:PassRole

network-interface

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

subnet

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

transit-gateway

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayId

transit-gateway-attachment

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

vpc

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

CreateFpgaImage 准許從設計檢查點 (AFI) 建立 Amazon FPGA Image (DCP) 寫入

fpga-image*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:Owner

ec2:Public

ec2:CreateTags

ec2:Region

CreateImage 准許AMI從已停止或執行的 Amazon EBS後端執行個體建立 Amazon EBS後端 寫入

image*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:ImageID

ec2:Owner

ec2:CreateTags

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

snapshot*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:OutpostArn

ec2:ParentVolume

ec2:SnapshotID

ec2:SnapshotTime

ec2:SourceOutpostArn

ec2:VolumeSize

ec2:Region

CreateInstanceConnectEndpoint 准許建立 EC2 Instance Connect Endpoint,可讓您在沒有公有IPv4地址的情況下連線到執行個體 寫入

instance-connect-endpoint*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:SubnetID

ec2:CreateTags

subnet*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

security-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

ec2:Region

CreateInstanceEventWindow 准許建立事件時段,其中關聯的 Amazon EC2執行個體的排程事件可以在其中執行 寫入

instance-event-window*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

ec2:Region

CreateInstanceExportTask 准許將執行中或已停止的執行個體匯出到 Amazon S3 儲存貯體 寫入

export-instance-task*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

CreateInternetGateway 准許為 建立網際網路閘道 VPC 寫入

internet-gateway*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:InternetGatewayID

ec2:CreateTags

ec2:Region

CreateIpam 准許建立 Amazon VPC IP Address Manager (IPAM) 寫入

ipam*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

iam:CreateServiceLinkedRole

ec2:Region

CreateIpamExternalResourceVerificationToken 准許建立驗證字符,以證明外部資源的擁有權 寫入

ipam*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:CreateTags

ipam-external-resource-verification-token*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:Region

CreateIpamPool 准許為 Amazon IP Address Manager (IPAM) 建立 VPC IP 地址集區,這是連續 IP 地址的集合 CIDRs 寫入

ipam-pool*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

ipam-scope*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

CreateIpamResourceDiscovery 准許建立IPAM資源探索 寫入

ipam-resource-discovery*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

iam:CreateServiceLinkedRole

ec2:Region

CreateIpamScope 准許建立 Amazon VPC IP Address Manager (IPAM) 範圍,這是 IPAM 寫入

ipam*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:CreateTags

ipam-scope*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:Region

CreateKeyPair 准許建立 2048 位元RSA金鑰對 寫入

key-pair*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:KeyPairType

ec2:CreateTags

ec2:Region

CreateLaunchTemplate 准許建立啟動範本 寫入

launch-template*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:ManagedResourceOperator

ec2:CreateTags

ssm:GetParameters

ec2:Region

CreateLaunchTemplateVersion 准許建立啟動範本的新版本 寫入

launch-template*

aws:ResourceTag/${TagKey}

ec2:ManagedResourceOperator

ec2:ResourceTag/${TagKey}

ssm:GetParameters

ec2:Region

CreateLocalGatewayRoute 准許建立本機閘道路由表的靜態路由 寫入

local-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

local-gateway-virtual-interface-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

network-interface

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

prefix-list

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

CreateLocalGatewayRouteTable 准許建立本機閘道路由表 寫入

local-gateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:CreateTags

local-gateway-route-table*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:Region

CreateLocalGatewayRouteTablePermission [僅限許可] 准許允許服務存取本機閘道路由表 寫入

local-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

CreateLocalGatewayRouteTableVirtualInterfaceGroupAssociation 准許建立本機閘道路由表虛擬介面群組關聯 寫入

local-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:CreateTags

local-gateway-route-table-virtual-interface-group-association*

aws:RequestTag/${TagKey}

aws:TagKeys

local-gateway-virtual-interface-group*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

CreateLocalGatewayRouteTableVpcAssociation 准許將 VPC與本機閘道路由表建立關聯 寫入

local-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:CreateTags

local-gateway-route-table-vpc-association*

aws:RequestTag/${TagKey}

aws:TagKeys

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

CreateManagedPrefixList 授予建立受管前綴清單的許可 寫入

prefix-list*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

ec2:Region

CreateNatGateway 准許在子網路中建立NAT閘道 寫入

natgateway*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

subnet*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

elastic-ip

aws:ResourceTag/${TagKey}

ec2:AllocationId

ec2:Domain

ec2:PublicIpAddress

ec2:ResourceTag/${TagKey}

ec2:Region

CreateNetworkAcl 准許在 ACL中建立網路 VPC 寫入

network-acl*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:NetworkAclID

ec2:CreateTags

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

CreateNetworkAclEntry 准許在網路中建立編號項目 (規則) ACL 寫入

network-acl*

aws:ResourceTag/${TagKey}

ec2:NetworkAclID

ec2:ResourceTag/${TagKey}

ec2:Vpc

ec2:Region

CreateNetworkInsightsAccessScope 准許建立 Network Access Scope 寫入

network-insights-access-scope*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

ec2:Region

CreateNetworkInsightsPath 准許建立路徑來分析連線能力 寫入

network-insights-path*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

instance

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

internet-gateway

aws:ResourceTag/${TagKey}

ec2:InternetGatewayID

ec2:ResourceTag/${TagKey}

network-interface

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

transit-gateway

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayId

vpc-endpoint

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

vpc-endpoint-service

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

vpc-peering-connection

aws:ResourceTag/${TagKey}

ec2:AccepterVpc

ec2:RequesterVpc

ec2:ResourceTag/${TagKey}

ec2:VpcPeeringConnectionID

vpn-gateway

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

CreateNetworkInterface 准許在子網路中建立網路界面 寫入

network-interface*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:CreateTags

subnet*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

security-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

ec2:Region

CreateNetworkInterfacePermission 准許為 AWS授權使用者建立許可,以在網路介面上執行特定操作 許可管理

network-interface*

aws:ResourceTag/${TagKey}

ec2:AuthorizedService

ec2:AuthorizedUser

ec2:AvailabilityZone

ec2:NetworkInterfaceID

ec2:Permission

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

ec2:Region

CreatePlacementGroup 准許建立置放群組 寫入

placement-group*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:PlacementGroupName

ec2:PlacementGroupStrategy

ec2:CreateTags

ec2:Region

CreatePublicIpv4Pool 准許為您擁有的公有IPv4地址集區建立公IPv4CIDRs有地址集區,並提供給 Amazon 使用 Amazon VPC IP Address Manager 進行管理 (IPAM) 寫入

ipv4pool-ec2*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

ec2:Region

CreateReplaceRootVolumeTask 准許建立根磁碟區取代任務 寫入

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:CreateTags

replace-root-volume-task*

aws:RequestTag/${TagKey}

aws:TagKeys

volume*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:ManagedResourceOperator

ec2:VolumeID

image

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

snapshot

aws:ResourceTag/${TagKey}

ec2:Owner

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:SnapshotID

ec2:SnapshotTime

ec2:VolumeSize

ec2:Region

CreateReservedInstancesListing 准許建立要在預留執行個體 Marketplace 銷售的標準預留執行個體清單 寫入

ec2:Region

CreateRestoreImageTask 准許啟動任務,AMI從先前使用 建立的 S3 物件還原 CreateStoreImageTask 寫入

image*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:ImageID

ec2:Owner

ec2:CreateTags

ec2:Region

CreateRoute 准許在路由表中建立VPC路由 寫入

route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:RouteTableID

ec2:Vpc

ec2:Region

CreateRouteTable 准許為 建立路由表 VPC 寫入

route-table*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:RouteTableID

ec2:CreateTags

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

CreateSecurityGroup 准許建立安全群組 寫入

security-group*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:SecurityGroupID

ec2:CreateTags

vpc

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

CreateSnapshot 准許建立EBS磁碟區的快照並將其存放在 Amazon S3 寫入

snapshot*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:OutpostArn

ec2:ParentVolume

ec2:SnapshotID

ec2:SourceOutpostArn

ec2:VolumeSize

ec2:CreateTags

volume*

aws:ResourceTag/${TagKey}

ec2:Encrypted

ec2:ResourceTag/${TagKey}

ec2:VolumeID

ec2:VolumeIops

ec2:VolumeSize

ec2:VolumeThroughput

ec2:VolumeType

ec2:Region

CreateSnapshots 准許建立多個EBS磁碟區的損毀一致性快照,並將其存放在 Amazon S3 中 寫入

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceID

ec2:InstanceProfile

ec2:InstanceType

ec2:PlacementGroup

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:CreateTags

snapshot*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:OutpostArn

ec2:ParentVolume

ec2:SnapshotID

ec2:SourceOutpostArn

ec2:VolumeSize

volume*

aws:ResourceTag/${TagKey}

ec2:Encrypted

ec2:ResourceTag/${TagKey}

ec2:VolumeID

ec2:VolumeIops

ec2:VolumeSize

ec2:VolumeThroughput

ec2:VolumeType

ec2:Region

CreateSpotDatafeedSubscription 准許建立 Spot 執行個體的資料饋送,以檢視 Spot 執行個體用量日誌 寫入

ec2:Region

CreateStoreImageTask 准許將 儲存AMI為 S3 儲存貯體中的單一物件 寫入

image*

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Region

CreateSubnet 准許在 中建立子網路 VPC 寫入

subnet*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:SubnetID

ec2:CreateTags

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ipam-pool

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

CreateSubnetCidrReservation 准許建立子網路CIDR保留 寫入

ec2:Region

CreateTags 准許新增或覆寫 Amazon EC2 資源的一或多個標籤 標記

capacity-reservation

aws:ResourceTag/${TagKey}

capacity-reservation-fleet

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

carrier-gateway

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:Vpc

client-vpn-endpoint

aws:ResourceTag/${TagKey}

ec2:ClientRootCertificateChainArn

ec2:CloudwatchLogGroupArn

ec2:CloudwatchLogStreamArn

ec2:DirectoryArn

ec2:ResourceTag/${TagKey}

ec2:SamlProviderArn

ec2:ServerCertificateArn

coip-pool

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

customer-gateway

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

declarative-policies-report

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

dedicated-host

aws:ResourceTag/${TagKey}

ec2:AutoPlacement

ec2:AvailabilityZone

ec2:HostRecovery

ec2:InstanceType

ec2:Quantity

ec2:ResourceTag/${TagKey}

dhcp-options

aws:ResourceTag/${TagKey}

ec2:DhcpOptionsID

ec2:ResourceTag/${TagKey}

egress-only-internet-gateway

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

elastic-gpu

aws:ResourceTag/${TagKey}

ec2:ElasticGpuType

ec2:ResourceTag/${TagKey}

elastic-ip

aws:ResourceTag/${TagKey}

ec2:AllocationId

ec2:Domain

ec2:PublicIpAddress

ec2:ResourceTag/${TagKey}

export-image-task

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

export-instance-task

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

fleet

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

fpga-image

aws:ResourceTag/${TagKey}

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

host-reservation

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

image

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

import-image-task

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

import-snapshot-task

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

instance

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

instance-connect-endpoint

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SubnetID

instance-event-window

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

internet-gateway

aws:ResourceTag/${TagKey}

ec2:InternetGatewayID

ec2:ResourceTag/${TagKey}

ipam

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ipam-external-resource-verification-token

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ipam-pool

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ipam-resource-discovery

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ipam-resource-discovery-association

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ipam-scope

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ipv4pool-ec2

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ipv6pool-ec2

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

key-pair

aws:ResourceTag/${TagKey}

ec2:KeyPairName

ec2:KeyPairType

ec2:ResourceTag/${TagKey}

launch-template

aws:ResourceTag/${TagKey}

ec2:ManagedResourceOperator

ec2:ResourceTag/${TagKey}

local-gateway

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

local-gateway-route-table

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

local-gateway-route-table-virtual-interface-group-association

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

local-gateway-route-table-vpc-association

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

local-gateway-virtual-interface

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

local-gateway-virtual-interface-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

natgateway

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

network-acl

aws:ResourceTag/${TagKey}

ec2:NetworkAclID

ec2:ResourceTag/${TagKey}

ec2:Vpc

network-insights-access-scope

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

network-insights-access-scope-analysis

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

network-insights-analysis

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

network-insights-path

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

network-interface

aws:ResourceTag/${TagKey}

ec2:AuthorizedUser

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:Permission

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

placement-group

aws:ResourceTag/${TagKey}

ec2:PlacementGroupName

ec2:PlacementGroupStrategy

ec2:ResourceTag/${TagKey}

prefix-list

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

replace-root-volume-task

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

reserved-instances

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:InstanceType

ec2:ReservedInstancesOfferingType

ec2:ResourceTag/${TagKey}

ec2:Tenancy

route-table

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:RouteTableID

ec2:Vpc

security-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

security-group-rule

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

snapshot

aws:ResourceTag/${TagKey}

ec2:Encrypted

ec2:Owner

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:SnapshotID

ec2:SnapshotTime

ec2:VolumeSize

spot-fleet-request

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

spot-instances-request

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

subnet

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

subnet-cidr-reservation

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

traffic-mirror-filter

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

traffic-mirror-session

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

traffic-mirror-target

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

transit-gateway

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayId

transit-gateway-attachment

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

transit-gateway-connect-peer

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayConnectPeerId

transit-gateway-multicast-domain

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayMulticastDomainId

transit-gateway-policy-table

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayPolicyTableId

transit-gateway-route-table

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableId

transit-gateway-route-table-announcement

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableAnnouncementId

verified-access-endpoint

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

verified-access-endpoint-target

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

verified-access-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

verified-access-instance

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

verified-access-policy

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

verified-access-trust-provider

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

volume

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:Encrypted

ec2:ManagedResourceOperator

ec2:ParentSnapshot

ec2:ResourceTag/${TagKey}

ec2:VolumeID

ec2:VolumeIops

ec2:VolumeSize

ec2:VolumeThroughput

ec2:VolumeType

vpc

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

vpc-endpoint

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

vpc-endpoint-connection

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

vpc-endpoint-service

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:vpceMultiRegion

ec2:vpceServiceRegion

ec2:vpceSupportedRegion

vpc-endpoint-service-permission

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

vpc-flow-log

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

vpc-peering-connection

aws:ResourceTag/${TagKey}

ec2:AccepterVpc

ec2:RequesterVpc

ec2:ResourceTag/${TagKey}

ec2:VpcPeeringConnectionID

vpn-connection

aws:ResourceTag/${TagKey}

ec2:AuthenticationType

ec2:DPDTimeoutSeconds

ec2:GatewayType

ec2:IKEVersions

ec2:InsideTunnelCidr

ec2:InsideTunnelIpv6Cidr

ec2:Phase1DHGroup

ec2:Phase1EncryptionAlgorithms

ec2:Phase1IntegrityAlgorithms

ec2:Phase1LifetimeSeconds

ec2:Phase2DHGroup

ec2:Phase2EncryptionAlgorithms

ec2:Phase2IntegrityAlgorithms

ec2:Phase2LifetimeSeconds

ec2:RekeyFuzzPercentage

ec2:RekeyMarginTimeSeconds

ec2:ReplayWindowSizePackets

ec2:ResourceTag/${TagKey}

ec2:RoutingType

vpn-gateway

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:CreateAction

ec2:Region

CreateTrafficMirrorFilter 准許建立流量鏡像篩選條件 寫入

traffic-mirror-filter*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

ec2:Region

CreateTrafficMirrorFilterRule 准許建立流量鏡像篩選條件規則 寫入

traffic-mirror-filter*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:CreateTags

traffic-mirror-filter-rule*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:Region

CreateTrafficMirrorSession 准許建立流量鏡像工作階段 寫入

network-interface*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

ec2:CreateTags

traffic-mirror-filter*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

traffic-mirror-session*

aws:RequestTag/${TagKey}

aws:TagKeys

traffic-mirror-target*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

CreateTrafficMirrorTarget 准許建立流量鏡像目標 寫入

traffic-mirror-target*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

network-interface

aws:ResourceTag/${TagKey}

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

vpc-endpoint

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:VpceServiceName

ec2:VpceServiceOwner

ec2:Region

CreateTransitGateway 准許建立傳輸閘道 寫入

transit-gateway*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:transitGatewayId

ec2:CreateTags

ec2:Region

CreateTransitGatewayConnect 准許從指定傳輸閘道附件建立 Connect 附件 寫入

transit-gateway-attachment*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:transitGatewayAttachmentId

ec2:CreateTags

ec2:Region

CreateTransitGatewayConnectPeer 准許在傳輸閘道和設備之間建立 Connect 對等 寫入

transit-gateway-attachment*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

ec2:CreateTags

transit-gateway-connect-peer*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:transitGatewayConnectPeerId

ec2:Region

CreateTransitGatewayMulticastDomain 准許為傳輸閘道建立多點傳送網域 寫入

transit-gateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayId

ec2:CreateTags

transit-gateway-multicast-domain*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:transitGatewayMulticastDomainId

ec2:Region

CreateTransitGatewayPeeringAttachment 准許在請求者與接受者傳輸閘道之間請求傳輸閘道對等附件 寫入

transit-gateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayId

ec2:CreateTags

transit-gateway-attachment*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:transitGatewayAttachmentId

ec2:Region

CreateTransitGatewayPolicyTable 准許建立傳輸閘道政策資料表 寫入

transit-gateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayId

ec2:CreateTags

transit-gateway-policy-table*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:transitGatewayPolicyTableId

ec2:Region

CreateTransitGatewayPrefixListReference 授予建立轉移閘道前綴清單參考的許可 寫入

prefix-list*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

transit-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableId

transit-gateway-attachment

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

ec2:Region

CreateTransitGatewayRoute 准許建立傳輸閘道路由表的靜態路由 寫入

transit-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableId

transit-gateway-attachment

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

ec2:Region

CreateTransitGatewayRouteTable 准許建立傳輸閘道的路由表 寫入

transit-gateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayId

ec2:CreateTags

transit-gateway-route-table*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:transitGatewayRouteTableId

ec2:Region

CreateTransitGatewayRouteTableAnnouncement 准許建立傳輸閘道路由表的公告 寫入

transit-gateway-attachment*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

ec2:CreateTags

transit-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableId

transit-gateway-route-table-announcement*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:transitGatewayRouteTableAnnouncementId

ec2:Region

CreateTransitGatewayVpcAttachment 准許將 VPC 連接至傳輸閘道 寫入

subnet*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

ec2:CreateTags

transit-gateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayId

transit-gateway-attachment*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:transitGatewayAttachmentId

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

CreateVerifiedAccessEndpoint 准許建立 Verified Access 端點 寫入

verified-access-endpoint*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

verified-access-group*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

network-interface

aws:ResourceTag/${TagKey}

ec2:AuthorizedUser

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:Permission

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

security-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

subnet

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

ec2:Region

CreateVerifiedAccessGroup 准許建立 Verified Access 群組 寫入

verified-access-group*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

verified-access-instance*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

CreateVerifiedAccessInstance 准許建立 Verified Access 執行個體 寫入

verified-access-instance*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

ec2:Region

CreateVerifiedAccessTrustProvider 准許建立已驗證的受信任提供者 寫入

verified-access-trust-provider*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

ec2:Region

CreateVolume 准許建立EBS磁碟區 寫入

volume*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:AvailabilityZone

ec2:Encrypted

ec2:KmsKeyId

ec2:ManagedResourceOperator

ec2:ParentSnapshot

ec2:VolumeID

ec2:VolumeIops

ec2:VolumeSize

ec2:VolumeThroughput

ec2:VolumeType

ec2:CreateTags

ec2:Region

CreateVpc 准許VPC使用指定的CIDR區塊建立 寫入

vpc*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:Ipv4IpamPoolId

ec2:Ipv6IpamPoolId

ec2:VpcID

ec2:CreateTags

ipam-pool

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ipv6pool-ec2

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

CreateVpcBlockPublicAccessExclusion 准許在 上建立封鎖公開存取的排除清單 VPC 寫入

subnet

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

ec2:CreateTags

vpc

aws:ResourceTag/${TagKey}

ec2:Ipv4IpamPoolId

ec2:Ipv6IpamPoolId

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

CreateVpcEndpoint 准許為 AWS 服務建立VPC端點 寫入

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:VpcID

ec2:CreateTags

route53:AssociateVPCWithHostedZone

vpc-endpoint*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:VpceServiceName

ec2:VpceServiceOwner

route-table

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:RouteTableID

security-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

subnet

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Region

CreateVpcEndpointConnectionNotification 准許為VPC端點或VPC端點服務建立連線通知 寫入

vpc-endpoint

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

vpc-endpoint-service

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:vpceMultiRegion

ec2:vpceServiceRegion

ec2:Region

CreateVpcEndpointServiceConfiguration 准許建立服務消費者 (AWS 帳戶、IAM使用者和IAM角色) 可以連線的VPC端點服務組態 寫入

vpc-endpoint-service*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:VpceServicePrivateDnsName

ec2:vpceMultiRegion

ec2:vpceServiceRegion

ec2:CreateTags

ec2:Region

CreateVpcPeeringConnection 准許在兩個 之間請求VPC對等互連 VPCs 寫入

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:CreateTags

vpc-peering-connection*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:AccepterVpc

ec2:RequesterVpc

ec2:VpcPeeringConnectionID

ec2:Region

CreateVpnConnection 准許在虛擬私有閘道或傳輸閘道與客戶閘道之間建立VPN連線 寫入

customer-gateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:CreateTags

vpn-connection*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:AuthenticationType

ec2:DPDTimeoutSeconds

ec2:GatewayType

ec2:IKEVersions

ec2:InsideTunnelCidr

ec2:InsideTunnelIpv6Cidr

ec2:Phase1DHGroup

ec2:Phase1EncryptionAlgorithms

ec2:Phase1IntegrityAlgorithms

ec2:Phase1LifetimeSeconds

ec2:Phase2DHGroup

ec2:Phase2EncryptionAlgorithms

ec2:Phase2IntegrityAlgorithms

ec2:Phase2LifetimeSeconds

ec2:RekeyFuzzPercentage

ec2:RekeyMarginTimeSeconds

ec2:ReplayWindowSizePackets

ec2:RoutingType

transit-gateway

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayId

transit-gateway-attachment

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

vpn-gateway

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

CreateVpnConnectionRoute 准許為虛擬私有閘道和客戶閘道之間的VPN連線建立靜態路由 寫入

vpn-connection*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

CreateVpnGateway 准許建立虛擬私有閘道 寫入

vpn-gateway*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

ec2:Region

DeleteCarrierGateway 准許刪除電信業者閘道 寫入

carrier-gateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteClientVpnEndpoint 准許刪除用戶端VPN端點 寫入

client-vpn-endpoint*

aws:ResourceTag/${TagKey}

ec2:ClientRootCertificateChainArn

ec2:CloudwatchLogGroupArn

ec2:CloudwatchLogStreamArn

ec2:DirectoryArn

ec2:ResourceTag/${TagKey}

ec2:SamlProviderArn

ec2:ServerCertificateArn

ec2:Region

DeleteClientVpnRoute 准許從用戶端VPN端點刪除路由 寫入

client-vpn-endpoint*

aws:ResourceTag/${TagKey}

ec2:ClientRootCertificateChainArn

ec2:CloudwatchLogGroupArn

ec2:CloudwatchLogStreamArn

ec2:DirectoryArn

ec2:ResourceTag/${TagKey}

ec2:SamlProviderArn

ec2:ServerCertificateArn

subnet

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

ec2:Region

DeleteCoipCidr 准許刪除客戶擁有的 IP (CoIP) 地址範圍 寫入

coip-pool*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteCoipPool 准許刪除客戶擁有的 IP (CoIP) 地址集區 寫入

coip-pool*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteCoipPoolPermission [僅限許可] 准許拒絕服務存取客戶擁有的 IP (CoIP) 集區 寫入

coip-pool*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteCustomerGateway 准許刪除客戶閘道 寫入

customer-gateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteDhcpOptions 准許刪除一組DHCP選項 寫入

dhcp-options*

aws:ResourceTag/${TagKey}

ec2:DhcpOptionsID

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteEgressOnlyInternetGateway 准許刪除僅輸出網際網路閘道 寫入

egress-only-internet-gateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteFleets 准許刪除一或多個EC2機群 寫入

fleet*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteFlowLogs 准許刪除一或多個流程日誌 寫入

vpc-flow-log*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteFpgaImage 准許刪除 Amazon FPGA Image (AFI) 寫入

fpga-image*

aws:ResourceTag/${TagKey}

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteInstanceConnectEndpoint 准許刪除 EC2 Instance Connect Endpoint 寫入

instance-connect-endpoint*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Region

DeleteInstanceEventWindow 准許刪除指定的事件時段 寫入

instance-event-window*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteInternetGateway 准許刪除網際網路閘道 寫入

internet-gateway*

aws:ResourceTag/${TagKey}

ec2:InternetGatewayID

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteIpam 准許刪除 Amazon VPC IP Address Manager (IPAM),並移除與 相關聯的所有監控資料,IPAM包括 的歷史資料 CIDRs 寫入

ipam*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteIpamExternalResourceVerificationToken 准許刪除驗證字符,以證明外部資源的擁有權 寫入

ipam-external-resource-verification-token*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteIpamPool 准許刪除 Amazon VPC IP Address Manager (IPAM) 集區 寫入

ipam-pool*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteIpamResourceDiscovery 准許刪除IPAM資源探索 寫入

ipam-resource-discovery*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteIpamScope 准許刪除 Amazon VPC IP Address Manager (IPAM) 的範圍 寫入

ipam-scope*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteKeyPair 准許從 Amazon 移除公有金鑰來刪除金鑰對 EC2 寫入

key-pair

aws:ResourceTag/${TagKey}

ec2:KeyPairName

ec2:KeyPairType

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteLaunchTemplate 准許刪除啟動範本及其相關聯版本 寫入

launch-template*

aws:ResourceTag/${TagKey}

ec2:ManagedResourceOperator

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteLaunchTemplateVersions 准許刪除啟動範本的一或多個版本 寫入

launch-template*

aws:ResourceTag/${TagKey}

ec2:ManagedResourceOperator

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteLocalGatewayRoute 准許從本機閘道路由表刪除路由 寫入

local-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

prefix-list

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteLocalGatewayRouteTable 准許刪除本機閘道路由表 寫入

local-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteLocalGatewayRouteTablePermission [僅限許可] 准許拒絕服務存取本機閘道路由表 寫入

local-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteLocalGatewayRouteTableVirtualInterfaceGroupAssociation 准許刪除本機閘道路由表虛擬介面群組關聯 寫入

local-gateway-route-table-virtual-interface-group-association*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteLocalGatewayRouteTableVpcAssociation 准許刪除 VPC與本機閘道路由表之間的關聯 寫入

local-gateway-route-table-vpc-association*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteManagedPrefixList 授予刪除受管前綴清單的許可 寫入

prefix-list*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteNatGateway 准許刪除NAT閘道 寫入

natgateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteNetworkAcl 准許刪除網路 ACL 寫入

network-acl*

aws:ResourceTag/${TagKey}

ec2:NetworkAclID

ec2:ResourceTag/${TagKey}

ec2:Vpc

ec2:Region

DeleteNetworkAclEntry 准許從網路刪除傳入或傳出項目 (規則) ACL 寫入

network-acl*

aws:ResourceTag/${TagKey}

ec2:NetworkAclID

ec2:ResourceTag/${TagKey}

ec2:Vpc

ec2:Region

DeleteNetworkInsightsAccessScope 准許刪除 Network Access Scope 寫入

network-insights-access-scope*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteNetworkInsightsAccessScopeAnalysis 准許刪除 Network Access Scope 分析 寫入

network-insights-access-scope-analysis*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteNetworkInsightsAnalysis 准許刪除網路洞見分析 寫入

network-insights-analysis*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteNetworkInsightsPath 准許刪除網路洞見路徑 寫入

network-insights-path*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteNetworkInterface 准許刪除分離的網路界面 寫入

network-interface*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

ec2:Region

DeleteNetworkInterfacePermission 准許刪除與網路界面相關聯的許可 許可管理

network-interface

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

ec2:Region

DeletePlacementGroup 准許刪除置放群組 寫入

placement-group

aws:ResourceTag/${TagKey}

ec2:PlacementGroupName

ec2:PlacementGroupStrategy

ec2:ResourceTag/${TagKey}

ec2:Region

DeletePublicIpv4Pool 准許刪除IPv4CIDRs您擁有的公有IPv4地址集區,並將其帶到 Amazon 以使用 Amazon VPC IP Address Manager 進行管理 (IPAM) 寫入

ipv4pool-ec2*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteQueuedReservedInstances 准許刪除在佇列中的對指定預留執行個體的購買 寫入

ec2:Region

DeleteResourcePolicy [僅限許可] 准許從資源移除啟用跨帳戶共用IAM的政策 寫入

ipam-pool

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

placement-group

aws:ResourceTag/${TagKey}

ec2:PlacementGroupName

ec2:PlacementGroupStrategy

ec2:ResourceTag/${TagKey}

verified-access-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteRoute 准許從路由表刪除路由 寫入

route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:RouteTableID

ec2:Vpc

ec2:Region

DeleteRouteTable 准許刪除路由表 寫入

route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:RouteTableID

ec2:Vpc

ec2:Region

DeleteSecurityGroup 准許刪除安全群組 寫入

security-group*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

ec2:Region

DeleteSnapshot 准許刪除EBS磁碟區的快照 寫入

snapshot*

aws:ResourceTag/${TagKey}

ec2:OutpostArn

ec2:Owner

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:SnapshotID

ec2:SnapshotTime

ec2:VolumeSize

ec2:Region

DeleteSpotDatafeedSubscription 准許刪除 Spot 執行個體的資料饋送 寫入

ec2:Region

DeleteSubnet 准許刪除子網路 寫入

subnet*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

ec2:Region

DeleteSubnetCidrReservation 准許刪除子網路CIDR保留 寫入

ec2:Region

DeleteTags 准許從 Amazon EC2 資源刪除一或多個標籤 標記

capacity-reservation

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

capacity-reservation-fleet

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

carrier-gateway

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

client-vpn-endpoint

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

coip-pool

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

customer-gateway

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

declarative-policies-report

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

dedicated-host

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

dhcp-options

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

egress-only-internet-gateway

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

elastic-gpu

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

elastic-ip

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

export-image-task

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

export-instance-task

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

fleet

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

fpga-image

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

host-reservation

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

image

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

import-image-task

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

import-snapshot-task

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

instance

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

instance-connect-endpoint

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

instance-event-window

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

internet-gateway

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ipam

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ipam-external-resource-verification-token

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ipam-pool

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ipam-resource-discovery

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ipam-resource-discovery-association

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ipam-scope

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ipv4pool-ec2

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ipv6pool-ec2

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

key-pair

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

launch-template

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

local-gateway

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

local-gateway-route-table

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

local-gateway-route-table-virtual-interface-group-association

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

local-gateway-route-table-vpc-association

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

local-gateway-virtual-interface

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

local-gateway-virtual-interface-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

natgateway

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

network-acl

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

network-insights-access-scope

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

network-insights-access-scope-analysis

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

network-insights-analysis

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

network-insights-path

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

network-interface

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

placement-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

prefix-list

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

replace-root-volume-task

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

reserved-instances

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

route-table

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

security-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

security-group-rule

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

snapshot

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

spot-fleet-request

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

spot-instances-request

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

subnet

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

subnet-cidr-reservation

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

traffic-mirror-filter

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

traffic-mirror-session

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

traffic-mirror-target

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

transit-gateway

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

transit-gateway-attachment

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

transit-gateway-connect-peer

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

transit-gateway-multicast-domain

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

transit-gateway-policy-table

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

transit-gateway-route-table

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

transit-gateway-route-table-announcement

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

verified-access-endpoint

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

verified-access-endpoint-target

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

verified-access-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

verified-access-instance

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

verified-access-policy

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

verified-access-trust-provider

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

volume

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

vpc

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

vpc-endpoint

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

vpc-endpoint-connection

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

vpc-endpoint-service

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

vpc-endpoint-service-permission

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

vpc-flow-log

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

vpc-peering-connection

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

vpn-connection

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

vpn-gateway

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

DeleteTrafficMirrorFilter 准許刪除流量鏡像篩選條件 寫入

traffic-mirror-filter*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteTrafficMirrorFilterRule 准許刪除流量鏡像篩選條件規則 寫入

traffic-mirror-filter*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

traffic-mirror-filter-rule*

aws:ResourceTag/${TagKey}

ec2:Region

DeleteTrafficMirrorSession 准許刪除流量鏡像工作階段 寫入

traffic-mirror-session*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteTrafficMirrorTarget 准許刪除流量鏡像目標 寫入

traffic-mirror-target*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteTransitGateway 准許刪除傳輸閘道 寫入

transit-gateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayId

ec2:Region

DeleteTransitGatewayConnect 准許刪除傳輸閘道 Connect 附件 寫入

transit-gateway-attachment*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

ec2:Region

DeleteTransitGatewayConnectPeer 准許刪除傳輸閘道 Connect 對等 寫入

transit-gateway-connect-peer*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayConnectPeerId

ec2:Region

DeleteTransitGatewayMulticastDomain 准許刪除傳輸閘道多點傳送網域 寫入

transit-gateway-multicast-domain*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayMulticastDomainId

ec2:Region

DeleteTransitGatewayPeeringAttachment 准許從傳輸閘道刪除對等附件 寫入

transit-gateway-attachment*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

ec2:Region

DeleteTransitGatewayPolicyTable 准許刪除傳輸閘道政策資料表 寫入

transit-gateway-policy-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayPolicyTableId

ec2:Region

DeleteTransitGatewayPrefixListReference 授予刪除傳輸閘道前綴清單參考的許可 寫入

prefix-list*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

transit-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableId

ec2:Region

DeleteTransitGatewayRoute 准許從傳輸閘道路由表刪除路由 寫入

transit-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableId

ec2:Region

DeleteTransitGatewayRouteTable 准許刪除傳輸閘道路由表 寫入

transit-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableId

ec2:Region

DeleteTransitGatewayRouteTableAnnouncement 准許刪除傳輸閘道路由表公告 寫入

transit-gateway-route-table-announcement*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableAnnouncementId

ec2:Region

DeleteTransitGatewayVpcAttachment 准許從傳輸閘道刪除VPC附件 寫入

transit-gateway-attachment*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

ec2:Region

DeleteVerifiedAccessEndpoint 准許刪除 Verified Access 端點 寫入

verified-access-endpoint*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteVerifiedAccessGroup 准許刪除 Verified Access 群組 寫入

verified-access-group*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteVerifiedAccessInstance 准許刪除 Verified Access 執行個體 寫入

verified-access-instance*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteVerifiedAccessTrustProvider 准許刪除已驗證的受信任提供者 寫入

verified-access-trust-provider*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteVolume 准許刪除EBS磁碟區 寫入

volume*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:Encrypted

ec2:ManagedResourceOperator

ec2:ParentSnapshot

ec2:ResourceTag/${TagKey}

ec2:VolumeID

ec2:VolumeIops

ec2:VolumeSize

ec2:VolumeThroughput

ec2:VolumeType

ec2:Region

DeleteVpc 准許刪除 VPC 寫入

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

DeleteVpcBlockPublicAccessExclusion 准許刪除 上封鎖公開存取的排除清單 VPC 寫入

vpc-block-public-access-exclusion*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteVpcEndpointConnectionNotifications 准許刪除一或多個VPC端點連線通知 寫入

vpc-endpoint

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

vpc-endpoint-service

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:vpceMultiRegion

ec2:vpceSupportedRegion

ec2:Region

DeleteVpcEndpointServiceConfigurations 准許刪除一或多個VPC端點服務組態 寫入

vpc-endpoint-service*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:vpceMultiRegion

ec2:vpceSupportedRegion

ec2:Region

DeleteVpcEndpoints 准許刪除一或多個VPC端點 寫入

vpc-endpoint*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:VpceServiceName

ec2:Region

DeleteVpcPeeringConnection 准許刪除VPC對等互連連線 寫入

vpc-peering-connection*

aws:ResourceTag/${TagKey}

ec2:AccepterVpc

ec2:RequesterVpc

ec2:ResourceTag/${TagKey}

ec2:VpcPeeringConnectionID

ec2:Region

DeleteVpnConnection 准許刪除VPN連線 寫入

vpn-connection*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteVpnConnectionRoute 准許刪除虛擬私有閘道與客戶閘道之間VPN連線的靜態路由 寫入

vpn-connection*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeleteVpnGateway 准許刪除虛擬私有閘道 寫入

vpn-gateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeprovisionByoipCidr 准許釋出透過攜帶您自己的 IP 地址 (BYOIP) 佈建的 IP 地址範圍,並刪除對應的地址集區 寫入

ec2:Region

DeprovisionIpamByoasn 准許從 Amazon Web Services 帳戶取消佈建自治系統編號 (ASN) 寫入

ipam*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeprovisionIpamPoolCidr 准許從 Amazon VPC IP Address Manager (IPAM) 集區取消佈建CIDR佈建 寫入

ipam-pool*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeprovisionPublicIpv4PoolCidr 准許CIDR從公有IPv4集區取消佈建 寫入

ipv4pool-ec2*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DeregisterImage 准許取消註冊 Amazon Machine Image (AMI) 寫入

image*

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Region

DeregisterInstanceEventNotificationAttributes 授予從要包含在您執行個體排程事件通知中的標籤集合內移除標籤的許可 寫入

ec2:Region

DeregisterTransitGatewayMulticastGroupMembers 准許從傳輸閘道多點傳送網域中的群組 IP 地址取消註冊一或多個網路界面成員 寫入

network-interface

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

transit-gateway-multicast-domain

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayMulticastDomainId

ec2:Region

DeregisterTransitGatewayMulticastGroupSources 准許從傳輸閘道多點傳送網域中的群組 IP 地址取消註冊一或多個網路界面來源 寫入

network-interface

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

transit-gateway-multicast-domain

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayMulticastDomainId

ec2:Region

DescribeAccountAttributes 准許描述 的屬性 AWS 帳戶 清單

ec2:Region

DescribeAddressTransfers 准許描述彈性 IP 地址轉移 清單

ec2:Region

DescribeAddresses 准許描述一或多個彈性 IP 地址 列出

ec2:Region

DescribeAddressesAttribute 准許描述指定彈性 IP 地址的屬性 列出

ec2:Region

DescribeAggregateIdFormat 准許描述所有資源類型的較長 ID 格式設定 列出

ec2:Region

DescribeAvailabilityZones 准許描述可供您使用的一個或多個可用區域 清單

ec2:Region

DescribeAwsNetworkPerformanceMetricSubscriptions 准許描述目前的基礎設施效能指標訂閱 清單

ec2:Region

DescribeBundleTasks 准許描述一個或多個綁定任務 清單

ec2:Region

DescribeByoipCidrs 准許描述透過攜帶您自己的 IP 地址 (BYOIP) 佈建的 IP 地址範圍 清單

ec2:Region

DescribeCapacityBlockExtensionHistory 准許描述容量區塊延伸歷史記錄 清單

capacity-reservation

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CapacityReservationFleet

ec2:CreateDate

ec2:DestinationCapacityReservationId

ec2:EbsOptimized

ec2:EndDate

ec2:EndDateType

ec2:InstanceCount

ec2:InstanceMatchCriteria

ec2:InstancePlatform

ec2:InstanceType

ec2:OutpostArn

ec2:PlacementGroup

ec2:ResourceTag/${TagKey}

ec2:SourceCapacityReservationId

ec2:Tenancy

ec2:Region

DescribeCapacityBlockExtensionOfferings 准許描述容量區塊延伸產品 清單

capacity-reservation*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CapacityReservationFleet

ec2:CreateDate

ec2:DestinationCapacityReservationId

ec2:EbsOptimized

ec2:EndDate

ec2:EndDateType

ec2:InstanceCount

ec2:InstanceMatchCriteria

ec2:InstancePlatform

ec2:InstanceType

ec2:OutpostArn

ec2:PlacementGroup

ec2:ResourceTag/${TagKey}

ec2:SourceCapacityReservationId

ec2:Tenancy

ec2:Region

DescribeCapacityBlockOfferings 准許描述可供購買的容量區塊方案 清單

ec2:Region

DescribeCapacityReservationBillingRequests 准許描述一或多個請求,以指派容量預留未使用容量的帳單 清單

ec2:Region

DescribeCapacityReservationFleets 准許描述一或多個容量預留機群 列出

ec2:Region

DescribeCapacityReservations 准許描述一或多個容量保留 列出

ec2:Region

DescribeCarrierGateways 准許描述一或多個電信業者閘道 清單

ec2:Region

DescribeClassicLinkInstances 准許描述一或多個連結的 EC2-Classic 執行個體 清單

ec2:Region

DescribeClientVpnAuthorizationRules 准許描述用戶端VPN端點的授權規則 清單

client-vpn-endpoint*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DescribeClientVpnConnections 准許描述用戶端VPN端點在過去 60 分鐘內終止的作用中用戶端連線和連線 清單

client-vpn-endpoint*

aws:ResourceTag/${TagKey}

ec2:ClientRootCertificateChainArn

ec2:CloudwatchLogGroupArn

ec2:CloudwatchLogStreamArn

ec2:DirectoryArn

ec2:ResourceTag/${TagKey}

ec2:SamlProviderArn

ec2:ServerCertificateArn

ec2:Region

DescribeClientVpnEndpoints 准許描述一或多個用戶端VPN端點 清單

client-vpn-endpoint

aws:ResourceTag/${TagKey}

ec2:ClientRootCertificateChainArn

ec2:CloudwatchLogGroupArn

ec2:CloudwatchLogStreamArn

ec2:DirectoryArn

ec2:ResourceTag/${TagKey}

ec2:SamlProviderArn

ec2:ServerCertificateArn

ec2:Region

DescribeClientVpnRoutes 准許描述用戶端VPN端點的路由 清單

client-vpn-endpoint*

aws:ResourceTag/${TagKey}

ec2:ClientRootCertificateChainArn

ec2:CloudwatchLogGroupArn

ec2:CloudwatchLogStreamArn

ec2:DirectoryArn

ec2:ResourceTag/${TagKey}

ec2:SamlProviderArn

ec2:ServerCertificateArn

ec2:Region

DescribeClientVpnTargetNetworks 准許描述與用戶端VPN端點相關聯的目標網路 清單

client-vpn-endpoint*

aws:ResourceTag/${TagKey}

ec2:ClientRootCertificateChainArn

ec2:CloudwatchLogGroupArn

ec2:CloudwatchLogStreamArn

ec2:DirectoryArn

ec2:ResourceTag/${TagKey}

ec2:SamlProviderArn

ec2:ServerCertificateArn

ec2:Region

DescribeCoipPools 授予描述指定客戶所擁有的地址集區,或是您所有客戶所擁有地址集區的許可 列出

ec2:Region

DescribeConversionTasks 准許描述一或多個轉換任務 列出

ec2:Region

DescribeCustomerGateways 准許描述一或多個客戶閘道 清單

ec2:Region

DescribeDeclarativePoliciesReports 准許描述一或多個宣告政策報告 清單

ec2:Region

DescribeDhcpOptions 准許描述一或多個DHCP選項集 清單

ec2:Region

DescribeEgressOnlyInternetGateways 准許描述一或多個僅限輸出網際網路閘道 列出

ec2:Region

DescribeElasticGpus 准許描述與執行個體相關聯的 Elastic Graphics 加速器 清單

ec2:Region

DescribeExportImageTasks 准許描述一或多個匯出映像任務 列出

ec2:Region

DescribeExportTasks 准許描述一或多個匯出執行個體任務 清單

ec2:Region

DescribeFastLaunchImages 准許描述已啟用快速啟動的 Windows AMIs 清單

ec2:Region

DescribeFastSnapshotRestores 准許描述快照之快速快照還原的狀態 清單

ec2:Region

DescribeFleetHistory 准許描述指定時間內EC2機群的事件 清單

fleet*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DescribeFleetInstances 准許描述EC2機群的執行中執行個體 清單

fleet*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DescribeFleets 准許描述一或多個EC2機群 清單

ec2:Region

DescribeFlowLogs 准許描述一或多個流程日誌 清單

ec2:Region

DescribeFpgaImageAttribute 准許描述 Amazon FPGA Image (AFI) 的屬性 清單

fpga-image*

aws:ResourceTag/${TagKey}

ec2:Owner

ec2:ResourceTag/${TagKey}

ec2:Region

DescribeFpgaImages 准許描述一或多個 Amazon FPGA Images (AFIs) 清單

ec2:Region

DescribeHostReservationOfferings 准許描述可供購買的專用主機預留 清單

ec2:Region

DescribeHostReservations 准許描述與 中的專用主機相關聯的專用主機預留 AWS 帳戶 清單

ec2:Region

DescribeHosts 准許描述一或多個專用主機 清單

ec2:Region

DescribeIamInstanceProfileAssociations 准許描述IAM執行個體描述檔關聯 清單

ec2:Region

DescribeIdFormat 准許描述資源的 ID 格式設定 清單

ec2:Region

DescribeIdentityIdFormat 准許描述IAM使用者、IAM角色或根使用者的 資源 ID 格式設定 清單

ec2:Region

DescribeImageAttribute 准許描述 Amazon Machine Image (AMI) 的屬性 清單

image*

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Region

DescribeImages 准許描述一或多個影像 (AMIs、 AKIs和 ARIs) 清單

ec2:Region

DescribeImportImageTasks 准許描述匯入虛擬機器或匯入快照任務 列出

ec2:Region

DescribeImportSnapshotTasks 准許描述匯入快照任務 列出

ec2:Region

DescribeInstanceAttribute 准許描述執行個體的屬性 清單

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

DescribeInstanceConnectEndpoints 准許描述 EC2 Instance Connect Endpoints 清單

ec2:Region

DescribeInstanceCreditSpecifications 准許描述一或多個高載效能執行個體CPU的使用額度選項 清單

ec2:Region

DescribeInstanceEventNotificationAttributes 授予描述要包含在您執行個體排程事件通知中標籤集合的許可 列出

ec2:Region

DescribeInstanceEventWindows 准許描述指定事件時段或所有事件時段 清單

ec2:Region

DescribeInstanceImageMetadata 准許描述用來啟動執行個體AMI的 清單

ec2:Region

DescribeInstanceStatus 准許描述一或多個執行個體的狀態 清單

ec2:Region

DescribeInstanceTopology 准許描述代表EC2執行個體實體主機置放的樹狀階層 清單

ec2:Region

DescribeInstanceTypeOfferings 授予描述在某一個位置所提供執行個體類型組的許可 列出

ec2:Region

DescribeInstanceTypes 授予描述在某一個位置所提供執行個體類型詳細資訊的許可 列出

ec2:Region

DescribeInstances 准許描述一或多個執行個體 列出

ec2:Region

DescribeInternetGateways 准許描述一或多個網際網路閘道 清單

ec2:Region

DescribeIpamByoasn 准許描述您帶至的自治系統編號 (BYOASN) IPAM 清單

ec2:Region

DescribeIpamExternalResourceVerificationTokens 准許描述驗證字符,以證明外部資源的擁有權 清單

ec2:Region

DescribeIpamPools 准許描述 Amazon VPC IP Address Manager (IPAM) 集區 清單

ec2:Region

DescribeIpamResourceDiscoveries 准許描述IPAM資源探索 清單

ec2:Region

DescribeIpamResourceDiscoveryAssociations 准許描述與 Amazon 的資源探索關聯 VPC IPAM 清單

ec2:Region

DescribeIpamScopes 准許描述 Amazon VPC IP Address Manager (IPAM) 範圍 清單

ec2:Region

DescribeIpams 准許描述 Amazon VPC IP Address Manager (IPAM) 清單

ec2:Region

DescribeIpv6Pools 准許描述一或多個IPv6地址集區 清單

ec2:Region

DescribeKeyPairs 准許描述一或多個金鑰對 列出

ec2:Region

DescribeLaunchTemplateVersions 准許描述一或多個啟動範本版本 列出

ec2:Region

ssm:GetParameters

DescribeLaunchTemplates 准許描述一或多個啟動範本 清單

ec2:Region

DescribeLocalGatewayRouteTablePermissions [僅限許可] 准許允許服務描述本機閘道路由表許可 清單

ec2:Region

DescribeLocalGatewayRouteTableVirtualInterfaceGroupAssociations 准許描述虛擬界面群組與本機閘道路由表之間的關聯 清單

ec2:Region

DescribeLocalGatewayRouteTableVpcAssociations 准許描述 VPCs與本機閘道路由表之間的關聯 清單

ec2:Region

DescribeLocalGatewayRouteTables 准許描述一或多個本機閘道路由表 列出

ec2:Region

DescribeLocalGatewayVirtualInterfaceGroups 准許描述本機閘道虛擬界面群組 列出

ec2:Region

DescribeLocalGatewayVirtualInterfaces 准許描述本機閘道虛擬界面 列出

ec2:Region

DescribeLocalGateways 准許描述一或多個本機閘道 清單

ec2:Region

DescribeLockedSnapshots 准許描述快照的鎖定狀態 清單

ec2:Region

DescribeMacHosts 准許描述您的 EC2 Mac 專用主機 清單

ec2:Region

DescribeManagedPrefixLists 准許描述您的受管字首清單和任何受 AWS管字首清單 清單

ec2:Region

DescribeMovingAddresses 准許描述要移至 EC2平台的彈性 IP VPC地址 清單

ec2:Region

DescribeNatGateways 准許描述一或多個NAT閘道 清單

ec2:Region

DescribeNetworkAcls 准許描述一或多個網路 ACLs 清單

ec2:Region

DescribeNetworkInsightsAccessScopeAnalyses 准許描述一或多個 Network Access Scope 分析 列出

ec2:Region

DescribeNetworkInsightsAccessScopes 准許描述 Network Access Scope 列出

ec2:Region

DescribeNetworkInsightsAnalyses 准許描述一或多個網路洞見分析 列出

ec2:Region

DescribeNetworkInsightsPaths 准許描述一或多個網路洞見路徑 列出

ec2:Region

DescribeNetworkInterfaceAttribute 准許描述網路界面屬性 列出

ec2:Region

DescribeNetworkInterfacePermissions 准許描述與網路界面相關聯的許可 列出

ec2:Region

DescribeNetworkInterfaces 准許描述一或多個網路界面 列出

ec2:Region

DescribePlacementGroups 准許描述一或多個置放群組 清單

ec2:Region

DescribePrefixLists 准許以字首清單格式描述可用的 AWS 服務 清單

ec2:Region

DescribePrincipalIdFormat 准許描述根使用者的 ID 格式設定,以及明確指定較長 ID (17 個字元 ID) 偏好設定的所有IAM角色和IAM使用者 清單

ec2:Region

DescribePublicIpv4Pools 准許描述一或多個IPv4地址集區 清單

ec2:Region

DescribeRegions 准許描述您帳戶中 AWS 區域 目前可用的一或多個 清單

ec2:Region

DescribeReplaceRootVolumeTasks 准許描述根磁碟區取代任務 列出

ec2:Region

DescribeReservedInstances 准許描述您帳戶中一或多個購買的預留執行個體 列出

ec2:Region

DescribeReservedInstancesListings 准許描述您帳戶在預留執行個體 Marketplace 中的預留執行個體清單 列出

ec2:Region

DescribeReservedInstancesModifications 准許描述對一或多個預留執行個體所做的修改 列出

ec2:Region

DescribeReservedInstancesOfferings 准許描述可供購買的預留執行個體產品 列出

ec2:Region

DescribeRouteTables 准許描述一或多個路由表 列出

ec2:Region

DescribeScheduledInstanceAvailability 准許尋找排程執行個體的可用排程 清單

ec2:Region

DescribeScheduledInstances 准許描述您帳戶中的一或多個排程執行個體 清單

ec2:Region

DescribeSecurityGroupReferences 准許在參考指定VPC安全群組的VPC對等連線VPCs的另一端描述 清單

security-group*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

ec2:Region

DescribeSecurityGroupRules 准許描述一或多個安全群組規則 清單

ec2:Region

DescribeSecurityGroupVpcAssociations 准許描述安全群組VPC關聯 清單

ec2:Region

DescribeSecurityGroups 准許描述一或多個安全群組 列出

ec2:Region

DescribeSnapshotAttribute 准許描述快照的屬性 清單

snapshot*

aws:ResourceTag/${TagKey}

ec2:Encrypted

ec2:OutpostArn

ec2:Owner

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:SnapshotID

ec2:SnapshotTime

ec2:SourceOutpostArn

ec2:VolumeSize

ec2:Region

DescribeSnapshotTierStatus 准許描述 Amazon EBS快照的儲存層狀態 清單

ec2:Region

DescribeSnapshots 准許描述一或多個EBS快照 清單

ec2:Region

DescribeSpotDatafeedSubscription 准許描述 Spot 執行個體的資料饋送 列出

ec2:Region

DescribeSpotFleetInstances 准許描述 Spot 機群的執行中執行個體 列出

spot-fleet-request*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DescribeSpotFleetRequestHistory 准許描述 Spot 機群請求在指定時間期間的事件 列出

spot-fleet-request*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DescribeSpotFleetRequests 准許描述一或多個 Spot 機群請求 列出

ec2:Region

DescribeSpotInstanceRequests 准許描述一或多個 Spot 執行個體請求 列出

ec2:Region

DescribeSpotPriceHistory 准許描述 Spot 執行個體價格歷史記錄 清單

ec2:Region

DescribeStaleSecurityGroups 准許描述指定 中安全群組的過時安全群組規則 VPC 清單

ec2:Region

DescribeStoreImageTasks 准許描述AMI存放區任務的進度 清單

ec2:Region

DescribeSubnets 准許描述一或多個子網路 清單

ec2:Region

DescribeTags 准許描述 Amazon EC2 資源的一或多個標籤 清單

ec2:Region

DescribeTrafficMirrorFilterRules 准許描述流量鏡射篩選條件,以判斷要鏡射的流量 清單

ec2:Region

DescribeTrafficMirrorFilters 准許描述一或多個流量鏡像篩選條件 列出

ec2:Region

DescribeTrafficMirrorSessions 准許描述一或多個流量鏡像工作階段 列出

ec2:Region

DescribeTrafficMirrorTargets 准許描述一或多個流量鏡像目標 列出

ec2:Region

DescribeTransitGatewayAttachments 准許描述資源與傳輸閘道之間的一或多個附件 列出

ec2:Region

DescribeTransitGatewayConnectPeers 准許描述一或多個傳輸閘道 Connect 對等 列出

ec2:Region

DescribeTransitGatewayConnects 准許描述一或多個傳輸閘道 Connect 附件 列出

ec2:Region

DescribeTransitGatewayMulticastDomains 准許描述一或多個傳輸閘道多點傳送網域 列出

ec2:Region

DescribeTransitGatewayPeeringAttachments 准許描述一或多個傳輸閘道對等附件 清單

ec2:Region

DescribeTransitGatewayPolicyTables 准許描述傳輸閘道政策資料表 清單

ec2:Region

DescribeTransitGatewayRouteTableAnnouncements 准許描述傳輸閘道路由表公告 清單

ec2:Region

DescribeTransitGatewayRouteTables 准許描述一或多個傳輸閘道路由表 清單

ec2:Region

DescribeTransitGatewayVpcAttachments 准許描述傳輸閘道上的一或多個VPC附件 清單

ec2:Region

DescribeTransitGateways 准許描述一或多個傳輸閘道 列出

ec2:Region

DescribeTrunkInterfaceAssociations 准許描述一或多個網路界面幹線關聯 清單

ec2:Region

DescribeVerifiedAccessEndpoints 准許描述指定的 Verified Access 端點或所有 Verified Access 端點 清單

ec2:Region

DescribeVerifiedAccessGroups 准許描述指定的 Verified Access 群組或所有 Verified Access 群組 清單

ec2:Region

DescribeVerifiedAccessInstanceLoggingConfigurations 准許描述 Verified Access 執行個體的目前記錄組態 清單

ec2:Region

DescribeVerifiedAccessInstanceWebAclAssociations [僅限許可] 准許描述已驗證存取執行個體的 AWS Web Application Firewall (WAF) Web 存取控制清單 (ACL) 關聯 清單

ec2:Region

DescribeVerifiedAccessInstances 准許描述指定的 Verified Access 執行個體或所有 Verified Access 執行個體 清單

ec2:Region

DescribeVerifiedAccessTrustProviders 准許描述現有 Verified Access 受信任提供者的詳細資訊 清單

ec2:Region

DescribeVolumeAttribute 准許描述EBS磁碟區的屬性 清單

volume*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:Encrypted

ec2:ManagedResourceOperator

ec2:ParentSnapshot

ec2:ResourceTag/${TagKey}

ec2:VolumeID

ec2:VolumeIops

ec2:VolumeSize

ec2:VolumeThroughput

ec2:VolumeType

ec2:Region

DescribeVolumeStatus 准許描述一或多個EBS磁碟區的狀態 清單

ec2:Region

DescribeVolumes 准許描述一或多個EBS磁碟區 清單

ec2:Region

DescribeVolumesModifications 准許描述一或多個EBS磁碟區的目前修改狀態 清單

ec2:Region

DescribeVpcAttribute 准許描述 屬性 VPC 清單

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

DescribeVpcBlockPublicAccessExclusions 准許描述 上封鎖公開存取的排除清單 VPC 清單

vpc-block-public-access-exclusion

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DescribeVpcBlockPublicAccessOptions 准許描述 上封鎖公開存取的選項 VPC 清單

ec2:Region

准許描述一或多個 ClassicLink 的狀態 VPCs 清單

ec2:Region

DescribeVpcClassicLinkDnsSupport 准許描述 ClassicLink DNS一或多個 的支援狀態 VPCs 清單

ec2:Region

DescribeVpcEndpointAssociations 准許描述VPC端點關聯 清單

vpc-endpoint

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:VpceServiceName

ec2:VpceServiceOwner

ec2:Region

DescribeVpcEndpointConnectionNotifications 准許描述VPC端點和VPC端點服務的連線通知 清單

ec2:Region

DescribeVpcEndpointConnections 准許描述VPC端點服務的VPC端點連線 清單

ec2:Region

DescribeVpcEndpointServiceConfigurations 准許描述VPC端點服務組態 (您的服務) 清單

ec2:Region

DescribeVpcEndpointServicePermissions 准許描述允許探索VPC端點服務的主體 (服務消費者) 清單

vpc-endpoint-service*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:vpceMultiRegion

ec2:vpceSupportedRegion

ec2:Region

DescribeVpcEndpointServices 准許描述建立VPC端點時 AWS 可指定的所有支援服務 清單

ec2:Region

DescribeVpcEndpoints 准許描述一或多個VPC端點 清單

ec2:Region

DescribeVpcPeeringConnections 准許描述一或多個VPC對等互連連線 清單

ec2:Region

DescribeVpcs 准許描述一或多個 VPCs 清單

ec2:Region

DescribeVpnConnections 准許描述一或多個VPN連線 清單

ec2:Region

DescribeVpnGateways 准許描述一或多個虛擬私有閘道 清單

ec2:Region

DetachClassicLinkVpc 准許從 取消連結 (移除) 連結的 EC2-Classic 執行個體 VPC 寫入

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

DetachInternetGateway 准許從 分離網際網路閘道 VPC 寫入

internet-gateway*

aws:ResourceTag/${TagKey}

ec2:InternetGatewayID

ec2:ResourceTag/${TagKey}

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

DetachNetworkInterface 准許從執行個體分離網路界面 寫入

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

network-interface*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

ec2:Region

DetachVerifiedAccessTrustProvider 准許將受信任提供者從 Verified Access 執行個體分離 寫入

verified-access-instance*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

verified-access-trust-provider*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DetachVolume 准許從執行個體分離EBS磁碟區 寫入

volume*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:Encrypted

ec2:ManagedResourceOperator

ec2:ParentSnapshot

ec2:ResourceTag/${TagKey}

ec2:VolumeID

ec2:VolumeIops

ec2:VolumeSize

ec2:VolumeThroughput

ec2:VolumeType

instance

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

DetachVpnGateway 准許從 分離虛擬私有閘道 VPC 寫入

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

vpn-gateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DisableAddressTransfer 准許停用彈性 IP 地址轉移 寫入

elastic-ip*

aws:ResourceTag/${TagKey}

ec2:AllocationId

ec2:Domain

ec2:PublicIpAddress

ec2:ResourceTag/${TagKey}

ec2:Region

DisableAllowedImagesSettings 准許停用允許的映像設定 寫入

ec2:Region

DisableAwsNetworkPerformanceMetricSubscription 准許停用基礎設施效能指標訂閱 寫入

ec2:Region

DisableEbsEncryptionByDefault 准許預設停用您帳戶的EBS加密 寫入

ec2:Region

DisableFastLaunch 准許停用 Windows 的更快速啟動 AMIs 寫入

image*

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Region

DisableFastSnapshotRestores 准許停用所指定可用區域中一或多個快照的快速快照還原 寫入

snapshot*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:Encrypted

ec2:Owner

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:SnapshotID

ec2:SnapshotTime

ec2:VolumeSize

ec2:Region

DisableImage 准許停用 AMI 寫入

image*

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Region

DisableImageBlockPublicAccess 准許AMIs在指定的帳戶層級停用 的封鎖公開存取 AWS 區域 寫入

ec2:Region

DisableImageDeprecation 准許取消已指定 的棄用 AMI 寫入

image*

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Region

DisableImageDeregistrationProtection 准許停用 的取消註冊保護AMI。停用取消註冊保護時,AMI可以取消註冊 寫入

image*

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Region

DisableIpamOrganizationAdminAccount 准許將 AWS Organizations 成員帳戶停用為 Amazon VPC IP Address Manager (IPAM) 管理員帳戶 寫入

ec2:Region

organizations:DeregisterDelegatedAdministrator

DisableSerialConsoleAccess 准許停用對您帳戶所有執行個體的EC2序列主控台的存取 寫入

ec2:Region

DisableSnapshotBlockPublicAccess 准許停用區域的快照封鎖公開存取設定 寫入

ec2:Region

DisableTransitGatewayRouteTablePropagation 准許停用從傳播路由到所指定傳播路由表的資源附件 寫入

transit-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableId

transit-gateway-attachment

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

transit-gateway-route-table-announcement

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableAnnouncementId

ec2:Region

DisableVgwRoutePropagation 准許停用虛擬私有閘道,將路由傳播到 的指定路由表 VPC 寫入

route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:RouteTableID

ec2:Vpc

vpn-gateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

准許停用 ClassicLink 的 VPC 寫入

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

DisableVpcClassicLinkDnsSupport 准許停用 ClassicLink DNS對 的支援 VPC 寫入

vpc

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

DisassociateAddress 准許解除彈性 IP 地址與執行個體或網路界面的關聯 寫入

elastic-ip

aws:ResourceTag/${TagKey}

ec2:AllocationId

ec2:Domain

ec2:PublicIpAddress

ec2:ResourceTag/${TagKey}

network-interface

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

ec2:Region

DisassociateCapacityReservationBillingOwner 准許取消待定請求,將容量預留未使用容量的帳單指派給取用者帳戶 寫入

capacity-reservation*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CapacityReservationFleet

ec2:CreateDate

ec2:DestinationCapacityReservationId

ec2:EbsOptimized

ec2:EndDate

ec2:EndDateType

ec2:InstanceCount

ec2:InstanceMatchCriteria

ec2:InstancePlatform

ec2:InstanceType

ec2:OutpostArn

ec2:PlacementGroup

ec2:ResourceTag/${TagKey}

ec2:SourceCapacityReservationId

ec2:Tenancy

ec2:Region

DisassociateClientVpnTargetNetwork 准許取消目標網路與用戶端VPN端點的關聯 寫入

client-vpn-endpoint*

aws:ResourceTag/${TagKey}

ec2:ClientRootCertificateChainArn

ec2:CloudwatchLogGroupArn

ec2:CloudwatchLogStreamArn

ec2:DirectoryArn

ec2:ResourceTag/${TagKey}

ec2:SamlProviderArn

ec2:ServerCertificateArn

ec2:Region

DisassociateEnclaveCertificateIamRole 准許取消ACM憑證與IAM角色的關聯 寫入

certificate*

role*

ec2:Region

DisassociateIamInstanceProfile 准許取消IAM執行個體描述檔與執行中或已停止執行個體的關聯 寫入

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

DisassociateInstanceEventWindow 准許將一或多個目標與事件時段取消關聯 寫入

instance-event-window*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DisassociateIpamByoasn 准許取消自治系統編號 (ASN) 與 的關聯 BYOIP CIDR 寫入

ec2:Region

DisassociateIpamResourceDiscovery 准許取消資源探索與 Amazon 的關聯 VPC IPAM 寫入

ipam-resource-discovery-association*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DisassociateNatGatewayAddress 准許取消次要彈性 IP 地址與公有NAT閘道的關聯 寫入

elastic-ip*

aws:ResourceTag/${TagKey}

ec2:AllocationId

ec2:Domain

ec2:PublicIpAddress

ec2:ResourceTag/${TagKey}

natgateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

network-interface*

aws:ResourceTag/${TagKey}

ec2:AuthorizedUser

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:Permission

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

ec2:Region

DisassociateRouteTable 准許解除子網路與路由表的關聯 寫入

internet-gateway

aws:ResourceTag/${TagKey}

ec2:InternetGatewayID

ec2:ResourceTag/${TagKey}

ipv4pool-ec2

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ipv6pool-ec2

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

route-table

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:RouteTableID

ec2:Vpc

subnet

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

vpn-gateway

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DisassociateSecurityGroupVpc 准許取消安全群組與 的關聯 VPC 寫入

security-group*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

vpc

aws:ResourceTag/${TagKey}

ec2:Ipv4IpamPoolId

ec2:Ipv6IpamPoolId

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

DisassociateSubnetCidrBlock 准許取消CIDR區塊與子網路的關聯 寫入

subnet*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

ec2:Region

DisassociateTransitGatewayMulticastDomain 准許解除一或多個子網路與傳輸閘道多點傳送網域的關聯 寫入

subnet*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

transit-gateway-attachment*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

transit-gateway-multicast-domain*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayMulticastDomainId

ec2:Region

DisassociateTransitGatewayPolicyTable 准許取消政策資料表與傳輸閘道的關聯 寫入

transit-gateway-attachment*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

transit-gateway-policy-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayPolicyTableId

ec2:Region

DisassociateTransitGatewayRouteTable 准許解除資源附件與傳輸閘道路由表的關聯 寫入

transit-gateway-attachment*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

transit-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableId

ec2:Region

DisassociateTrunkInterface 准許將分支網路界面與幹線網路界面取消關聯 寫入

ec2:Region

DisassociateVerifiedAccessInstanceWebAcl [僅限許可] 准許取消 AWS Web Application Firewall (WAF) Web 存取控制清單 (ACL) 與驗證存取執行個體的關聯 寫入

verified-access-instance*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

DisassociateVpcCidrBlock 准許取消CIDR區塊與 的關聯 VPC 寫入

vpc

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

EnableAddressTransfer 准許啟用彈性 IP 地址轉移 寫入

elastic-ip*

aws:ResourceTag/${TagKey}

ec2:AllocationId

ec2:Domain

ec2:PublicIpAddress

ec2:ResourceTag/${TagKey}

ec2:Region

EnableAllowedImagesSettings 准許啟用允許的映像設定 寫入

ec2:Region

EnableAwsNetworkPerformanceMetricSubscription 准許啟用基礎設施效能訂閱 寫入

ec2:Region

EnableEbsEncryptionByDefault 准許為您的帳戶預設啟用EBS加密 寫入

ec2:Region

EnableFastLaunch 准許為 Windows 啟用更快速的啟動 AMIs 寫入

image*

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:CreateLaunchTemplate

ec2:CreateSnapshot

ec2:CreateTags

ec2:DeleteSnapshot

ec2:DescribeImages

ec2:DescribeInstanceAttribute

ec2:DescribeInstanceStatus

ec2:DescribeInstanceTypeOfferings

ec2:DescribeInstances

ec2:DescribeLaunchTemplateVersions

ec2:DescribeLaunchTemplates

ec2:DescribeSnapshots

ec2:DescribeSubnets

ec2:RunInstances

ec2:StopInstances

ec2:TerminateInstances

iam:PassRole

launch-template

aws:ResourceTag/${TagKey}

ec2:ManagedResourceOperator

ec2:ResourceTag/${TagKey}

ec2:Region

EnableFastSnapshotRestores 准許啟用所指定可用區域中一或多個快照的快速快照還原 寫入

snapshot*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:Encrypted

ec2:Owner

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:SnapshotID

ec2:SnapshotTime

ec2:VolumeSize

ec2:Region

EnableImage 准許重新啟用已停用的 AMI 寫入

image*

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Region

EnableImageBlockPublicAccess 准許AMIs在指定的帳戶層級啟用 的封鎖公開存取 AWS 區域 寫入

ec2:Region

EnableImageDeprecation 准許在指定的AMI日期和時間啟用指定的 取代 寫入

image*

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Region

EnableImageDeregistrationProtection 准許啟用 的取消註冊保護AMI。啟用取消註冊保護時,AMI無法取消註冊 寫入

image*

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Region

EnableIpamOrganizationAdminAccount 准許將 AWS Organizations 成員帳戶啟用為 Amazon VPC IP Address Manager (IPAM) 管理員帳戶 寫入

ec2:Region

iam:CreateServiceLinkedRole

organizations:EnableAWSServiceAccess

organizations:RegisterDelegatedAdministrator

EnableReachabilityAnalyzerOrganizationSharing 准許啟用 Reachability Analyzer 的組織共用 寫入

ec2:Region

iam:CreateServiceLinkedRole

organizations:EnableAWSServiceAccess

EnableSerialConsoleAccess 准許允許存取您帳戶所有執行個體的EC2序列主控台 寫入

ec2:Region

EnableSnapshotBlockPublicAccess 准許啟用或修改區域的快照封鎖公開存取設定 寫入

ec2:Region

EnableTransitGatewayRouteTablePropagation 准許附件可將路由傳播至傳輸路由表 寫入

transit-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableId

transit-gateway-attachment

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

transit-gateway-route-table-announcement

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableAnnouncementId

ec2:Region

EnableVgwRoutePropagation 准許讓虛擬私有閘道將路由傳播到VPC路由表 寫入

route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:RouteTableID

ec2:Vpc

vpn-gateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

EnableVolumeIO 准許對已停用 I/O 操作的磁碟區啟用 I/O 操作 寫入

volume*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:Encrypted

ec2:ManagedResourceOperator

ec2:ParentSnapshot

ec2:ResourceTag/${TagKey}

ec2:VolumeID

ec2:VolumeIops

ec2:VolumeSize

ec2:VolumeThroughput

ec2:VolumeType

ec2:Region

准許啟用 VPC的 ClassicLink 寫入

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

EnableVpcClassicLinkDnsSupport 准許 啟用 VPC 以支援 的DNS主機名稱解析 ClassicLink 寫入

vpc

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

ExportClientVpnClientCertificateRevocationList 准許下載用戶端VPN端點的用戶端憑證撤銷清單 讀取

client-vpn-endpoint*

aws:ResourceTag/${TagKey}

ec2:ClientRootCertificateChainArn

ec2:CloudwatchLogGroupArn

ec2:CloudwatchLogStreamArn

ec2:DirectoryArn

ec2:ResourceTag/${TagKey}

ec2:SamlProviderArn

ec2:ServerCertificateArn

ec2:Region

ExportClientVpnClientConfiguration 准許下載用戶端VPN端點的用戶端VPN端點組態檔案內容 讀取

client-vpn-endpoint*

aws:ResourceTag/${TagKey}

ec2:ClientRootCertificateChainArn

ec2:CloudwatchLogGroupArn

ec2:CloudwatchLogStreamArn

ec2:DirectoryArn

ec2:ResourceTag/${TagKey}

ec2:SamlProviderArn

ec2:ServerCertificateArn

ec2:Region

ExportImage 准許將 Amazon Machine Image (AMI) 匯出至 VM 檔案 寫入

export-image-task*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

image*

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Region

ExportTransitGatewayRoutes 准許將路由從傳輸閘道路由表匯出到 Amazon S3 儲存貯體 寫入

ec2:Region

ExportVerifiedAccessInstanceClientConfiguration 准許匯出已驗證的存取執行個體用戶端組態 讀取

verified-access-instance*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetAllowedImagesSettings 准許取得影像的允許設定 讀取

ec2:Region

GetAssociatedEnclaveCertificateIamRoles 准許取得與ACM憑證相關聯的角色清單 讀取

certificate*

ec2:Region

GetAssociatedIpv6PoolCidrs 准許取得指定IPv6地址集區之IPv6CIDR區塊關聯的相關資訊 讀取

ec2:Region

GetAwsNetworkPerformanceData 准許取得網路效能資料 讀取

ec2:Region

GetCapacityReservationUsage 准許取得有關容量預留的用量資訊 讀取

capacity-reservation*

aws:ResourceTag/${TagKey}

ec2:CapacityReservationFleet

ec2:Region

GetCoipPoolUsage 授予描述從指定客戶所擁有地址集區所進行配置的許可 讀取

coip-pool*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetConsoleOutput 准許取得執行個體的主控台輸出 讀取

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

GetConsoleScreenshot 准許擷取執行中執行個體的 JPG- 格式螢幕擷取畫面 讀取

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:NewInstanceProfile

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

GetDeclarativePoliciesReportSummary 准許取得宣告政策的報告摘要 讀取

declarative-policies-report*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetDefaultCreditSpecification 准許取得CPU使用高載效能執行個體系列的預設額度選項 讀取

ec2:Region

GetEbsDefaultKmsKeyId 准許取得預設客戶主金鑰 (CMK) 的 ID 以進行預設EBS加密 讀取

ec2:Region

GetEbsEncryptionByDefault 准許描述您的帳戶是否預設啟用EBS加密 讀取

ec2:Region

GetFlowLogsIntegrationTemplate 准許產生 CloudFormation 範本,以簡化VPC流程日誌與 Amazon Athena 的整合 讀取

vpc-flow-log*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetGroupsForCapacityReservation 准許列出已新增某個容量保留的資源群組清單 列出

capacity-reservation*

aws:ResourceTag/${TagKey}

ec2:CapacityReservationFleet

ec2:Region

GetHostReservationPurchasePreview 准許預覽其組態符合專用主機組態的預留購買 讀取

ec2:Region

GetImageBlockPublicAccessState 准許在指定的AMIs帳戶層級取得 的封鎖公開存取的目前狀態 AWS 區域 讀取

ec2:Region

GetInstanceMetadataDefaults 准許檢視您帳戶在指定區域中設定的預設執行個體中繼資料服務 (IMDS) 設定 清單

ec2:Region

GetInstanceTpmEkPub 准許取得與指定執行個體之 Nitro 信任平台模組 (NitroTPM) 相關聯的公有背書金鑰 讀取

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

GetInstanceTypesFromInstanceRequirements 准許檢視具有指定執行個體屬性的執行個體類型清單 清單

ec2:Region

GetInstanceUefiData 准許擷取UEFI變數存放區的二進位表示 讀取

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:NewInstanceProfile

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

GetIpamAddressHistory 准許擷取 CIDR Amazon VPC IP Address Manager (IPAM) 範圍內 的歷史資訊 讀取

ipam-scope*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetIpamDiscoveredAccounts 准許擷取IPAM探索的帳戶 讀取

ipam-resource-discovery*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetIpamDiscoveredPublicAddresses 准許擷取 發現的公有 IP 地址 IPAM 讀取

ipam-resource-discovery*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetIpamDiscoveredResourceCidrs 准許擷取CIDRs作為資源探索一部分而監控的資源 讀取

ipam-resource-discovery*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetIpamPoolAllocations 准許取得 Amazon VPC IP Address Manager (IPAM) 集區中所有CIDR配置的清單 清單

ipam-pool*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetIpamPoolCidrs 准許將 CIDRs佈建至 Amazon VPC IP Address Manager (IPAM) 集區 讀取

ipam-pool*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetIpamResourceCidrs 准許取得 Amazon VPC IP Address Manager (IPAM) 範圍內資源的相關資訊 讀取

ipam-scope*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ipam-pool

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetLaunchTemplateData 准許取得所指定執行個體的組態資料,此執行個體用於與新啟動範本或啟動範本版本搭配使用 讀取

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

GetManagedPrefixListAssociations 授予取得與指定受管前綴清單相關資源資訊的許可 讀取

prefix-list*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetManagedPrefixListEntries 授予取得指定受管前綴清單項目相關資訊的許可 讀取

prefix-list*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetNetworkInsightsAccessScopeAnalysisFindings 准許取得一或多個 Network Access Scope 分析的問題清單 讀取

network-insights-access-scope-analysis*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetNetworkInsightsAccessScopeContent 准許取得指定 Network Access Scope 的內容 讀取

network-insights-access-scope*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetPasswordData 准許擷取執行中 Windows 執行個體的加密管理員密碼 讀取

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

GetReservedInstancesExchangeQuote 准許傳回報價和交換資訊,用於將一或多個可轉換預留執行個體交換為新的可轉換預留執行個體 讀取

ec2:Region

GetResourcePolicy [僅限許可] 准許描述啟用跨帳戶共用IAM的政策 讀取

ipam-pool

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

placement-group

aws:ResourceTag/${TagKey}

ec2:PlacementGroupName

ec2:PlacementGroupStrategy

ec2:ResourceTag/${TagKey}

verified-access-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetSecurityGroupsForVpc 准許擷取指定 的安全群組清單 VPC 讀取

vpc*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

GetSerialConsoleAccessStatus 准許將您的帳戶存取狀態擷取至所有執行個體的EC2序列主控台 讀取

ec2:Region

GetSnapshotBlockPublicAccessState 准許擷取區域的快照封鎖公開存取目前狀態 讀取

ec2:Region

GetSpotPlacementScores 准許根據指定的目標容量和運算需求計算區域或可用區域的 Spot 置放分數 讀取

ec2:Region

GetSubnetCidrReservations 准許擷取子網路CIDR保留的相關資訊 讀取

ec2:Region

GetTransitGatewayAttachmentPropagations 准許列出資源附件將路由傳播至其中的路由表 列出

ec2:Region

GetTransitGatewayMulticastDomainAssociations 准許取得傳輸閘道多點傳送網域之關聯的相關資訊 清單

transit-gateway-multicast-domain*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayMulticastDomainId

ec2:Region

GetTransitGatewayPolicyTableAssociations 准許取得傳輸閘道政策資料表之關聯的相關資訊 清單

transit-gateway-policy-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayPolicyTableId

ec2:Region

GetTransitGatewayPolicyTableEntries 准許取得傳輸閘道政策資料表條目之關聯的相關資訊 清單

transit-gateway-policy-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayPolicyTableId

ec2:Region

GetTransitGatewayPrefixListReferences 授予取得轉移閘道路由表格前綴清單參考相關資訊的許可 列出

ec2:Region

GetTransitGatewayRouteTableAssociations 准許取得傳輸閘道路由表之關聯的相關資訊 列出

ec2:Region

GetTransitGatewayRouteTablePropagations 准許取得傳輸閘道路由表之路由表傳播的相關資訊 清單

ec2:Region

GetVerifiedAccessEndpointPolicy 准許顯示與端點相關聯的 Verified Access 政策 清單

verified-access-endpoint*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetVerifiedAccessEndpointTargets 准許取得已驗證的存取端點目標 清單

verified-access-endpoint*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetVerifiedAccessGroupPolicy 准許顯示與群組相關聯的 Verified Access 政策內容 清單

verified-access-group*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetVerifiedAccessInstanceWebAcl [僅限許可] 准許顯示已驗證存取執行個體的 AWS Web Application Firewall (WAF) Web 存取控制清單 (ACL) 清單

verified-access-instance*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

GetVpnConnectionDeviceSampleConfiguration 准許下載 AWS提供的範例組態檔案,以與客戶閘道裝置搭配使用 清單

vpn-connection*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

vpn-connection-device-type*

ec2:Region

GetVpnConnectionDeviceTypes 准許取得可提供範例組態檔案之客戶閘道裝置的清單 清單

ec2:Region

GetVpnTunnelReplacementStatus 准許檢視可用的通道端點維護事件 清單

vpn-connection*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

ImportByoipCidrToIpam [僅限許可] 准許將現有的 BYOIP IPv4 CIDRs 轉移到 IPAM 寫入

ipam-pool*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

ImportClientVpnClientCertificateRevocationList 准許將用戶端憑證撤銷清單上傳至用戶端VPN端點 寫入

client-vpn-endpoint*

aws:ResourceTag/${TagKey}

ec2:ClientRootCertificateChainArn

ec2:CloudwatchLogGroupArn

ec2:CloudwatchLogStreamArn

ec2:DirectoryArn

ec2:ResourceTag/${TagKey}

ec2:SamlProviderArn

ec2:ServerCertificateArn

ec2:Region

ImportImage 准許將單一或多磁碟區磁碟映像或EBS快照匯入 Amazon Machine Image (AMI) 寫入

image*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:RootDeviceType

ec2:CreateTags

import-image-task*

aws:RequestTag/${TagKey}

aws:TagKeys

snapshot

aws:ResourceTag/${TagKey}

ec2:Owner

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:SnapshotID

ec2:SnapshotTime

ec2:VolumeSize

ec2:Region

ImportInstance 准許使用磁碟映像中的中繼資料建立匯入執行個體任務 寫入

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:InstanceID

ec2:ManagedResourceOperator

ec2:ResourceTag/${TagKey}

volume*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:Encrypted

ec2:ManagedResourceOperator

ec2:ParentSnapshot

ec2:ResourceTag/${TagKey}

ec2:VolumeID

ec2:VolumeIops

ec2:VolumeSize

ec2:VolumeThroughput

ec2:VolumeType

security-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

subnet

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

ec2:Region

ImportKeyPair 准許從使用第三方工具建立的RSA金鑰對匯入公有金鑰 寫入

key-pair*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

ec2:Region

ImportSnapshot 准許將磁碟匯入EBS快照 寫入

import-snapshot-task*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

snapshot*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:Owner

ec2:ParentVolume

ec2:SnapshotID

ec2:SnapshotTime

ec2:VolumeSize

ec2:Region

ImportVolume 准許使用磁碟映像中的中繼資料建立匯入磁碟區任務 寫入

volume*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:Encrypted

ec2:ManagedResourceOperator

ec2:ParentSnapshot

ec2:ResourceTag/${TagKey}

ec2:VolumeID

ec2:VolumeIops

ec2:VolumeSize

ec2:VolumeThroughput

ec2:VolumeType

ec2:Region

InjectApiError [僅限許可] 准許暫時注入目標API請求的錯誤 寫入

ec2:FisActionId

ec2:FisTargetArns

ec2:Region

ListImagesInRecycleBin 准許列出目前在資源回收筒中的 Amazon Machine Image (AMIs) 清單

ec2:Region

ListSnapshotsInRecycleBin 准許列出目前在資源回收筒中的 Amazon EBS快照 清單

ec2:Region

LockSnapshot 准許在控管或合規模式下鎖定 Amazon EBS快照,以防止意外或惡意刪除 寫入

snapshot*

aws:ResourceTag/${TagKey}

ec2:Encrypted

ec2:Owner

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:SnapshotCoolOffPeriod

ec2:SnapshotID

ec2:SnapshotLockDuration

ec2:SnapshotTime

ec2:VolumeSize

ec2:Region

ModifyAddressAttribute 准許修改指定彈性 IP 地址的屬性 寫入

elastic-ip*

aws:ResourceTag/${TagKey}

ec2:AllocationId

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Domain

ec2:PublicIpAddress

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyAvailabilityZoneGroup 准許修改帳戶之本地區域和 Wavelength 區域群組選擇的選擇加入狀態 寫入

ec2:Region

ModifyCapacityReservation 准許修改容量預留的容量及釋出容量的條件 寫入

capacity-reservation*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:CapacityReservationFleet

ec2:Region

ModifyCapacityReservationFleet 准許修改容量保留機群 寫入

capacity-reservation-fleet*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:ModifyCapacityReservation

ec2:Region

ModifyClientVpnEndpoint 准許修改用戶端VPN端點 寫入

client-vpn-endpoint*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ClientRootCertificateChainArn

ec2:CloudwatchLogGroupArn

ec2:CloudwatchLogStreamArn

ec2:DirectoryArn

ec2:ResourceTag/${TagKey}

ec2:SamlProviderArn

ec2:ServerCertificateArn

security-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

vpc

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

ModifyDefaultCreditSpecification 准許變更帳戶層級的預設額度選項,以CPU使用爆量效能執行個體 寫入

ec2:Region

ModifyEbsDefaultKmsKeyId 准許變更您帳戶預設EBS加密的預設客戶主金鑰 (CMK) 寫入

ec2:Region

ModifyFleet 准許修改EC2機群 寫入

fleet*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

image

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

launch-template

aws:ResourceTag/${TagKey}

ec2:ManagedResourceOperator

ec2:ResourceTag/${TagKey}

subnet

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

ec2:Region

ModifyFpgaImageAttribute 准許修改 Amazon FPGA Image (AFI) 的屬性 寫入

fpga-image*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyHosts 准許修改專用主機 寫入

dedicated-host*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyIdFormat 准許修改資源的 ID 格式 寫入

ec2:Region

ModifyIdentityIdFormat 准許修改您帳戶中特定委託人的資源 ID 格式 寫入

ec2:Region

ModifyImageAttribute 准許修改 Amazon Machine Image (AMI) 的屬性 寫入

image*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Region

ModifyInstanceAttribute 准許修改執行個體的屬性 寫入

instance*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

security-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

volume

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:Encrypted

ec2:ManagedResourceOperator

ec2:ParentSnapshot

ec2:ResourceTag/${TagKey}

ec2:VolumeID

ec2:VolumeIops

ec2:VolumeSize

ec2:VolumeThroughput

ec2:VolumeType

ec2:Region

ModifyInstanceCapacityReservationAttributes 准許修改已停止執行個體的容量預留設定 寫入

instance*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

capacity-reservation

aws:ResourceTag/${TagKey}

ec2:Region

ModifyInstanceCpuOptions 准許修改執行個體上的CPU選項 寫入

instance*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

ModifyInstanceCreditSpecification 准許修改執行個體CPU上使用的額度選項 寫入

instance*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

ModifyInstanceEventStartTime 准許修改排程EC2執行個體事件的開始時間 寫入

instance*

aws:ResourceTag/${TagKey}

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

ModifyInstanceEventWindow 准許修改指定的事件時段 寫入

instance-event-window*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyInstanceMaintenanceOptions 准許修改執行個體的復原行為 寫入

instance*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

ModifyInstanceMetadataDefaults 准許修改指定區域中您帳戶的預設執行個體中繼資料服務 (IMDS) 設定 寫入

ec2:Attribute/${AttributeName}

ec2:Region

ModifyInstanceMetadataOptions 准許修改執行個體的中繼資料選項 寫入

instance*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

ModifyInstancePlacement 准許修改執行個體的置放屬性 寫入

instance*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

dedicated-host

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

placement-group

aws:ResourceTag/${TagKey}

ec2:PlacementGroupName

ec2:PlacementGroupStrategy

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyIpam 准許修改 Amazon VPC IP Address Manager (IPAM) 的組態 寫入

ipam*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyIpamPool 准許修改 Amazon VPC IP Address Manager (IPAM) 集區的組態 寫入

ipam-pool*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyIpamResourceCidr 准許修改 Amazon VPC IP Address Manager (IPAM) 資源的組態 CIDR 寫入

ipam-scope*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyIpamResourceDiscovery 准許修改資源探索 寫入

ipam-resource-discovery*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyIpamScope 准許修改 Amazon VPC IP Address Manager (IPAM) 範圍的組態 寫入

ipam-scope*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyLaunchTemplate 准許修改啟動範本 寫入

launch-template*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ManagedResourceOperator

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyLocalGatewayRoute 准許修改本機閘道路由 寫入

local-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

local-gateway-virtual-interface-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

network-interface

aws:ResourceTag/${TagKey}

ec2:AuthorizedUser

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:Permission

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

prefix-list

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyManagedPrefixList 授予修改受管前綴清單的許可 寫入

prefix-list*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyNetworkInterfaceAttribute 准許修改網路界面的屬性 寫入

network-interface*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

instance

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

security-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

ec2:Region

ModifyPrivateDnsNameOptions 准許修改指定執行個體的執行個體主機名稱選項 寫入

instance*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:NewInstanceProfile

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

ModifyReservedInstances 准許修改一或多個預留執行個體的屬性 寫入

reserved-instances*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:InstanceType

ec2:ReservedInstancesOfferingType

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:Region

ModifySecurityGroupRules 准許修改安全群組的規則 寫入

security-group*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

security-group-rule*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

prefix-list

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifySnapshotAttribute 准許新增或移除快照的許可設定 許可管理

snapshot*

aws:ResourceTag/${TagKey}

ec2:Add/group

ec2:Add/userId

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Owner

ec2:ParentVolume

ec2:Remove/group

ec2:Remove/userId

ec2:ResourceTag/${TagKey}

ec2:SnapshotID

ec2:SnapshotTime

ec2:VolumeSize

ec2:Region

ModifySnapshotTier 准許封存 Amazon EBS快照 寫入

snapshot*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Encrypted

ec2:Owner

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:SnapshotID

ec2:SnapshotTime

ec2:VolumeSize

ec2:Region

ModifySpotFleetRequest 准許修改 Spot 機群請求 寫入

spot-fleet-request*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

launch-template

aws:ResourceTag/${TagKey}

ec2:ManagedResourceOperator

ec2:ResourceTag/${TagKey}

subnet

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

ec2:Region

ModifySubnetAttribute 准許修改子網路的屬性 寫入

subnet*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

ec2:Region

ModifyTrafficMirrorFilterNetworkServices 授與允許或限制鏡像網路服務的許可 寫入

traffic-mirror-filter*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyTrafficMirrorFilterRule 准許修改流量鏡像規則 寫入

traffic-mirror-filter*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

traffic-mirror-filter-rule*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ModifyTrafficMirrorSession 准許修改流量鏡像工作階段 寫入

traffic-mirror-session*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

traffic-mirror-filter

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

traffic-mirror-target

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyTransitGateway 准許修改傳輸閘道 寫入

transit-gateway*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayId

transit-gateway-route-table

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableId

ec2:Region

ModifyTransitGatewayPrefixListReference 授予修改轉移閘道前綴清單參考的許可 寫入

prefix-list*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

transit-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableId

transit-gateway-attachment

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

ec2:Region

ModifyTransitGatewayVpcAttachment 准許修改傳輸閘道上的VPC附件 寫入

transit-gateway-attachment*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

subnet

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

ec2:Region

ModifyVerifiedAccessEndpoint 准許修改 Verified Access 端點的組態 寫入

verified-access-endpoint*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

subnet

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

verified-access-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyVerifiedAccessEndpointPolicy 准許修改指定的 Verified Access 端點政策 寫入

verified-access-endpoint*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyVerifiedAccessGroup 准許修改指定的 Verified Access 群組組態 寫入

verified-access-group*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

verified-access-instance

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyVerifiedAccessGroupPolicy 准許修改指定的 Verified Access 群組政策 寫入

verified-access-group*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyVerifiedAccessInstance 准許修改指定的 Verified Access 執行個體的組態 寫入

verified-access-instance*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyVerifiedAccessInstanceLoggingConfiguration 准許修改指定的 Verified Access 執行個體的記錄組態 寫入

verified-access-instance*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyVerifiedAccessTrustProvider 准許修改指定的 Verified Access 受信任提供者的組態 寫入

verified-access-trust-provider*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyVolume 准許修改EBS磁碟區的參數 寫入

volume*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:Encrypted

ec2:ManagedResourceOperator

ec2:ParentSnapshot

ec2:ResourceTag/${TagKey}

ec2:VolumeID

ec2:VolumeIops

ec2:VolumeSize

ec2:VolumeThroughput

ec2:VolumeType

ec2:Region

ModifyVolumeAttribute 准許修改磁碟區的屬性 寫入

volume*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:Encrypted

ec2:ManagedResourceOperator

ec2:ParentSnapshot

ec2:ResourceTag/${TagKey}

ec2:VolumeID

ec2:VolumeIops

ec2:VolumeSize

ec2:VolumeThroughput

ec2:VolumeType

ec2:Region

ModifyVpcAttribute 准許修改 屬性 VPC 寫入

vpc*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

ModifyVpcBlockPublicAccessExclusion 准許修改 上封鎖公開存取的排除清單 VPC 寫入

vpc-block-public-access-exclusion*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyVpcBlockPublicAccessOptions 准許在 上修改封鎖公開存取的選項 VPC 寫入

ec2:Region

ModifyVpcEndpoint 准許修改VPC端點的屬性 寫入

vpc-endpoint*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

route-table

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:RouteTableID

security-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

subnet

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

ec2:Region

ModifyVpcEndpointConnectionNotification 准許修改VPC端點或VPC端點服務的連線通知 寫入

vpc-endpoint

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

vpc-endpoint-service

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:vpceMultiRegion

ec2:vpceSupportedRegion

ec2:Region

ModifyVpcEndpointServiceConfiguration 准許修改VPC端點服務組態的屬性 寫入

vpc-endpoint-service*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:VpceServicePrivateDnsName

ec2:vpceMultiRegion

ec2:vpceSupportedRegion

ec2:Region

ModifyVpcEndpointServicePayerResponsibility 准許修改VPC端點服務的付款人責任 寫入

vpc-endpoint-service*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:vpceMultiRegion

ec2:vpceSupportedRegion

ec2:Region

ModifyVpcEndpointServicePermissions 准許修改VPC端點服務的許可 許可管理

vpc-endpoint-service*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:vpceMultiRegion

ec2:vpceSupportedRegion

ec2:Region

ModifyVpcPeeringConnectionOptions 准許修改VPC對等連線一側的VPC對等連線選項 寫入

vpc-peering-connection*

aws:ResourceTag/${TagKey}

ec2:AccepterVpc

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:RequesterVpc

ec2:ResourceTag/${TagKey}

ec2:VpcPeeringConnectionID

ec2:Region

ModifyVpcTenancy 准許修改 的執行個體租用屬性 VPC 寫入

vpc*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

ec2:Region

ModifyVpnConnection 准許修改VPN連線的目標閘道 Site-to-Site 寫入

vpn-connection*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AuthenticationType

ec2:DPDTimeoutSeconds

ec2:GatewayType

ec2:IKEVersions

ec2:InsideTunnelCidr

ec2:InsideTunnelIpv6Cidr

ec2:Phase1DHGroup

ec2:Phase1EncryptionAlgorithms

ec2:Phase1IntegrityAlgorithms

ec2:Phase1LifetimeSeconds

ec2:Phase2DHGroup

ec2:Phase2EncryptionAlgorithms

ec2:Phase2IntegrityAlgorithms

ec2:Phase2LifetimeSeconds

ec2:RekeyFuzzPercentage

ec2:RekeyMarginTimeSeconds

ec2:ReplayWindowSizePackets

ec2:ResourceTag/${TagKey}

ec2:RoutingType

ec2:Region

ModifyVpnConnectionOptions 准許修改連線 Site-to-Site的VPN連線選項 寫入

vpn-connection*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyVpnTunnelCertificate 准許修改VPN連線的憑證 Site-to-Site 寫入

vpn-connection*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ResourceTag/${TagKey}

ec2:Region

ModifyVpnTunnelOptions 准許修改VPN連線的選項 Site-to-Site 寫入

vpn-connection*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AuthenticationType

ec2:DPDTimeoutSeconds

ec2:GatewayType

ec2:IKEVersions

ec2:InsideTunnelCidr

ec2:InsideTunnelIpv6Cidr

ec2:Phase1DHGroup

ec2:Phase1EncryptionAlgorithms

ec2:Phase1IntegrityAlgorithms

ec2:Phase1LifetimeSeconds

ec2:Phase2DHGroup

ec2:Phase2EncryptionAlgorithms

ec2:Phase2IntegrityAlgorithms

ec2:Phase2LifetimeSeconds

ec2:RekeyFuzzPercentage

ec2:RekeyMarginTimeSeconds

ec2:ReplayWindowSizePackets

ec2:ResourceTag/${TagKey}

ec2:RoutingType

ec2:Region

MonitorInstances 准許對執行中執行個體啟用詳細監控 寫入

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

MoveAddressToVpc 准許將彈性 IP 地址從 EC2-Classic 平台移至 EC2-VPC 平台 寫入

ec2:Region

MoveByoipCidrToIpam 准許從公有IPv4集區BYOIPIPv4CIDR將 移至 Amazon VPC IP Address Manager (IPAM) 寫入

ipam-pool*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

MoveCapacityReservationInstances 准許將可用容量從來源容量保留移至目的地容量保留 寫入

capacity-reservation*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CapacityReservationFleet

ec2:CreateDate

ec2:DestinationCapacityReservationId

ec2:EbsOptimized

ec2:EndDate

ec2:EndDateType

ec2:InstanceCount

ec2:InstanceMatchCriteria

ec2:InstancePlatform

ec2:InstanceType

ec2:OutpostArn

ec2:PlacementGroup

ec2:ResourceTag/${TagKey}

ec2:SourceCapacityReservationId

ec2:Tenancy

ec2:Region

PauseVolumeIO [僅限許可] 准許暫時暫停目標 Amazon EBS磁碟區的 I/O 操作 寫入

volume*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:Encrypted

ec2:ManagedResourceOperator

ec2:ParentSnapshot

ec2:ResourceTag/${TagKey}

ec2:VolumeID

ec2:VolumeIops

ec2:VolumeSize

ec2:VolumeThroughput

ec2:VolumeType

instance

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

ProvisionByoipCidr 准許 AWS 透過自備 IP 地址 (BYOIP) 來佈建 中使用的地址範圍,並建立對應的地址集區 寫入

ec2:Region

ProvisionIpamByoasn 准許佈建自治系統編號 (ASN) 以供 Amazon Web Services 帳戶使用 寫入

ipam*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

ProvisionIpamPoolCidr 准許將 佈建CIDR至 Amazon VPC IP Address Manager (IPAM) 集區 寫入

ipam-pool*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ipam-external-resource-verification-token

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

ProvisionPublicIpv4PoolCidr 准許將 佈建CIDR至公有IPv4集區 寫入

ipam-pool*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ipv4pool-ec2*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

PurchaseCapacityBlock 准許購買容量區塊方案 寫入

capacity-reservation*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CapacityReservationFleet

ec2:CreateTags

ec2:Region

PurchaseCapacityBlockExtension 准許購買容量區塊延伸 寫入

capacity-reservation*

aws:ResourceTag/${TagKey}

ec2:CapacityReservationFleet

ec2:Region

PurchaseHostReservation 准許購買其組態符合專用主機組態的預留 寫入

dedicated-host*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:CreateTags

ec2:Region

PurchaseReservedInstancesOffering 准許購買預留執行個體產品 寫入

ec2:Region

PurchaseScheduledInstances 准許購買具有指定排程的一或多個排程執行個體 寫入

ec2:Region

PutResourcePolicy [僅限許可] 准許將啟用跨帳戶共用IAM的政策連接至資源 寫入

ipam-pool

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

placement-group

aws:ResourceTag/${TagKey}

ec2:PlacementGroupName

ec2:PlacementGroupStrategy

ec2:ResourceTag/${TagKey}

verified-access-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

RebootInstances 准許請求重新啟動一或多個執行個體 寫入

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

RegisterImage 准許註冊 Amazon Machine Image (AMI) 寫入

image*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:ImageID

ec2:Owner

ec2:CreateTags

snapshot

aws:ResourceTag/${TagKey}

ec2:OutpostArn

ec2:Owner

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:SnapshotID

ec2:SnapshotTime

ec2:SourceOutpostArn

ec2:VolumeSize

ec2:Region

RegisterInstanceEventNotificationAttributes 授予將標籤新增到要包含在您執行個體排程事件通知中標籤集合的許可 寫入

ec2:Region

RegisterTransitGatewayMulticastGroupMembers 准許將一或多個網路界面註冊為傳輸閘道多點傳送網域中群組 IP 地址的成員 寫入

network-interface*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

transit-gateway-multicast-domain*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayMulticastDomainId

ec2:Region

RegisterTransitGatewayMulticastGroupSources 准許將一或多個網路界面註冊為傳輸閘道多點傳送網域中群組 IP 地址的來源 寫入

network-interface*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

transit-gateway-multicast-domain*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayMulticastDomainId

ec2:Region

RejectCapacityReservationBillingOwnership 准許拒絕請求,以將共用容量預留的可用容量計費指派給您的帳戶 寫入

capacity-reservation*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CapacityReservationFleet

ec2:CreateDate

ec2:DestinationCapacityReservationId

ec2:EbsOptimized

ec2:EndDate

ec2:EndDateType

ec2:InstanceCount

ec2:InstanceMatchCriteria

ec2:InstancePlatform

ec2:InstanceType

ec2:OutpostArn

ec2:PlacementGroup

ec2:ResourceTag/${TagKey}

ec2:SourceCapacityReservationId

ec2:Tenancy

ec2:Region

RejectTransitGatewayMulticastDomainAssociations 准許拒絕將跨帳戶子網路與傳輸閘道多點傳送網域相關聯的請求 寫入

transit-gateway-attachment

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

transit-gateway-multicast-domain

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayMulticastDomainId

ec2:Region

RejectTransitGatewayPeeringAttachment 准許拒絕傳輸閘道對等附件請求 寫入

transit-gateway-attachment*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

ec2:Region

RejectTransitGatewayVpcAttachment 准許拒絕將 VPC 連接至傳輸閘道的請求 寫入

transit-gateway-attachment*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

ec2:Region

RejectVpcEndpointConnections 准許拒絕一或多個VPC端點對端點服務的VPC端點連線請求 寫入

vpc-endpoint-service*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:vpceMultiRegion

ec2:vpceSupportedRegion

ec2:Region

RejectVpcPeeringConnection 准許拒絕VPC對等互連連線請求 寫入

vpc-peering-connection*

aws:ResourceTag/${TagKey}

ec2:AccepterVpc

ec2:RequesterVpc

ec2:ResourceTag/${TagKey}

ec2:VpcPeeringConnectionID

ec2:Region

ReleaseAddress 准許釋出彈性 IP 地址 寫入

elastic-ip

aws:ResourceTag/${TagKey}

ec2:AllocationId

ec2:Domain

ec2:PublicIpAddress

ec2:ResourceTag/${TagKey}

ec2:Region

ReleaseHosts 准許釋出一或多個隨需專用主機 寫入

dedicated-host*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

ReleaseIpamPoolAllocation 准許在 Amazon VPC IP Address Manager (IPAM) 集區中釋出配置 寫入

ipam-pool*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

ReplaceIamInstanceProfileAssociation 准許取代IAM執行個體的執行個體設定檔 寫入

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:NewInstanceProfile

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

iam:PassRole

ec2:Region

ReplaceImageCriteriaInAllowedImagesSettings 准許在允許的映像設定中取代映像條件 寫入

ec2:Region

ReplaceNetworkAclAssociation 准許變更ACL子網路與哪個網路相關聯 寫入

network-acl*

aws:ResourceTag/${TagKey}

ec2:NetworkAclID

ec2:ResourceTag/${TagKey}

ec2:Vpc

subnet*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

ec2:Region

ReplaceNetworkAclEntry 准許取代網路中的項目 (規則) ACL 寫入

network-acl*

aws:ResourceTag/${TagKey}

ec2:NetworkAclID

ec2:ResourceTag/${TagKey}

ec2:Vpc

ec2:Region

ReplaceRoute 准許在 中取代路由表中的路由 VPC 寫入

route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:RouteTableID

ec2:Vpc

ec2:Region

ReplaceRouteTableAssociation 准許變更與子網路相關聯的路由表 寫入

route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:RouteTableID

ec2:Vpc

internet-gateway

aws:ResourceTag/${TagKey}

ec2:InternetGatewayID

ec2:ResourceTag/${TagKey}

ipv4pool-ec2

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ipv6pool-ec2

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

subnet

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

vpn-gateway

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

ReplaceTransitGatewayRoute 准許取代傳輸閘道路由表中的路由 寫入

transit-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableId

transit-gateway-attachment

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

ec2:Region

ReplaceVpnTunnel 准許取代VPN通道 寫入

vpn-connection*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

ReportInstanceStatus 准許提交有關執行個體狀態的意見回饋 寫入

ec2:Region

RequestSpotFleet 准許建立 Spot 機群請求 寫入

spot-fleet-request*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

image

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

key-pair

aws:ResourceTag/${TagKey}

ec2:KeyPairName

ec2:KeyPairType

ec2:ResourceTag/${TagKey}

launch-template

aws:ResourceTag/${TagKey}

ec2:ManagedResourceOperator

ec2:ResourceTag/${TagKey}

placement-group

aws:ResourceTag/${TagKey}

ec2:PlacementGroupName

ec2:PlacementGroupStrategy

ec2:ResourceTag/${TagKey}

security-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

snapshot

aws:ResourceTag/${TagKey}

ec2:OutpostArn

ec2:Owner

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:SnapshotID

ec2:SnapshotTime

ec2:SourceOutpostArn

ec2:VolumeSize

subnet

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

ec2:Region

RequestSpotInstances 准許建立 Spot 執行個體請求 寫入

spot-instances-request*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

iam:PassRole

image

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

key-pair

aws:ResourceTag/${TagKey}

ec2:KeyPairName

ec2:KeyPairType

ec2:ResourceTag/${TagKey}

network-interface

aws:ResourceTag/${TagKey}

ec2:AuthorizedUser

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:Permission

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

placement-group

aws:ResourceTag/${TagKey}

ec2:PlacementGroupName

ec2:PlacementGroupStrategy

ec2:ResourceTag/${TagKey}

security-group

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

snapshot

aws:ResourceTag/${TagKey}

ec2:OutpostArn

ec2:Owner

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:SnapshotID

ec2:SnapshotTime

ec2:SourceOutpostArn

ec2:VolumeSize

subnet

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

ec2:Region

ResetAddressAttribute 准許重設指定 IP 地址的屬性 寫入

elastic-ip*

aws:ResourceTag/${TagKey}

ec2:AllocationId

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Domain

ec2:PublicIpAddress

ec2:ResourceTag/${TagKey}

ec2:Region

ResetEbsDefaultKmsKeyId 准許重設預設客戶主金鑰 EBS (CMK),讓您的帳戶使用 AWS受管CMK的 EBS 寫入

ec2:Region

ResetFpgaImageAttribute 准許將 Amazon FPGA Image (AFI) 的屬性重設為其預設值 寫入

fpga-image*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:Region

ResetImageAttribute 准許將 Amazon Machine Image (AMI) 的屬性重設為其預設值 寫入

image*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Region

ResetInstanceAttribute 准許將執行個體的屬性重設為其預設值 寫入

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

ResetNetworkInterfaceAttribute 准許重設網路界面的屬性 寫入

network-interface*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

ec2:Region

ResetSnapshotAttribute 准許重設快照的許可設定 許可管理

snapshot*

aws:ResourceTag/${TagKey}

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Owner

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:SnapshotID

ec2:SnapshotTime

ec2:VolumeSize

ec2:Region

RestoreAddressToClassic 准許還原先前已移至 EC2-VPC 平台的彈性 IP 地址,並將其移回 EC2-Classic 平台 寫入

ec2:Region

RestoreImageFromRecycleBin 准許從資源回收筒還原 Amazon Machine Image (AMI) 寫入

image*

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Region

RestoreManagedPrefixListVersion 授予將項目從舊版受管的前綴清單還原至新版前綴清單的許可 寫入

prefix-list*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

RestoreSnapshotFromRecycleBin 准許從資源回收筒還原 Amazon EBS快照 寫入

snapshot*

aws:ResourceTag/${TagKey}

ec2:Encrypted

ec2:Owner

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:SnapshotID

ec2:SnapshotTime

ec2:VolumeSize

ec2:Region

RestoreSnapshotTier 准許還原封存的 Amazon EBS快照以暫時或永久使用,或修改先前暫時還原的快照的還原期間或還原類型 寫入

snapshot*

aws:ResourceTag/${TagKey}

ec2:Encrypted

ec2:Owner

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:SnapshotID

ec2:SnapshotTime

ec2:VolumeSize

ec2:Region

RevokeClientVpnIngress 准許從用戶端VPN端點移除傳入授權規則 寫入

client-vpn-endpoint*

aws:ResourceTag/${TagKey}

ec2:ClientRootCertificateChainArn

ec2:CloudwatchLogGroupArn

ec2:CloudwatchLogStreamArn

ec2:DirectoryArn

ec2:ResourceTag/${TagKey}

ec2:SamlProviderArn

ec2:ServerCertificateArn

ec2:Region

RevokeSecurityGroupEgress 准許從VPC安全群組移除一或多個傳出規則 寫入

security-group*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

ec2:Region

RevokeSecurityGroupIngress 准許從安全群組移除一或多個輸入規則 寫入

security-group*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

ec2:Region

RunInstances 准許啟動一或多個執行個體 寫入

image*

aws:ResourceTag/${TagKey}

ec2:ImageID

ec2:ImageType

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:Owner

ec2:Public

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:CreateTags

iam:PassRole

ssm:GetParameters

instance*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:RootDeviceType

ec2:Tenancy

network-interface*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:AssociatePublicIpAddress

ec2:AuthorizedService

ec2:AvailabilityZone

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:Subnet

ec2:Vpc

security-group*

aws:ResourceTag/${TagKey}

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

subnet*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

capacity-reservation

aws:ResourceTag/${TagKey}

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

elastic-gpu

aws:ResourceTag/${TagKey}

ec2:ElasticGpuType

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:ResourceTag/${TagKey}

elastic-inference

group

key-pair

aws:ResourceTag/${TagKey}

ec2:IsLaunchTemplateResource

ec2:KeyPairName

ec2:KeyPairType

ec2:LaunchTemplate

ec2:ResourceTag/${TagKey}

launch-template

aws:ResourceTag/${TagKey}

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:ManagedResourceOperator

ec2:ResourceTag/${TagKey}

license-configuration

placement-group

aws:ResourceTag/${TagKey}

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:PlacementGroupName

ec2:PlacementGroupStrategy

ec2:ResourceTag/${TagKey}

snapshot

aws:ResourceTag/${TagKey}

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:Owner

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:SnapshotID

ec2:SnapshotTime

ec2:VolumeSize

volume

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:AvailabilityZone

ec2:Encrypted

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:ManagedResourceOperator

ec2:ParentSnapshot

ec2:VolumeID

ec2:VolumeIops

ec2:VolumeSize

ec2:VolumeThroughput

ec2:VolumeType

ec2:Region

SCENARIO: EC2-Classic-EBS

image*

instance*

security-group*

volume*

key-pair

placement-group

snapshot

SCENARIO: EC2-Classic-InstanceStore

image*

instance*

security-group*

key-pair

placement-group

snapshot

SCENARIO: EC2-VPC-EBS

image*

instance*

network-interface*

security-group*

volume*

key-pair

placement-group

snapshot

SCENARIO: EC2-VPC-EBS-Subnet

image*

instance*

network-interface*

security-group*

subnet*

volume*

key-pair

placement-group

snapshot

SCENARIO: EC2-VPC-InstanceStore

image*

instance*

network-interface*

security-group*

key-pair

placement-group

snapshot

SCENARIO: EC2-VPC-InstanceStore-Subnet

image*

instance*

network-interface*

security-group*

subnet*

key-pair

placement-group

snapshot

RunScheduledInstances 准許啟動一或多個排程執行個體 寫入

ec2:Region

SearchLocalGatewayRoutes 准許在本機閘道路由表中搜尋路由 列出

local-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

SearchTransitGatewayMulticastGroups 准許搜尋傳輸閘道多點傳送網域中的群組、來源和成員 列出

transit-gateway-multicast-domain*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayMulticastDomainId

ec2:Region

SearchTransitGatewayRoutes 准許在傳輸閘道路由表中搜尋路由 清單

transit-gateway-route-table*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableId

ec2:Region

SendDiagnosticInterrupt 准許將診斷中斷傳送至 Amazon EC2執行個體 寫入

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

SendSpotInstanceInterruptions [僅限許可] 准許中斷 Spot 執行個體 寫入

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

StartDeclarativePoliciesReport 准許啟動宣告政策報告 讀取

ec2:Region

StartInstances 准許啟動已停止的執行個體 寫入

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

license-configuration

ec2:Region

StartNetworkInsightsAccessScopeAnalysis 准許啟動 Network Access Scope 分析 寫入

network-insights-access-scope*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:CreateTags

network-insights-access-scope-analysis*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:Region

StartNetworkInsightsAnalysis 准許開始分析指定路徑 寫入

network-insights-analysis*

aws:RequestTag/${TagKey}

aws:TagKeys

ec2:CreateTags

network-insights-path*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

StartVpcEndpointServicePrivateDnsVerification 准許啟動VPC端點服務的私有DNS驗證程序 寫入

vpc-endpoint-service*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:vpceMultiRegion

ec2:vpceSupportedRegion

ec2:Region

StopInstances 准許停止 Amazon EBS後端執行個體 寫入

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

TerminateClientVpnConnections 准許終止作用中的用戶端VPN端點連線 寫入

client-vpn-endpoint*

aws:ResourceTag/${TagKey}

ec2:ClientRootCertificateChainArn

ec2:CloudwatchLogGroupArn

ec2:CloudwatchLogStreamArn

ec2:DirectoryArn

ec2:ResourceTag/${TagKey}

ec2:SamlProviderArn

ec2:ServerCertificateArn

ec2:Region

TerminateInstances 准許關閉一或多個執行個體 寫入

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

UnassignIpv6Addresses 准許從網路介面取消指派一或多個IPv6地址 寫入

network-interface*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

ec2:Region

UnassignPrivateIpAddresses 准許從網路界面取消指派一或多個次要私有 IP 地址 寫入

network-interface*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

ec2:Region

UnassignPrivateNatGatewayAddress 准許從私有NAT閘道取消指派次要私有IPv4地址 寫入

natgateway*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:Region

UnlockSnapshot 准許在冷靜期解除鎖定以治理模式或合規模式鎖定的快照 寫入

snapshot*

aws:ResourceTag/${TagKey}

ec2:Encrypted

ec2:Owner

ec2:ParentVolume

ec2:ResourceTag/${TagKey}

ec2:SnapshotCoolOffPeriod

ec2:SnapshotID

ec2:SnapshotLockDuration

ec2:SnapshotTime

ec2:VolumeSize

ec2:Region

UnmonitorInstances 准許停用執行中執行個體的詳細監控 寫入

instance*

aws:ResourceTag/${TagKey}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:PlacementGroup

ec2:ProductCode

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

ec2:Region

UpdateSecurityGroupRuleDescriptionsEgress 准許更新VPC安全群組中一或多個傳出規則的描述 寫入

security-group*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

ec2:Region

UpdateSecurityGroupRuleDescriptionsIngress 准許更新安全群組中一或多個傳入規則的描述 寫入

security-group*

aws:ResourceTag/${TagKey}

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

ec2:Region

WithdrawByoipCidr 准許停止公告已佈建用於 的地址範圍, AWS 方法是攜帶您自己的 IP 地址 (BYOIP) 寫入

ec2:Region

Amazon 定義的資源類型 EC2

此服務會定義下列資源類型,並可用在 IAM 許可政策陳述式的 Resource 元素中。動作表格中的每個動作都代表可使用該動作指定的資源類型。資源類型也能定義您可以在政策中包含哪些條件索引鍵。這些索引鍵都會顯示在「資源類型」資料表的最後一欄。如需下表各欄的詳細資訊,請參閱資源類型資料表

資源類型 ARN 條件索引鍵
elastic-ip arn:${Partition}:ec2:${Region}:${Account}:elastic-ip/${AllocationId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:AllocationId

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Domain

ec2:PublicIpAddress

ec2:Region

ec2:ResourceTag/${TagKey}

capacity-reservation-fleet arn:${Partition}:ec2:${Region}:${Account}:capacity-reservation-fleet/${CapacityReservationFleetId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

capacity-reservation arn:${Partition}:ec2:${Region}:${Account}:capacity-reservation/${CapacityReservationId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:CapacityReservationFleet

ec2:CreateDate

ec2:DestinationCapacityReservationId

ec2:EbsOptimized

ec2:EndDate

ec2:EndDateType

ec2:InstanceCount

ec2:InstanceMatchCriteria

ec2:InstancePlatform

ec2:InstanceType

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:OutpostArn

ec2:PlacementGroup

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:SourceCapacityReservationId

ec2:Tenancy

carrier-gateway arn:${Partition}:ec2:${Region}:${Account}:carrier-gateway/${CarrierGatewayId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:Vpc

certificate arn:${Partition}:acm:${Region}:${Account}:certificate/${CertificateId}
client-vpn-endpoint arn:${Partition}:ec2:${Region}:${Account}:client-vpn-endpoint/${ClientVpnEndpointId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ClientRootCertificateChainArn

ec2:CloudwatchLogGroupArn

ec2:CloudwatchLogStreamArn

ec2:DirectoryArn

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:SamlProviderArn

ec2:ServerCertificateArn

customer-gateway arn:${Partition}:ec2:${Region}:${Account}:customer-gateway/${CustomerGatewayId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

declarative-policies-report arn:${Partition}:ec2:${Region}:${Account}:declarative-policies-report/${DeclarativePoliciesReportId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

dedicated-host arn:${Partition}:ec2:${Region}:${Account}:dedicated-host/${DedicatedHostId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AutoPlacement

ec2:AvailabilityZone

ec2:HostRecovery

ec2:InstanceType

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:Quantity

ec2:Region

ec2:ResourceTag/${TagKey}

dhcp-options arn:${Partition}:ec2:${Region}:${Account}:dhcp-options/${DhcpOptionsId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:DhcpOptionsID

ec2:Region

ec2:ResourceTag/${TagKey}

egress-only-internet-gateway arn:${Partition}:ec2:${Region}:${Account}:egress-only-internet-gateway/${EgressOnlyInternetGatewayId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

elastic-gpu arn:${Partition}:ec2:${Region}:${Account}:elastic-gpu/${ElasticGpuId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:ElasticGpuType

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:Region

ec2:ResourceTag/${TagKey}

elastic-inference arn:${Partition}:elastic-inference:${Region}:${Account}:elastic-inference-accelerator/${AcceleratorId}
export-image-task arn:${Partition}:ec2:${Region}:${Account}:export-image-task/${ExportImageTaskId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

export-instance-task arn:${Partition}:ec2:${Region}:${Account}:export-instance-task/${ExportTaskId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

fleet arn:${Partition}:ec2:${Region}:${Account}:fleet/${FleetId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

fpga-image arn:${Partition}:ec2:${Region}:${Account}:fpga-image/${FpgaImageId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Owner

ec2:Public

ec2:Region

ec2:ResourceTag/${TagKey}

host-reservation arn:${Partition}:ec2:${Region}:${Account}:host-reservation/${HostReservationId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

image arn:${Partition}:ec2:${Region}::image/${ImageId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:ImageID

ec2:ImageType

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:Owner

ec2:Public

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

import-image-task arn:${Partition}:ec2:${Region}:${Account}:import-image-task/${ImportImageTaskId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

import-snapshot-task arn:${Partition}:ec2:${Region}:${Account}:import-snapshot-task/${ImportSnapshotTaskId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

instance-connect-endpoint arn:${Partition}:ec2:${Region}:${Account}:instance-connect-endpoint/${InstanceConnectEndpointId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:SubnetID

instance-event-window arn:${Partition}:ec2:${Region}:${Account}:instance-event-window/${InstanceEventWindowId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

instance arn:${Partition}:ec2:${Region}:${Account}:instance/${InstanceId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:CpuOptionsAmdSevSnp

ec2:EbsOptimized

ec2:InstanceAutoRecovery

ec2:InstanceID

ec2:InstanceMarketType

ec2:InstanceMetadataTags

ec2:InstanceProfile

ec2:InstanceType

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:ManagedResourceOperator

ec2:MetadataHttpEndpoint

ec2:MetadataHttpPutResponseHopLimit

ec2:MetadataHttpTokens

ec2:NewInstanceProfile

ec2:PlacementGroup

ec2:ProductCode

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:RootDeviceType

ec2:Tenancy

internet-gateway arn:${Partition}:ec2:${Region}:${Account}:internet-gateway/${InternetGatewayId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:InternetGatewayID

ec2:Region

ec2:ResourceTag/${TagKey}

ipam-external-resource-verification-token arn:${Partition}:ec2::${Account}:ipam-external-resource-verification-token/${IpamExternalResourceVerificationTokenId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

ipam arn:${Partition}:ec2::${Account}:ipam/${IpamId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

ipam-pool arn:${Partition}:ec2::${Account}:ipam-pool/${IpamPoolId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

ipam-resource-discovery-association arn:${Partition}:ec2::${Account}:ipam-resource-discovery-association/${IpamResourceDiscoveryAssociationId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

ipam-resource-discovery arn:${Partition}:ec2::${Account}:ipam-resource-discovery/${IpamResourceDiscoveryId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

ipam-scope arn:${Partition}:ec2::${Account}:ipam-scope/${IpamScopeId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

coip-pool arn:${Partition}:ec2:${Region}:${Account}:coip-pool/${Ipv4PoolCoipId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

ipv4pool-ec2 arn:${Partition}:ec2:${Region}:${Account}:ipv4pool-ec2/${Ipv4PoolEc2Id}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

ipv6pool-ec2 arn:${Partition}:ec2:${Region}:${Account}:ipv6pool-ec2/${Ipv6PoolEc2Id}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

key-pair arn:${Partition}:ec2:${Region}:${Account}:key-pair/${KeyPairName}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:IsLaunchTemplateResource

ec2:KeyPairName

ec2:KeyPairType

ec2:LaunchTemplate

ec2:Region

ec2:ResourceTag/${TagKey}

launch-template arn:${Partition}:ec2:${Region}:${Account}:launch-template/${LaunchTemplateId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:ManagedResourceOperator

ec2:Region

ec2:ResourceTag/${TagKey}

license-configuration arn:${Partition}:license-manager:${Region}:${Account}:license-configuration:${LicenseConfigurationId}
local-gateway arn:${Partition}:ec2:${Region}:${Account}:local-gateway/${LocalGatewayId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

local-gateway-route-table-virtual-interface-group-association arn:${Partition}:ec2:${Region}:${Account}:local-gateway-route-table-virtual-interface-group-association/${LocalGatewayRouteTableVirtualInterfaceGroupAssociationId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

local-gateway-route-table-vpc-association arn:${Partition}:ec2:${Region}:${Account}:local-gateway-route-table-vpc-association/${LocalGatewayRouteTableVpcAssociationId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

local-gateway-route-table arn:${Partition}:ec2:${Region}:${Account}:local-gateway-route-table/${LocalGatewayRoutetableId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

local-gateway-virtual-interface-group arn:${Partition}:ec2:${Region}:${Account}:local-gateway-virtual-interface-group/${LocalGatewayVirtualInterfaceGroupId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

local-gateway-virtual-interface arn:${Partition}:ec2:${Region}:${Account}:local-gateway-virtual-interface/${LocalGatewayVirtualInterfaceId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

natgateway arn:${Partition}:ec2:${Region}:${Account}:natgateway/${NatGatewayId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

network-acl arn:${Partition}:ec2:${Region}:${Account}:network-acl/${NaclId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:NetworkAclID

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:Vpc

network-insights-access-scope-analysis arn:${Partition}:ec2:${Region}:${Account}:network-insights-access-scope-analysis/${NetworkInsightsAccessScopeAnalysisId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

network-insights-access-scope arn:${Partition}:ec2:${Region}:${Account}:network-insights-access-scope/${NetworkInsightsAccessScopeId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

network-insights-analysis arn:${Partition}:ec2:${Region}:${Account}:network-insights-analysis/${NetworkInsightsAnalysisId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

network-insights-path arn:${Partition}:ec2:${Region}:${Account}:network-insights-path/${NetworkInsightsPathId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

network-interface arn:${Partition}:ec2:${Region}:${Account}:network-interface/${NetworkInterfaceId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:AssociatePublicIpAddress

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AuthorizedService

ec2:AuthorizedUser

ec2:AvailabilityZone

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:ManagedResourceOperator

ec2:NetworkInterfaceID

ec2:Permission

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:Subnet

ec2:Vpc

placement-group arn:${Partition}:ec2:${Region}:${Account}:placement-group/${PlacementGroupName}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:PlacementGroupName

ec2:PlacementGroupStrategy

ec2:Region

ec2:ResourceTag/${TagKey}

prefix-list arn:${Partition}:ec2:${Region}:${Account}:prefix-list/${PrefixListId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

replace-root-volume-task arn:${Partition}:ec2:${Region}:${Account}:replace-root-volume-task/${ReplaceRootVolumeTaskId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

reserved-instances arn:${Partition}:ec2:${Region}:${Account}:reserved-instances/${ReservationId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:InstanceType

ec2:Region

ec2:ReservedInstancesOfferingType

ec2:ResourceTag/${TagKey}

ec2:Tenancy

group arn:${Partition}:resource-groups:${Region}:${Account}:group/${GroupName}
role arn:${Partition}:iam::${Account}:role/${RoleNameWithPath}
route-table arn:${Partition}:ec2:${Region}:${Account}:route-table/${RouteTableId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:RouteTableID

ec2:Vpc

security-group arn:${Partition}:ec2:${Region}:${Account}:security-group/${SecurityGroupId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:SecurityGroupID

ec2:Vpc

security-group-rule arn:${Partition}:ec2:${Region}:${Account}:security-group-rule/${SecurityGroupRuleId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

snapshot arn:${Partition}:ec2:${Region}::snapshot/${SnapshotId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Add/group

ec2:Add/userId

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:Encrypted

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:OutpostArn

ec2:Owner

ec2:ParentVolume

ec2:Region

ec2:Remove/group

ec2:Remove/userId

ec2:ResourceTag/${TagKey}

ec2:SnapshotCoolOffPeriod

ec2:SnapshotID

ec2:SnapshotLockDuration

ec2:SnapshotTime

ec2:SourceOutpostArn

ec2:VolumeSize

spot-fleet-request arn:${Partition}:ec2:${Region}:${Account}:spot-fleet-request/${SpotFleetRequestId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

spot-instances-request arn:${Partition}:ec2:${Region}:${Account}:spot-instances-request/${SpotInstanceRequestId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

subnet-cidr-reservation arn:${Partition}:ec2:${Region}:${Account}:subnet-cidr-reservation/${SubnetCidrReservationId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

subnet arn:${Partition}:ec2:${Region}:${Account}:subnet/${SubnetId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:IsLaunchTemplateResource

ec2:LaunchTemplate

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:SubnetID

ec2:Vpc

traffic-mirror-filter arn:${Partition}:ec2:${Region}:${Account}:traffic-mirror-filter/${TrafficMirrorFilterId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

traffic-mirror-filter-rule arn:${Partition}:ec2:${Region}:${Account}:traffic-mirror-filter-rule/${TrafficMirrorFilterRuleId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

traffic-mirror-session arn:${Partition}:ec2:${Region}:${Account}:traffic-mirror-session/${TrafficMirrorSessionId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

traffic-mirror-target arn:${Partition}:ec2:${Region}:${Account}:traffic-mirror-target/${TrafficMirrorTargetId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

transit-gateway-attachment arn:${Partition}:ec2:${Region}:${Account}:transit-gateway-attachment/${TransitGatewayAttachmentId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:transitGatewayAttachmentId

transit-gateway-connect-peer arn:${Partition}:ec2:${Region}:${Account}:transit-gateway-connect-peer/${TransitGatewayConnectPeerId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:transitGatewayConnectPeerId

transit-gateway arn:${Partition}:ec2:${Region}:${Account}:transit-gateway/${TransitGatewayId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:transitGatewayId

transit-gateway-multicast-domain arn:${Partition}:ec2:${Region}:${Account}:transit-gateway-multicast-domain/${TransitGatewayMulticastDomainId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:transitGatewayMulticastDomainId

transit-gateway-policy-table arn:${Partition}:ec2:${Region}:${Account}:transit-gateway-policy-table/${TransitGatewayPolicyTableId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:transitGatewayPolicyTableId

transit-gateway-route-table-announcement arn:${Partition}:ec2:${Region}:${Account}:transit-gateway-route-table-announcement/${TransitGatewayRouteTableAnnouncementId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableAnnouncementId

transit-gateway-route-table arn:${Partition}:ec2:${Region}:${Account}:transit-gateway-route-table/${TransitGatewayRouteTableId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:transitGatewayRouteTableId

verified-access-endpoint arn:${Partition}:ec2:${Region}:${Account}:verified-access-endpoint/${VerifiedAccessEndpointId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

verified-access-endpoint-target arn:${Partition}:ec2:${Region}:${Account}:verified-access-endpoint-target/${VerifiedAccessEndpointTargetId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

verified-access-group arn:${Partition}:ec2:${Region}:${Account}:verified-access-group/${VerifiedAccessGroupId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

verified-access-instance arn:${Partition}:ec2:${Region}:${Account}:verified-access-instance/${VerifiedAccessInstanceId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

verified-access-policy arn:${Partition}:ec2:${Region}:${Account}:verified-access-policy/${VerifiedAccessPolicyId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

verified-access-trust-provider arn:${Partition}:ec2:${Region}:${Account}:verified-access-trust-provider/${VerifiedAccessTrustProviderId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

volume arn:${Partition}:ec2:${Region}:${Account}:volume/${VolumeId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AvailabilityZone

ec2:Encrypted

ec2:IsLaunchTemplateResource

ec2:KmsKeyId

ec2:LaunchTemplate

ec2:ManagedResourceOperator

ec2:ParentSnapshot

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:VolumeID

ec2:VolumeIops

ec2:VolumeSize

ec2:VolumeThroughput

ec2:VolumeType

vpc-block-public-access-exclusion arn:${Partition}:ec2:${Region}:${Account}:vpc-block-public-access-exclusion/${VpcBlockPublicAccessExclusionId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

vpc-endpoint-connection arn:${Partition}:ec2:${Region}:${Account}:vpc-endpoint-connection/${VpcEndpointConnectionId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

vpc-endpoint arn:${Partition}:ec2:${Region}:${Account}:vpc-endpoint/${VpcEndpointId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:VpceServiceName

ec2:VpceServiceOwner

vpc-endpoint-service arn:${Partition}:ec2:${Region}:${Account}:vpc-endpoint-service/${VpcEndpointServiceId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:VpceServicePrivateDnsName

ec2:vpceMultiRegion

ec2:vpceServiceRegion

ec2:vpceSupportedRegion

vpc-endpoint-service-permission arn:${Partition}:ec2:${Region}:${Account}:vpc-endpoint-service-permission/${VpcEndpointServicePermissionId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

vpc-flow-log arn:${Partition}:ec2:${Region}:${Account}:vpc-flow-log/${VpcFlowLogId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

vpc arn:${Partition}:ec2:${Region}:${Account}:vpc/${VpcId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Ipv4IpamPoolId

ec2:Ipv6IpamPoolId

ec2:Region

ec2:ResourceTag/${TagKey}

ec2:Tenancy

ec2:VpcID

vpc-peering-connection arn:${Partition}:ec2:${Region}:${Account}:vpc-peering-connection/${VpcPeeringConnectionId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:AccepterVpc

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:Region

ec2:RequesterVpc

ec2:ResourceTag/${TagKey}

ec2:VpcPeeringConnectionID

vpn-connection-device-type arn:${Partition}:ec2:${Region}:${Account}:vpn-connection-device-type/${VpnConnectionDeviceTypeId}

ec2:Region

vpn-connection arn:${Partition}:ec2:${Region}:${Account}:vpn-connection/${VpnConnectionId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Attribute

ec2:Attribute/${AttributeName}

ec2:AuthenticationType

ec2:DPDTimeoutSeconds

ec2:GatewayType

ec2:IKEVersions

ec2:InsideTunnelCidr

ec2:InsideTunnelIpv6Cidr

ec2:Phase1DHGroup

ec2:Phase1EncryptionAlgorithms

ec2:Phase1IntegrityAlgorithms

ec2:Phase1LifetimeSeconds

ec2:Phase2DHGroup

ec2:Phase2EncryptionAlgorithms

ec2:Phase2IntegrityAlgorithms

ec2:Phase2LifetimeSeconds

ec2:Region

ec2:RekeyFuzzPercentage

ec2:RekeyMarginTimeSeconds

ec2:ReplayWindowSizePackets

ec2:ResourceTag/${TagKey}

ec2:RoutingType

vpn-gateway arn:${Partition}:ec2:${Region}:${Account}:vpn-gateway/${VpnGatewayId}

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

ec2:Region

ec2:ResourceTag/${TagKey}

Amazon 的條件索引鍵 EC2

Amazon EC2定義下列條件索引鍵,可用於 IAM政策的 Condition元素。您可以使用這些索引鍵來縮小套用政策陳述式的條件。如需下表各欄的詳細資訊,請參閱條件索引鍵表

若要檢視所有服務都可使用的全域條件鍵,請參閱可用全域條件鍵

條件索引鍵 描述 類型
aws:RequestTag/${TagKey} 依在請求中允許的標籤索引鍵和值對篩選存取 字串
aws:ResourceTag/${TagKey} 依資源的標籤索引鍵和值對篩選存取 字串
aws:TagKeys 依在請求中允許的標籤索引鍵清單篩選存取 ArrayOfString
ec2:AccepterVpc 依VPC對等連線VPC中接受者 ARN 的 篩選存取權 ARN
ec2:Add/group 依新增至快照的群組篩選存取權 字串
ec2:Add/userId 依新增至快照的帳戶 ID 篩選存取權 字串
ec2:AllocationId 依彈性 IP 地址的配置 ID 篩選存取 字串
ec2:AssociatePublicIpAddress 根據使用者是否要將公有 IP 地址與執行個體建立關聯來篩選存取 Bool
ec2:Attribute 依資源的屬性篩選存取權 字串
ec2:Attribute/${AttributeName} 依資源上設定的屬性篩選存取 字串
ec2:AuthenticationType 依VPN通道端點的身分驗證類型篩選存取權 字串
ec2:AuthorizedService 依具有資源使用許可 AWS 的服務篩選存取權 字串
ec2:AuthorizedUser 依具有資源使用許可的IAM主體篩選存取權 字串
ec2:AutoPlacement 依專用主機的自動置放屬性篩選存取 字串
ec2:AvailabilityZone 依 中的可用區域名稱篩選存取權 AWS 區域 字串
ec2:CapacityReservationFleet 依容量保留機群ARN的 篩選存取權 ARN
ec2:ClientRootCertificateChainArn 依用戶端根憑證鏈ARN的 篩選存取權 ARN
ec2:CloudwatchLogGroupArn 依 CloudWatch Logs 日誌群組ARN的 篩選存取權 ARN
ec2:CloudwatchLogStreamArn 依 CloudWatch Logs 日誌串流ARN的 篩選存取權 ARN
ec2:CpuOptionsAmdSevSnp 依 SEV- AMD SNP CPU選項的狀態篩選存取權。目前僅支援美國東部 (俄亥俄) 和歐洲 (愛爾蘭) 字串
ec2:CreateAction 依資源建立API動作的名稱篩選存取權 字串
ec2:CreateDate 依容量預留建立的日期和時間篩選存取權 日期
ec2:DPDTimeoutSeconds 依VPN通道發生DPD逾時後的持續時間篩選存取權 數值
ec2:DestinationCapacityReservationId 依您要將容量移入的容量保留 ID 篩選存取權 ARN
ec2:DhcpOptionsID 依動態主機組態通訊協定 (DHCP) 選項集的 ID 篩選存取權 字串
ec2:DirectoryArn 依目錄ARN的 篩選存取權 ARN
ec2:Domain 根據彈性 IP 地址的網域篩選存取權 字串
ec2:EbsOptimized 依執行個體是否已啟用EBS最佳化來篩選存取權 Bool
ec2:ElasticGpuType 依 Elastic Graphics 加速器的類型篩選存取 字串
ec2:Encrypted 依EBS磁碟區是否已加密來篩選存取權 Bool
ec2:EndDate 依容量預留結束的日期和時間篩選存取權 日期
ec2:EndDateType 依容量保留結束的方式篩選存取權 字串
ec2:FisActionId 依動作 AWS FIS的 ID 篩選存取權 字串
ec2:FisTargetArns 依目標ARN的 AWS FIS 篩選存取權 ArrayOfARN
ec2:GatewayType 依VPN連線 AWS 端VPN端點的閘道類型篩選存取權 字串
ec2:HostRecovery 依專用主機是否啟用主機復原篩選存取 字串
ec2:IKEVersions 依允許用於VPN通道的網際網路金鑰交換 (IKE) 版本篩選存取權 ArrayOfString
ec2:ImageID 依映像的 ID 篩選存取 字串
ec2:ImageType 依映像類型 (機器、aki 或 ari) 篩選存取 字串
ec2:InsideTunnelCidr 依VPN通道的內部 IP 地址範圍篩選存取權 字串
ec2:InsideTunnelIpv6Cidr 依VPN通道的內部IPv6地址範圍篩選存取權 字串
ec2:InstanceAutoRecovery 依執行個體類型是否支援自動復原篩選存取權 字串
ec2:InstanceCount 依執行個體數量篩選存取權 數值
ec2:InstanceID 依執行個體的 ID 篩選存取權 字串
ec2:InstanceMarketType 依執行個體的市場或購買選項 (容量區塊、隨需或 Spot) 篩選存取權 字串
ec2:InstanceMatchCriteria 依容量預留接受的執行個體啟動類型篩選存取權 字串
ec2:InstanceMetadataTags 依執行個體是否允許從執行個體中繼資料存取執行個體標籤篩選存取權 字串
ec2:InstancePlatform 依容量預留保留容量的作業系統類型篩選存取權 ARN
ec2:InstanceProfile 依執行個體設定檔ARN的 篩選存取權 ARN
ec2:InstanceType 依執行個體的類型篩選存取 字串
ec2:InternetGatewayID 依網際網路閘道的 ID 篩選存取權 字串
ec2:Ipv4IpamPoolId 依提供區塊IPv4CIDR配置的IPAM集區 ID 篩選存取權 字串
ec2:Ipv6IpamPoolId 依提供區塊IPv6CIDR配置的IPAM集區 ID 篩選存取權 字串
ec2:IsLaunchTemplateResource 依使用者是否能夠覆寫啟動範本中指定的資源篩選存取 Bool
ec2:KeyPairName 根據金鑰對名稱篩選存取權 字串
ec2:KeyPairType 根據金鑰對類型篩選存取權 字串
ec2:KmsKeyId 依請求中提供的金鑰 ID AWS KMS 篩選存取權 字串
ec2:LaunchTemplate 依啟動範本ARN的 篩選存取權 ARN
ec2:ManagedResourceOperator 依EC2操作員是否存在佈建受管資源來篩選存取權 字串
ec2:MetadataHttpEndpoint 依是否針對執行個體中繼資料服務啟用HTTP端點來篩選存取權 字串
ec2:MetadataHttpPutResponseHopLimit 依呼叫執行個體中繼資料服務時允許的躍點數篩選存取 數值
ec2:MetadataHttpTokens 依呼叫執行個體中繼資料服務時所需的字符篩選存取 (選用或必需) 字串
ec2:NetworkAclID 依網路存取控制清單的 ID 篩選存取權 (ACL) 字串
ec2:NetworkInterfaceID 依彈性網絡介面的 ID 篩選存取權 字串
ec2:NewInstanceProfile 依要連接之執行個體描述檔ARN的 篩選存取權 ARN
ec2:OutpostArn 依 Outpost ARN的 篩選存取權 ARN
ec2:Owner 依資源擁有者 (amazon、aws-marketplace 或 AWS 帳戶 ID) 篩選存取權 字串
ec2:ParentSnapshot 依父系快照ARN的 篩選存取權 ARN
ec2:ParentVolume 依建立快照ARN的父磁碟區的 篩選存取權 ARN
ec2:Permission 依資源的許可類型篩選存取權 (INSTANCE-ATTACH 或 EIP-ASSOCIATE) 字串
ec2:Phase1DHGroup 依 Diffie-Hellman 群組號碼篩選存取,該號碼允許用於階段 1 IKE交涉的VPN通道 ArrayOfString
ec2:Phase1EncryptionAlgorithms 依階段 1 IKE交涉中VPN通道允許的加密演算法篩選存取權 ArrayOfString
ec2:Phase1IntegrityAlgorithms 依第 1 階段IKE交涉所允許VPN通道的完整性演算法篩選存取權 ArrayOfString
ec2:Phase1LifetimeSeconds 針對VPN通道交IKE涉的第 1 階段,依生命週期篩選存取權,以秒為單位 數值
ec2:Phase2DHGroup 依 Diffie-Hellman 群組號碼篩選存取,該號碼允許用於階段 2 IKE交涉的VPN通道 ArrayOfString
ec2:Phase2EncryptionAlgorithms 依第 2 階段IKE交涉所允許VPN通道的加密演算法篩選存取權 ArrayOfString
ec2:Phase2IntegrityAlgorithms 依第 2 階段IKE交涉所允許VPN通道的完整性演算法篩選存取權 ArrayOfString
ec2:Phase2LifetimeSeconds 針對VPN通道交IKE涉的第 2 階段,依生命週期篩選存取權,以秒為單位 數值
ec2:PlacementGroup 依置放群組ARN的 篩選存取權 ARN
ec2:PlacementGroupName 依置放群組的名稱篩選存取權 字串
ec2:PlacementGroupStrategy 依置放群組 (叢集、分散或分區) 所使用的執行個體置放策略篩選存取 字串
ec2:ProductCode 依與 相關聯的產品碼篩選存取權 AMI 字串
ec2:Public 依映像是否具有公有啟動許可篩選存取 Bool
ec2:PublicIpAddress 根據公有 IP 地址篩選存取權 字串
ec2:Quantity 依請求中的專用主機數目篩選存取 數值
ec2:Region 依 的名稱篩選存取權 AWS 區域 字串
ec2:RekeyFuzzPercentage 依重新輸入時段的增加百分比 (由重新輸入邊界時間決定) 篩選存取權,其中VPN通道隨機選取重新輸入時間 數值
ec2:RekeyMarginTimeSeconds 依VPN通道的階段 2 生命週期到期前的邊界時間篩選存取權 數值
ec2:Remove/group 依從快照移除的群組篩選存取權 字串
ec2:Remove/userId 依從快照移除的帳戶 ID 篩選存取權 字串
ec2:ReplayWindowSizePackets 依IKE重播視窗中的封包數量篩選存取權 字串
ec2:RequesterVpc 依VPC對等連線VPC中ARN請求者的 篩選存取權 ARN
ec2:ReservedInstancesOfferingType 依預留執行個體產品的付款選項 (無預付、部分預付或全部預付) 篩選存取 字串
ec2:ResourceTag/${TagKey} 依資源的標籤索引鍵和值對篩選存取 字串
ec2:RoleDelivery 依執行個體中繼資料服務的版本篩選存取權,以擷取 IAM的角色登入資料 EC2 數值
ec2:RootDeviceType 依執行個體的根裝置類型 (ebs 或 instance-store) 篩選存取 字串
ec2:RouteTableID 依路由表的 ID 篩選存取權 字串
ec2:RoutingType 依VPN連線的路由類型篩選存取權 字串
ec2:SamlProviderArn 依IAMSAML身分提供者ARN的 篩選存取權 ARN
ec2:SecurityGroupID 依安全群組的 ID 篩選存取權 字串
ec2:ServerCertificateArn 依伺服器憑證ARN的 篩選存取權 ARN
ec2:SnapshotCoolOffPeriod 依合規模式冷靜期篩選存取權 數值
ec2:SnapshotID 依快照的 ID 篩選存取權 字串
ec2:SnapshotLockDuration 依快照鎖定期間篩選存取權 數值
ec2:SnapshotTime 依快照的啟動時間篩選存取 字串
ec2:SourceCapacityReservationId 依您要從中移動容量的容量預留 ID 篩選存取權 ARN
ec2:SourceInstanceARN 依發出請求之執行個體ARN的 篩選存取權 ARN
ec2:SourceOutpostArn 依發出請求ARN的 Outpost 的 篩選存取權 ARN
ec2:Subnet 依子網路ARN的 篩選存取權 ARN
ec2:SubnetID 依子網路的 ID 篩選存取權 字串
ec2:Tenancy 依 VPC或 執行個體的租用 (預設、專用或主機) 篩選存取權 字串
ec2:VolumeID 依磁碟區的 ID 篩選存取權 字串
ec2:VolumeIops 依為磁碟區佈建的每秒輸入/輸出操作數 (IOPS) 篩選存取權 數值
ec2:VolumeSize 依磁碟區的大小 (以 GiB 為單位) 篩選存取權 數值
ec2:VolumeThroughput 依磁碟區的輸送量篩選存取權,位於 MiBps 數值
ec2:VolumeType 依磁碟區的類型 (gp2、gp3、io1、io2、st1、sc1 或 Standard) 篩選存取權 字串
ec2:Vpc 依 ARN的 篩選存取權 VPC ARN
ec2:VpcID 依虛擬私有雲端的 ID 篩選存取權 (VPC) 字串
ec2:VpcPeeringConnectionID 依VPC對等連線的 ID 篩選存取權 字串
ec2:VpceServiceName 依VPC端點服務的名稱篩選存取權 字串
ec2:VpceServiceOwner 依VPC端點服務的服務擁有者 (amazon、aws-marketplace 或 AWS 帳戶 ID) 篩選存取權 字串
ec2:VpceServicePrivateDnsName 依VPC端點服務的私有DNS名稱篩選存取權 字串
ec2:transitGatewayAttachmentId 依傳輸閘道連接的 ID 篩選存取權 字串
ec2:transitGatewayConnectPeerId 依傳輸閘道連線對等的 ID 篩選存取權 字串
ec2:transitGatewayId 依傳輸閘道的 ID 篩選存取權 字串
ec2:transitGatewayMulticastDomainId 依傳輸閘道多點傳送網域的 ID 篩選存取權 字串
ec2:transitGatewayPolicyTableId 依傳輸閘道政策表的 ID 篩選存取權 字串
ec2:transitGatewayRouteTableAnnouncementId 依傳輸閘道路由表公告的 ID 篩選存取權 字串
ec2:transitGatewayRouteTableId 依傳輸閘道路由表的 ID 篩選存取權 字串
ec2:vpceMultiRegion 依VPC端點服務的多區域篩選存取權 字串
ec2:vpceServiceRegion 依VPC端點服務的區域篩選存取權 字串
ec2:vpceSupportedRegion 依VPC端點服務的支援區域篩選存取權 字串