Amazon Web Services

Información general

Conecta Amazon Web Services (AWS) para:

  • Consulta de las actualizaciones automáticas del estado de AWS en tu Explorador de eventos
  • Obtener las métricas de CloudWatch de los hosts EC2 sin necesidad de instalar el Agent
  • Etiquetar tus hosts EC2 con información concreta sobre EC2
  • Ver los eventos de mantenimiento programados de EC2 en tu flujo (stream)
  • Recopilar las métricas y eventos de CloudWatch de muchos otros productos de AWS
  • Consulta de las alarmas de CloudWatch en tu Explorador de eventos

Para empezar a utilizar la integración de AWS cuanto antes, consulta la guía sobre cómo empezar con AWS.

La integración Amazon Web Services de Datadog recopila logs, eventos y la mayoría de las métricas de CloudWatch para más de 90 servicios AWS.

Configurar

Usa uno de los siguientes métodos para integrar tus cuentas de AWS en Datadog con el fin de recopilar métricas, eventos, etiquetas y logs.

Automático

Manual

  • Delegación de roles Para configurar manualmente la integración AWS con delegación de roles, consulta la guía de configuración manual.

  • Claves de acceso (sólo GovCloud o China) Para configurar la integración de AWS con las claves de acceso, consulta la guía de configuración manual.

    * Cualquier uso de los servicios Datadog en China continental (o relacionados con entornos de esta localización) está sujeto a la cláusula de exención de responsabilidad, publicada en la sección Localizaciones con restricciones de servicio de nuestro sitio web.

AWS IAM permissions

AWS IAM permissions enable Datadog to collect metrics, tags, EventBridge events and other data necessary to monitor your AWS environment. To correctly set up the AWS Integration, you must attach the relevant IAM policies to the Datadog AWS Integration IAM Role in your AWS account.

AWS integration IAM policy

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Action": [
        "account:GetAccountInformation",
        "airflow:GetEnvironment",
        "airflow:ListEnvironments",
        "apigateway:GET",
        "appsync:ListGraphqlApis",
        "autoscaling:Describe*",
        "backup:List*",
        "batch:DescribeJobDefinitions",
        "batch:DescribeJobQueues",
        "batch:DescribeJobs",
        "batch:ListJobs",
        "bcm-data-exports:GetExport",
        "bcm-data-exports:ListExports",
        "budgets:ViewBudget",
        "cloudfront:GetDistributionConfig",
        "cloudfront:ListDistributions",
        "cloudtrail:DescribeTrails",
        "cloudtrail:GetTrail",
        "cloudtrail:GetTrailStatus",
        "cloudtrail:ListTrails",
        "cloudtrail:LookupEvents",
        "cloudwatch:Describe*",
        "cloudwatch:Get*",
        "cloudwatch:List*",
        "codebuild:BatchGetProjects",
        "codebuild:ListProjects",
        "codedeploy:BatchGet*",
        "codedeploy:List*",
        "cur:DescribeReportDefinitions",
        "directconnect:Describe*",
        "dms:DescribeReplicationInstances",
        "dynamodb:Describe*",
        "dynamodb:List*",
        "ec2:Describe*",
        "ecs:Describe*",
        "ecs:List*",
        "eks:DescribeCluster",
        "eks:ListClusters",
        "elasticache:Describe*",
        "elasticache:List*",
        "elasticfilesystem:DescribeAccessPoints",
        "elasticfilesystem:DescribeFileSystems",
        "elasticfilesystem:DescribeTags",
        "elasticloadbalancing:Describe*",
        "elasticmapreduce:Describe*",
        "elasticmapreduce:List*",
        "es:DescribeElasticsearchDomains",
        "es:ListDomainNames",
        "es:ListTags",
        "events:CreateEventBus",
        "fsx:DescribeFileSystems",
        "fsx:ListTagsForResource",
        "health:DescribeAffectedEntities",
        "health:DescribeEventDetails",
        "health:DescribeEvents",
        "iam:ListAccountAliases",
        "kinesis:Describe*",
        "kinesis:List*",
        "lambda:List*",
        "logs:DeleteSubscriptionFilter",
        "logs:DescribeDeliveries",
        "logs:DescribeDeliverySources",
        "logs:DescribeLogGroups",
        "logs:DescribeLogStreams",
        "logs:DescribeSubscriptionFilters",
        "logs:FilterLogEvents",
        "logs:GetDeliveryDestination",
        "logs:PutSubscriptionFilter",
        "logs:TestMetricFilter",
        "network-firewall:DescribeLoggingConfiguration",
        "network-firewall:ListFirewalls",
        "oam:ListAttachedLinks",
        "oam:ListSinks",
        "organizations:Describe*",
        "organizations:List*",
        "rds:Describe*",
        "rds:List*",
        "redshift-serverless:ListNamespaces",
        "redshift:DescribeClusters",
        "redshift:DescribeLoggingStatus",
        "route53:List*",
        "route53resolver:ListResolverQueryLogConfigs",
        "s3:GetBucketLocation",
        "s3:GetBucketLogging",
        "s3:GetBucketNotification",
        "s3:GetBucketTagging",
        "s3:ListAllMyBuckets",
        "s3:PutBucketNotification",
        "ses:Get*",
        "ses:List*",
        "sns:GetSubscriptionAttributes",
        "sns:List*",
        "sns:Publish",
        "sqs:ListQueues",
        "ssm:GetServiceSetting",
        "ssm:ListCommands",
        "states:DescribeStateMachine",
        "states:ListStateMachines",
        "support:DescribeTrustedAdvisor*",
        "support:RefreshTrustedAdvisorCheck",
        "tag:GetResources",
        "tag:GetTagKeys",
        "tag:GetTagValues",
        "timestream:DescribeEndpoints",
        "wafv2:ListLoggingConfigurations",
        "xray:BatchGetTraces",
        "xray:GetTraceSummaries"
      ],
      "Effect": "Allow",
      "Resource": "*"
    }
  ]
}

AWS resource collection IAM policy

To use resource collection, you must attach AWS’s managed SecurityAudit Policy to your Datadog IAM role.

Notes:

  • Warning messages appear on the AWS integration tile in Datadog if you enable resource collection, but do not have the AWS Security Audit Policy attached to your Datadog IAM role.
  • To enable Datadog to collect account management resources from account.GetAlternateContact and account.GetContactInformation, you need to enable trusted access for AWS account management.
  • AWS Govcloud and AWS China accounts are not currently supported.
  • Enabling resource collection can also impact your AWS CloudWatch costs. To avoid these charges, disable Usage (AWS/Usage) metrics in the Metric Collection tab of the Datadog AWS integration page.

Recopilación de logs

Existen dos formas de enviar los logs de los servicios de AWS a Datadog:

  • Destino Amazon Data Firehose: Utiliza el destino Datadog en tu flujo de entrega de Amazon Data Firehose para reenviar logs a Datadog. Recomendamos utilizar esta estrategia para el envío de grandes volúmenes de logs desde CloudWatch.
  • Función Lambda del Forwarder: Despliega la función Lambda del Datadog Forwarder, que está suscripta a buckets de S3 o a tus grupos de logs de CloudWatch y reenvía logs a Datadog. Datadog también te recomienda utilizar esta estrategia para enviar logs desde S3 u otros recursos que no puedan transmitir datos directamente a Amazon Data Firehose.

Recopilación de métricas

Existen dos formas de enviar las métricas de AWS a Datadog:

  • Sondeo de métricas: El sondeo de la API se incluye de forma predefinida con la integración AWS. Un rastreo métrica-por-métrica de la API CloudWatch extrae datos y los envía a Datadog. En promedio, se extraen nuevas métricas cada diez minutos.
  • Metric Streams con Amazon Data Firehose: Puedes utilizar Amazon CloudWatch Metric Streams y Amazon Data Firehose para ver tus métricas. Nota: Este método tiene una latencia de dos a tres minutos y requiere una configuración individual.

En la página Integraciones encontrarás una lista completa de las sub-integraciones disponibles. Muchas de estas integraciones se instalan por defecto cuando Datadog reconoce los datos procedentes de tu cuenta AWS. Para conocer las opciones de exclusión de recursos específicos y controlar tus costes, consulta la página Facturación de integraciones AWS.

Recopilación de recursos

Algunos productos de Datadog aprovechan la información de configuración de tus recursos de AWS (como buckets de S3, snapshots de RDS y distribuciones de CloudFront). Datadog recopila esta información realizando llamadas de API de sólo lectura a tu cuenta AWS.

AWS resource collection IAM policy

To use resource collection, you must attach AWS’s managed SecurityAudit Policy to your Datadog IAM role.

Notes:

  • Warning messages appear on the AWS integration tile in Datadog if you enable resource collection, but do not have the AWS Security Audit Policy attached to your Datadog IAM role.
  • To enable Datadog to collect account management resources from account.GetAlternateContact and account.GetContactInformation, you need to enable trusted access for AWS account management.
  • AWS Govcloud and AWS China accounts are not currently supported.
  • Enabling resource collection can also impact your AWS CloudWatch costs. To avoid these charges, disable Usage (AWS/Usage) metrics in the Metric Collection tab of the Datadog AWS integration page.

Tipos de recursos y permisos

En las siguientes secciones se enumeran los tipos de recursos recopilados para los distintos productos de Datadog y los permisos asociados necesarios para que el rol de IAM de Datadog recopile datos en tu nombre. Añade estos permisos a tu política de IAM de la integración de AWS existente (con la política SecurityAudit adjunta).

Resource TypePermissions
aws:ec2:volumeec2:DescribeVolumes
aws:ec2:availabilityzoneec2:DescribeAvailabilityZones
aws:ec2:instanceec2:DescribeInstances
Resource TypePermissions
aws:apigateway:apiapigateway:GET
aws:apigatewayv2:apiapigateway:GetApis,
apigateway:GetRoutes
aws:autoscaling:groupautoscaling:DescribeAutoScalingGroups
aws:cloudfront:distributioncloudfront:GetDistribution,
cloudfront:ListDistributions
aws:directconnect:connectiondirectconnect:DescribeConnections
aws:docdb:clusterrds:DescribeDBClusters
aws:dynamodb:tabledynamodb:DescribeContinuousBackups,
dynamodb:DescribeTable,
dynamodb:DescribeTimeToLive,
dynamodb:ListTables
aws:ec2:ebs-encryption-by-defaultec2:GetEbsEncryptionByDefault
aws:ec2:snapshotec2:DescribeSnapshotAttribute,
ec2:DescribeSnapshots
aws:ec2:volumeec2:DescribeVolumes
aws:ec2:availabilityzoneec2:DescribeAvailabilityZones
aws:ec2:customergatewayec2:DescribeCustomerGateways
aws:ec2:vpnconnectionec2:DescribeVpnConnections
aws:ec2:vpngatewayec2:DescribeVpnGateways
aws:ec2:instanceec2:DescribeInstances
aws:ec2:securitygroupec2:DescribeSecurityGroups
aws:ec2:vpcendpointec2:DescribeVpcEndpoints
aws:ec2:vpcec2:DescribeVpcs
aws:ec2:vpcinternetgatewayec2:DescribeInternetGateways
aws:ec2:vpcnatgatewayec2:DescribeNatGateways
aws:ecr:repositoryecr:DescribeRepositories,
ecr:GetLifecyclePolicy,
ecr:GetRepositoryPolicy
aws:ecrpublic:repositoryecr-public:DescribeImages,
ecr-public:DescribeRepositories,
ecr-public:GetRepositoryPolicy
aws:ecs:clusterecs:DescribeClusters,
ecs:ListClusters
aws:ecs:serviceecs:DescribeServices,
ecs:ListClusters,
ecs:ListServices
aws:efs:accesspointelasticfilesystem:DescribeAccessPoints
aws:efs:filesystemelasticfilesystem:DescribeFileSystems,
elasticfilesystem:DescribeLifecycleConfiguration
aws:efs:mounttargetelasticfilesystem:DescribeFileSystems,
elasticfilesystem:DescribeMountTargetSecurityGroups,
elasticfilesystem:DescribeMountTargets
aws:eks:clustereks:DescribeCluster,
eks:ListClusters
aws:eks:nodegroupeks:DescribeCluster,
eks:DescribeNodeGroup,
eks:ListClusters,
eks:ListNodeGroups
aws:elasticache:cachesubnetgroupelasticache:DescribeCacheSubnetGroups
aws:elasticache:parametergroupelasticache:DescribeCacheParameterGroups
aws:elasticache:replicationgroupelasticache:DescribeReplicationGroups
aws:elasticache:securitygroupelasticache:DescribeCacheSecurityGroups
aws:elasticache:snapshotelasticache:DescribeSnapshots
aws:elasticache:userelasticache:DescribeUsers
aws:elasticache:usergroupelasticache:DescribeUserGroups
aws:elasticache:clusterelasticache:DescribeCacheClusters
aws:elasticloadbalancing:loadbalancerelasticloadbalancing:DescribeInstanceHealth,
elasticloadbalancing:DescribeLoadBalancerAttributes,
elasticloadbalancing:DescribeLoadBalancerPolicies,
elasticloadbalancing:DescribeLoadBalancers
aws:elasticloadbalancingv2:loadbalancerelasticloadbalancing:DescribeListeners,
elasticloadbalancing:DescribeLoadBalancerAttributes,
elasticloadbalancing:DescribeLoadBalancers
aws:elasticsearchservice:domaines:DescribeElasticsearchDomains,
es:ListDomainNames
aws:eventbridge:eventbusevents:ListEventBuses,
events:ListRules
aws:fsx:backupfsx:DescribeBackups
aws:fsx:file-systemfsx:DescribeFileSystems
aws:glacier:vaultglacier:GetVaultNotifications,
glacier:ListVaults
aws:keyspaces:keyspacecassandra:Select
aws:kinesis:streamkinesis:DescribeStreamSummary,
kinesis:ListStreams
aws:lambda:functionlambda:GetFunction,
lambda:GetPolicy,
lambda:ListFunctionUrlConfigs,
lambda:ListFunctions,
lambda:ListProvisionedConcurrencyConfigs
aws:neptune:clusterrds:DescribeDBClusters
aws:neptune:cluster-snapshotrds:DescribeDBClusterSnapshotAttributes,
rds:DescribeDBClusterSnapshots
aws:neptune:dbinstancerds:DescribeDBInstances
aws:rds:clusterrds:DescribeDBClusters
aws:rds:cluster-snapshotrds:DescribeDBClusterSnapshotAttributes,
rds:DescribeDBClusterSnapshots
aws:rds:dbclusterparametergrouprds:DescribeDBClusterParameterGroups
aws:rds:dbinstanceautomatedbackuprds:DescribeDBInstanceAutomatedBackups
aws:rds:dbparametergrouprds:DescribeDBParameterGroups
aws:rds:dbsubnetgrouprds:DescribeDBSubnetGroups
aws:rds:eventsubscriptionrds:DescribeEventSubscriptions
aws:rds:exporttaskrds:DescribeExportTasks
aws:rds:instancerds:DescribeDBInstances
aws:rds:optiongrouprds:DescribeOptionGroups
aws:rds:securitygrouprds:DescribeDBSecurityGroups
aws:rds:snapshotrds:DescribeDBSnapshotAttributes,
rds:DescribeDBSnapshots
aws:rds:reserveddbinstancerds:DescribeReservedDBInstances
aws:redshift:eventsubscriptionredshift:DescribeEventSubscriptions
aws:redshift:parametergroupredshift:DescribeClusterParameterGroups
aws:redshift:securitygroupredshift:DescribeClusterSecurityGroups
aws:redshift:snapshotredshift:DescribeClusterSnapshots,
redshift:DescribeClusters
aws:redshift:subnetgroupredshift:DescribeClusterSubnetGroups,
redshift:DescribeClusters
aws:route53:hostedzoneroute53:GetDNSSEC,
route53:GetHostedZone,
route53:ListHostedZones
aws:s3:buckets3:GetBucketAcl,
s3:GetEncryptionConfiguration,
s3:GetLifecycleConfiguration,
s3:GetBucketLogging,
s3:GetBucketMetadataConfiguration,
s3:GetBucketNotification,
s3:GetBucketOwnershipControls,
s3:GetBucketPolicy,
s3:GetBucketPolicyStatus,
s3:GetReplicationConfiguration,
s3:GetBucketVersioning,
s3:GetBucketWebsite,
s3:GetBucketPublicAccessBlock,
s3:GetInventoryConfiguration,
s3:ListAllMyBuckets
aws:sns:subscriptionsns:ListSubscriptions
aws:sns:topicsns:GetTopicAttributes,
sns:ListTopics
aws:sqs:queuesqs:GetQueueAttributes,
sqs:GetQueueUrl,
sqs:ListQueues
aws:ec2:subnetec2:DescribeSubnets
aws:timestreamwrite:tabletimestream:ListTables
aws:ec2:transitgatewayec2:DescribeTransitGateways
aws:waf:aclwaf:GetWebACL,
waf:ListWebACLs
aws:waf:rulewaf:GetRule,
waf:ListRules
aws:waf:rulegroupwaf:GetRuleGroup,
waf:ListRuleGroups
aws:wafregional:aclwaf-regional:GetWebACL,
waf-regional:ListWebACLs
aws:wafregional:rulewaf-regional:GetRule,
waf-regional:ListRules
aws:wafregional:rulegroupwaf-regional:GetRuleGroup,
waf-regional:ListRuleGroups
aws:wafv2:aclwafv2:GetLoggingConfiguration,
wafv2:GetWebACL,
wafv2:ListResourcesForWebACL,
wafv2:ListWebACLs
Resource TypePermissions
aws:accessanalyzer:analyzeraccess-analyzer:GetAnalyzer,
access-analyzer:ListAnalyzers
aws:account:accountorganizations:DescribeOrganization,
account:GetAlternateContact,
account:GetContactInformation,
account:GetPrimaryEmail,
organizations:ListAccounts
aws:acm:acmacm:DescribeCertificate,
acm:ListCertificates
aws:acmpca:certificateauthorityacm-pca:DescribeCertificateAuthority,
acm-pca:ListCertificateAuthorities
aws:amp:rulegroupsnamespaceaps:DescribeRuleGroupsNamespace,
aps:DescribeWorkspace,
aps:ListRuleGroupsNamespaces,
aps:ListWorkspaces
aws:amp:scraperaps:DescribeScraper,
aps:ListScrapers
aws:amp:workspaceaps:DescribeWorkspace,
aps:ListWorkspaces
aws:amplify:appamplify:ListApps
aws:amplify:backend-environmentamplify:ListApps,
amplify:ListBackendEnvironments
aws:amplify:branchamplify:ListApps,
amplify:ListBranches
aws:amplify:domain-associationamplify:ListApps,
amplify:ListDomainAssociations
aws:amplify:jobamplify:ListApps,
amplify:ListBranches,
amplify:ListJobs
aws:amplify:webhookamplify:ListApps,
amplify:ListWebhooks
aws:apigateway:accountapigateway:GetAccount
aws:apigateway:apiapigateway:GET
aws:apigateway:apikeyapigateway:GetApiKeys
aws:apigateway:authorizerapigateway:GetAuthorizers,
apigateway:GET
aws:apigateway:basepathmappingapigateway:GetBasePathMappings,
apigateway:GetDomainNames
aws:apigateway:clientcertificateapigateway:GetClientCertificates
aws:apigateway:deploymentapigateway:GetDeployments,
apigateway:GET
aws:apigateway:documentationpartapigateway:GetDocumentationParts,
apigateway:GET
aws:apigateway:domainnameapigateway:GetDomainNames
aws:apigateway:domainnameaccessassociationapigateway:GetDomainNameAccessAssociations
aws:apigateway:gatewayresponseapigateway:GetGatewayResponses,
apigateway:GET
aws:apigateway:integrationapigateway:GetMethod,
apigateway:GetResources,
apigateway:GET
aws:apigateway:modelapigateway:GetModels,
apigateway:GET
aws:apigateway:requestvalidatorapigateway:GetRequestValidators,
apigateway:GET
aws:apigateway:resourceapigateway:GetResources,
apigateway:GET
aws:apigateway:stageapigateway:GET,
apigateway:GET
aws:apigateway:usageplanapigateway:GetApiKeys,
apigateway:GetUsagePlans
aws:apigateway:usageplankeyapigateway:GetApiKeys,
apigateway:GetUsagePlanKeys,
apigateway:GetUsagePlans
aws:apigateway:vpclinkapigateway:GetVpcLinks
aws:apigatewayv2:apiapigateway:GetApis,
apigateway:GetRoutes
aws:apigatewayv2:apimappingapigateway:GetApiMappings,
apigateway:GetDomainNames
aws:apigatewayv2:authorizerapigateway:GetApis,
apigateway:GetAuthorizers
aws:apigatewayv2:deploymentapigateway:GetApis,
apigateway:GetDeployments
aws:apigatewayv2:domainnameapigateway:GetDomainNames
aws:apigatewayv2:integrationapigateway:GetApis,
apigateway:GetIntegrations
aws:apigatewayv2:integrationresponseapigateway:GetApis,
apigateway:GetIntegrationResponses,
apigateway:GetIntegrations
aws:apigatewayv2:modelapigateway:GetApis,
apigateway:GetModels
aws:apigatewayv2:routeapigateway:GetApis,
apigateway:GetRoutes
aws:apigatewayv2:routeresponseapigateway:GetApis,
apigateway:GetRouteResponses,
apigateway:GetRoutes
aws:apigatewayv2:stageapigateway:GetApis,
apigateway:GetStages
aws:apigatewayv2:vpclinkapigateway:GetVpcLinks
aws:appintegrations:applicationapp-integrations:GetApplication,
app-integrations:ListApplicationAssociations,
app-integrations:ListApplications
aws:appintegrations:application-associationapp-integrations:ListApplicationAssociations,
app-integrations:ListApplications
aws:appintegrations:data-integrationapp-integrations:GetDataIntegration,
app-integrations:ListDataIntegrationAssociations,
app-integrations:ListDataIntegrations
aws:appintegrations:data-integration-associationapp-integrations:ListDataIntegrationAssociations,
app-integrations:ListDataIntegrations
aws:appintegrations:event-integrationapp-integrations:ListEventIntegrations
aws:appintegrations:event-integration-associationapp-integrations:ListEventIntegrationAssociations,
app-integrations:ListEventIntegrations
aws:applicationautoscaling:scalingactivityapplicationautoscaling:DescribeScalingActivities
aws:applicationautoscaling:scalingpolicyapplicationautoscaling:DescribeScalingPolicies
aws:applicationautoscaling:scheduled-actionapplicationautoscaling:DescribeScheduledActions
aws:apprunner:autoscaling-configurationapprunner:DescribeAutoScalingConfiguration,
apprunner:ListAutoScalingConfigurations
aws:apprunner:connectionapprunner:ListConnections
aws:apprunner:observability-configurationapprunner:DescribeObservabilityConfiguration,
apprunner:ListObservabilityConfigurations
aws:apprunner:serviceapprunner:DescribeService,
apprunner:ListServices
aws:apprunner:vpc-connectorapprunner:DescribeVpcConnector,
apprunner:ListVpcConnectors
aws:apprunner:vpc-ingress-connectionapprunner:DescribeVpcIngressConnection,
apprunner:ListVpcIngressConnections
aws:appstream:app-blockappstream:DescribeAppBlocks
aws:appstream:app-block-builderappstream:DescribeAppBlockBuilders
aws:appstream:applicationappstream:DescribeApplications
aws:appstream:fleetappstream:DescribeFleets
aws:appstream:imageappstream:DescribeImages
aws:appstream:image-builderappstream:DescribeImageBuilders
aws:appstream:stackappstream:DescribeStacks
aws:appstream:public-imageappstream:DescribeImages
aws:appsync:apiappsync:ListApis
aws:appsync:channel-namespaceappsync:ListApis,
appsync:ListChannelNamespaces
aws:appsync:data-sourceappsync:ListDataSources,
appsync:ListGraphqlApis
aws:appsync:domain-nameappsync:ListDomainNames
aws:appsync:functionappsync:ListFunctions,
appsync:ListGraphqlApis
aws:appsync:graphqlapiappsync:GetGraphqlApi,
appsync:ListGraphqlApis
aws:appsync:source-api-associationappsync:ListGraphqlApis,
appsync:ListSourceApiAssociations
aws:athena:capacityreservationathena:ListCapacityReservations
aws:athena:datacatalogathena:ListDataCatalogs
aws:athena:named-queryathena:BatchGetNamedQuery,
athena:ListNamedQueries
aws:athena:prepared-statementathena:BatchGetPreparedStatement,
athena:GetWorkGroup,
athena:ListPreparedStatements,
athena:ListWorkGroups
aws:athena:workgroupathena:GetWorkGroup,
athena:ListWorkGroups
aws:auditmanager:assessmentauditmanager:GetAssessment,
auditmanager:ListAssessments
aws:auditmanager:assessmentcontrolsetauditmanager:GetAssessment,
auditmanager:ListAssessments
aws:auditmanager:assessmentframeworkauditmanager:GetAssessmentFramework,
auditmanager:ListAssessmentFrameworks
aws:auditmanager:controlauditmanager:GetControl,
auditmanager:ListControls
aws:autoscaling:groupautoscaling:DescribeAutoScalingGroups
aws:autoscaling:launchconfigurationautoscaling:DescribeLaunchConfigurations
aws:autoscaling:policyautoscaling:DescribePolicies
aws:autoscaling:scheduled-actionautoscaling:DescribeScheduledActions
aws:b2bi:capabilityb2bi:GetCapability,
b2bi:ListCapabilities
aws:b2bi:partnershipb2bi:GetPartnership,
b2bi:GetProfile,
b2bi:ListPartnerships,
b2bi:ListProfiles
aws:b2bi:profileb2bi:GetProfile,
b2bi:ListProfiles
aws:b2bi:transformerb2bi:GetTransformer,
b2bi:ListTransformers
aws:backup:frameworkbackup:DescribeFramework,
backup:ListFrameworks
aws:backup:legalholdbackup:GetLegalHold,
backup:ListLegalHolds
aws:backup:planbackup:ListBackupPlans
aws:backup:protected-resourcebackup:ListProtectedResources
aws:backup:recoverypointbackup:ListBackupVaults,
backup:ListRecoveryPointsByBackupVault
aws:backup:vaultbackup:ListBackupVaults
aws:backup-gateway:gatewaybackup-gateway:GetGateway,
backup-gateway:ListGateways
aws:backup-gateway:hypervisorbackup-gateway:GetHypervisor,
backup-gateway:ListHypervisors
aws:backup-gateway:virtual-machinebackup-gateway:GetVirtualMachine,
backup-gateway:ListVirtualMachines
aws:batch:compute-environmentbatch:DescribeComputeEnvironments
aws:batch:job-definitionbatch:DescribeJobDefinitions
aws:batch:job-queuebatch:DescribeJobQueues
aws:batch:scheduling-policybatch:DescribeSchedulingPolicies,
batch:ListSchedulingPolicies
aws:bedrock:foundationmodelbedrock:GetFoundationModel,
bedrock:ListFoundationModels
aws:bedrock:system-defined-inference-profilebedrock:GetInferenceProfile,
bedrock:ListInferenceProfiles
aws:bedrock:agentbedrock:GetAgent,
bedrock:ListAgentCollaborators,
bedrock:ListAgentVersions,
bedrock:ListAgents
aws:bedrock:agent-action-groupbedrock:GetAgentActionGroup,
bedrock:ListAgentActionGroups,
bedrock:ListAgents
aws:bedrock:agent-aliasbedrock:GetAgentAlias,
bedrock:ListAgentAliases,
bedrock:ListAgents
aws:bedrock:application-inference-profilebedrock:GetInferenceProfile,
bedrock:ListInferenceProfiles
aws:bedrock:blueprintbedrock:GetBlueprint,
bedrock:ListBlueprints
aws:bedrock:custom-modelbedrock:GetCustomModel,
bedrock:ListCustomModels
aws:bedrock:data-sourcebedrock:GetDataSource,
bedrock:GetKnowledgeBase,
bedrock:ListDataSources,
bedrock:ListKnowledgeBaseDocuments,
bedrock:ListKnowledgeBases
aws:bedrock:flowbedrock:GetFlow,
bedrock:GetFlowVersion,
bedrock:ListFlows
aws:bedrock:flow-aliasbedrock:GetFlowAlias,
bedrock:ListFlowAliases,
bedrock:ListFlows
aws:bedrock:guardrailbedrock:GetGuardrail,
bedrock:ListGuardrails,
bedrock:ListGuardrails
aws:bedrock:imported-modelbedrock:GetImportedModel,
bedrock:ListImportedModels
aws:bedrock:ingestion-jobbedrock:GetDataSource,
bedrock:GetIngestionJob,
bedrock:GetKnowledgeBase,
bedrock:ListDataSources,
bedrock:ListIngestionJobs,
bedrock:ListKnowledgeBases
aws:bedrock:knowledge-basebedrock:GetKnowledgeBase,
bedrock:ListKnowledgeBases
aws:bedrock:marketplace-model-endpointbedrock:GetMarketplaceModelEndpoint,
bedrock:ListMarketplaceModelEndpoints
aws:bedrock:promptbedrock:GetPrompt,
bedrock:ListPrompts
aws:bedrock:prompt-routerbedrock:ListPromptRouters
aws:bedrock:provisioned-model-throughputbedrock:ListProvisionedModelThroughputs
aws:bedrock:async-invokebedrock:GetAsyncInvoke,
bedrock:ListAsyncInvokes
aws:bedrock:evaluation-jobbedrock:GetEvaluationJob,
bedrock:ListEvaluationJobs
aws:bedrock:model-copy-jobbedrock:GetModelCopyJob,
bedrock:ListModelCopyJobs
aws:bedrock:model-customization-jobbedrock:GetModelCustomizationJob,
bedrock:ListModelCustomizationJobs
aws:bedrock:model-invocation-jobbedrock:GetModelInvocationJob,
bedrock:ListModelInvocationJobs
aws:bedrock:settingsbedrock:GetModelInvocationLoggingConfiguration
aws:cloudformation:generatedtemplatecloudformation:DescribeGeneratedTemplate,
cloudformation:ListGeneratedTemplates
aws:cloudformation:resourcescancloudformation:DescribeResourceScan,
cloudformation:ListResourceScans
aws:cloudformation:stackcloudformation:DescribeStacks,
cloudformation:ListStacks
aws:cloudformation:stacksetcloudformation:ListStackSets
aws:cloudformation:typecloudformation:ListTypes
aws:cloudfront:anycast-ip-listcloudfront:GetAnycastIpList,
cloudfront:ListAnycastIpLists
aws:cloudfront:cache-policycloudfront:GetCachePolicy,
cloudfront:ListCachePolicies
aws:cloudfront:continuous-deployment-policycloudfront:GetContinuousDeploymentPolicy,
cloudfront:ListContinuousDeploymentPolicies
aws:cloudfront:distributioncloudfront:GetDistribution,
cloudfront:ListDistributions
aws:cloudfront:field-level-encryption-configcloudfront:GetFieldLevelEncryptionConfig,
cloudfront:ListFieldLevelEncryptionConfigs
aws:cloudfront:field-level-encryption-profilecloudfront:GetFieldLevelEncryptionProfile,
cloudfront:ListFieldLevelEncryptionProfiles
aws:cloudfront:functioncloudfront:ListFunctions
aws:cloudfront:keygroupcloudfront:ListKeyGroups
aws:cloudfront:origin-request-policycloudfront:GetOriginRequestPolicy,
cloudfront:ListOriginRequestPolicies
aws:cloudfront:originaccesscontrolcloudfront:ListOriginAccessControls
aws:cloudfront:publickeycloudfront:ListPublicKeys
aws:cloudfront:realtime-log-configcloudfront:ListRealtimeLogConfigs
aws:cloudfront:response-headers-policycloudfront:GetResponseHeadersPolicy,
cloudfront:ListResponseHeadersPolicies
aws:cloudfront:streaming-distributioncloudfront:GetStreamingDistribution,
cloudfront:ListStreamingDistributions
aws:cloudfront:vpc-origincloudfront:GetVpcOrigin,
cloudfront:ListVpcOrigins
aws:cloudfront:managed-cache-policycloudfront:GetCachePolicy,
cloudfront:ListCachePolicies
aws:cloudfront:managed-origin-request-policycloudfront:GetOriginRequestPolicy,
cloudfront:ListOriginRequestPolicies
aws:cloudfront:managed-response-headers-policycloudfront:GetResponseHeadersPolicy,
cloudfront:ListResponseHeadersPolicies
aws:cloudhsm:backupcloudhsm:DescribeBackups
aws:cloudhsm:clustercloudhsm:DescribeClusters
aws:cloudtrail:trailcloudtrail:DescribeTrails,
cloudtrail:GetEventSelectors,
cloudtrail:GetTrailStatus
aws:cloudwatchlogs:log-grouplogs:DescribeLogGroups,
logs:DescribeSubscriptionFilters
aws:cloudwatchlogs:metricfilterlogs:DescribeMetricFilters
aws:codeartifact:domaincodeartifact:DescribeDomain,
codeartifact:ListDomains
aws:codeartifact:packagecodeartifact:ListPackages,
codeartifact:ListRepositories
aws:codeartifact:package-groupcodeartifact:DescribePackageGroup,
codeartifact:ListDomains,
codeartifact:ListPackageGroups
aws:codeartifact:repositorycodeartifact:DescribeRepository,
codeartifact:ListRepositories
aws:codebuild:projectcodebuild:BatchGetProjects,
codebuild:ListProjects
aws:codebuild:source-credentialscodebuild:ListSourceCredentials
aws:codedeploy:applicationcodedeploy:BatchGetApplications,
codedeploy:ListApplications
aws:codedeploy:deployment-configcodedeploy:GetDeploymentConfig,
codedeploy:ListDeploymentConfigs
aws:codeguru-profiler:findingcodeguru-profiler:ListFindingsReports,
codeguru-profiler:ListProfilingGroups
aws:codeguru-profiler:profilinggroupcodeguru-profiler:ListProfilingGroups
aws:codeguru-reviewer:associationcodeguru-reviewer:ListRepositoryAssociations
aws:codeguru-reviewer:codereviewcodeguru-reviewer:ListCodeReviews
aws:codeguru-security:findingcodeguru-security:GetFindings,
codeguru-security:ListScans
aws:codeguru-security:scannamecodeguru-security:GetScan,
codeguru-security:ListScans
aws:codepipeline:actiontypecodepipeline:GetActionType,
codepipeline:ListActionTypes
aws:codepipeline:pipelinecodepipeline:GetPipeline,
codepipeline:ListPipelines
aws:codepipeline:webhookcodepipeline:ListWebhooks
aws:cognitoidentity:identitypoolcognito-identity:DescribeIdentityPool,
cognito-identity:GetIdentityPoolRoles,
cognito-identity:ListIdentityPools
aws:cognitoidentityprovider:userpoolcognito-idp:DescribeUserPool,
cognito-idp:ListIdentityProviders,
cognito-idp:ListUserPools
aws:comprehend:document-classification-jobcomprehend:ListDocumentClassificationJobs
aws:comprehend:document-classifiercomprehend:ListDocumentClassifiers
aws:comprehend:dominant-language-detection-jobcomprehend:ListDominantLanguageDetectionJobs
aws:comprehend:endpointcomprehend:ListEndpoints
aws:comprehend:entities-detection-jobcomprehend:ListEntitiesDetectionJobs
aws:comprehend:entity-recognizercomprehend:ListEntityRecognizers
aws:comprehend:events-detection-jobcomprehend:ListEventsDetectionJobs
aws:comprehend:flywheelcomprehend:DescribeFlywheel,
comprehend:ListFlywheels
aws:comprehend:flywheel-datasetcomprehend:DescribeFlywheel,
comprehend:ListDatasets,
comprehend:ListFlywheels
aws:comprehend:key-phrases-detection-jobcomprehend:ListKeyPhrasesDetectionJobs
aws:comprehend:pii-entities-detection-jobcomprehend:ListPiiEntitiesDetectionJobs
aws:comprehend:sentiment-detection-jobcomprehend:ListSentimentDetectionJobs
aws:comprehend:targeted-sentiment-detection-jobcomprehend:ListTargetedSentimentDetectionJobs
aws:comprehend:topics-detection-jobcomprehend:ListTopicsDetectionJobs
aws:configservice:recorderconfig:DescribeConfigurationRecorders
aws:configservice:recorderstatusconfig:DescribeConfigurationRecorderStatus
aws:connect:agent-statusconnect:DescribeAgentStatus,
connect:DescribeInstance,
connect:ListAgentStatuses,
connect:ListInstances
aws:connect:authentication-profileconnect:DescribeAuthenticationProfile,
connect:DescribeInstance,
connect:ListAuthenticationProfiles,
connect:ListInstances
aws:connect:contact-flowconnect:DescribeContactFlow,
connect:DescribeInstance,
connect:ListContactFlows,
connect:ListInstances
aws:connect:contact-flow-moduleconnect:DescribeContactFlowModule,
connect:DescribeInstance,
connect:ListContactFlowModules,
connect:ListInstances
aws:connect:hours-of-operationconnect:DescribeHoursOfOperation,
connect:DescribeInstance,
connect:ListHoursOfOperations,
connect:ListInstances
aws:connect:instanceconnect:DescribeInstance,
connect:ListInstances
aws:connect:integration-associationconnect:DescribeInstance,
connect:ListInstances,
connect:ListIntegrationAssociations
aws:connect:queueconnect:DescribeInstance,
connect:DescribeQueue,
connect:ListInstances,
connect:ListQueues
aws:connect:quick-connectconnect:DescribeInstance,
connect:DescribeQuickConnect,
connect:ListInstances,
connect:ListQuickConnects
aws:connect:routing-profileconnect:DescribeInstance,
connect:DescribeRoutingProfile,
connect:ListInstances,
connect:ListRoutingProfiles
aws:connect:security-profileconnect:DescribeInstance,
connect:DescribeSecurityProfile,
connect:ListInstances,
connect:ListSecurityProfiles
aws:connect:userconnect:DescribeInstance,
connect:DescribeUser,
connect:ListInstances,
connect:ListUsers
aws:controltower:enabled-baselinecontroltower:ListEnabledBaselines
aws:controltower:enabled-controlcontroltower:ListEnabledControls
aws:controltower:landing-zonecontroltower:GetLandingZone,
controltower:ListLandingZones
aws:costexplorer:anomalymonitorce:GetAnomalyMonitors
aws:costexplorer:anomalysubscriptionce:GetAnomalySubscriptions
aws:costexplorer:costcategoryce:DescribeCostCategoryDefinition,
ce:GetCostCategories
aws:profile:domainprofile:GetDomain,
profile:ListDomains
aws:dms:certificatedms:DescribeCertificates
aws:dms:data-migrationdms:DescribeDataMigrations
aws:dms:data-providerdms:DescribeDataProviders
aws:dms:endpointdms:DescribeEndpoints
aws:dms:event-subscriptiondms:DescribeEventSubscriptions
aws:dms:instance-profiledms:DescribeInstanceProfiles
aws:dms:migration-projectdms:DescribeMigrationProjects
aws:dms:replication-configdms:DescribeReplicationConfigs
aws:dms:replication-subnet-groupdms:DescribeReplicationSubnetGroups
aws:dms:replicationinstancedms:DescribeReplicationInstances
aws:dms:replicationtaskdms:DescribeReplicationTasks
aws:databrew:datasetdatabrew:ListDatasets
aws:databrew:jobdatabrew:ListJobs
aws:databrew:projectdatabrew:ListProjects
aws:databrew:recipedatabrew:ListRecipes
aws:databrew:rulesetdatabrew:ListRulesets
aws:databrew:scheduledatabrew:ListSchedules
aws:datasync:agentdatasync:DescribeAgent,
datasync:ListAgents
aws:datasync:location-efsdatasync:DescribeLocationEfs,
datasync:ListLocations
aws:datasync:location-fsx-lustredatasync:DescribeLocationFsxLustre,
datasync:ListLocations
aws:datasync:location-fsx-ontapdatasync:DescribeLocationFsxOntap,
datasync:ListLocations
aws:datasync:location-fsx-openzfsdatasync:DescribeLocationFsxOpenZfs,
datasync:ListLocations
aws:datasync:location-fsx-windowsdatasync:DescribeLocationFsxWindows,
datasync:ListLocations
aws:datasync:location-hdfsdatasync:DescribeLocationHdfs,
datasync:ListLocations
aws:datasync:location-nfsdatasync:DescribeLocationNfs,
datasync:ListLocations
aws:datasync:location-objectstoragedatasync:DescribeLocationObjectStorage,
datasync:ListLocations
aws:datasync:location-s3datasync:DescribeLocationS3,
datasync:ListLocations
aws:datasync:location-smbdatasync:DescribeLocationSmb,
datasync:ListLocations
aws:datasync:taskdatasync:DescribeTask,
datasync:ListTasks
aws:datazone:domaindatazone:GetDomain,
datazone:ListDomains
aws:dax:clusterdax:DescribeClusters
aws:deadline:budgetdeadline:GetBudget,
deadline:ListBudgets,
deadline:ListFarms
aws:deadline:farmdeadline:ListFarms
aws:deadline:fleetdeadline:ListFarms,
deadline:ListFleets
aws:deadline:license-endpointdeadline:GetLicenseEndpoint,
deadline:ListLicenseEndpoints
aws:deadline:monitordeadline:ListMonitors
aws:deadline:queuedeadline:GetQueue,
deadline:ListFarms,
deadline:ListQueues
aws:deadline:workerdeadline:ListFarms,
deadline:ListFleets,
deadline:ListWorkers
aws:detective:graphdetective:ListGraphs
aws:devicefarm:devicedevicefarm:ListDevices,
devicefarm:ListProjects
aws:devicefarm:deviceinstancedevicefarm:ListDeviceInstances
aws:devicefarm:devicepooldevicefarm:ListDevicePools,
devicefarm:ListProjects
aws:devicefarm:instanceprofiledevicefarm:ListInstanceProfiles
aws:devicefarm:networkprofiledevicefarm:ListNetworkProfiles,
devicefarm:ListProjects
aws:devicefarm:projectdevicefarm:ListProjects
aws:devicefarm:sessiondevicefarm:ListProjects,
devicefarm:ListRemoteAccessSessions
aws:devicefarm:testgrid-projectdevicefarm:ListTestGridProjects
aws:devicefarm:testgrid-sessiondevicefarm:ListTestGridProjects,
devicefarm:ListTestGridSessions
aws:devicefarm:uploaddevicefarm:GetUpload,
devicefarm:ListProjects,
devicefarm:ListUploads
aws:devicefarm:vpceconfigurationdevicefarm:ListVPCEConfigurations
aws:directconnect:connectiondirectconnect:DescribeConnections
aws:directconnect:gatewaydirectconnect:DescribeDirectConnectGatewayAssociations,
directconnect:DescribeDirectConnectGateways
aws:directconnect:virtualinterfacedirectconnect:DescribeVirtualInterfaces
aws:ds:directoryds:DescribeDirectories
aws:dlm:policydlm:GetLifecyclePolicies,
dlm:GetLifecyclePolicy
aws:docdb:clusterrds:DescribeDBClusters
aws:docdb:clustersnapshotrds:DescribeDBClusterSnapshotAttributes,
rds:DescribeDBClusterSnapshots,
rds:DescribeDBClusters
aws:docdb:dbinstancerds:DescribeDBInstances
aws:docdbelastic:clusterdocdb-elastic:GetCluster,
docdb-elastic:ListClusters
aws:docdbelastic:cluster-snapshotdocdb-elastic:GetClusterSnapshot,
docdb-elastic:ListClusterSnapshots
aws:drs:jobdrs:DescribeJobs
aws:drs:launch-configuration-templatedrs:DescribeLaunchConfigurationTemplates
aws:drs:recovery-instancedrs:DescribeRecoveryInstances
aws:drs:replication-configuration-templatedrs:DescribeReplicationConfigurationTemplates
aws:drs:source-networkdrs:DescribeSourceNetworks
aws:drs:source-serverdrs:DescribeSourceServers
aws:dsql:clusterdsql:GetCluster,
dsql:ListClusters
aws:dynamodb:backupdynamodb:DescribeBackup,
dynamodb:ListBackups
aws:dynamodb:global-tabledynamodb:DescribeGlobalTable,
dynamodb:ListGlobalTables
aws:dynamodb:streamdynamodb:DescribeStream,
dynamodb:ListStreams
aws:dynamodb:tabledynamodb:DescribeContinuousBackups,
dynamodb:DescribeTable,
dynamodb:DescribeTimeToLive,
dynamodb:ListTables
aws:dynamodb:exportdynamodb:DescribeExport,
dynamodb:ListExports
aws:ec2:ebs-encryption-by-defaultec2:GetEbsEncryptionByDefault
aws:ec2:snapshotec2:DescribeSnapshotAttribute,
ec2:DescribeSnapshots
aws:ec2:volumeec2:DescribeVolumes
aws:ec2:imageec2:DescribeImageAttribute,
ec2:DescribeImages
aws:ec2:availabilityzoneec2:DescribeAvailabilityZones
aws:ec2:instance-event-windowec2:DescribeInstanceEventWindows
aws:ec2:fpga-imageec2:DescribeFpgaImages
aws:ec2:carriergatewayec2:DescribeCarrierGateways
aws:ec2:customergatewayec2:DescribeCustomerGateways
aws:ec2:vpnconnectionec2:DescribeVpnConnections
aws:ec2:vpngatewayec2:DescribeVpnGateways
aws:ec2:instanceec2:DescribeInstances
aws:ec2:instancetypeec2:DescribeInstanceTypes
aws:ec2:launchtemplateec2:DescribeLaunchTemplates
aws:ec2:launchtemplateversionec2:DescribeLaunchTemplateVersions,
ec2:DescribeLaunchTemplates
aws:ec2:co-ip-poolec2:DescribeCoipPools
aws:ec2:local-gatewayec2:DescribeLocalGateways
aws:ec2:local-gateway-route-tableec2:DescribeLocalGatewayRouteTables
aws:ec2:local-gateway-route-table-vpc-associationec2:DescribeLocalGatewayRouteTableVpcAssociations
aws:ec2:local-gateway-virtual-interfaceec2:DescribeLocalGatewayVirtualInterfaces
aws:ec2:local-gateway-virtual-interface-groupec2:DescribeLocalGatewayVirtualInterfaceGroups
aws:ec2:dhcpoptionsec2:DescribeDhcpOptions
aws:ec2:instanceconnectendpointec2:DescribeInstanceConnectEndpoints
aws:ec2:ipamec2:DescribeIpams
aws:ec2:ipam-external-resource-verification-tokenec2:DescribeIpamExternalResourceVerificationTokens
aws:ec2:ipam-poolec2:DescribeIpamPools
aws:ec2:ipam-resource-discoveryec2:DescribeIpamResourceDiscoveries
aws:ec2:ipam-resource-discovery-associationec2:DescribeIpamResourceDiscoveryAssociations
aws:ec2:ipam-scopeec2:DescribeIpamScopes
aws:ec2:ipv6pool-ec2ec2:DescribeIpv6Pools
aws:ec2:keypairec2:DescribeKeyPairs
aws:ec2:networkaclec2:DescribeNetworkAcls
aws:ec2:placementgroupec2:DescribePlacementGroups
aws:ec2:networkinterfaceec2:DescribeNetworkInterfaces
aws:ec2:customermanagedprefixlistec2:DescribeManagedPrefixLists,
ec2:GetManagedPrefixListEntries
aws:ec2:awsmanagedprefixlistec2:DescribeManagedPrefixLists,
ec2:GetManagedPrefixListEntries
aws:ec2:public-fpga-imageec2:DescribeFpgaImages
aws:ec2:publicimageec2:DescribeImages
aws:ec2:regionec2:DescribeRegions
aws:ec2:capacityreservationec2:DescribeCapacityReservations
aws:ec2:capacityreservationfleetec2:DescribeCapacityReservationFleets
aws:ec2:dedicatedhostec2:DescribeHosts
aws:ec2:fleetec2:DescribeFleets
aws:ec2:reservedinstanceec2:DescribeReservedInstances
aws:ec2:spotfleetrequestec2:DescribeSpotFleetRequests
aws:ec2:spotinstancerequestec2:DescribeSpotInstanceRequests
aws:ec2:securitygroupec2:DescribeSecurityGroups
aws:ec2:securitygroupruleec2:DescribeSecurityGroupRules,
ec2:DescribeSecurityGroups
aws:ec2:settingsec2:DescribeVpcBlockPublicAccessExclusions,
ec2:DescribeVpcBlockPublicAccessOptions,
ec2:GetAllowedImagesSettings,
ec2:GetEbsDefaultKmsKeyId,
ec2:GetEbsEncryptionByDefault,
ec2:GetImageBlockPublicAccessState,
ec2:GetInstanceMetadataDefaults,
ec2:GetSerialConsoleAccessStatus,
ec2:GetSnapshotBlockPublicAccessState
aws:ec2:traffic-mirror-filterec2:DescribeTrafficMirrorFilters
aws:ec2:traffic-mirror-filter-ruleec2:DescribeTrafficMirrorFilterRules,
ec2:DescribeTrafficMirrorFilters
aws:ec2:traffic-mirror-sessionec2:DescribeTrafficMirrorSessions
aws:ec2:traffic-mirror-targetec2:DescribeTrafficMirrorTargets
aws:ec2:verified-access-endpointec2:DescribeVerifiedAccessEndpoints,
ec2:GetVerifiedAccessEndpointPolicy,
ec2:GetVerifiedAccessEndpointTargets
aws:ec2:verified-access-groupec2:DescribeVerifiedAccessGroups,
ec2:GetVerifiedAccessGroupPolicy
aws:ec2:verified-access-instanceec2:DescribeVerifiedAccessInstances
aws:ec2:verified-access-trust-providerec2:DescribeVerifiedAccessTrustProviders
aws:ec2:vpcendpointec2:DescribeVpcEndpoints
aws:ec2:vpcendpoint-serviceec2:DescribeVpcEndpointServices
aws:ec2:vpcendpoint-service-permissionec2:DescribeVpcEndpointServicePermissions,
ec2:DescribeVpcEndpointServices
aws:ec2:vpcec2:DescribeVpcs
aws:ec2:vpcflowlogec2:DescribeFlowLogs
aws:ec2:egressonlyinternetgatewayec2:DescribeEgressOnlyInternetGateways
aws:ec2:elasticipec2:DescribeAddresses
aws:ec2:vpcinternetgatewayec2:DescribeInternetGateways
aws:ec2:vpcnatgatewayec2:DescribeNatGateways
aws:ec2:routetableec2:DescribeRouteTables
aws:ec2:vpcendpointconnectionnotificationec2:DescribeVpcEndpointConnectionNotifications
aws:ec2:vpcpeeringconnectionec2:DescribeVpcPeeringConnections
aws:ec2:client-vpn-endpointec2:DescribeClientVpnEndpoints
aws:ecr:imageecr:DescribeImages,
ecr:DescribeRepositories
aws:ecr:repositoryecr:DescribeRepositories,
ecr:GetLifecyclePolicy,
ecr:GetRepositoryPolicy
aws:ecr:registryecr:DescribeRegistry,
ecr:GetRegistryPolicy,
ecr:GetRegistryScanningConfiguration
aws:ecrpublic:imageecr-public:DescribeImages,
ecr-public:DescribeRepositories
aws:ecrpublic:repositoryecr-public:DescribeImages,
ecr-public:DescribeRepositories,
ecr-public:GetRepositoryPolicy
aws:ecrpublic:registryecr-public:DescribeRegistries
aws:ecs:capacityproviderecs:DescribeCapacityProviders
aws:ecs:clusterecs:DescribeClusters,
ecs:ListClusters
aws:ecs:instanceecs:DescribeContainerInstances,
ecs:ListClusters,
ecs:ListContainerInstances
aws:ecs:serviceecs:DescribeServices,
ecs:ListClusters,
ecs:ListServices
aws:ecs:service-deploymentecs:DescribeServiceDeployments,
ecs:DescribeServices,
ecs:ListClusters,
ecs:ListServiceDeployments,
ecs:ListServices
aws:ecs:taskecs:DescribeServices,
ecs:DescribeTasks,
ecs:ListClusters,
ecs:ListServices,
ecs:ListTasks
aws:ecs:task-definitionecs:DescribeServices,
ecs:DescribeTaskDefinition,
ecs:DescribeTasks,
ecs:ListClusters,
ecs:ListServices,
ecs:ListTasks
aws:efs:accesspointelasticfilesystem:DescribeAccessPoints
aws:efs:filesystemelasticfilesystem:DescribeFileSystems,
elasticfilesystem:DescribeLifecycleConfiguration
aws:efs:mounttargetelasticfilesystem:DescribeFileSystems,
elasticfilesystem:DescribeMountTargetSecurityGroups,
elasticfilesystem:DescribeMountTargets
aws:eks:access-entryeks:DescribeAccessEntry,
eks:DescribeCluster,
eks:ListAccessEntries,
eks:ListClusters
aws:eks:access-policyeks:DescribeAccessEntry,
eks:DescribeCluster,
eks:ListAccessEntries,
eks:ListAssociatedAccessPolicies,
eks:ListClusters
aws:eks:addoneks:DescribeAddon,
eks:DescribeCluster,
eks:ListAddons,
eks:ListClusters
aws:eks:clustereks:DescribeCluster,
eks:ListClusters
aws:eks:eks-anywhere-subscriptioneks:ListEksAnywhereSubscriptions
aws:eks:fargateprofileeks:DescribeCluster,
eks:DescribeFargateProfile,
eks:ListClusters,
eks:ListFargateProfiles
aws:eks:identityproviderconfigeks:DescribeCluster,
eks:DescribeIdentityProviderConfig,
eks:ListClusters,
eks:ListIdentityProviderConfigs
aws:eks:insighteks:DescribeCluster,
eks:DescribeInsight,
eks:ListClusters,
eks:ListInsights
aws:eks:nodegroupeks:DescribeCluster,
eks:DescribeNodeGroup,
eks:ListClusters,
eks:ListNodeGroups
aws:eks:podidentityassociationeks:DescribeCluster,
eks:DescribePodIdentityAssociation,
eks:ListClusters,
eks:ListPodIdentityAssociations
aws:eks:updateeks:DescribeCluster,
eks:DescribeUpdate,
eks:ListClusters,
eks:ListUpdates
aws:elasticache:cachesubnetgroupelasticache:DescribeCacheSubnetGroups
aws:elasticache:global-replicationgroupelasticache:DescribeGlobalReplicationGroups
aws:elasticache:parametergroupelasticache:DescribeCacheParameterGroups
aws:elasticache:replicationgroupelasticache:DescribeReplicationGroups
aws:elasticache:reserved-instanceelasticache:DescribeReservedCacheNodes
aws:elasticache:securitygroupelasticache:DescribeCacheSecurityGroups
aws:elasticache:serverless-cacheelasticache:DescribeServerlessCaches
aws:elasticache:serverless-cache-snapshotelasticache:DescribeServerlessCacheSnapshots
aws:elasticache:snapshotelasticache:DescribeSnapshots
aws:elasticache:userelasticache:DescribeUsers
aws:elasticache:usergroupelasticache:DescribeUserGroups
aws:elasticache:clusterelasticache:DescribeCacheClusters
aws:elasticbeanstalk:environmentelasticbeanstalk:DescribeConfigurationSettings,
elasticbeanstalk:DescribeEnvironments
aws:elasticloadbalancing:loadbalancerelasticloadbalancing:DescribeInstanceHealth,
elasticloadbalancing:DescribeLoadBalancerAttributes,
elasticloadbalancing:DescribeLoadBalancerPolicies,
elasticloadbalancing:DescribeLoadBalancers
aws:elasticloadbalancingv2:listener-ruleelasticloadbalancing:DescribeListeners,
elasticloadbalancing:DescribeLoadBalancers,
elasticloadbalancing:DescribeRules
aws:elasticloadbalancingv2:loadbalancerelasticloadbalancing:DescribeListeners,
elasticloadbalancing:DescribeLoadBalancerAttributes,
elasticloadbalancing:DescribeLoadBalancers
aws:elasticloadbalancingv2:targetgroupelasticloadbalancing:DescribeTargetGroups,
elasticloadbalancing:DescribeTargetHealth
aws:elasticloadbalancingv2:truststoreelasticloadbalancing:DescribeTrustStores
aws:elasticsearchservice:domaines:DescribeElasticsearchDomains,
es:ListDomainNames
aws:emr:clusterelasticmapreduce:DescribeCluster,
elasticmapreduce:GetAutoTerminationPolicy,
elasticmapreduce:GetManagedScalingPolicy,
elasticmapreduce:ListClusters
aws:emr:instanceelasticmapreduce:ListClusters,
elasticmapreduce:ListInstances
aws:emr:instance-fleetelasticmapreduce:DescribeCluster,
elasticmapreduce:ListClusters,
elasticmapreduce:ListInstanceFleets
aws:emr:instance-groupelasticmapreduce:DescribeCluster,
elasticmapreduce:ListClusters,
elasticmapreduce:ListInstanceGroups
aws:emr:security-configurationelasticmapreduce:DescribeSecurityConfiguration,
elasticmapreduce:ListSecurityConfigurations
aws:emrcontainers:managed-endpointemr-containers:ListManagedEndpoints,
emr-containers:ListVirtualClusters
aws:emrcontainers:security-configurationemr-containers:ListSecurityConfigurations
aws:emrcontainers:virtual-clusteremr-containers:ListVirtualClusters
aws:emrserverless:applicationemr-serverless:GetApplication,
emr-serverless:ListApplications
aws:emr:settingselasticmapreduce:GetBlockPublicAccessConfiguration
aws:eventbridge:api-destinationevents:ListApiDestinations,
events:ListConnections
aws:eventbridge:archiveevents:ListArchives,
events:ListEventBuses
aws:eventbridge:connectionevents:ListConnections
aws:eventbridge:endpointevents:ListEndpoints
aws:eventbridge:event-sourceevents:ListEventSources
aws:eventbridge:eventbusevents:ListEventBuses,
events:ListRules
aws:eventbridge:replayevents:ListReplays
aws:eventbridge:ruleevents:ListEventBuses,
events:ListRules
aws:eventbridge:ruletargetevents:ListEventBuses,
events:ListRules,
events:ListTargetsByRule
aws:firehose:delivery-streamfirehose:DescribeDeliveryStream,
firehose:ListDeliveryStreams
aws:frauddetector:batch-import-jobfrauddetector:GetBatchImportJobs
aws:frauddetector:batch-prediction-jobfrauddetector:GetBatchPredictionJobs
aws:frauddetector:detectorfrauddetector:GetDetectors
aws:frauddetector:detector-versionfrauddetector:DescribeDetector,
frauddetector:GetDetectorVersion,
frauddetector:GetDetectors
aws:frauddetector:entity-typefrauddetector:GetEntityTypes
aws:frauddetector:event-typefrauddetector:GetEventTypes
aws:frauddetector:external-modelfrauddetector:GetExternalModels
aws:frauddetector:labelfrauddetector:GetLabels
aws:frauddetector:listfrauddetector:GetListsMetadata
aws:frauddetector:modelfrauddetector:GetModels
aws:frauddetector:model-versionfrauddetector:DescribeModelVersions
aws:frauddetector:outcomefrauddetector:GetOutcomes
aws:frauddetector:rulefrauddetector:GetDetectors,
frauddetector:GetRules
aws:frauddetector:variablefrauddetector:GetVariables
aws:fsx:associationfsx:DescribeDataRepositoryAssociations
aws:fsx:backupfsx:DescribeBackups
aws:fsx:file-cachefsx:DescribeFileCaches
aws:fsx:file-systemfsx:DescribeFileSystems
aws:fsx:snapshotfsx:DescribeSnapshots
aws:fsx:storage-virtual-machinefsx:DescribeStorageVirtualMachines
aws:fsx:taskfsx:DescribeDataRepositoryTasks
aws:fsx:volumefsx:DescribeVolumes
aws:gamelift:aliasgamelift:ListAliases
aws:gamelift:buildgamelift:ListBuilds
aws:gamelift:container-fleetgamelift:ListContainerFleets
aws:gamelift:container-group-definitiongamelift:ListContainerGroupDefinitions
aws:gamelift:game-server-groupgamelift:ListGameServerGroups
aws:gamelift:game-session-queuegamelift:DescribeGameSessionQueues
aws:gamelift:locationgamelift:ListLocations
aws:gamelift:matchmaking-configurationgamelift:DescribeMatchmakingConfigurations
aws:gamelift:matchmaking-rule-setgamelift:DescribeMatchmakingRuleSets
aws:gamelift:scriptgamelift:ListScripts
aws:glacier:vaultglacier:GetVaultNotifications,
glacier:ListVaults
aws:globalaccelerator:acceleratorglobalaccelerator:ListAccelerators
aws:globalaccelerator:endpointgroupglobalaccelerator:ListAccelerators,
globalaccelerator:ListEndpointGroups,
globalaccelerator:ListListeners
aws:globalaccelerator:listenerglobalaccelerator:ListAccelerators,
globalaccelerator:ListListeners
aws:glue:registryglue:ListRegistries
aws:grafana:workspacegrafana:DescribeWorkspace,
grafana:ListWorkspaces
aws:greengrass:bulk-deploymentgreengrass:GetBulkDeploymentStatus,
greengrass:ListBulkDeployments
aws:greengrass:connector-definitiongreengrass:ListConnectorDefinitions
aws:greengrass:core-definitiongreengrass:ListCoreDefinitions
aws:greengrass:deploymentgreengrass:ListDeployments,
greengrass:ListGroups
aws:greengrass:device-definitiongreengrass:ListDeviceDefinitions
aws:greengrass:function-definitiongreengrass:ListFunctionDefinitions
aws:greengrass:groupgreengrass:GetGroup,
greengrass:ListGroups
aws:greengrass:logger-definitiongreengrass:ListLoggerDefinitions
aws:greengrass:resource-definitiongreengrass:ListResourceDefinitions
aws:greengrass:subscription-definitiongreengrass:ListSubscriptionDefinitions
aws:greengrass:componentgreengrass:GetComponent,
greengrass:ListComponents
aws:greengrass:connectivity-infogreengrass:GetConnectivityInfo,
greengrass:ListCoreDevices
aws:greengrass:core-devicegreengrass:GetCoreDevice,
greengrass:ListCoreDevices
aws:guardduty:detectorguardduty:GetCoverageStatistics,
guardduty:GetDetector,
guardduty:ListDetectors
aws:guardduty:filterguardduty:GetFilter,
guardduty:ListDetectors,
guardduty:ListFilters
aws:guardduty:ipsetguardduty:GetIPSet,
guardduty:ListDetectors,
guardduty:ListIPSets
aws:guardduty:malwareprotectionplanguardduty:GetMalwareProtectionPlan,
guardduty:ListMalwareProtectionPlans
aws:guardduty:publishingdestinationguardduty:DescribePublishingDestination,
guardduty:ListDetectors,
guardduty:ListPublishingDestinations
aws:guardduty:settingsguardduty:GetAdministratorAccount,
guardduty:GetMalwareScanSettings,
guardduty:GetMasterAccount,
guardduty:ListDetectors
aws:guardduty:threatintelsetguardduty:GetThreatIntelSet,
guardduty:ListDetectors,
guardduty:ListThreatIntelSets
aws:health:settingshealth:DescribeHealthServiceStatusForOrganization,
organizations:DescribeOrganization
aws:healthlake:datastorehealthlake:ListFHIRDatastores
aws:iam:accountorganizations:DescribeOrganization,
iam:GetAccountPasswordPolicy,
iam:GetAccountSummary
aws:iam:instanceprofileiam:GetInstanceProfile,
iam:ListInstanceProfiles
aws:iam:open-id-connect-provideriam:GetOpenIDConnectProvider,
iam:ListOpenIDConnectProviders
aws:iam:saml-provideriam:GetSAMLProvider,
iam:ListSAMLProviders
aws:iam:server-certificateiam:ListServerCertificates
aws:iam:service-specific-credentialiam:ListServiceSpecificCredentials
aws:iam:groupiam:GetGroup,
iam:ListAttachedGroupPolicies,
iam:ListGroups
aws:iam:groupinlinepolicyiam:GetGroupPolicy,
iam:ListGroupPolicies,
iam:ListGroups
aws:iam:policyiam:GetPolicy,
iam:GetPolicyVersion,
iam:ListPolicies
aws:iam:aws-managed-policyiam:GetPolicyVersion,
iam:ListPolicies
aws:iam:roleiam:GetAccountAuthorizationDetails,
iam:GetRole,
iam:ListAttachedRolePolicies
aws:iam:roleinlinepolicyiam:GetAccountAuthorizationDetails,
iam:GetRole,
iam:GetRolePolicy,
iam:ListRolePolicies
aws:iam:accesskeymetadataiam:GetUser,
iam:ListAccessKeys,
iam:ListUsers,
iam:ListVirtualMFADevices
aws:iam:useriam:GetLoginProfile,
iam:GetUser,
iam:ListAttachedUserPolicies,
iam:ListGroupsForUser,
iam:ListMFADevices,
iam:ListSSHPublicKeys,
iam:ListUsers,
iam:ListVirtualMFADevices
aws:iam:userinlinepolicyiam:GetUser,
iam:GetUserPolicy,
iam:ListUserPolicies,
iam:ListUsers,
iam:ListVirtualMFADevices
aws:iam:virtualmfadeviceiam:ListUsers,
iam:ListVirtualMFADevices
aws:identitystore:grouporganizations:DescribeOrganization,
identitystore:ListGroups,
sso:ListInstances
aws:identitystore:userorganizations:DescribeOrganization,
identitystore:ListGroupMembershipsForMember,
sso:ListInstances,
identitystore:ListUsers
aws:imagebuilder:component-versionimagebuilder:ListComponents
aws:imagebuilder:container-recipeimagebuilder:GetContainerRecipe,
imagebuilder:ListContainerRecipes
aws:imagebuilder:distribution-configurationimagebuilder:GetDistributionConfiguration,
imagebuilder:ListDistributionConfigurations
aws:imagebuilder:image-pipelineimagebuilder:ListImagePipelines
aws:imagebuilder:image-recipeimagebuilder:GetImageRecipe,
imagebuilder:ListImageRecipes
aws:imagebuilder:image-versionimagebuilder:ListImages
aws:imagebuilder:infrastructure-configurationimagebuilder:GetInfrastructureConfiguration,
imagebuilder:ListInfrastructureConfigurations
aws:imagebuilder:lifecycle-policyimagebuilder:GetLifecyclePolicy,
imagebuilder:ListLifecyclePolicies
aws:imagebuilder:workflowimagebuilder:GetWorkflow,
imagebuilder:ListWorkflows
aws:imagebuilder:public-componentimagebuilder:ListComponents
aws:imagebuilder:public-container-recipeimagebuilder:GetContainerRecipe,
imagebuilder:ListContainerRecipes
aws:imagebuilder:public-imageimagebuilder:ListImages
aws:imagebuilder:public-image-recipeimagebuilder:GetImageRecipe,
imagebuilder:ListImageRecipes
aws:imagebuilder:public-workflowimagebuilder:GetWorkflow,
imagebuilder:ListWorkflows
aws:inspector2:coveredresourceinspector2:ListCoverage
aws:iot:authorizeriot:DescribeAuthorizer,
iot:ListAuthorizers
aws:iot:certiot:DescribeCertificate,
iot:ListCertificates
aws:iot:certificateprovideriot:DescribeCertificateProvider,
iot:ListCertificateProviders
aws:iot:dimensioniot:DescribeDimension,
iot:ListDimensions
aws:iot:domainconfigurationiot:DescribeDomainConfiguration,
iot:ListDomainConfigurations
aws:iot:fleetmetriciot:DescribeFleetMetric,
iot:ListFleetMetrics
aws:iot:jobiot:DescribeJob,
iot:ListJobs
aws:iot:jobtemplateiot:DescribeJobTemplate,
iot:ListJobTemplates
aws:iot:policyiot:GetPolicy,
iot:ListPolicies
aws:iot:provisioningtemplateiot:DescribeProvisioningTemplate,
iot:ListProvisioningTemplates
aws:iot:rolealiasiot:DescribeRoleAlias,
iot:ListRoleAliases
aws:iot:securityprofileiot:DescribeSecurityProfile,
iot:ListSecurityProfiles
aws:iot:streamiot:DescribeStream,
iot:ListStreams
aws:iot:thingiot:DescribeThing,
iot:ListThings
aws:iot:thinggroupiot:DescribeThingGroup,
iot:ListThingGroups
aws:iot:thingtypeiot:DescribeThingType,
iot:ListThingTypes
aws:iotfleetwise:campaigniotfleetwise:GetCampaign,
iotfleetwise:ListCampaigns
aws:iotfleetwise:decoder-manifestiotfleetwise:ListDecoderManifests
aws:iotfleetwise:fleetiotfleetwise:ListFleets
aws:iotfleetwise:model-manifestiotfleetwise:ListModelManifests
aws:iotfleetwise:signal-catalogiotfleetwise:GetSignalCatalog,
iotfleetwise:ListSignalCatalogs
aws:iotfleetwise:state-templateiotfleetwise:GetStateTemplate,
iotfleetwise:ListStateTemplates
aws:iotfleetwise:vehicleiotfleetwise:GetVehicle,
iotfleetwise:ListVehicles
aws:iot:tunneliot:DescribeTunnel,
iot:ListTunnels
aws:iotsitewise:assetiotsitewise:DescribeAsset,
iotsitewise:DescribeAssetModel,
iotsitewise:ListAssetModels,
iotsitewise:ListAssets
aws:iotsitewise:asset-modeliotsitewise:DescribeAssetModel,
iotsitewise:ListAssetModels
aws:iotsitewise:dashboardiotsitewise:DescribeDashboard,
iotsitewise:DescribePortal,
iotsitewise:DescribeProject,
iotsitewise:ListDashboards,
iotsitewise:ListPortals,
iotsitewise:ListProjects
aws:iotsitewise:datasetiotsitewise:DescribeDataset,
iotsitewise:ListDatasets
aws:iotsitewise:gatewayiotsitewise:ListGateways
aws:iotsitewise:portaliotsitewise:DescribePortal,
iotsitewise:ListPortals
aws:iotsitewise:projectiotsitewise:DescribePortal,
iotsitewise:DescribeProject,
iotsitewise:ListPortals,
iotsitewise:ListProjects
aws:iotsitewise:timeseriesiotsitewise:ListTimeSeries
aws:iottwinmaker:component-typeiottwinmaker:GetComponentType,
iottwinmaker:GetWorkspace,
iottwinmaker:ListComponentTypes,
iottwinmaker:ListWorkspaces
aws:iottwinmaker:entityiottwinmaker:GetEntity,
iottwinmaker:GetWorkspace,
iottwinmaker:ListEntities,
iottwinmaker:ListWorkspaces
aws:iottwinmaker:sceneiottwinmaker:GetScene,
iottwinmaker:GetWorkspace,
iottwinmaker:ListScenes,
iottwinmaker:ListWorkspaces
aws:iottwinmaker:workspaceiottwinmaker:GetWorkspace,
iottwinmaker:ListWorkspaces
aws:iotwireless:destinationiotwireless:ListDestinations
aws:iotwireless:device-profileiotwireless:GetDeviceProfile,
iotwireless:ListDeviceProfiles
aws:iotwireless:gatewayiotwireless:GetWirelessGateway,
iotwireless:ListWirelessGateways
aws:iotwireless:multicast-groupiotwireless:GetMulticastGroup,
iotwireless:ListMulticastGroups
aws:iotwireless:network-analyzer-configurationiotwireless:GetNetworkAnalyzerConfiguration,
iotwireless:ListNetworkAnalyzerConfigurations
aws:iotwireless:service-profileiotwireless:GetServiceProfile,
iotwireless:ListServiceProfiles
aws:iotwireless:wireless-deviceiotwireless:GetWirelessDevice,
iotwireless:ListWirelessDevices
aws:ivs:channelivs:GetChannel,
ivs:ListChannels
aws:ivs:playback-key-pairivs:ListPlaybackKeyPairs
aws:ivs:playback-restriction-policyivs:ListPlaybackRestrictionPolicies
aws:ivs:recording-configurationivs:GetRecordingConfiguration,
ivs:ListRecordingConfigurations
aws:ivs:stream-keyivs:GetChannel,
ivs:ListChannels,
ivs:ListStreamKeys
aws:ivschat:logging-configurationivschat:GetLoggingConfiguration,
ivschat:ListLoggingConfigurations
aws:ivschat:roomivschat:GetRoom,
ivschat:ListRooms
aws:ivs:compositionivs:GetComposition,
ivs:ListCompositions
aws:ivs:encoder-configurationivs:GetEncoderConfiguration,
ivs:ListEncoderConfigurations
aws:ivs:ingest-configurationivs:GetIngestConfiguration,
ivs:ListIngestConfigurations
aws:ivs:public-keyivs:GetPublicKey,
ivs:ListPublicKeys
aws:ivs:stageivs:GetStage,
ivs:ListStages
aws:ivs:storage-configurationivs:ListStorageConfigurations
aws:kafka:clusterkafka:DescribeClusterV2,
kafka:ListClustersV2
aws:kafka:configurationkafka:ListConfigurations
aws:kafka:nodekafka:DescribeClusterV2,
kafka:ListClustersV2,
kafka:ListNodes
aws:kafka:replicatorkafka:DescribeReplicator,
kafka:ListReplicators
aws:kafka:vpc-connectionkafka:DescribeVpcConnection,
kafka:ListVpcConnections
aws:kafkaconnect:connectorkafkaconnect:DescribeConnector,
kafkaconnect:ListConnectors
aws:kafkaconnect:connector-operationkafkaconnect:DescribeConnector,
kafkaconnect:DescribeConnectorOperation,
kafkaconnect:ListConnectorOperations,
kafkaconnect:ListConnectors
aws:kafkaconnect:custom-pluginkafkaconnect:DescribeCustomPlugin,
kafkaconnect:ListCustomPlugins
aws:kafkaconnect:worker-configurationkafkaconnect:ListWorkerConfigurations
aws:keyspaces:keyspacecassandra:Select
aws:keyspaces:tablecassandra:Select,
cassandra:Select,
cassandra:Select
aws:kinesis:streamkinesis:DescribeStreamSummary,
kinesis:ListStreams
aws:kinesisvideo:channelkinesisvideo:ListSignalingChannels
aws:kinesisvideo:streamkinesisvideo:ListStreams
aws:kms:aliaskms:GetKeyPolicy,
kms:ListAliases
aws:kms:custom-key-storekms:DescribeCustomKeyStores
aws:kms:keykms:DescribeKey,
kms:GetKeyRotationStatus,
kms:ListKeys
aws:lakeformation:data-lake-settingslakeformation:GetDataLakeSettings
aws:lakeformation:permissionslakeformation:ListPermissions
aws:lambda:eventsourcemappinglambda:ListEventSourceMappings,
lambda:ListFunctions
aws:lambda:functionlambda:GetFunction,
lambda:GetPolicy,
lambda:ListFunctionUrlConfigs,
lambda:ListFunctions,
lambda:ListProvisionedConcurrencyConfigs
aws:lambda:codesigningconfiglambda:ListCodeSigningConfigs
aws:lambda:functionlambda:GetPolicy,
lambda:ListFunctions
aws:lambda:layerlambda:GetLayerVersionPolicy,
lambda:ListLayers
aws:launchwizard:deploymentlaunchwizard:GetDeployment,
launchwizard:ListDeployments
aws:lexv2:botlex:DescribeBot,
lex:ListBots
aws:lightsail:alarmlightsail:GetAlarms
aws:lightsail:bucketlightsail:GetBuckets
aws:lightsail:certificatelightsail:GetCertificates
aws:lightsail:container-servicelightsail:GetContainerServices
aws:lightsail:disklightsail:GetDisks
aws:lightsail:disk-snapshotlightsail:GetDiskSnapshots
aws:lightsail:distributionlightsail:GetDistributions
aws:lightsail:instancelightsail:GetInstancePortStates,
lightsail:GetInstances
aws:lightsail:loadbalancerlightsail:GetLoadBalancers
aws:lightsail:relational-databaselightsail:GetRelationalDatabaseParameters,
lightsail:GetRelationalDatabases
aws:lightsail:relational-database-snapshotlightsail:GetRelationalDatabaseSnapshots
aws:lightsail:static-iplightsail:GetStaticIps
aws:location:api-keygeo:DescribeKey,
geo:ListKeys
aws:location:geofence-collectiongeo:DescribeGeofenceCollection,
geo:ListGeofenceCollections
aws:location:mapgeo:DescribeMap,
geo:ListMaps
aws:location:place-indexgeo:DescribePlaceIndex,
geo:ListPlaceIndexes
aws:location:route-calculatorgeo:DescribeRouteCalculator,
geo:ListRouteCalculators
aws:location:trackergeo:DescribeTracker,
geo:ListTrackers
aws:m2:applicationm2:GetApplication,
m2:ListApplications
aws:m2:environmentm2:GetEnvironment,
m2:ListEnvironments
aws:macie2:allow-listmacie2:GetAllowList,
macie2:GetMacieSession,
macie2:ListAllowLists
aws:macie2:custom-data-identifiermacie2:GetCustomDataIdentifier,
macie2:GetMacieSession,
macie2:ListCustomDataIdentifiers
aws:macie2:membermacie2:GetMacieSession,
macie2:ListMembers
aws:macie2:settingsmacie2:GetMacieSession
aws:ses:addon-instanceses:ListAddonInstances
aws:ses:addon-subscriptionses:ListAddonSubscriptions
aws:ses:address-listses:ListAddressLists
aws:ses:archiveses:GetArchive,
ses:ListArchives
aws:ses:ingress-pointses:GetIngressPoint,
ses:ListIngressPoints
aws:ses:relayses:GetRelay,
ses:ListRelays
aws:ses:rule-setses:GetRuleSet,
ses:ListRuleSets
aws:ses:traffic-policyses:GetTrafficPolicy,
ses:ListTrafficPolicies
aws:managedblockchain:accessormanagedblockchain:GetAccessor,
managedblockchain:ListAccessors
aws:managedblockchain:invitationmanagedblockchain:ListInvitations
aws:managedblockchain:membermanagedblockchain:GetMember,
managedblockchain:ListMembers,
managedblockchain:ListNetworks
aws:managedblockchain:networkmanagedblockchain:GetNetwork,
managedblockchain:ListNetworks
aws:managedblockchain:nodemanagedblockchain:GetNode,
managedblockchain:ListMembers,
managedblockchain:ListNetworks,
managedblockchain:ListNodes
aws:managedblockchain:proposalmanagedblockchain:GetProposal,
managedblockchain:ListNetworks,
managedblockchain:ListProposals
aws:mediaconnect:bridgemediaconnect:DescribeBridge,
mediaconnect:ListBridges
aws:mediaconnect:entitlementmediaconnect:ListEntitlements
aws:mediaconnect:flowmediaconnect:DescribeFlow,
mediaconnect:ListFlows
aws:mediaconnect:gatewaymediaconnect:DescribeGateway,
mediaconnect:ListGateways
aws:mediaconnect:gatewayinstancemediaconnect:DescribeGatewayInstance,
mediaconnect:ListGatewayInstances
aws:medialive:channelmedialive:ListChannels
aws:medialive:channel-placement-groupmedialive:ListChannelPlacementGroups,
medialive:ListClusters
aws:medialive:cloudwatch-alarm-templatemedialive:ListCloudWatchAlarmTemplates
aws:medialive:cloudwatch-alarm-template-groupmedialive:ListCloudWatchAlarmTemplateGroups
aws:medialive:clustermedialive:ListClusters
aws:medialive:eventbridge-rule-templatemedialive:ListEventBridgeRuleTemplates
aws:medialive:eventbridge-rule-template-groupmedialive:ListEventBridgeRuleTemplateGroups
aws:medialive:inputmedialive:ListInputs
aws:medialive:input-devicemedialive:ListInputDevices
aws:medialive:input-security-groupmedialive:ListInputSecurityGroups
aws:medialive:multiplexmedialive:ListMultiplexes
aws:medialive:networkmedialive:ListNetworks
aws:medialive:nodemedialive:ListClusters,
medialive:ListNodes
aws:medialive:reservationmedialive:ListReservations
aws:medialive:sdi-sourcemedialive:ListSdiSources
aws:medialive:signal-mapmedialive:ListSignalMaps
aws:mediapackage:harvest-jobsmediapackage:ListHarvestJobs
aws:mediapackage:origin-endpointsmediapackage:ListOriginEndpoints
aws:mediapackage-v2:channelmediapackagev2:GetChannel,
mediapackagev2:GetChannelGroup,
mediapackagev2:GetChannelPolicy,
mediapackagev2:ListChannelGroups,
mediapackagev2:ListChannels
aws:mediapackage-v2:channel-groupmediapackagev2:GetChannelGroup,
mediapackagev2:ListChannelGroups
aws:mediapackage-v2:harvest-jobmediapackagev2:GetChannelGroup,
mediapackagev2:ListChannelGroups,
mediapackagev2:ListHarvestJobs
aws:mediapackage-v2:origin-endpointmediapackagev2:GetChannelGroup,
mediapackagev2:GetOriginEndpoint,
mediapackagev2:GetOriginEndpointPolicy,
mediapackagev2:ListChannelGroups,
mediapackagev2:ListChannels,
mediapackagev2:ListOriginEndpoints
aws:mediapackage-vod:assetsmediapackage-vod:DescribeAsset,
mediapackage-vod:ListAssets
aws:mediapackage-vod:packaging-configurationsmediapackage-vod:ListPackagingConfigurations
aws:mediapackage-vod:packaging-groupsmediapackage-vod:ListPackagingGroups
aws:memorydb:aclmemorydb:DescribeAcls
aws:memorydb:clustermemorydb:DescribeClusters,
memorydb:DescribeMultiRegionClusters
aws:memorydb:parameter-groupmemorydb:DescribeParameterGroups
aws:memorydb:reserved-nodememorydb:DescribeReservedNodes
aws:memorydb:snapshotmemorydb:DescribeSnapshots
aws:memorydb:subnet-groupmemorydb:DescribeSubnetGroups
aws:memorydb:usermemorydb:DescribeUsers
aws:cloudwatch:metricalarmcloudwatch:DescribeAlarms
aws:cloudwatchlogs:metricfilterlogs:DescribeMetricFilters
aws:migrationhubrefactorspaces:applicationrefactor-spaces:ListApplications,
refactor-spaces:ListEnvironments
aws:migrationhubrefactorspaces:environmentrefactor-spaces:ListEnvironments
aws:migrationhubrefactorspaces:routerefactor-spaces:ListApplications,
refactor-spaces:ListEnvironments,
refactor-spaces:ListRoutes
aws:migrationhubrefactorspaces:servicerefactor-spaces:ListApplications,
refactor-spaces:ListEnvironments,
refactor-spaces:ListServices
aws:mq:brokermq:DescribeBroker,
mq:ListBrokers
aws:mq:configurationmq:ListConfigurations
aws:mq:configurationrevisionmq:DescribeConfigurationRevision,
mq:ListConfigurationRevisions,
mq:ListConfigurations
aws:mq:usermq:DescribeBroker,
mq:DescribeUser,
mq:ListBrokers
aws:mwaa:environmentairflow:GetEnvironment,
airflow:ListEnvironments
aws:neptune:clusterrds:DescribeDBClusters
aws:neptune:cluster-snapshotrds:DescribeDBClusterSnapshotAttributes,
rds:DescribeDBClusterSnapshots
aws:neptune:dbinstancerds:DescribeDBInstances
aws:network-firewall:firewallnetwork-firewall:DescribeFirewall,
network-firewall:DescribeFirewallPolicy,
network-firewall:DescribeLoggingConfiguration,
network-firewall:ListFirewalls
aws:network-firewall:rulegroupnetwork-firewall:DescribeRuleGroup,
network-firewall:ListRuleGroups
aws:network-firewall:tls-configurationnetwork-firewall:DescribeTLSInspectionConfiguration,
network-firewall:ListTLSInspectionConfigurations
aws:network-firewall:vpc-endpoint-associationnetwork-firewall:DescribeVpcEndpointAssociation,
network-firewall:ListVpcEndpointAssociations
aws:networkmanager:attachmentnetworkmanager:ListAttachments
aws:networkmanager:connect-peernetworkmanager:GetConnectPeer,
networkmanager:ListConnectPeers
aws:networkmanager:connectionnetworkmanager:DescribeGlobalNetworks,
networkmanager:GetConnections
aws:networkmanager:core-networknetworkmanager:GetCoreNetwork,
networkmanager:ListCoreNetworks
aws:networkmanager:devicenetworkmanager:DescribeGlobalNetworks,
networkmanager:GetDevices
aws:networkmanager:global-networknetworkmanager:DescribeGlobalNetworks
aws:networkmanager:linknetworkmanager:DescribeGlobalNetworks,
networkmanager:GetLinks
aws:networkmanager:peeringnetworkmanager:ListPeerings
aws:networkmanager:sitenetworkmanager:DescribeGlobalNetworks,
networkmanager:GetSites
aws:opensearch:domaines:DescribeDomain,
es:ListDomainNames
aws:opensearchserverless:collectionaoss:BatchGetCollection,
aoss:ListCollections
aws:organizations:accountorganizations:DescribeOrganization,
organizations:ListAccountsForParent,
organizations:ListDelegatedAdministrators,
organizations:ListOrganizationalUnitsForParent,
organizations:ListPoliciesForTarget,
organizations:ListRoots
aws:organizations:featuresorganizations:DescribeOrganization,
organizations:ListDelegatedAdministrators,
iam:ListOrganizationsFeatures
aws:organizations:organizationorganizations:DescribeOrganization,
organizations:ListDelegatedAdministrators
aws:organizations:organizationalunitorganizations:DescribeOrganization,
organizations:ListAccountsForParent,
organizations:ListDelegatedAdministrators,
organizations:ListOrganizationalUnitsForParent,
organizations:ListPoliciesForTarget,
organizations:ListRoots
aws:organizations:policyorganizations:DescribeOrganization,
organizations:DescribePolicy,
organizations:ListDelegatedAdministrators,
organizations:ListPolicies,
organizations:ListTargetsForPolicy
aws:organizations:rootorganizations:DescribeOrganization,
organizations:ListAccountsForParent,
organizations:ListDelegatedAdministrators,
organizations:ListOrganizationalUnitsForParent,
organizations:ListPoliciesForTarget,
organizations:ListRoots
aws:osis:pipelineosis:GetPipeline,
osis:ListPipelines
aws:osis:pipeline-blueprintosis:GetPipelineBlueprint,
osis:ListPipelineBlueprints
aws:payment-cryptography:aliaspayment-cryptography:GetKey,
payment-cryptography:ListAliases,
payment-cryptography:ListKeys
aws:payment-cryptography:keypayment-cryptography:GetKey,
payment-cryptography:ListKeys
aws:pca-connector-ad:connectorpca-connector-ad:ListConnectors
aws:pca-connector-ad:directory-registrationpca-connector-ad:ListDirectoryRegistrations
aws:pca-connector-ad:templatepca-connector-ad:ListConnectors,
pca-connector-ad:ListTemplates
aws:pca-connector-scep:connectorpca-connector-scep:ListConnectors
aws:pcs:clusterpcs:GetCluster,
pcs:ListClusters
aws:pcs:compute-node-grouppcs:GetComputeNodeGroup,
pcs:ListClusters,
pcs:ListComputeNodeGroups
aws:pcs:queuepcs:GetQueue,
pcs:ListClusters,
pcs:ListQueues
aws:personalize:batch-inference-jobpersonalize:DescribeBatchInferenceJob,
personalize:ListBatchInferenceJobs
aws:personalize:batch-segment-jobpersonalize:DescribeBatchSegmentJob,
personalize:ListBatchSegmentJobs
aws:personalize:campaignpersonalize:DescribeCampaign,
personalize:ListCampaigns
aws:personalize:data-deletion-jobpersonalize:DescribeDataDeletionJob,
personalize:ListDataDeletionJobs
aws:personalize:datasetpersonalize:DescribeDataset,
personalize:ListDatasets
aws:personalize:dataset-export-jobpersonalize:DescribeDatasetExportJob,
personalize:ListDatasetExportJobs
aws:personalize:dataset-grouppersonalize:DescribeDatasetGroup,
personalize:ListDatasetGroups
aws:personalize:dataset-import-jobpersonalize:DescribeDatasetImportJob,
personalize:ListDatasetImportJobs
aws:personalize:event-trackerpersonalize:DescribeEventTracker,
personalize:ListEventTrackers
aws:personalize:filterpersonalize:DescribeFilter,
personalize:ListFilters
aws:personalize:metric-attributionpersonalize:DescribeMetricAttribution,
personalize:ListMetricAttributions
aws:personalize:recommenderpersonalize:DescribeRecommender,
personalize:ListRecommenders
aws:personalize:schemapersonalize:DescribeSchema,
personalize:ListSchemas
aws:personalize:solutionpersonalize:DescribeSolution,
personalize:ListSolutions
aws:personalize:algorithmpersonalize:DescribeAlgorithm,
personalize:DescribeRecipe,
personalize:ListRecipes
aws:personalize:feature-transformationpersonalize:DescribeFeatureTransformation,
personalize:DescribeRecipe,
personalize:ListRecipes
aws:personalize:recipepersonalize:DescribeRecipe,
personalize:ListRecipes
aws:pinpoint:appmobiletargeting:GetApps,
mobiletargeting:GetEventStream
aws:pinpoint:campaignmobiletargeting:GetApps,
mobiletargeting:GetCampaigns
aws:pinpoint:channelmobiletargeting:GetApps,
mobiletargeting:GetChannels
aws:pinpoint:journeymobiletargeting:GetApps,
mobiletargeting:ListJourneys
aws:pinpoint:segmentmobiletargeting:GetApps,
mobiletargeting:GetSegments
aws:pinpoint:templatemobiletargeting:ListTemplates
aws:smsvoice:configuration-setsms-voice:DescribeConfigurationSets
aws:smsvoice:opt-out-listsms-voice:DescribeOptOutLists
aws:smsvoice:phone-numbersms-voice:DescribePhoneNumbers
aws:smsvoice:poolsms-voice:DescribePools
aws:smsvoice:protect-configurationsms-voice:DescribeProtectConfigurations
aws:smsvoice:registrationsms-voice:DescribeRegistrations
aws:smsvoice:registration-attachmentsms-voice:DescribeRegistrationAttachments
aws:smsvoice:sender-idsms-voice:DescribeSenderIds
aws:smsvoice:verified-destination-numbersms-voice:DescribeVerifiedDestinationNumbers
aws:pipes:pipepipes:ListPipes
aws:proton:componentproton:GetComponent,
proton:ListComponents
aws:proton:deploymentproton:GetDeployment,
proton:ListDeployments
aws:proton:environmentproton:GetEnvironment,
proton:ListEnvironments
aws:proton:environment-account-connectionproton:GetEnvironmentAccountConnection,
proton:ListEnvironmentAccountConnections
aws:proton:environment-templateproton:GetEnvironmentTemplate,
proton:ListEnvironmentTemplates
aws:proton:environment-template-versionproton:GetEnvironmentTemplate,
proton:GetEnvironmentTemplateVersion,
proton:ListEnvironmentTemplateVersions,
proton:ListEnvironmentTemplates
aws:proton:repositoryproton:GetRepository,
proton:ListRepositories
aws:proton:serviceproton:GetService,
proton:ListServices
aws:proton:service-instanceproton:GetServiceInstance,
proton:ListServiceInstances
aws:proton:service-templateproton:GetServiceTemplate,
proton:ListServiceTemplates
aws:proton:service-template-versionproton:GetServiceTemplate,
proton:GetServiceTemplateVersion,
proton:ListServiceTemplateVersions,
proton:ListServiceTemplates
aws:qbusiness:applicationqbusiness:GetApplication,
qbusiness:ListApplications
aws:qbusiness:data-accessorqbusiness:GetApplication,
qbusiness:GetDataAccessor,
qbusiness:ListApplications,
qbusiness:ListDataAccessors
aws:qbusiness:data-sourceqbusiness:GetApplication,
qbusiness:GetDataSource,
qbusiness:GetIndex,
qbusiness:ListApplications,
qbusiness:ListDataSources,
qbusiness:ListIndices
aws:qbusiness:indexqbusiness:GetApplication,
qbusiness:GetIndex,
qbusiness:ListApplications,
qbusiness:ListIndices
aws:qbusiness:pluginqbusiness:GetApplication,
qbusiness:GetPlugin,
qbusiness:ListApplications,
qbusiness:ListPlugins
aws:qbusiness:retrieverqbusiness:GetApplication,
qbusiness:GetRetriever,
qbusiness:ListApplications,
qbusiness:ListRetrievers
aws:qbusiness:subscriptionqbusiness:GetApplication,
qbusiness:ListApplications,
qbusiness:ListSubscriptions
aws:qbusiness:web-experienceqbusiness:GetApplication,
qbusiness:GetWebExperience,
qbusiness:ListApplications,
qbusiness:ListWebExperiences
aws:quicksight:accountquicksight:DescribeAccountSettings
aws:quicksight:analysisquicksight:DescribeAccountSettings,
quicksight:DescribeAnalysis,
quicksight:ListAnalyses
aws:quicksight:brandquicksight:DescribeAccountSettings,
quicksight:DescribeBrand,
quicksight:ListBrands
aws:quicksight:custom-permissionquicksight:DescribeAccountSettings,
quicksight:ListCustomPermissions
aws:quicksight:dashboardquicksight:DescribeAccountSettings,
quicksight:DescribeDashboard,
quicksight:ListDashboards
aws:quicksight:data-setquicksight:DescribeAccountSettings,
quicksight:ListDataSets
aws:quicksight:data-sourcequicksight:DescribeAccountSettings,
quicksight:ListDataSources
aws:quicksight:folderquicksight:DescribeAccountSettings,
quicksight:DescribeFolder,
quicksight:ListFolders
aws:quicksight:groupquicksight:DescribeAccountSettings,
quicksight:ListGroups,
quicksight:ListNamespaces
aws:quicksight:ingestionquicksight:DescribeAccountSettings,
quicksight:ListDataSets,
quicksight:ListIngestions
aws:quicksight:namespacequicksight:DescribeAccountSettings,
quicksight:ListNamespaces
aws:quicksight:refresh-schedulequicksight:DescribeAccountSettings,
quicksight:ListDataSets,
quicksight:ListRefreshSchedules
aws:quicksight:templatequicksight:DescribeAccountSettings,
quicksight:DescribeTemplate,
quicksight:ListTemplates
aws:quicksight:themequicksight:DescribeAccountSettings,
quicksight:DescribeTheme,
quicksight:ListThemes
aws:quicksight:topicquicksight:DescribeAccountSettings,
quicksight:DescribeTopic,
quicksight:ListTopics
aws:quicksight:userquicksight:DescribeAccountSettings,
quicksight:ListUsers
aws:quicksight:vpc-connectionquicksight:DescribeAccountSettings,
quicksight:ListVPCConnections
aws:ram:customer-managed-permissionram:ListPermissions
aws:ram:resource-shareram:GetResourceShares
aws:ram:resource-share-invitationram:GetResourceShareInvitations
aws:ram:permissionram:ListPermissions
aws:rbin:rulerbin:GetRule,
rbin:ListRules
aws:rds:blue-green-deploymentrds:DescribeBlueGreenDeployments
aws:rds:clusterrds:DescribeDBClusters
aws:rds:cluster-endpointrds:DescribeDBClusterEndpoints,
rds:DescribeDBClusters
aws:rds:cluster-snapshotrds:DescribeDBClusterSnapshotAttributes,
rds:DescribeDBClusterSnapshots
aws:rds:db-cluster-automated-backuprds:DescribeDBClusterAutomatedBackups
aws:rds:db-shard-grouprds:DescribeDBShardGroups
aws:rds:dbclusterparametergrouprds:DescribeDBClusterParameterGroups
aws:rds:dbinstanceautomatedbackuprds:DescribeDBInstanceAutomatedBackups
aws:rds:dbparametergrouprds:DescribeDBParameterGroups
aws:rds:dbsubnetgrouprds:DescribeDBSubnetGroups
aws:rds:eventsubscriptionrds:DescribeEventSubscriptions
aws:rds:exporttaskrds:DescribeExportTasks
aws:rds:globalclusterrds:DescribeGlobalClusters
aws:rds:instancerds:DescribeDBInstances
aws:rds:integrationrds:DescribeIntegrations
aws:rds:optiongrouprds:DescribeOptionGroups
aws:rds:proxyrds:DescribeDBProxies
aws:rds:proxy-endpointrds:DescribeDBProxyEndpoints
aws:rds:proxy-target-grouprds:DescribeDBProxies,
rds:DescribeDBProxyTargetGroups,
rds:DescribeDBProxyTargets
aws:rds:securitygrouprds:DescribeDBSecurityGroups
aws:rds:snapshotrds:DescribeDBSnapshotAttributes,
rds:DescribeDBSnapshots
aws:rds:snapshot-tenant-databaserds:DescribeDBSnapshotTenantDatabases
aws:rds:tenant-databaserds:DescribeTenantDatabases
aws:rds:reserveddbinstancerds:DescribeReservedDBInstances
aws:redshift:clusterredshift:DescribeClusterParameters,
redshift:DescribeClusters,
redshift:DescribeEndpointAccess,
redshift:DescribeLoggingStatus
aws:redshift:eventsubscriptionredshift:DescribeEventSubscriptions
aws:redshift:hsm-client-certificateredshift:DescribeHsmClientCertificates
aws:redshift:hsm-configurationredshift:DescribeHsmConfigurations
aws:redshift:integrationredshift:DescribeIntegrations
aws:redshift:parametergroupredshift:DescribeClusterParameterGroups
aws:redshift:redshift-idc-applicationredshift:DescribeRedshiftIdcApplications
aws:redshift:securitygroupredshift:DescribeClusterSecurityGroups
aws:redshift:snapshotredshift:DescribeClusterSnapshots,
redshift:DescribeClusters
aws:redshift:subnetgroupredshift:DescribeClusterSubnetGroups,
redshift:DescribeClusters
aws:redshiftserverless:endpoint-accessredshift-serverless:ListEndpointAccess
aws:redshiftserverless:managed-workgroupredshift-serverless:ListManagedWorkgroups
aws:redshiftserverless:namespaceredshift-serverless:ListNamespaces
aws:redshiftserverless:recovery-pointredshift-serverless:ListNamespaces,
redshift-serverless:ListRecoveryPoints
aws:redshiftserverless:snapshotredshift-serverless:GetSnapshot,
redshift-serverless:ListNamespaces,
redshift-serverless:ListSnapshots
aws:redshiftserverless:workgroupredshift-serverless:ListWorkgroups
aws:rekognition:collectionrekognition:DescribeCollection,
rekognition:ListCollections
aws:rekognition:projectrekognition:DescribeProjects
aws:rekognition:project-versionrekognition:DescribeProjectVersions,
rekognition:DescribeProjects
aws:rekognition:stream-processorrekognition:DescribeStreamProcessor,
rekognition:ListStreamProcessors
aws:resiliencehub:app-assessmentresiliencehub:DescribeAppAssessment,
resiliencehub:ListAppAssessments
aws:resiliencehub:applicationresiliencehub:DescribeApp,
resiliencehub:ListApps
aws:resiliencehub:resiliency-policyresiliencehub:ListResiliencyPolicies
aws:resourceexplorer2:indexresource-explorer-2:GetIndex
aws:resourceexplorer2:viewresource-explorer-2:GetView,
resource-explorer-2:ListViews
aws:resourceexplorer2:managed-viewresource-explorer-2:GetManagedView,
resource-explorer-2:ListManagedViews
aws:resourcegroups:groupresource-groups:GetGroup,
resource-groups:ListGroups
aws:route53:hostedzoneroute53:GetDNSSEC,
route53:GetHostedZone,
route53:ListHostedZones
aws:route53:queryloggingconfigroute53:ListQueryLoggingConfigs
aws:route53:resourcerecordsetroute53:ListHostedZones,
route53:ListResourceRecordSets
aws:route53domains:domainroute53domains:ListDomains
aws:route53-recovery-control:assertion-safety-ruleroute53-recovery-control-config:ListControlPanels,
route53-recovery-control-config:ListSafetyRules
aws:route53-recovery-control:clusterroute53-recovery-control-config:ListClusters
aws:route53-recovery-control:control-panelroute53-recovery-control-config:ListControlPanels,
route53-recovery-control-config:ListSafetyRules
aws:route53-recovery-control:gating-safety-ruleroute53-recovery-control-config:ListControlPanels,
route53-recovery-control-config:ListSafetyRules
aws:route53-recovery-control:routing-controlroute53-recovery-control-config:ListControlPanels,
route53-recovery-control-config:ListRoutingControls
aws:route53-recovery-readiness:cellroute53-recovery-readiness:ListCells
aws:route53-recovery-readiness:readiness-checkroute53-recovery-readiness:ListReadinessChecks
aws:route53-recovery-readiness:recovery-grouproute53-recovery-readiness:ListRecoveryGroups
aws:route53-recovery-readiness:resource-setroute53-recovery-readiness:ListResourceSets
aws:route53resolver:firewall-configroute53resolver:ListFirewallConfigs
aws:route53resolver:firewall-domain-listroute53resolver:ListFirewallDomainLists
aws:route53resolver:firewall-rule-grouproute53resolver:ListFirewallRuleGroups,
route53resolver:ListFirewallRules
aws:route53resolver:firewall-rule-group-associationroute53resolver:ListFirewallRuleGroupAssociations
aws:route53resolver:outpost-resolverroute53resolver:ListOutpostResolvers
aws:route53resolver:resolver-configroute53resolver:ListResolverConfigs
aws:route53resolver:resolver-dnssec-configroute53resolver:ListResolverDnssecConfigs
aws:route53resolver:resolver-endpointroute53resolver:ListResolverEndpoints
aws:route53resolver:resolver-query-log-configroute53resolver:ListResolverQueryLogConfigs
aws:route53resolver:resolver-ruleroute53resolver:ListResolverRules
aws:rum:app-monitorrum:GetAppMonitor,
rum:ListAppMonitors
aws:s3:buckets3:GetBucketAcl,
s3:GetEncryptionConfiguration,
s3:GetLifecycleConfiguration,
s3:GetBucketLogging,
s3:GetBucketMetadataConfiguration,
s3:GetBucketNotification,
s3:GetBucketOwnershipControls,
s3:GetBucketPolicy,
s3:GetBucketPolicyStatus,
s3:GetReplicationConfiguration,
s3:GetBucketVersioning,
s3:GetBucketWebsite,
s3:GetBucketPublicAccessBlock,
s3:GetInventoryConfiguration,
s3:ListAllMyBuckets
aws:s3:accessgrants3:ListAccessGrants
aws:s3:accesspoints3:GetAccessPointPolicy,
s3:ListAccessPoints
aws:s3express:buckets3express:GetEncryptionConfiguration,
s3express:GetBucketPolicy,
s3express:ListAllMyDirectoryBuckets
aws:s3-object-lambda:object-lambda-access-points3:GetAccessPointForObjectLambda,
s3:ListAccessPointsForObjectLambda
aws:outposts:outposts3-outposts:ListOutpostsWithS3
aws:s3outposts:buckets3-outposts:ListOutpostsWithS3,
s3-outposts:ListRegionalBuckets
aws:s3outposts:endpoints3-outposts:ListEndpoints
aws:s3control:accountpublicaccessblocks3:GetBucketPublicAccessBlock
aws:sagemaker:notebookinstancesagemaker:DescribeNotebookInstance,
sagemaker:ListNotebookInstances
aws:sagemaker:inference-recommendations-jobsagemaker:DescribeInferenceRecommendationsJob,
sagemaker:ListInferenceRecommendationsJobs
aws:sagemaker:pipelinesagemaker:DescribePipeline,
sagemaker:ListPipelines
aws:scheduler:groupscheduler:ListScheduleGroups
aws:scheduler:schedulescheduler:GetSchedule,
scheduler:ListSchedules
aws:schemas:discovererschemas:ListDiscoverers
aws:schemas:registryschemas:ListRegistries
aws:schemas:schemaschemas:DescribeSchema,
schemas:ListRegistries,
schemas:ListSchemas
aws:schemas:aws-schemaschemas:DescribeSchema,
schemas:ListRegistries,
schemas:ListSchemas
aws:schemas:registryschemas:ListRegistries
aws:secretsmanager:secretsecretsmanager:DescribeSecret,
secretsmanager:GetResourcePolicy,
secretsmanager:ListSecrets
aws:securityhub:automation-rulesecurityhub:BatchGetAutomationRules,
securityhub:DescribeHub,
securityhub:ListAutomationRules
aws:securityhub:configuration-policysecurityhub:DescribeHub,
organizations:DescribeOrganization,
securityhub:GetConfigurationPolicy,
securityhub:ListConfigurationPolicies
aws:securityhub:finding-aggregatorsecurityhub:DescribeHub,
securityhub:GetFindingAggregator,
securityhub:ListFindingAggregators
aws:securityhub:hubsecurityhub:DescribeHub
aws:securityhub:productsecurityhub:DescribeHub,
securityhub:DescribeProducts
aws:securitylake:data-lakesecuritylake:ListDataLakes
aws:securitylake:subscribersecuritylake:ListSubscribers
aws:servicecatalog:applicationservicecatalog:GetApplication,
servicecatalog:ListApplications
aws:servicecatalog:attribute-groupservicecatalog:GetAttributeGroup,
servicecatalog:ListAttributeGroups
aws:servicecatalog:portfolioservicecatalog:DescribePortfolio,
servicecatalog:ListPortfolios
aws:servicecatalog:productservicecatalog:DescribeProduct,
servicecatalog:SearchProducts
aws:servicediscovery:namespaceservicediscovery:GetNamespace,
servicediscovery:ListNamespaces
aws:servicediscovery:serviceservicediscovery:GetService,
servicediscovery:ListServices
aws:servicequotas:quota-changeservicequotas:ListRequestedServiceQuotaChangeHistory,
servicequotas:ListServices
aws:ses:configuration-setses:DescribeConfigurationSet,
ses:ListConfigurationSets
aws:ses:custom-verification-email-templateses:GetCustomVerificationEmailTemplate,
ses:ListCustomVerificationEmailTemplates
aws:ses:identityses:GetIdentityDkimAttributes,
ses:GetIdentityMailFromDomainAttributes,
ses:GetIdentityVerificationAttributes,
ses:ListIdentities
aws:ses:templateses:GetTemplate,
ses:ListTemplates
aws:ses:contact-listses:GetContactList,
ses:ListContactLists
aws:ses:dedicated-ip-poolses:GetDedicatedIpPool,
ses:ListDedicatedIpPools
aws:ses:multi-region-endpointses:GetMultiRegionEndpoint,
ses:ListMultiRegionEndpoints
aws:sfn:statemachinestates:DescribeStateMachine,
states:ListStateMachines
aws:sfn:activitystates:DescribeActivity,
states:ListActivities
aws:sfn:executionstates:DescribeExecution,
states:ListExecutions,
states:ListStateMachines
aws:sfn:statemachinealiasstates:DescribeStateMachineAlias,
states:ListStateMachineAliases,
states:ListStateMachines
aws:shield:attackshield:DescribeAttack,
shield:ListAttacks
aws:shield:protectionshield:ListProtections
aws:shield:protection-groupshield:ListProtectionGroups,
shield:ListResourcesInProtectionGroup
aws:shield:settingsshield:DescribeEmergencyContactSettings,
shield:DescribeSubscription,
shield:GetSubscriptionState
aws:signer:signing-profilesigner:GetSigningProfile,
signer:ListSigningProfiles
aws:snowball:clustersnowball:DescribeCluster,
snowball:ListClusters
aws:snowball:jobsnowball:DescribeJob,
snowball:ListJobs
aws:sns:topicsns:GetTopicAttributes,
sns:ListTopics
aws:sns:platform-applicationsns:ListPlatformApplications
aws:socialmessaging:wabasocial-messaging:GetLinkedWhatsAppBusinessAccount,
social-messaging:ListLinkedWhatsAppBusinessAccounts
aws:sqs:queuesqs:GetQueueAttributes,
sqs:GetQueueUrl,
sqs:ListQueues
aws:ssm:documentssm:DescribeDocument,
ssm:DescribeDocumentPermission,
ssm:ListDocuments
aws:ssm:instancessm:DescribeInstanceInformation,
ssm:ListComplianceItems
aws:ssm-incidents:incident-recordssm-incidents:GetIncidentRecord,
ssm-incidents:ListIncidentRecords
aws:ssm-incidents:replication-setssm-incidents:GetReplicationSet,
ssm-incidents:ListReplicationSets
aws:ssm-incidents:response-planssm-incidents:GetResponsePlan,
ssm-incidents:ListResponsePlans
aws:sso:applicationorganizations:DescribeOrganization,
sso:GetApplicationAssignmentConfiguration,
sso:ListApplicationAssignments,
sso:ListApplications,
sso:ListInstances
aws:sso:instancesso:DescribeInstanceAccessControlAttributeConfiguration,
organizations:DescribeOrganization,
sso:ListInstances
aws:sso:permission-setorganizations:DescribeOrganization,
sso:DescribePermissionSet,
sso:GetInlinePolicyForPermissionSet,
sso:GetPermissionsBoundaryForPermissionSet,
sso:ListCustomerManagedPolicyReferencesInPermissionSet,
sso:ListInstances,
sso:ListManagedPoliciesInPermissionSet,
sso:ListPermissionSets
aws:sso:trusted-token-issuerorganizations:DescribeOrganization,
sso:DescribeTrustedTokenIssuer,
sso:ListInstances,
sso:ListTrustedTokenIssuers
aws:sso:application-providersso:ListApplicationProviders
aws:storagegateway:cache-reportstoragegateway:ListCacheReports
aws:storagegateway:devicestoragegateway:DescribeGatewayInformation,
storagegateway:DescribeVTLDevices,
storagegateway:ListGateways
aws:storagegateway:fs-associationstoragegateway:DescribeFileSystemAssociations,
storagegateway:ListFileSystemAssociations
aws:storagegateway:gatewaystoragegateway:DescribeGatewayInformation,
storagegateway:ListGateways
aws:storagegateway:nfs-filesharestoragegateway:DescribeNFSFileShares,
storagegateway:ListFileShares
aws:storagegateway:smb-filesharestoragegateway:DescribeSMBFileShares,
storagegateway:ListFileShares
aws:storagegateway:tapestoragegateway:DescribeGatewayInformation,
storagegateway:DescribeTapes,
storagegateway:ListGateways
aws:storagegateway:tapepoolstoragegateway:ListTapePools
aws:storagegateway:volumestoragegateway:ListVolumes
aws:ec2:subnetec2:DescribeSubnets
aws:synthetics:canarysynthetics:DescribeCanaries
aws:synthetics:groupsynthetics:GetGroup,
synthetics:ListGroups
aws:textract:adaptertextract:GetAdapter,
textract:ListAdapters
aws:textract:adapter-versiontextract:GetAdapterVersion,
textract:ListAdapterVersions,
textract:ListAdapters
aws:timestream:scheduled-querytimestream:ListScheduledQueries
aws:timestreamwrite:tabletimestream:ListTables
aws:transcribe:call-analytics-categorytranscribe:ListCallAnalyticsCategories
aws:transcribe:call-analytics-jobtranscribe:GetCallAnalyticsJob,
transcribe:ListCallAnalyticsJobs
aws:transcribe:language-modeltranscribe:ListLanguageModels
aws:transcribe:medical-scribe-jobtranscribe:GetMedicalScribeJob,
transcribe:ListMedicalScribeJobs
aws:transcribe:medical-transcription-jobtranscribe:GetMedicalTranscriptionJob,
transcribe:ListMedicalTranscriptionJobs
aws:transcribe:medical-vocabularytranscribe:GetMedicalVocabulary,
transcribe:ListMedicalVocabularies
aws:transcribe:transcription-jobtranscribe:GetTranscriptionJob,
transcribe:ListTranscriptionJobs
aws:transcribe:vocabularytranscribe:GetVocabulary,
transcribe:ListVocabularies
aws:transcribe:vocabulary-filtertranscribe:GetVocabularyFilter,
transcribe:ListVocabularyFilters
aws:transfer:agreementtransfer:DescribeAgreement,
transfer:DescribeServer,
transfer:ListAgreements,
transfer:ListServers
aws:transfer:certificatetransfer:DescribeCertificate,
transfer:ListCertificates
aws:transfer:connectortransfer:DescribeConnector,
transfer:ListConnectors
aws:transfer:host-keytransfer:DescribeHostKey,
transfer:DescribeServer,
transfer:ListHostKeys,
transfer:ListServers
aws:transfer:profiletransfer:DescribeProfile,
transfer:ListProfiles
aws:transfer:servertransfer:DescribeServer,
transfer:ListServers
aws:transfer:usertransfer:DescribeServer,
transfer:DescribeUser,
transfer:ListServers,
transfer:ListUsers
aws:transfer:webapptransfer:DescribeWebApp,
transfer:ListWebApps
aws:transfer:workflowtransfer:DescribeWorkflow,
transfer:ListWorkflows
aws:ec2:transitgatewayec2:DescribeTransitGateways
aws:ec2:transitgateway-routetable-announcementec2:DescribeTransitGatewayRouteTableAnnouncements
aws:ec2:transitgatewayattachmentec2:DescribeTransitGatewayAttachments
aws:ec2:transitgatewayconnectpeerec2:DescribeTransitGatewayConnectPeers
aws:ec2:transitgatewaymulticastdomainec2:DescribeTransitGatewayMulticastDomains
aws:ec2:transitgatewaypeeringattachmentec2:DescribeTransitGatewayPeeringAttachments
aws:ec2:transitgatewaypolicytableec2:DescribeTransitGatewayPolicyTables
aws:ec2:transitgatewayroutetableec2:DescribeTransitGatewayRouteTables,
ec2:GetTransitGatewayPrefixListReferences,
ec2:SearchTransitGatewayRoutes
aws:ec2:transitgatewayvpcattachmentec2:DescribeTransitGatewayVpcAttachments
aws:translate:parallel-datatranslate:GetParallelData,
translate:ListParallelData
aws:translate:terminologytranslate:GetTerminology,
translate:ListTerminologies
aws:verifiedpermissions:identity-sourceverifiedpermissions:GetPolicyStore,
verifiedpermissions:ListIdentitySources,
verifiedpermissions:ListPolicyStores
aws:verifiedpermissions:policyverifiedpermissions:GetPolicyStore,
verifiedpermissions:ListPolicies,
verifiedpermissions:ListPolicyStores
aws:verifiedpermissions:policy-storeverifiedpermissions:GetPolicyStore,
verifiedpermissions:ListPolicyStores
aws:verifiedpermissions:policy-templateverifiedpermissions:GetPolicyStore,
verifiedpermissions:ListPolicyStores,
verifiedpermissions:ListPolicyTemplates
aws:vpc-lattice:access-log-subscriptionvpc-lattice:GetService,
vpc-lattice:GetServiceNetwork,
vpc-lattice:ListAccessLogSubscriptions,
vpc-lattice:ListServiceNetworks,
vpc-lattice:ListServices
aws:vpc-lattice:listenervpc-lattice:GetListener,
vpc-lattice:GetService,
vpc-lattice:ListListeners,
vpc-lattice:ListServices
aws:vpc-lattice:resource-configurationvpc-lattice:GetResourceConfiguration,
vpc-lattice:ListResourceConfigurations
aws:vpc-lattice:resource-endpoint-associationvpc-lattice:GetResourceConfiguration,
vpc-lattice:ListResourceConfigurations,
vpc-lattice:ListResourceEndpointAssociations
aws:vpc-lattice:resource-gatewayvpc-lattice:GetResourceGateway,
vpc-lattice:ListResourceGateways
aws:vpc-lattice:rulevpc-lattice:GetListener,
vpc-lattice:GetRule,
vpc-lattice:GetService,
vpc-lattice:ListListeners,
vpc-lattice:ListRules,
vpc-lattice:ListServices
aws:vpc-lattice:servicevpc-lattice:GetService,
vpc-lattice:ListServices
aws:vpc-lattice:service-networkvpc-lattice:GetServiceNetwork,
vpc-lattice:ListServiceNetworks
aws:vpc-lattice:service-network-resource-associationvpc-lattice:ListServiceNetworkResourceAssociations
aws:vpc-lattice:service-network-service-associationvpc-lattice:GetServiceNetwork,
vpc-lattice:ListServiceNetworkServiceAssociations,
vpc-lattice:ListServiceNetworks
aws:vpc-lattice:service-network-vpc-associationvpc-lattice:GetServiceNetwork,
vpc-lattice:ListServiceNetworkVpcAssociations,
vpc-lattice:ListServiceNetworks
aws:vpc-lattice:target-groupvpc-lattice:GetTargetGroup,
vpc-lattice:ListTargetGroups
aws:waf:aclwaf:GetWebACL,
waf:ListWebACLs
aws:waf:rulewaf:GetRule,
waf:ListRules
aws:waf:rulegroupwaf:GetRuleGroup,
waf:ListRuleGroups
aws:wafregional:aclwaf-regional:GetWebACL,
waf-regional:ListWebACLs
aws:wafregional:rulewaf-regional:GetRule,
waf-regional:ListRules
aws:wafregional:rulegroupwaf-regional:GetRuleGroup,
waf-regional:ListRuleGroups
aws:wafv2:aclwafv2:GetLoggingConfiguration,
wafv2:GetWebACL,
wafv2:ListWebACLs
aws:wafv2:ipsetwafv2:GetIPSet,
wafv2:ListIPSets
aws:wafv2:regexpatternsetwafv2:GetRegexPatternSet,
wafv2:ListRegexPatternSets
aws:wafv2:rulegroupwafv2:GetRuleGroup,
wafv2:ListRuleGroups
aws:wafv2:aclwafv2:GetLoggingConfiguration,
wafv2:GetWebACL,
wafv2:ListResourcesForWebACL,
wafv2:ListWebACLs
aws:wafv2:ipsetwafv2:GetIPSet,
wafv2:ListIPSets
aws:wafv2:regexpatternsetwafv2:GetRegexPatternSet,
wafv2:ListRegexPatternSets
aws:wafv2:rulegroupwafv2:GetRuleGroup,
wafv2:ListRuleGroups
aws:workmail:organizationworkmail:DescribeOrganization,
workmail:ListOrganizations
aws:workspaces:applicationworkspaces:DescribeApplications
aws:workspaces:bundleworkspaces:DescribeWorkspaceBundles
aws:workspaces:connection-aliasworkspaces:DescribeConnectionAliases
aws:workspaces:directoryworkspaces:DescribeWorkspaceDirectories
aws:workspaces:imageworkspaces:DescribeWorkspaceImages
aws:workspaces:ip-groupworkspaces:DescribeIpGroups
aws:workspaces:poolworkspaces:DescribeWorkspacesPools
aws:workspaces:workspaceworkspaces:DescribeWorkspaces
aws:workspaces:amazon-bundleworkspaces:DescribeWorkspaceBundles
aws:workspaces-web:browser-settingsworkspaces-web:GetBrowserSettings,
workspaces-web:ListBrowserSettings
aws:workspaces-web:data-protection-settingsworkspaces-web:GetDataProtectionSettings,
workspaces-web:ListDataProtectionSettings
aws:workspaces-web:identity-providerworkspaces-web:GetIdentityProvider,
workspaces-web:ListIdentityProviders,
workspaces-web:ListPortals
aws:workspaces-web:ip-access-settingsworkspaces-web:GetIpAccessSettings,
workspaces-web:ListIpAccessSettings
aws:workspaces-web:network-settingsworkspaces-web:GetNetworkSettings,
workspaces-web:ListNetworkSettings
aws:workspaces-web:portalworkspaces-web:ListPortals
aws:workspaces-web:trust-storeworkspaces-web:GetTrustStore,
workspaces-web:ListTrustStores
aws:workspaces-web:user-access-logging-settingsworkspaces-web:GetUserAccessLoggingSettings,
workspaces-web:ListUserAccessLoggingSettings
aws:workspaces-web:user-settingsworkspaces-web:GetUserSettings,
workspaces-web:ListUserSettings
aws:xray:groupxray:GetGroups
aws:xray:sampling-rulexray:GetSamplingRules
aws:iam:credentialreportiam:GenerateCredentialReport,
iam:GetCredentialReport
Resource TypePermissions
aws:ec2:vpngatewayec2:DescribeVpnGateways
aws:ec2:egressonlyinternetgatewayec2:DescribeEgressOnlyInternetGateways
aws:ec2:vpcinternetgatewayec2:DescribeInternetGateways
aws:ec2:vpcnatgatewayec2:DescribeNatGateways
aws:ec2:vpcendpointconnectionnotificationec2:DescribeVpcEndpointConnectionNotifications
aws:ec2:vpcpeeringconnectionec2:DescribeVpcPeeringConnections
aws:network-firewall:firewallnetwork-firewall:DescribeFirewall,
network-firewall:DescribeFirewallPolicy,
network-firewall:DescribeLoggingConfiguration,
network-firewall:ListFirewalls
aws:ec2:transitgatewayec2:DescribeTransitGateways
Resource TypePermissions
aws:acm:acmacm:DescribeCertificate,
acm:ListCertificates
aws:cloudfront:distributioncloudfront:GetDistribution,
cloudfront:ListDistributions
aws:cloudtrail:trailcloudtrail:DescribeTrails,
cloudtrail:GetEventSelectors,
cloudtrail:GetTrailStatus
aws:docdb:clusterrds:DescribeDBClusters
aws:dynamodb:tabledynamodb:DescribeContinuousBackups,
dynamodb:DescribeTable,
dynamodb:DescribeTimeToLive,
dynamodb:ListTables
aws:ec2:snapshotec2:DescribeSnapshotAttribute,
ec2:DescribeSnapshots
aws:ec2:volumeec2:DescribeVolumes
aws:ec2:imageec2:DescribeImageAttribute,
ec2:DescribeImages
aws:ec2:instanceec2:DescribeInstances
aws:ec2:networkaclec2:DescribeNetworkAcls
aws:ec2:networkinterfaceec2:DescribeNetworkInterfaces
aws:ec2:securitygroupec2:DescribeSecurityGroups
aws:ec2:vpcendpointec2:DescribeVpcEndpoints
aws:ec2:vpcec2:DescribeVpcs
aws:ec2:vpcnatgatewayec2:DescribeNatGateways
aws:ecs:clusterecs:DescribeClusters,
ecs:ListClusters
aws:eks:clustereks:DescribeCluster,
eks:ListClusters
aws:elasticache:clusterelasticache:DescribeCacheClusters
aws:elasticloadbalancing:loadbalancerelasticloadbalancing:DescribeInstanceHealth,
elasticloadbalancing:DescribeLoadBalancerAttributes,
elasticloadbalancing:DescribeLoadBalancerPolicies,
elasticloadbalancing:DescribeLoadBalancers
aws:elasticloadbalancingv2:loadbalancerelasticloadbalancing:DescribeListeners,
elasticloadbalancing:DescribeLoadBalancerAttributes,
elasticloadbalancing:DescribeLoadBalancers
aws:elasticsearchservice:domaines:DescribeElasticsearchDomains,
es:ListDomainNames
aws:iam:accountorganizations:DescribeOrganization,
iam:GetAccountPasswordPolicy,
iam:GetAccountSummary
aws:iam:server-certificateiam:ListServerCertificates
aws:iam:policyiam:GetPolicy,
iam:GetPolicyVersion,
iam:ListPolicies
aws:iam:roleiam:GetAccountAuthorizationDetails,
iam:GetRole,
iam:ListAttachedRolePolicies
aws:iam:useriam:GetLoginProfile,
iam:GetUser,
iam:ListAttachedUserPolicies,
iam:ListGroupsForUser,
iam:ListMFADevices,
iam:ListSSHPublicKeys,
iam:ListUsers,
iam:ListVirtualMFADevices
aws:kms:keykms:DescribeKey,
kms:GetKeyRotationStatus,
kms:ListKeys
aws:lambda:functionlambda:GetFunction,
lambda:GetPolicy,
lambda:ListFunctionUrlConfigs,
lambda:ListFunctions,
lambda:ListProvisionedConcurrencyConfigs
aws:mq:brokermq:DescribeBroker,
mq:ListBrokers
aws:rds:instancerds:DescribeDBInstances
aws:rds:snapshotrds:DescribeDBSnapshotAttributes,
rds:DescribeDBSnapshots
aws:redshift:clusterredshift:DescribeClusterParameters,
redshift:DescribeClusters,
redshift:DescribeEndpointAccess,
redshift:DescribeLoggingStatus
aws:s3:buckets3:GetBucketAcl,
s3:GetEncryptionConfiguration,
s3:GetLifecycleConfiguration,
s3:GetBucketLogging,
s3:GetBucketMetadataConfiguration,
s3:GetBucketNotification,
s3:GetBucketOwnershipControls,
s3:GetBucketPolicy,
s3:GetBucketPolicyStatus,
s3:GetReplicationConfiguration,
s3:GetBucketVersioning,
s3:GetBucketWebsite,
s3:GetBucketPublicAccessBlock,
s3:GetInventoryConfiguration,
s3:ListAllMyBuckets
aws:s3control:accountpublicaccessblocks3:GetBucketPublicAccessBlock
aws:sns:topicsns:GetTopicAttributes,
sns:ListTopics
aws:sqs:queuesqs:GetQueueAttributes,
sqs:GetQueueUrl,
sqs:ListQueues

Próximos lanzamientos

Los permisos enumerados aquí reflejan los recursos que está previsto añadir en los próximos 30 días. Incluye estos permisos en tu política de IAM de integración de AWS existente (con la política SecurityAudit adjunta) para obtener todos los beneficios de la cobertura y el seguimiento de recursos de Datadog.

Cloud Security

Configurar

Si no tienes configurada la integración AWS para tu cuenta AWS, completa el proceso de configuración anterior. Asegúrate de habilitar Cloud Security cuando se mencione.

Nota: Para usar esta función, es necesario configurar la integración de AWS con Delegación de roles.

Para añadir Cloud Security a una integración existente en AWS, sigue los pasos que se indican a continuación para habilitar la recopilación de recursos.

  1. Proporciona los permisos necesarios al rol de IAM Datadog adjuntando la política de AWS gestionada SecurityAudit a tu rol de IAM AWS Datadog. Puedes encontrar este política en la consola de AWS.

  2. Completa la configuración en la página de la integración AWS Datadog con los pasos que se indican a continuación. Como alternativa, puedes utilizar el endpoint de la API Actualizar una integración AWS.

    1. Selecciona la cuenta AWS en la que quieres habilitar la recopilación de recursos.
    2. En la pestaña Resource collection (Recopilación de recursos), haz clic en Enable (Habilitar) junto a Cloud Security. Se te redirigirá a la página de configuración de Cloud Security y se abrirá automáticamente un cuadro de diálogo de configuración para la cuenta seleccionada.
    3. En el cuadro de diálogo de configuración, activa la casilla Enable Resource Scanning (Activar escaneado de recursos).
    4. Haz clic en Done (Hecho) para completar la configuración.

Recopilación de alarmas

Hay dos maneras de enviar alarmas de CloudWatch AWS al Explorador de eventos de Datadog:

  • Sondeo de alarmas: El sondeo de alarmas se incluye de forma predefinida en la integración AWS y recupera las alarmas de las métricas a través de la API DescribeAlarmHistory. Si sigues este método, tus alarmas se organizarán por categorías en la fuente de eventos Amazon Web Services. Nota: El rastreador no recopila alarmas compuestas.
  • Tema SNS: Puedes ver todas las alarmas de CloudWatch AWS en tu Explorador de eventos suscribiendo las alarmas a un tema SNS y luego reenviando los mensajes SNS a Datadog. Para saber cómo recibir mensajes SNS como eventos en Datadog, consulta Recibir mensajes SNS. Si sigues este método, tus alarmas se organizarán por categorías en la fuente de eventos Amazon SNS.

Datos recopilados

Métricas

Nota: Puedes habilitar la recopilación de métricas personalizadas de AWS, así como métricas de servicios para los que Datadog no tiene una integración. Consulta las FAQ sobre la integración de AWS y CloudWatch para obtener más información.

Eventos

Los eventos de AWS se recopilan por cada servicio AWS. Para obtener más información sobre eventos recopilados, consulta la documentación de tu servicio AWS.

Etiquetas (Tags)

Las siguientes etiquetas se recopilan con la integración de AWS. Nota: Algunas etiquetas solo se muestran en determinadas métricas.

IntegraciónClaves de etiqueta de Datadog
Todosregion
API Gatewayapiid, apiname, method, resource, stage
App Runnerinstance, serviceid, servicename
Auto Scalingautoscalinggroupname, autoscaling_group
Billingaccount_id, budget_name, budget_type, currency, servicename, time_unit
CloudFrontdistributionid
CodeBuildproject_name
CodeDeployapplication, creator, deployment_config, deployment_group, deployment_option, deployment_type, status
DirectConnectconnectionid
DynamoDBglobalsecondaryindexname, operation, streamlabel, tablename
EBSvolumeid, volume-name, volume-type
EC2autoscaling_group, availability-zone, image, instance-id, instance-type, kernel, name, security_group_name
ECSclustername, servicename, instance_id
EFSfilesystemid
ElastiCachecachenodeid, cache_node_type, cacheclusterid, cluster_name, engine, engine_version, preferred_availability-zone, replication_group
ElasticBeanstalkenvironmentname, enviromentid
ELBavailability-zone, hostname, loadbalancername, name, targetgroup
EMRcluster_name, jobflowid
ESdedicated_master_enabled, ebs_enabled, elasticsearch_version, instance_type, zone_awareness_enabled
Firehosedeliverystreamname
FSxfilesystemid, filesystemtype
Healthevent_category, status, service
IoTactiontype, protocol, rulename
Kinesisstreamname, name, state
KMSkeyid
Lambdafunctionname, resource, executedversion, memorysize, runtime
Machine Learningmlmodelid, requestmode
MQbroker, queue, topic
OpsWorksstackid, layerid, instanceid
Pollyoperation
RDSauto_minor_version_upgrade, dbinstanceclass, dbclusteridentifier, dbinstanceidentifier, dbname, engine, engineversion, hostname, name, publicly_accessible, secondary_availability-zone
RDS Proxyproxyname, target, targetgroup, targetrole
Redshiftclusteridentifier, latency, nodeid, service_class, stage, wlmid
Route 53healthcheckid
S3bucketname, filterid, storagetype
SESLas claves de las etiquetas son un conjunto personalizado en AWS.
SNStopicname
SQSqueuename
VPCnategatewayid, vpnid, tunnelipaddress
WorkSpacesdirectoryid, workspaceid

Checks de servicio

Solucionar problemas

Para solucionar problemas relacionados con la integración AWS, consulta la guía para la resolución de problemas de integraciones AWS.

Referencias adicionales

Documentación útil adicional, enlaces y artículos: