Amazon Web Services

Overview

Connect to Amazon Web Services (AWS) to:

  • See automatic AWS status updates in your Events Explorer
  • Get CloudWatch metrics for EC2 hosts without installing the Agent
  • Tag your EC2 hosts with EC2-specific information
  • See EC2 scheduled maintenance events in your stream
  • Collect CloudWatch metrics and events from many other AWS products
  • See CloudWatch alarms in your Events Explorer

To quickly get started using the AWS integration, check out the AWS getting started guide.

Datadog’s Amazon Web Services integration collects logs, events, and most metrics from CloudWatch for over 90 AWS services.

Setup

Use one of the following methods to integrate your AWS accounts into Datadog for metric, event, tag, and log collection.

Automatic

Manual

  • Role delegation To set up the AWS integration manually with role delegation, see the manual setup guide.

  • Access keys (GovCloud or China* Only) To set up the AWS integration with access keys, see the manual setup guide.

    * All use of Datadog Services in (or in connection with environments within) mainland China is subject to the disclaimer published in the Restricted Service Locations section on our website.

Note: After setup is complete, you can configure integration settings (such as which AWS regions and integrations to collect data from) in the Datadog AWS integration page.

AWS IAM permissions

AWS IAM permissions enable Datadog to collect metrics, tags, EventBridge events and other data necessary to monitor your AWS environment. To correctly set up the AWS Integration, you must attach the relevant IAM policies to the Datadog AWS Integration IAM Role in your AWS account.

AWS integration IAM policy

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Action": [
        "account:GetAccountInformation",
        "airflow:GetEnvironment",
        "airflow:ListEnvironments",
        "apigateway:GET",
        "appsync:ListGraphqlApis",
        "autoscaling:Describe*",
        "backup:List*",
        "batch:DescribeJobDefinitions",
        "batch:DescribeJobQueues",
        "batch:DescribeJobs",
        "batch:ListJobs",
        "bcm-data-exports:GetExport",
        "bcm-data-exports:ListExports",
        "budgets:ViewBudget",
        "cloudfront:GetDistributionConfig",
        "cloudfront:ListDistributions",
        "cloudtrail:DescribeTrails",
        "cloudtrail:GetTrail",
        "cloudtrail:GetTrailStatus",
        "cloudtrail:ListTrails",
        "cloudtrail:LookupEvents",
        "cloudwatch:Describe*",
        "cloudwatch:Get*",
        "cloudwatch:List*",
        "codebuild:BatchGetProjects",
        "codebuild:ListProjects",
        "codedeploy:BatchGet*",
        "codedeploy:List*",
        "cur:DescribeReportDefinitions",
        "directconnect:Describe*",
        "dms:DescribeReplicationInstances",
        "dynamodb:Describe*",
        "dynamodb:List*",
        "ec2:Describe*",
        "ecs:Describe*",
        "ecs:List*",
        "eks:DescribeCluster",
        "eks:ListClusters",
        "elasticache:Describe*",
        "elasticache:List*",
        "elasticfilesystem:DescribeAccessPoints",
        "elasticfilesystem:DescribeFileSystems",
        "elasticfilesystem:DescribeTags",
        "elasticloadbalancing:Describe*",
        "elasticmapreduce:Describe*",
        "elasticmapreduce:List*",
        "es:DescribeElasticsearchDomains",
        "es:ListDomainNames",
        "es:ListTags",
        "events:CreateEventBus",
        "fsx:DescribeFileSystems",
        "fsx:ListTagsForResource",
        "health:DescribeAffectedEntities",
        "health:DescribeEventDetails",
        "health:DescribeEvents",
        "iam:ListAccountAliases",
        "kinesis:Describe*",
        "kinesis:List*",
        "lambda:List*",
        "logs:DeleteSubscriptionFilter",
        "logs:DescribeDeliveries",
        "logs:DescribeDeliverySources",
        "logs:DescribeLogGroups",
        "logs:DescribeLogStreams",
        "logs:DescribeSubscriptionFilters",
        "logs:FilterLogEvents",
        "logs:GetDeliveryDestination",
        "logs:PutSubscriptionFilter",
        "logs:TestMetricFilter",
        "network-firewall:DescribeLoggingConfiguration",
        "network-firewall:ListFirewalls",
        "oam:ListAttachedLinks",
        "oam:ListSinks",
        "organizations:Describe*",
        "organizations:List*",
        "rds:Describe*",
        "rds:List*",
        "redshift-serverless:ListNamespaces",
        "redshift:DescribeClusters",
        "redshift:DescribeLoggingStatus",
        "route53:List*",
        "route53resolver:ListResolverQueryLogConfigs",
        "s3:GetBucketLocation",
        "s3:GetBucketLogging",
        "s3:GetBucketNotification",
        "s3:GetBucketTagging",
        "s3:ListAllMyBuckets",
        "s3:PutBucketNotification",
        "ses:Get*",
        "ses:List*",
        "sns:GetSubscriptionAttributes",
        "sns:List*",
        "sns:Publish",
        "sqs:ListQueues",
        "ssm:GetServiceSetting",
        "ssm:ListCommands",
        "states:DescribeStateMachine",
        "states:ListStateMachines",
        "support:DescribeTrustedAdvisor*",
        "support:RefreshTrustedAdvisorCheck",
        "tag:GetResources",
        "tag:GetTagKeys",
        "tag:GetTagValues",
        "timestream:DescribeEndpoints",
        "wafv2:ListLoggingConfigurations",
        "xray:BatchGetTraces",
        "xray:GetTraceSummaries"
      ],
      "Effect": "Allow",
      "Resource": "*"
    }
  ]
}

AWS resource collection IAM policy

To use resource collection, you must attach AWS’s managed SecurityAudit Policy to your Datadog IAM role.

Notes:

  • Warning messages appear on the AWS integration tile in Datadog if you enable resource collection, but do not have the AWS Security Audit Policy attached to your Datadog IAM role.
  • To enable Datadog to collect account management resources from account.GetAlternateContact and account.GetContactInformation, you need to enable trusted access for AWS account management.
  • AWS Govcloud and AWS China accounts are not currently supported.
  • Enabling resource collection can also impact your AWS CloudWatch costs. To avoid these charges, disable Usage (AWS/Usage) metrics in the Metric Collection tab of the Datadog AWS integration page.

Log collection

There are two ways of sending AWS service logs to Datadog:

  • Amazon Data Firehose destination: Use the Datadog destination in your Amazon Data Firehose delivery stream to forward logs to Datadog. It is recommended to use this approach when sending logs from CloudWatch in a very high volume.
  • Forwarder Lambda function: Deploy the Datadog Forwarder Lambda function, which subscribes to S3 buckets or your CloudWatch log groups and forwards logs to Datadog. Datadog also recommends you use this approach for sending logs from S3 or other resources that cannot directly stream data to Amazon Data Firehose.

Metric collection

There are two ways to send AWS metrics to Datadog:

  • Metric polling: API polling comes out of the box with the AWS integration. A metric-by-metric crawl of the CloudWatch API pulls data and sends it to Datadog. New metrics are pulled every ten minutes, on average.
  • Metric streams with Amazon Data Firehose: You can use Amazon CloudWatch Metric Streams and Amazon Data Firehose to see your metrics. Note: This method has a two to three minute latency, and requires a separate setup.

You can find a full list of the available sub-integrations on the Integrations page. Many of these integrations are installed by default when Datadog recognizes data coming in from your AWS account. See the AWS Integration Billing page for options to exclude specific resources for cost control.

Resource collection

Some Datadog products leverage information about how your AWS resources (such as S3 buckets, RDS snapshots, and CloudFront distributions) are configured. Datadog collects this information by making read-only API calls to your AWS account.

Note: If you use AWS CloudTrail or GuardDuty, there may be some associated costs. Datadog’s resource collection makes periodic calls to AWS APIs, which can increase CloudTrail log volume (affecting S3 storage costs) and may result in higher GuardDuty charges due to additional data being analyzed.

AWS resource collection IAM policy

To use resource collection, you must attach AWS’s managed SecurityAudit Policy to your Datadog IAM role.

Notes:

  • Warning messages appear on the AWS integration tile in Datadog if you enable resource collection, but do not have the AWS Security Audit Policy attached to your Datadog IAM role.
  • To enable Datadog to collect account management resources from account.GetAlternateContact and account.GetContactInformation, you need to enable trusted access for AWS account management.
  • AWS Govcloud and AWS China accounts are not currently supported.
  • Enabling resource collection can also impact your AWS CloudWatch costs. To avoid these charges, disable Usage (AWS/Usage) metrics in the Metric Collection tab of the Datadog AWS integration page.

Resource types and permissions

The following sections list the resource types collected for different Datadog products, and the associated permissions required for the Datadog IAM role to collect data on your behalf. Add these permissions to your existing AWS integration IAM policy (with attached SecurityAudit policy).

Resource TypePermissions
aws:ec2:volumeec2:DescribeVolumes
aws:ec2:availabilityzoneec2:DescribeAvailabilityZones
aws:ec2:instanceec2:DescribeInstances
Resource TypePermissions
aws:apigateway:apiapigateway:GET
aws:apigatewayv2:apiapigateway:GetApis,
apigateway:GetRoutes
aws:autoscaling:groupautoscaling:DescribeAutoScalingGroups
aws:cloudfront:distributioncloudfront:GetDistribution,
cloudfront:ListDistributions
aws:directconnect:connectiondirectconnect:DescribeConnections
aws:docdb:clusterrds:DescribeDBClusters
aws:dynamodb:tabledynamodb:DescribeContinuousBackups,
dynamodb:DescribeTable,
dynamodb:DescribeTimeToLive,
dynamodb:ListTables
aws:ec2:ebs-encryption-by-defaultec2:GetEbsEncryptionByDefault
aws:ec2:snapshotec2:DescribeSnapshotAttribute,
ec2:DescribeSnapshots
aws:ec2:volumeec2:DescribeVolumes
aws:ec2:availabilityzoneec2:DescribeAvailabilityZones
aws:ec2:customergatewayec2:DescribeCustomerGateways
aws:ec2:vpnconnectionec2:DescribeVpnConnections
aws:ec2:vpngatewayec2:DescribeVpnGateways
aws:ec2:instanceec2:DescribeInstances
aws:ec2:securitygroupec2:DescribeSecurityGroups
aws:ec2:vpcendpointec2:DescribeVpcEndpoints
aws:ec2:vpcec2:DescribeVpcs
aws:ec2:vpcinternetgatewayec2:DescribeInternetGateways
aws:ec2:vpcnatgatewayec2:DescribeNatGateways
aws:ecr:repositoryecr:DescribeRepositories,
ecr:GetLifecyclePolicy,
ecr:GetRepositoryPolicy
aws:ecrpublic:repositoryecr-public:DescribeImages,
ecr-public:DescribeRepositories,
ecr-public:GetRepositoryPolicy
aws:ecs:clusterecs:DescribeClusters,
ecs:ListClusters
aws:ecs:serviceecs:DescribeServices,
ecs:ListClusters,
ecs:ListServices
aws:efs:accesspointelasticfilesystem:DescribeAccessPoints
aws:efs:filesystemelasticfilesystem:DescribeFileSystems,
elasticfilesystem:DescribeLifecycleConfiguration
aws:efs:mounttargetelasticfilesystem:DescribeFileSystems,
elasticfilesystem:DescribeMountTargetSecurityGroups,
elasticfilesystem:DescribeMountTargets
aws:eks:clustereks:DescribeCluster,
eks:ListClusters
aws:eks:nodegroupeks:DescribeCluster,
eks:DescribeNodeGroup,
eks:ListClusters,
eks:ListNodeGroups
aws:elasticache:cachesubnetgroupelasticache:DescribeCacheSubnetGroups
aws:elasticache:parametergroupelasticache:DescribeCacheParameterGroups
aws:elasticache:replicationgroupelasticache:DescribeReplicationGroups
aws:elasticache:securitygroupelasticache:DescribeCacheSecurityGroups
aws:elasticache:snapshotelasticache:DescribeSnapshots
aws:elasticache:userelasticache:DescribeUsers
aws:elasticache:usergroupelasticache:DescribeUserGroups
aws:elasticache:clusterelasticache:DescribeCacheClusters
aws:elasticloadbalancing:loadbalancerelasticloadbalancing:DescribeInstanceHealth,
elasticloadbalancing:DescribeLoadBalancerAttributes,
elasticloadbalancing:DescribeLoadBalancerPolicies,
elasticloadbalancing:DescribeLoadBalancers
aws:elasticloadbalancingv2:loadbalancerelasticloadbalancing:DescribeListeners,
elasticloadbalancing:DescribeLoadBalancerAttributes,
elasticloadbalancing:DescribeLoadBalancers
aws:elasticsearchservice:domaines:DescribeElasticsearchDomains,
es:ListDomainNames
aws:eventbridge:eventbusevents:ListEventBuses,
events:ListRules
aws:fsx:backupfsx:DescribeBackups
aws:fsx:file-systemfsx:DescribeFileSystems
aws:glacier:vaultglacier:GetVaultNotifications,
glacier:ListVaults
aws:keyspaces:keyspacecassandra:Select
aws:kinesis:streamkinesis:DescribeStreamSummary,
kinesis:ListStreams
aws:lambda:functionlambda:GetFunction,
lambda:GetPolicy,
lambda:ListFunctionUrlConfigs,
lambda:ListFunctions,
lambda:ListProvisionedConcurrencyConfigs
aws:neptune:clusterrds:DescribeDBClusters
aws:neptune:cluster-snapshotrds:DescribeDBClusterSnapshotAttributes,
rds:DescribeDBClusterSnapshots
aws:neptune:dbinstancerds:DescribeDBInstances
aws:rds:clusterrds:DescribeDBClusters
aws:rds:cluster-snapshotrds:DescribeDBClusterSnapshotAttributes,
rds:DescribeDBClusterSnapshots
aws:rds:dbclusterparametergrouprds:DescribeDBClusterParameterGroups
aws:rds:dbinstanceautomatedbackuprds:DescribeDBInstanceAutomatedBackups
aws:rds:dbparametergrouprds:DescribeDBParameterGroups
aws:rds:dbsubnetgrouprds:DescribeDBSubnetGroups
aws:rds:eventsubscriptionrds:DescribeEventSubscriptions
aws:rds:exporttaskrds:DescribeExportTasks
aws:rds:instancerds:DescribeDBInstances
aws:rds:optiongrouprds:DescribeOptionGroups
aws:rds:securitygrouprds:DescribeDBSecurityGroups
aws:rds:snapshotrds:DescribeDBSnapshotAttributes,
rds:DescribeDBSnapshots
aws:rds:reserveddbinstancerds:DescribeReservedDBInstances
aws:redshift:eventsubscriptionredshift:DescribeEventSubscriptions
aws:redshift:parametergroupredshift:DescribeClusterParameterGroups
aws:redshift:securitygroupredshift:DescribeClusterSecurityGroups
aws:redshift:snapshotredshift:DescribeClusterSnapshots,
redshift:DescribeClusters
aws:redshift:subnetgroupredshift:DescribeClusterSubnetGroups,
redshift:DescribeClusters
aws:route53:hostedzoneroute53:GetDNSSEC,
route53:GetHostedZone,
route53:ListHostedZones
aws:s3:buckets3:GetBucketAcl,
s3:GetEncryptionConfiguration,
s3:GetLifecycleConfiguration,
s3:GetBucketLogging,
s3:GetBucketMetadataConfiguration,
s3:GetBucketNotification,
s3:GetBucketOwnershipControls,
s3:GetBucketPolicy,
s3:GetBucketPolicyStatus,
s3:GetReplicationConfiguration,
s3:GetBucketVersioning,
s3:GetBucketWebsite,
s3:GetBucketPublicAccessBlock,
s3:GetInventoryConfiguration,
s3:ListAllMyBuckets
aws:sns:subscriptionsns:ListSubscriptions
aws:sns:topicsns:GetTopicAttributes,
sns:ListTopics
aws:sqs:queuesqs:GetQueueAttributes,
sqs:GetQueueUrl,
sqs:ListQueues
aws:ec2:subnetec2:DescribeSubnets
aws:timestreamwrite:tabletimestream:ListTables
aws:ec2:transitgatewayec2:DescribeTransitGateways
aws:waf:aclwaf:GetWebACL,
waf:ListWebACLs
aws:waf:rulewaf:GetRule,
waf:ListRules
aws:waf:rulegroupwaf:GetRuleGroup,
waf:ListRuleGroups
aws:wafregional:aclwaf-regional:GetWebACL,
waf-regional:ListWebACLs
aws:wafregional:rulewaf-regional:GetRule,
waf-regional:ListRules
aws:wafregional:rulegroupwaf-regional:GetRuleGroup,
waf-regional:ListRuleGroups
aws:wafv2:aclwafv2:GetLoggingConfiguration,
wafv2:GetWebACL,
wafv2:ListResourcesForWebACL,
wafv2:ListWebACLs
Resource TypePermissions
aws:accessanalyzer:analyzeraccess-analyzer:GetAnalyzer,
access-analyzer:ListAnalyzers
aws:account:accountorganizations:DescribeOrganization,
account:GetAlternateContact,
account:GetContactInformation,
account:GetPrimaryEmail,
organizations:ListAccounts
aws:acm:acmacm:DescribeCertificate,
acm:ListCertificates
aws:acmpca:certificateauthorityacm-pca:DescribeCertificateAuthority,
acm-pca:ListCertificateAuthorities
aws:amp:rulegroupsnamespaceaps:DescribeRuleGroupsNamespace,
aps:DescribeWorkspace,
aps:ListRuleGroupsNamespaces,
aps:ListWorkspaces
aws:amp:scraperaps:DescribeScraper,
aps:ListScrapers
aws:amp:workspaceaps:DescribeWorkspace,
aps:ListWorkspaces
aws:amplify:appamplify:ListApps
aws:amplify:backend-environmentamplify:ListApps,
amplify:ListBackendEnvironments
aws:amplify:branchamplify:ListApps,
amplify:ListBranches
aws:amplify:domain-associationamplify:ListApps,
amplify:ListDomainAssociations
aws:amplify:jobamplify:ListApps,
amplify:ListBranches,
amplify:ListJobs
aws:amplify:webhookamplify:ListApps,
amplify:ListWebhooks
aws:apigateway:accountapigateway:GetAccount
aws:apigateway:apiapigateway:GET
aws:apigateway:apikeyapigateway:GetApiKeys
aws:apigateway:authorizerapigateway:GetAuthorizers,
apigateway:GET
aws:apigateway:basepathmappingapigateway:GetBasePathMappings,
apigateway:GetDomainNames
aws:apigateway:clientcertificateapigateway:GetClientCertificates
aws:apigateway:deploymentapigateway:GetDeployments,
apigateway:GET
aws:apigateway:documentationpartapigateway:GetDocumentationParts,
apigateway:GET
aws:apigateway:domainnameapigateway:GetDomainNames
aws:apigateway:domainnameaccessassociationapigateway:GetDomainNameAccessAssociations
aws:apigateway:gatewayresponseapigateway:GetGatewayResponses,
apigateway:GET
aws:apigateway:integrationapigateway:GetMethod,
apigateway:GetResources,
apigateway:GET
aws:apigateway:modelapigateway:GetModels,
apigateway:GET
aws:apigateway:requestvalidatorapigateway:GetRequestValidators,
apigateway:GET
aws:apigateway:resourceapigateway:GetResources,
apigateway:GET
aws:apigateway:stageapigateway:GET,
apigateway:GET
aws:apigateway:usageplanapigateway:GetApiKeys,
apigateway:GetUsagePlans
aws:apigateway:usageplankeyapigateway:GetApiKeys,
apigateway:GetUsagePlanKeys,
apigateway:GetUsagePlans
aws:apigateway:vpclinkapigateway:GetVpcLinks
aws:apigatewayv2:apiapigateway:GetApis,
apigateway:GetRoutes
aws:apigatewayv2:apimappingapigateway:GetApiMappings,
apigateway:GetDomainNames
aws:apigatewayv2:authorizerapigateway:GetApis,
apigateway:GetAuthorizers
aws:apigatewayv2:deploymentapigateway:GetApis,
apigateway:GetDeployments
aws:apigatewayv2:domainnameapigateway:GetDomainNames
aws:apigatewayv2:integrationapigateway:GetApis,
apigateway:GetIntegrations
aws:apigatewayv2:integrationresponseapigateway:GetApis,
apigateway:GetIntegrationResponses,
apigateway:GetIntegrations
aws:apigatewayv2:modelapigateway:GetApis,
apigateway:GetModels
aws:apigatewayv2:routeapigateway:GetApis,
apigateway:GetRoutes
aws:apigatewayv2:routeresponseapigateway:GetApis,
apigateway:GetRouteResponses,
apigateway:GetRoutes
aws:apigatewayv2:stageapigateway:GetApis,
apigateway:GetStages
aws:apigatewayv2:vpclinkapigateway:GetVpcLinks
aws:appintegrations:applicationapp-integrations:GetApplication,
app-integrations:ListApplicationAssociations,
app-integrations:ListApplications
aws:appintegrations:application-associationapp-integrations:ListApplicationAssociations,
app-integrations:ListApplications
aws:appintegrations:data-integrationapp-integrations:GetDataIntegration,
app-integrations:ListDataIntegrationAssociations,
app-integrations:ListDataIntegrations
aws:appintegrations:data-integration-associationapp-integrations:ListDataIntegrationAssociations,
app-integrations:ListDataIntegrations
aws:appintegrations:event-integrationapp-integrations:ListEventIntegrations
aws:appintegrations:event-integration-associationapp-integrations:ListEventIntegrationAssociations,
app-integrations:ListEventIntegrations
aws:applicationautoscaling:scalingactivityapplicationautoscaling:DescribeScalingActivities
aws:applicationautoscaling:scalingpolicyapplicationautoscaling:DescribeScalingPolicies
aws:applicationautoscaling:scheduled-actionapplicationautoscaling:DescribeScheduledActions
aws:apprunner:autoscaling-configurationapprunner:DescribeAutoScalingConfiguration,
apprunner:ListAutoScalingConfigurations
aws:apprunner:connectionapprunner:ListConnections
aws:apprunner:observability-configurationapprunner:DescribeObservabilityConfiguration,
apprunner:ListObservabilityConfigurations
aws:apprunner:serviceapprunner:DescribeService,
apprunner:ListServices
aws:apprunner:vpc-connectorapprunner:DescribeVpcConnector,
apprunner:ListVpcConnectors
aws:apprunner:vpc-ingress-connectionapprunner:DescribeVpcIngressConnection,
apprunner:ListVpcIngressConnections
aws:appstream:app-blockappstream:DescribeAppBlocks
aws:appstream:app-block-builderappstream:DescribeAppBlockBuilders
aws:appstream:applicationappstream:DescribeApplications
aws:appstream:fleetappstream:DescribeFleets
aws:appstream:imageappstream:DescribeImages
aws:appstream:image-builderappstream:DescribeImageBuilders
aws:appstream:stackappstream:DescribeStacks
aws:appstream:public-imageappstream:DescribeImages
aws:appsync:apiappsync:ListApis
aws:appsync:channel-namespaceappsync:ListApis,
appsync:ListChannelNamespaces
aws:appsync:data-sourceappsync:ListDataSources,
appsync:ListGraphqlApis
aws:appsync:domain-nameappsync:ListDomainNames
aws:appsync:functionappsync:ListFunctions,
appsync:ListGraphqlApis
aws:appsync:graphqlapiappsync:GetGraphqlApi,
appsync:ListGraphqlApis
aws:appsync:source-api-associationappsync:ListGraphqlApis,
appsync:ListSourceApiAssociations
aws:athena:capacityreservationathena:ListCapacityReservations
aws:athena:datacatalogathena:ListDataCatalogs
aws:athena:named-queryathena:BatchGetNamedQuery,
athena:ListNamedQueries
aws:athena:prepared-statementathena:BatchGetPreparedStatement,
athena:GetWorkGroup,
athena:ListPreparedStatements,
athena:ListWorkGroups
aws:athena:workgroupathena:GetWorkGroup,
athena:ListWorkGroups
aws:auditmanager:assessmentauditmanager:GetAssessment,
auditmanager:ListAssessments
aws:auditmanager:assessmentcontrolsetauditmanager:GetAssessment,
auditmanager:ListAssessments
aws:auditmanager:assessmentframeworkauditmanager:GetAssessmentFramework,
auditmanager:ListAssessmentFrameworks
aws:auditmanager:controlauditmanager:GetControl,
auditmanager:ListControls
aws:autoscaling:groupautoscaling:DescribeAutoScalingGroups
aws:autoscaling:launchconfigurationautoscaling:DescribeLaunchConfigurations
aws:autoscaling:policyautoscaling:DescribePolicies
aws:autoscaling:scheduled-actionautoscaling:DescribeScheduledActions
aws:b2bi:capabilityb2bi:GetCapability,
b2bi:ListCapabilities
aws:b2bi:partnershipb2bi:GetPartnership,
b2bi:GetProfile,
b2bi:ListPartnerships,
b2bi:ListProfiles
aws:b2bi:profileb2bi:GetProfile,
b2bi:ListProfiles
aws:b2bi:transformerb2bi:GetTransformer,
b2bi:ListTransformers
aws:backup:frameworkbackup:DescribeFramework,
backup:ListFrameworks
aws:backup:legalholdbackup:GetLegalHold,
backup:ListLegalHolds
aws:backup:planbackup:ListBackupPlans
aws:backup:protected-resourcebackup:ListProtectedResources
aws:backup:recoverypointbackup:ListBackupVaults,
backup:ListRecoveryPointsByBackupVault
aws:backup:vaultbackup:ListBackupVaults
aws:backup-gateway:gatewaybackup-gateway:GetGateway,
backup-gateway:ListGateways
aws:backup-gateway:hypervisorbackup-gateway:GetHypervisor,
backup-gateway:ListHypervisors
aws:backup-gateway:virtual-machinebackup-gateway:GetVirtualMachine,
backup-gateway:ListVirtualMachines
aws:batch:compute-environmentbatch:DescribeComputeEnvironments
aws:batch:job-definitionbatch:DescribeJobDefinitions
aws:batch:job-queuebatch:DescribeJobQueues
aws:batch:scheduling-policybatch:DescribeSchedulingPolicies,
batch:ListSchedulingPolicies
aws:bedrock:foundationmodelbedrock:GetFoundationModel,
bedrock:ListFoundationModels
aws:bedrock:system-defined-inference-profilebedrock:GetInferenceProfile,
bedrock:ListInferenceProfiles
aws:bedrock:agentbedrock:GetAgent,
bedrock:ListAgentCollaborators,
bedrock:ListAgentVersions,
bedrock:ListAgents
aws:bedrock:agent-action-groupbedrock:GetAgentActionGroup,
bedrock:ListAgentActionGroups,
bedrock:ListAgents
aws:bedrock:agent-aliasbedrock:GetAgentAlias,
bedrock:ListAgentAliases,
bedrock:ListAgents
aws:bedrock:application-inference-profilebedrock:GetInferenceProfile,
bedrock:ListInferenceProfiles
aws:bedrock:blueprintbedrock:GetBlueprint,
bedrock:ListBlueprints
aws:bedrock:custom-modelbedrock:GetCustomModel,
bedrock:ListCustomModels
aws:bedrock:data-sourcebedrock:GetDataSource,
bedrock:GetKnowledgeBase,
bedrock:ListDataSources,
bedrock:ListKnowledgeBaseDocuments,
bedrock:ListKnowledgeBases
aws:bedrock:flowbedrock:GetFlow,
bedrock:GetFlowVersion,
bedrock:ListFlows
aws:bedrock:flow-aliasbedrock:GetFlowAlias,
bedrock:ListFlowAliases,
bedrock:ListFlows
aws:bedrock:guardrailbedrock:GetGuardrail,
bedrock:ListGuardrails,
bedrock:ListGuardrails
aws:bedrock:imported-modelbedrock:GetImportedModel,
bedrock:ListImportedModels
aws:bedrock:ingestion-jobbedrock:GetDataSource,
bedrock:GetIngestionJob,
bedrock:GetKnowledgeBase,
bedrock:ListDataSources,
bedrock:ListIngestionJobs,
bedrock:ListKnowledgeBases
aws:bedrock:knowledge-basebedrock:GetKnowledgeBase,
bedrock:ListKnowledgeBases
aws:bedrock:marketplace-model-endpointbedrock:GetMarketplaceModelEndpoint,
bedrock:ListMarketplaceModelEndpoints
aws:bedrock:promptbedrock:GetPrompt,
bedrock:ListPrompts
aws:bedrock:prompt-routerbedrock:ListPromptRouters
aws:bedrock:provisioned-model-throughputbedrock:ListProvisionedModelThroughputs
aws:bedrock:async-invokebedrock:GetAsyncInvoke,
bedrock:ListAsyncInvokes
aws:bedrock:evaluation-jobbedrock:GetEvaluationJob,
bedrock:ListEvaluationJobs
aws:bedrock:model-copy-jobbedrock:GetModelCopyJob,
bedrock:ListModelCopyJobs
aws:bedrock:model-customization-jobbedrock:GetModelCustomizationJob,
bedrock:ListModelCustomizationJobs
aws:bedrock:model-invocation-jobbedrock:GetModelInvocationJob,
bedrock:ListModelInvocationJobs
aws:bedrock:settingsbedrock:GetModelInvocationLoggingConfiguration
aws:cloudformation:generatedtemplatecloudformation:DescribeGeneratedTemplate,
cloudformation:ListGeneratedTemplates
aws:cloudformation:resourcescancloudformation:DescribeResourceScan,
cloudformation:ListResourceScans
aws:cloudformation:stackcloudformation:DescribeStacks,
cloudformation:ListStacks
aws:cloudformation:stacksetcloudformation:ListStackSets
aws:cloudformation:typecloudformation:ListTypes
aws:cloudfront:anycast-ip-listcloudfront:GetAnycastIpList,
cloudfront:ListAnycastIpLists
aws:cloudfront:cache-policycloudfront:GetCachePolicy,
cloudfront:ListCachePolicies
aws:cloudfront:continuous-deployment-policycloudfront:GetContinuousDeploymentPolicy,
cloudfront:ListContinuousDeploymentPolicies
aws:cloudfront:distributioncloudfront:GetDistribution,
cloudfront:ListDistributions
aws:cloudfront:field-level-encryption-configcloudfront:GetFieldLevelEncryptionConfig,
cloudfront:ListFieldLevelEncryptionConfigs
aws:cloudfront:field-level-encryption-profilecloudfront:GetFieldLevelEncryptionProfile,
cloudfront:ListFieldLevelEncryptionProfiles
aws:cloudfront:functioncloudfront:ListFunctions
aws:cloudfront:keygroupcloudfront:ListKeyGroups
aws:cloudfront:origin-request-policycloudfront:GetOriginRequestPolicy,
cloudfront:ListOriginRequestPolicies
aws:cloudfront:originaccesscontrolcloudfront:ListOriginAccessControls
aws:cloudfront:publickeycloudfront:ListPublicKeys
aws:cloudfront:realtime-log-configcloudfront:ListRealtimeLogConfigs
aws:cloudfront:response-headers-policycloudfront:GetResponseHeadersPolicy,
cloudfront:ListResponseHeadersPolicies
aws:cloudfront:streaming-distributioncloudfront:GetStreamingDistribution,
cloudfront:ListStreamingDistributions
aws:cloudfront:vpc-origincloudfront:GetVpcOrigin,
cloudfront:ListVpcOrigins
aws:cloudfront:managed-cache-policycloudfront:GetCachePolicy,
cloudfront:ListCachePolicies
aws:cloudfront:managed-origin-request-policycloudfront:GetOriginRequestPolicy,
cloudfront:ListOriginRequestPolicies
aws:cloudfront:managed-response-headers-policycloudfront:GetResponseHeadersPolicy,
cloudfront:ListResponseHeadersPolicies
aws:cloudhsm:backupcloudhsm:DescribeBackups
aws:cloudhsm:clustercloudhsm:DescribeClusters
aws:cloudtrail:trailcloudtrail:DescribeTrails,
cloudtrail:GetEventSelectors,
cloudtrail:GetTrailStatus
aws:cloudwatchlogs:log-grouplogs:DescribeLogGroups,
logs:DescribeSubscriptionFilters
aws:cloudwatchlogs:metricfilterlogs:DescribeMetricFilters
aws:codeartifact:domaincodeartifact:DescribeDomain,
codeartifact:ListDomains
aws:codeartifact:packagecodeartifact:ListPackages,
codeartifact:ListRepositories
aws:codeartifact:package-groupcodeartifact:DescribePackageGroup,
codeartifact:ListDomains,
codeartifact:ListPackageGroups
aws:codeartifact:repositorycodeartifact:DescribeRepository,
codeartifact:ListRepositories
aws:codebuild:projectcodebuild:BatchGetProjects,
codebuild:ListProjects
aws:codebuild:source-credentialscodebuild:ListSourceCredentials
aws:codedeploy:applicationcodedeploy:BatchGetApplications,
codedeploy:ListApplications
aws:codedeploy:deployment-configcodedeploy:GetDeploymentConfig,
codedeploy:ListDeploymentConfigs
aws:codeguru-profiler:findingcodeguru-profiler:ListFindingsReports,
codeguru-profiler:ListProfilingGroups
aws:codeguru-profiler:profilinggroupcodeguru-profiler:ListProfilingGroups
aws:codeguru-reviewer:associationcodeguru-reviewer:ListRepositoryAssociations
aws:codeguru-reviewer:codereviewcodeguru-reviewer:ListCodeReviews
aws:codeguru-security:findingcodeguru-security:GetFindings,
codeguru-security:ListScans
aws:codeguru-security:scannamecodeguru-security:GetScan,
codeguru-security:ListScans
aws:codepipeline:actiontypecodepipeline:GetActionType,
codepipeline:ListActionTypes
aws:codepipeline:pipelinecodepipeline:GetPipeline,
codepipeline:ListPipelines
aws:codepipeline:webhookcodepipeline:ListWebhooks
aws:cognitoidentity:identitypoolcognito-identity:DescribeIdentityPool,
cognito-identity:GetIdentityPoolRoles,
cognito-identity:ListIdentityPools
aws:cognitoidentityprovider:userpoolcognito-idp:DescribeUserPool,
cognito-idp:ListIdentityProviders,
cognito-idp:ListUserPools
aws:comprehend:document-classification-jobcomprehend:ListDocumentClassificationJobs
aws:comprehend:document-classifiercomprehend:ListDocumentClassifiers
aws:comprehend:dominant-language-detection-jobcomprehend:ListDominantLanguageDetectionJobs
aws:comprehend:endpointcomprehend:ListEndpoints
aws:comprehend:entities-detection-jobcomprehend:ListEntitiesDetectionJobs
aws:comprehend:entity-recognizercomprehend:ListEntityRecognizers
aws:comprehend:events-detection-jobcomprehend:ListEventsDetectionJobs
aws:comprehend:flywheelcomprehend:DescribeFlywheel,
comprehend:ListFlywheels
aws:comprehend:flywheel-datasetcomprehend:DescribeFlywheel,
comprehend:ListDatasets,
comprehend:ListFlywheels
aws:comprehend:key-phrases-detection-jobcomprehend:ListKeyPhrasesDetectionJobs
aws:comprehend:pii-entities-detection-jobcomprehend:ListPiiEntitiesDetectionJobs
aws:comprehend:sentiment-detection-jobcomprehend:ListSentimentDetectionJobs
aws:comprehend:targeted-sentiment-detection-jobcomprehend:ListTargetedSentimentDetectionJobs
aws:comprehend:topics-detection-jobcomprehend:ListTopicsDetectionJobs
aws:configservice:recorderconfig:DescribeConfigurationRecorders
aws:configservice:recorderstatusconfig:DescribeConfigurationRecorderStatus
aws:connect:agent-statusconnect:DescribeAgentStatus,
connect:DescribeInstance,
connect:ListAgentStatuses,
connect:ListInstances
aws:connect:authentication-profileconnect:DescribeAuthenticationProfile,
connect:DescribeInstance,
connect:ListAuthenticationProfiles,
connect:ListInstances
aws:connect:contact-flowconnect:DescribeContactFlow,
connect:DescribeInstance,
connect:ListContactFlows,
connect:ListInstances
aws:connect:contact-flow-moduleconnect:DescribeContactFlowModule,
connect:DescribeInstance,
connect:ListContactFlowModules,
connect:ListInstances
aws:connect:hours-of-operationconnect:DescribeHoursOfOperation,
connect:DescribeInstance,
connect:ListHoursOfOperations,
connect:ListInstances
aws:connect:instanceconnect:DescribeInstance,
connect:ListInstances
aws:connect:integration-associationconnect:DescribeInstance,
connect:ListInstances,
connect:ListIntegrationAssociations
aws:connect:queueconnect:DescribeInstance,
connect:DescribeQueue,
connect:ListInstances,
connect:ListQueues
aws:connect:quick-connectconnect:DescribeInstance,
connect:DescribeQuickConnect,
connect:ListInstances,
connect:ListQuickConnects
aws:connect:routing-profileconnect:DescribeInstance,
connect:DescribeRoutingProfile,
connect:ListInstances,
connect:ListRoutingProfiles
aws:connect:security-profileconnect:DescribeInstance,
connect:DescribeSecurityProfile,
connect:ListInstances,
connect:ListSecurityProfiles
aws:connect:userconnect:DescribeInstance,
connect:DescribeUser,
connect:ListInstances,
connect:ListUsers
aws:controltower:enabled-baselinecontroltower:ListEnabledBaselines
aws:controltower:enabled-controlcontroltower:ListEnabledControls
aws:controltower:landing-zonecontroltower:GetLandingZone,
controltower:ListLandingZones
aws:costexplorer:anomalymonitorce:GetAnomalyMonitors
aws:costexplorer:anomalysubscriptionce:GetAnomalySubscriptions
aws:costexplorer:costcategoryce:DescribeCostCategoryDefinition,
ce:GetCostCategories
aws:profile:domainprofile:GetDomain,
profile:ListDomains
aws:dms:certificatedms:DescribeCertificates
aws:dms:data-migrationdms:DescribeDataMigrations
aws:dms:data-providerdms:DescribeDataProviders
aws:dms:endpointdms:DescribeEndpoints
aws:dms:event-subscriptiondms:DescribeEventSubscriptions
aws:dms:instance-profiledms:DescribeInstanceProfiles
aws:dms:migration-projectdms:DescribeMigrationProjects
aws:dms:replication-configdms:DescribeReplicationConfigs
aws:dms:replication-subnet-groupdms:DescribeReplicationSubnetGroups
aws:dms:replicationinstancedms:DescribeReplicationInstances
aws:dms:replicationtaskdms:DescribeReplicationTasks
aws:databrew:datasetdatabrew:ListDatasets
aws:databrew:jobdatabrew:ListJobs
aws:databrew:projectdatabrew:ListProjects
aws:databrew:recipedatabrew:ListRecipes
aws:databrew:rulesetdatabrew:ListRulesets
aws:databrew:scheduledatabrew:ListSchedules
aws:datasync:agentdatasync:DescribeAgent,
datasync:ListAgents
aws:datasync:location-efsdatasync:DescribeLocationEfs,
datasync:ListLocations
aws:datasync:location-fsx-lustredatasync:DescribeLocationFsxLustre,
datasync:ListLocations
aws:datasync:location-fsx-ontapdatasync:DescribeLocationFsxOntap,
datasync:ListLocations
aws:datasync:location-fsx-openzfsdatasync:DescribeLocationFsxOpenZfs,
datasync:ListLocations
aws:datasync:location-fsx-windowsdatasync:DescribeLocationFsxWindows,
datasync:ListLocations
aws:datasync:location-hdfsdatasync:DescribeLocationHdfs,
datasync:ListLocations
aws:datasync:location-nfsdatasync:DescribeLocationNfs,
datasync:ListLocations
aws:datasync:location-objectstoragedatasync:DescribeLocationObjectStorage,
datasync:ListLocations
aws:datasync:location-s3datasync:DescribeLocationS3,
datasync:ListLocations
aws:datasync:location-smbdatasync:DescribeLocationSmb,
datasync:ListLocations
aws:datasync:taskdatasync:DescribeTask,
datasync:ListTasks
aws:datazone:domaindatazone:GetDomain,
datazone:ListDomains
aws:dax:clusterdax:DescribeClusters
aws:deadline:budgetdeadline:GetBudget,
deadline:ListBudgets,
deadline:ListFarms
aws:deadline:farmdeadline:ListFarms
aws:deadline:fleetdeadline:ListFarms,
deadline:ListFleets
aws:deadline:license-endpointdeadline:GetLicenseEndpoint,
deadline:ListLicenseEndpoints
aws:deadline:monitordeadline:ListMonitors
aws:deadline:queuedeadline:GetQueue,
deadline:ListFarms,
deadline:ListQueues
aws:deadline:workerdeadline:ListFarms,
deadline:ListFleets,
deadline:ListWorkers
aws:detective:graphdetective:ListGraphs
aws:devicefarm:devicedevicefarm:ListDevices,
devicefarm:ListProjects
aws:devicefarm:deviceinstancedevicefarm:ListDeviceInstances
aws:devicefarm:devicepooldevicefarm:ListDevicePools,
devicefarm:ListProjects
aws:devicefarm:instanceprofiledevicefarm:ListInstanceProfiles
aws:devicefarm:networkprofiledevicefarm:ListNetworkProfiles,
devicefarm:ListProjects
aws:devicefarm:projectdevicefarm:ListProjects
aws:devicefarm:sessiondevicefarm:ListProjects,
devicefarm:ListRemoteAccessSessions
aws:devicefarm:testgrid-projectdevicefarm:ListTestGridProjects
aws:devicefarm:testgrid-sessiondevicefarm:ListTestGridProjects,
devicefarm:ListTestGridSessions
aws:devicefarm:uploaddevicefarm:GetUpload,
devicefarm:ListProjects,
devicefarm:ListUploads
aws:devicefarm:vpceconfigurationdevicefarm:ListVPCEConfigurations
aws:directconnect:connectiondirectconnect:DescribeConnections
aws:directconnect:gatewaydirectconnect:DescribeDirectConnectGatewayAssociations,
directconnect:DescribeDirectConnectGateways
aws:directconnect:virtualinterfacedirectconnect:DescribeVirtualInterfaces
aws:ds:directoryds:DescribeDirectories
aws:dlm:policydlm:GetLifecyclePolicies,
dlm:GetLifecyclePolicy
aws:docdb:clusterrds:DescribeDBClusters
aws:docdb:clustersnapshotrds:DescribeDBClusterSnapshotAttributes,
rds:DescribeDBClusterSnapshots,
rds:DescribeDBClusters
aws:docdb:dbinstancerds:DescribeDBInstances
aws:docdbelastic:clusterdocdb-elastic:GetCluster,
docdb-elastic:ListClusters
aws:docdbelastic:cluster-snapshotdocdb-elastic:GetClusterSnapshot,
docdb-elastic:ListClusterSnapshots
aws:drs:jobdrs:DescribeJobs
aws:drs:launch-configuration-templatedrs:DescribeLaunchConfigurationTemplates
aws:drs:recovery-instancedrs:DescribeRecoveryInstances
aws:drs:replication-configuration-templatedrs:DescribeReplicationConfigurationTemplates
aws:drs:source-networkdrs:DescribeSourceNetworks
aws:drs:source-serverdrs:DescribeSourceServers
aws:dsql:clusterdsql:GetCluster,
dsql:ListClusters
aws:dynamodb:backupdynamodb:DescribeBackup,
dynamodb:ListBackups
aws:dynamodb:global-tabledynamodb:DescribeGlobalTable,
dynamodb:ListGlobalTables
aws:dynamodb:streamdynamodb:DescribeStream,
dynamodb:ListStreams
aws:dynamodb:tabledynamodb:DescribeContinuousBackups,
dynamodb:DescribeTable,
dynamodb:DescribeTimeToLive,
dynamodb:ListTables
aws:dynamodb:exportdynamodb:DescribeExport,
dynamodb:ListExports
aws:ec2:ebs-encryption-by-defaultec2:GetEbsEncryptionByDefault
aws:ec2:snapshotec2:DescribeSnapshotAttribute,
ec2:DescribeSnapshots
aws:ec2:volumeec2:DescribeVolumes
aws:ec2:imageec2:DescribeImageAttribute,
ec2:DescribeImages
aws:ec2:availabilityzoneec2:DescribeAvailabilityZones
aws:ec2:instance-event-windowec2:DescribeInstanceEventWindows
aws:ec2:fpga-imageec2:DescribeFpgaImages
aws:ec2:carriergatewayec2:DescribeCarrierGateways
aws:ec2:customergatewayec2:DescribeCustomerGateways
aws:ec2:vpnconnectionec2:DescribeVpnConnections
aws:ec2:vpngatewayec2:DescribeVpnGateways
aws:ec2:instanceec2:DescribeInstances
aws:ec2:instancetypeec2:DescribeInstanceTypes
aws:ec2:launchtemplateec2:DescribeLaunchTemplates
aws:ec2:launchtemplateversionec2:DescribeLaunchTemplateVersions,
ec2:DescribeLaunchTemplates
aws:ec2:co-ip-poolec2:DescribeCoipPools
aws:ec2:local-gatewayec2:DescribeLocalGateways
aws:ec2:local-gateway-route-tableec2:DescribeLocalGatewayRouteTables
aws:ec2:local-gateway-route-table-vpc-associationec2:DescribeLocalGatewayRouteTableVpcAssociations
aws:ec2:local-gateway-virtual-interfaceec2:DescribeLocalGatewayVirtualInterfaces
aws:ec2:local-gateway-virtual-interface-groupec2:DescribeLocalGatewayVirtualInterfaceGroups
aws:ec2:dhcpoptionsec2:DescribeDhcpOptions
aws:ec2:instanceconnectendpointec2:DescribeInstanceConnectEndpoints
aws:ec2:ipamec2:DescribeIpams
aws:ec2:ipam-external-resource-verification-tokenec2:DescribeIpamExternalResourceVerificationTokens
aws:ec2:ipam-poolec2:DescribeIpamPools
aws:ec2:ipam-resource-discoveryec2:DescribeIpamResourceDiscoveries
aws:ec2:ipam-resource-discovery-associationec2:DescribeIpamResourceDiscoveryAssociations
aws:ec2:ipam-scopeec2:DescribeIpamScopes
aws:ec2:ipv6pool-ec2ec2:DescribeIpv6Pools
aws:ec2:keypairec2:DescribeKeyPairs
aws:ec2:networkaclec2:DescribeNetworkAcls
aws:ec2:placementgroupec2:DescribePlacementGroups
aws:ec2:networkinterfaceec2:DescribeNetworkInterfaces
aws:ec2:customermanagedprefixlistec2:DescribeManagedPrefixLists,
ec2:GetManagedPrefixListEntries
aws:ec2:awsmanagedprefixlistec2:DescribeManagedPrefixLists,
ec2:GetManagedPrefixListEntries
aws:ec2:public-fpga-imageec2:DescribeFpgaImages
aws:ec2:publicimageec2:DescribeImages
aws:ec2:regionec2:DescribeRegions
aws:ec2:capacityreservationec2:DescribeCapacityReservations
aws:ec2:capacityreservationfleetec2:DescribeCapacityReservationFleets
aws:ec2:dedicatedhostec2:DescribeHosts
aws:ec2:fleetec2:DescribeFleets
aws:ec2:reservedinstanceec2:DescribeReservedInstances
aws:ec2:spotfleetrequestec2:DescribeSpotFleetRequests
aws:ec2:spotinstancerequestec2:DescribeSpotInstanceRequests
aws:ec2:securitygroupec2:DescribeSecurityGroups
aws:ec2:securitygroupruleec2:DescribeSecurityGroupRules,
ec2:DescribeSecurityGroups
aws:ec2:settingsec2:DescribeVpcBlockPublicAccessExclusions,
ec2:DescribeVpcBlockPublicAccessOptions,
ec2:GetAllowedImagesSettings,
ec2:GetEbsDefaultKmsKeyId,
ec2:GetEbsEncryptionByDefault,
ec2:GetImageBlockPublicAccessState,
ec2:GetInstanceMetadataDefaults,
ec2:GetSerialConsoleAccessStatus,
ec2:GetSnapshotBlockPublicAccessState
aws:ec2:traffic-mirror-filterec2:DescribeTrafficMirrorFilters
aws:ec2:traffic-mirror-filter-ruleec2:DescribeTrafficMirrorFilterRules,
ec2:DescribeTrafficMirrorFilters
aws:ec2:traffic-mirror-sessionec2:DescribeTrafficMirrorSessions
aws:ec2:traffic-mirror-targetec2:DescribeTrafficMirrorTargets
aws:ec2:verified-access-endpointec2:DescribeVerifiedAccessEndpoints,
ec2:GetVerifiedAccessEndpointPolicy,
ec2:GetVerifiedAccessEndpointTargets
aws:ec2:verified-access-groupec2:DescribeVerifiedAccessGroups,
ec2:GetVerifiedAccessGroupPolicy
aws:ec2:verified-access-instanceec2:DescribeVerifiedAccessInstances
aws:ec2:verified-access-trust-providerec2:DescribeVerifiedAccessTrustProviders
aws:ec2:vpcendpointec2:DescribeVpcEndpoints
aws:ec2:vpcendpoint-serviceec2:DescribeVpcEndpointServices
aws:ec2:vpcendpoint-service-permissionec2:DescribeVpcEndpointServicePermissions,
ec2:DescribeVpcEndpointServices
aws:ec2:vpcec2:DescribeVpcs
aws:ec2:vpcflowlogec2:DescribeFlowLogs
aws:ec2:egressonlyinternetgatewayec2:DescribeEgressOnlyInternetGateways
aws:ec2:elasticipec2:DescribeAddresses
aws:ec2:vpcinternetgatewayec2:DescribeInternetGateways
aws:ec2:vpcnatgatewayec2:DescribeNatGateways
aws:ec2:routetableec2:DescribeRouteTables
aws:ec2:vpcendpointconnectionnotificationec2:DescribeVpcEndpointConnectionNotifications
aws:ec2:vpcpeeringconnectionec2:DescribeVpcPeeringConnections
aws:ec2:client-vpn-endpointec2:DescribeClientVpnEndpoints
aws:ecr:imageecr:DescribeImages,
ecr:DescribeRepositories
aws:ecr:repositoryecr:DescribeRepositories,
ecr:GetLifecyclePolicy,
ecr:GetRepositoryPolicy
aws:ecr:registryecr:DescribeRegistry,
ecr:GetRegistryPolicy,
ecr:GetRegistryScanningConfiguration
aws:ecrpublic:imageecr-public:DescribeImages,
ecr-public:DescribeRepositories
aws:ecrpublic:repositoryecr-public:DescribeImages,
ecr-public:DescribeRepositories,
ecr-public:GetRepositoryPolicy
aws:ecrpublic:registryecr-public:DescribeRegistries
aws:ecs:capacityproviderecs:DescribeCapacityProviders
aws:ecs:clusterecs:DescribeClusters,
ecs:ListClusters
aws:ecs:instanceecs:DescribeContainerInstances,
ecs:ListClusters,
ecs:ListContainerInstances
aws:ecs:serviceecs:DescribeServices,
ecs:ListClusters,
ecs:ListServices
aws:ecs:service-deploymentecs:DescribeServiceDeployments,
ecs:DescribeServices,
ecs:ListClusters,
ecs:ListServiceDeployments,
ecs:ListServices
aws:ecs:taskecs:DescribeServices,
ecs:DescribeTasks,
ecs:ListClusters,
ecs:ListServices,
ecs:ListTasks
aws:ecs:task-definitionecs:DescribeServices,
ecs:DescribeTaskDefinition,
ecs:DescribeTasks,
ecs:ListClusters,
ecs:ListServices,
ecs:ListTasks
aws:efs:accesspointelasticfilesystem:DescribeAccessPoints
aws:efs:filesystemelasticfilesystem:DescribeFileSystems,
elasticfilesystem:DescribeLifecycleConfiguration
aws:efs:mounttargetelasticfilesystem:DescribeFileSystems,
elasticfilesystem:DescribeMountTargetSecurityGroups,
elasticfilesystem:DescribeMountTargets
aws:eks:access-entryeks:DescribeAccessEntry,
eks:DescribeCluster,
eks:ListAccessEntries,
eks:ListClusters
aws:eks:access-policyeks:DescribeAccessEntry,
eks:DescribeCluster,
eks:ListAccessEntries,
eks:ListAssociatedAccessPolicies,
eks:ListClusters
aws:eks:addoneks:DescribeAddon,
eks:DescribeCluster,
eks:ListAddons,
eks:ListClusters
aws:eks:clustereks:DescribeCluster,
eks:ListClusters
aws:eks:eks-anywhere-subscriptioneks:ListEksAnywhereSubscriptions
aws:eks:fargateprofileeks:DescribeCluster,
eks:DescribeFargateProfile,
eks:ListClusters,
eks:ListFargateProfiles
aws:eks:identityproviderconfigeks:DescribeCluster,
eks:DescribeIdentityProviderConfig,
eks:ListClusters,
eks:ListIdentityProviderConfigs
aws:eks:insighteks:DescribeCluster,
eks:DescribeInsight,
eks:ListClusters,
eks:ListInsights
aws:eks:nodegroupeks:DescribeCluster,
eks:DescribeNodeGroup,
eks:ListClusters,
eks:ListNodeGroups
aws:eks:podidentityassociationeks:DescribeCluster,
eks:DescribePodIdentityAssociation,
eks:ListClusters,
eks:ListPodIdentityAssociations
aws:eks:updateeks:DescribeCluster,
eks:DescribeUpdate,
eks:ListClusters,
eks:ListUpdates
aws:elasticache:cachesubnetgroupelasticache:DescribeCacheSubnetGroups
aws:elasticache:global-replicationgroupelasticache:DescribeGlobalReplicationGroups
aws:elasticache:parametergroupelasticache:DescribeCacheParameterGroups
aws:elasticache:replicationgroupelasticache:DescribeReplicationGroups
aws:elasticache:reserved-instanceelasticache:DescribeReservedCacheNodes
aws:elasticache:securitygroupelasticache:DescribeCacheSecurityGroups
aws:elasticache:serverless-cacheelasticache:DescribeServerlessCaches
aws:elasticache:serverless-cache-snapshotelasticache:DescribeServerlessCacheSnapshots
aws:elasticache:snapshotelasticache:DescribeSnapshots
aws:elasticache:userelasticache:DescribeUsers
aws:elasticache:usergroupelasticache:DescribeUserGroups
aws:elasticache:clusterelasticache:DescribeCacheClusters
aws:elasticbeanstalk:environmentelasticbeanstalk:DescribeConfigurationSettings,
elasticbeanstalk:DescribeEnvironments
aws:elasticloadbalancing:loadbalancerelasticloadbalancing:DescribeInstanceHealth,
elasticloadbalancing:DescribeLoadBalancerAttributes,
elasticloadbalancing:DescribeLoadBalancerPolicies,
elasticloadbalancing:DescribeLoadBalancers
aws:elasticloadbalancingv2:listener-ruleelasticloadbalancing:DescribeListeners,
elasticloadbalancing:DescribeLoadBalancers,
elasticloadbalancing:DescribeRules
aws:elasticloadbalancingv2:loadbalancerelasticloadbalancing:DescribeListeners,
elasticloadbalancing:DescribeLoadBalancerAttributes,
elasticloadbalancing:DescribeLoadBalancers
aws:elasticloadbalancingv2:targetgroupelasticloadbalancing:DescribeTargetGroups,
elasticloadbalancing:DescribeTargetHealth
aws:elasticloadbalancingv2:truststoreelasticloadbalancing:DescribeTrustStores
aws:elasticsearchservice:domaines:DescribeElasticsearchDomains,
es:ListDomainNames
aws:emr:clusterelasticmapreduce:DescribeCluster,
elasticmapreduce:GetAutoTerminationPolicy,
elasticmapreduce:GetManagedScalingPolicy,
elasticmapreduce:ListClusters
aws:emr:instanceelasticmapreduce:ListClusters,
elasticmapreduce:ListInstances
aws:emr:instance-fleetelasticmapreduce:DescribeCluster,
elasticmapreduce:ListClusters,
elasticmapreduce:ListInstanceFleets
aws:emr:instance-groupelasticmapreduce:DescribeCluster,
elasticmapreduce:ListClusters,
elasticmapreduce:ListInstanceGroups
aws:emr:security-configurationelasticmapreduce:DescribeSecurityConfiguration,
elasticmapreduce:ListSecurityConfigurations
aws:emrcontainers:managed-endpointemr-containers:ListManagedEndpoints,
emr-containers:ListVirtualClusters
aws:emrcontainers:security-configurationemr-containers:ListSecurityConfigurations
aws:emrcontainers:virtual-clusteremr-containers:ListVirtualClusters
aws:emrserverless:applicationemr-serverless:GetApplication,
emr-serverless:ListApplications
aws:emr:settingselasticmapreduce:GetBlockPublicAccessConfiguration
aws:eventbridge:api-destinationevents:ListApiDestinations,
events:ListConnections
aws:eventbridge:archiveevents:ListArchives,
events:ListEventBuses
aws:eventbridge:connectionevents:ListConnections
aws:eventbridge:endpointevents:ListEndpoints
aws:eventbridge:event-sourceevents:ListEventSources
aws:eventbridge:eventbusevents:ListEventBuses,
events:ListRules
aws:eventbridge:replayevents:ListReplays
aws:eventbridge:ruleevents:ListEventBuses,
events:ListRules
aws:eventbridge:ruletargetevents:ListEventBuses,
events:ListRules,
events:ListTargetsByRule
aws:firehose:delivery-streamfirehose:DescribeDeliveryStream,
firehose:ListDeliveryStreams
aws:frauddetector:batch-import-jobfrauddetector:GetBatchImportJobs
aws:frauddetector:batch-prediction-jobfrauddetector:GetBatchPredictionJobs
aws:frauddetector:detectorfrauddetector:GetDetectors
aws:frauddetector:detector-versionfrauddetector:DescribeDetector,
frauddetector:GetDetectorVersion,
frauddetector:GetDetectors
aws:frauddetector:entity-typefrauddetector:GetEntityTypes
aws:frauddetector:event-typefrauddetector:GetEventTypes
aws:frauddetector:external-modelfrauddetector:GetExternalModels
aws:frauddetector:labelfrauddetector:GetLabels
aws:frauddetector:listfrauddetector:GetListsMetadata
aws:frauddetector:modelfrauddetector:GetModels
aws:frauddetector:model-versionfrauddetector:DescribeModelVersions
aws:frauddetector:outcomefrauddetector:GetOutcomes
aws:frauddetector:rulefrauddetector:GetDetectors,
frauddetector:GetRules
aws:frauddetector:variablefrauddetector:GetVariables
aws:fsx:associationfsx:DescribeDataRepositoryAssociations
aws:fsx:backupfsx:DescribeBackups
aws:fsx:file-cachefsx:DescribeFileCaches
aws:fsx:file-systemfsx:DescribeFileSystems
aws:fsx:snapshotfsx:DescribeSnapshots
aws:fsx:storage-virtual-machinefsx:DescribeStorageVirtualMachines
aws:fsx:taskfsx:DescribeDataRepositoryTasks
aws:fsx:volumefsx:DescribeVolumes
aws:gamelift:aliasgamelift:ListAliases
aws:gamelift:buildgamelift:ListBuilds
aws:gamelift:container-fleetgamelift:ListContainerFleets
aws:gamelift:container-group-definitiongamelift:ListContainerGroupDefinitions
aws:gamelift:game-server-groupgamelift:ListGameServerGroups
aws:gamelift:game-session-queuegamelift:DescribeGameSessionQueues
aws:gamelift:locationgamelift:ListLocations
aws:gamelift:matchmaking-configurationgamelift:DescribeMatchmakingConfigurations
aws:gamelift:matchmaking-rule-setgamelift:DescribeMatchmakingRuleSets
aws:gamelift:scriptgamelift:ListScripts
aws:glacier:vaultglacier:GetVaultNotifications,
glacier:ListVaults
aws:globalaccelerator:acceleratorglobalaccelerator:ListAccelerators
aws:globalaccelerator:endpointgroupglobalaccelerator:ListAccelerators,
globalaccelerator:ListEndpointGroups,
globalaccelerator:ListListeners
aws:globalaccelerator:listenerglobalaccelerator:ListAccelerators,
globalaccelerator:ListListeners
aws:glue:registryglue:ListRegistries
aws:grafana:workspacegrafana:DescribeWorkspace,
grafana:ListWorkspaces
aws:greengrass:bulk-deploymentgreengrass:GetBulkDeploymentStatus,
greengrass:ListBulkDeployments
aws:greengrass:connector-definitiongreengrass:ListConnectorDefinitions
aws:greengrass:core-definitiongreengrass:ListCoreDefinitions
aws:greengrass:deploymentgreengrass:ListDeployments,
greengrass:ListGroups
aws:greengrass:device-definitiongreengrass:ListDeviceDefinitions
aws:greengrass:function-definitiongreengrass:ListFunctionDefinitions
aws:greengrass:groupgreengrass:GetGroup,
greengrass:ListGroups
aws:greengrass:logger-definitiongreengrass:ListLoggerDefinitions
aws:greengrass:resource-definitiongreengrass:ListResourceDefinitions
aws:greengrass:subscription-definitiongreengrass:ListSubscriptionDefinitions
aws:greengrass:componentgreengrass:GetComponent,
greengrass:ListComponents
aws:greengrass:connectivity-infogreengrass:GetConnectivityInfo,
greengrass:ListCoreDevices
aws:greengrass:core-devicegreengrass:GetCoreDevice,
greengrass:ListCoreDevices
aws:guardduty:detectorguardduty:GetCoverageStatistics,
guardduty:GetDetector,
guardduty:ListDetectors
aws:guardduty:filterguardduty:GetFilter,
guardduty:ListDetectors,
guardduty:ListFilters
aws:guardduty:ipsetguardduty:GetIPSet,
guardduty:ListDetectors,
guardduty:ListIPSets
aws:guardduty:malwareprotectionplanguardduty:GetMalwareProtectionPlan,
guardduty:ListMalwareProtectionPlans
aws:guardduty:publishingdestinationguardduty:DescribePublishingDestination,
guardduty:ListDetectors,
guardduty:ListPublishingDestinations
aws:guardduty:settingsguardduty:GetAdministratorAccount,
guardduty:GetMalwareScanSettings,
guardduty:GetMasterAccount,
guardduty:ListDetectors
aws:guardduty:threatintelsetguardduty:GetThreatIntelSet,
guardduty:ListDetectors,
guardduty:ListThreatIntelSets
aws:health:settingshealth:DescribeHealthServiceStatusForOrganization,
organizations:DescribeOrganization
aws:healthlake:datastorehealthlake:ListFHIRDatastores
aws:iam:accountorganizations:DescribeOrganization,
iam:GetAccountPasswordPolicy,
iam:GetAccountSummary
aws:iam:instanceprofileiam:GetInstanceProfile,
iam:ListInstanceProfiles
aws:iam:open-id-connect-provideriam:GetOpenIDConnectProvider,
iam:ListOpenIDConnectProviders
aws:iam:saml-provideriam:GetSAMLProvider,
iam:ListSAMLProviders
aws:iam:server-certificateiam:ListServerCertificates
aws:iam:service-specific-credentialiam:ListServiceSpecificCredentials
aws:iam:groupiam:GetGroup,
iam:ListAttachedGroupPolicies,
iam:ListGroups
aws:iam:groupinlinepolicyiam:GetGroupPolicy,
iam:ListGroupPolicies,
iam:ListGroups
aws:iam:policyiam:GetPolicy,
iam:GetPolicyVersion,
iam:ListPolicies
aws:iam:aws-managed-policyiam:GetPolicyVersion,
iam:ListPolicies
aws:iam:roleiam:GetAccountAuthorizationDetails,
iam:GetRole,
iam:ListAttachedRolePolicies
aws:iam:roleinlinepolicyiam:GetAccountAuthorizationDetails,
iam:GetRole,
iam:GetRolePolicy,
iam:ListRolePolicies
aws:iam:accesskeymetadataiam:GetUser,
iam:ListAccessKeys,
iam:ListUsers,
iam:ListVirtualMFADevices
aws:iam:useriam:GetLoginProfile,
iam:GetUser,
iam:ListAttachedUserPolicies,
iam:ListGroupsForUser,
iam:ListMFADevices,
iam:ListSSHPublicKeys,
iam:ListUsers,
iam:ListVirtualMFADevices
aws:iam:userinlinepolicyiam:GetUser,
iam:GetUserPolicy,
iam:ListUserPolicies,
iam:ListUsers,
iam:ListVirtualMFADevices
aws:iam:virtualmfadeviceiam:ListUsers,
iam:ListVirtualMFADevices
aws:identitystore:grouporganizations:DescribeOrganization,
identitystore:ListGroups,
sso:ListInstances
aws:identitystore:userorganizations:DescribeOrganization,
identitystore:ListGroupMembershipsForMember,
sso:ListInstances,
identitystore:ListUsers
aws:imagebuilder:component-versionimagebuilder:ListComponents
aws:imagebuilder:container-recipeimagebuilder:GetContainerRecipe,
imagebuilder:ListContainerRecipes
aws:imagebuilder:distribution-configurationimagebuilder:GetDistributionConfiguration,
imagebuilder:ListDistributionConfigurations
aws:imagebuilder:image-pipelineimagebuilder:ListImagePipelines
aws:imagebuilder:image-recipeimagebuilder:GetImageRecipe,
imagebuilder:ListImageRecipes
aws:imagebuilder:image-versionimagebuilder:ListImages
aws:imagebuilder:infrastructure-configurationimagebuilder:GetInfrastructureConfiguration,
imagebuilder:ListInfrastructureConfigurations
aws:imagebuilder:lifecycle-policyimagebuilder:GetLifecyclePolicy,
imagebuilder:ListLifecyclePolicies
aws:imagebuilder:workflowimagebuilder:GetWorkflow,
imagebuilder:ListWorkflows
aws:imagebuilder:public-componentimagebuilder:ListComponents
aws:imagebuilder:public-container-recipeimagebuilder:GetContainerRecipe,
imagebuilder:ListContainerRecipes
aws:imagebuilder:public-imageimagebuilder:ListImages
aws:imagebuilder:public-image-recipeimagebuilder:GetImageRecipe,
imagebuilder:ListImageRecipes
aws:imagebuilder:public-workflowimagebuilder:GetWorkflow,
imagebuilder:ListWorkflows
aws:inspector2:coveredresourceinspector2:ListCoverage
aws:iot:authorizeriot:DescribeAuthorizer,
iot:ListAuthorizers
aws:iot:certiot:DescribeCertificate,
iot:ListCertificates
aws:iot:certificateprovideriot:DescribeCertificateProvider,
iot:ListCertificateProviders
aws:iot:dimensioniot:DescribeDimension,
iot:ListDimensions
aws:iot:domainconfigurationiot:DescribeDomainConfiguration,
iot:ListDomainConfigurations
aws:iot:fleetmetriciot:DescribeFleetMetric,
iot:ListFleetMetrics
aws:iot:jobiot:DescribeJob,
iot:ListJobs
aws:iot:jobtemplateiot:DescribeJobTemplate,
iot:ListJobTemplates
aws:iot:policyiot:GetPolicy,
iot:ListPolicies
aws:iot:provisioningtemplateiot:DescribeProvisioningTemplate,
iot:ListProvisioningTemplates
aws:iot:rolealiasiot:DescribeRoleAlias,
iot:ListRoleAliases
aws:iot:securityprofileiot:DescribeSecurityProfile,
iot:ListSecurityProfiles
aws:iot:streamiot:DescribeStream,
iot:ListStreams
aws:iot:thingiot:DescribeThing,
iot:ListThings
aws:iot:thinggroupiot:DescribeThingGroup,
iot:ListThingGroups
aws:iot:thingtypeiot:DescribeThingType,
iot:ListThingTypes
aws:iotfleetwise:campaigniotfleetwise:GetCampaign,
iotfleetwise:ListCampaigns
aws:iotfleetwise:decoder-manifestiotfleetwise:ListDecoderManifests
aws:iotfleetwise:fleetiotfleetwise:ListFleets
aws:iotfleetwise:model-manifestiotfleetwise:ListModelManifests
aws:iotfleetwise:signal-catalogiotfleetwise:GetSignalCatalog,
iotfleetwise:ListSignalCatalogs
aws:iotfleetwise:state-templateiotfleetwise:GetStateTemplate,
iotfleetwise:ListStateTemplates
aws:iotfleetwise:vehicleiotfleetwise:GetVehicle,
iotfleetwise:ListVehicles
aws:iot:tunneliot:DescribeTunnel,
iot:ListTunnels
aws:iotsitewise:assetiotsitewise:DescribeAsset,
iotsitewise:DescribeAssetModel,
iotsitewise:ListAssetModels,
iotsitewise:ListAssets
aws:iotsitewise:asset-modeliotsitewise:DescribeAssetModel,
iotsitewise:ListAssetModels
aws:iotsitewise:dashboardiotsitewise:DescribeDashboard,
iotsitewise:DescribePortal,
iotsitewise:DescribeProject,
iotsitewise:ListDashboards,
iotsitewise:ListPortals,
iotsitewise:ListProjects
aws:iotsitewise:datasetiotsitewise:DescribeDataset,
iotsitewise:ListDatasets
aws:iotsitewise:gatewayiotsitewise:ListGateways
aws:iotsitewise:portaliotsitewise:DescribePortal,
iotsitewise:ListPortals
aws:iotsitewise:projectiotsitewise:DescribePortal,
iotsitewise:DescribeProject,
iotsitewise:ListPortals,
iotsitewise:ListProjects
aws:iotsitewise:timeseriesiotsitewise:ListTimeSeries
aws:iottwinmaker:component-typeiottwinmaker:GetComponentType,
iottwinmaker:GetWorkspace,
iottwinmaker:ListComponentTypes,
iottwinmaker:ListWorkspaces
aws:iottwinmaker:entityiottwinmaker:GetEntity,
iottwinmaker:GetWorkspace,
iottwinmaker:ListEntities,
iottwinmaker:ListWorkspaces
aws:iottwinmaker:sceneiottwinmaker:GetScene,
iottwinmaker:GetWorkspace,
iottwinmaker:ListScenes,
iottwinmaker:ListWorkspaces
aws:iottwinmaker:workspaceiottwinmaker:GetWorkspace,
iottwinmaker:ListWorkspaces
aws:iotwireless:destinationiotwireless:ListDestinations
aws:iotwireless:device-profileiotwireless:GetDeviceProfile,
iotwireless:ListDeviceProfiles
aws:iotwireless:gatewayiotwireless:GetWirelessGateway,
iotwireless:ListWirelessGateways
aws:iotwireless:multicast-groupiotwireless:GetMulticastGroup,
iotwireless:ListMulticastGroups
aws:iotwireless:network-analyzer-configurationiotwireless:GetNetworkAnalyzerConfiguration,
iotwireless:ListNetworkAnalyzerConfigurations
aws:iotwireless:service-profileiotwireless:GetServiceProfile,
iotwireless:ListServiceProfiles
aws:iotwireless:wireless-deviceiotwireless:GetWirelessDevice,
iotwireless:ListWirelessDevices
aws:ivs:channelivs:GetChannel,
ivs:ListChannels
aws:ivs:playback-key-pairivs:ListPlaybackKeyPairs
aws:ivs:playback-restriction-policyivs:ListPlaybackRestrictionPolicies
aws:ivs:recording-configurationivs:GetRecordingConfiguration,
ivs:ListRecordingConfigurations
aws:ivs:stream-keyivs:GetChannel,
ivs:ListChannels,
ivs:ListStreamKeys
aws:ivschat:logging-configurationivschat:GetLoggingConfiguration,
ivschat:ListLoggingConfigurations
aws:ivschat:roomivschat:GetRoom,
ivschat:ListRooms
aws:ivs:compositionivs:GetComposition,
ivs:ListCompositions
aws:ivs:encoder-configurationivs:GetEncoderConfiguration,
ivs:ListEncoderConfigurations
aws:ivs:ingest-configurationivs:GetIngestConfiguration,
ivs:ListIngestConfigurations
aws:ivs:public-keyivs:GetPublicKey,
ivs:ListPublicKeys
aws:ivs:stageivs:GetStage,
ivs:ListStages
aws:ivs:storage-configurationivs:ListStorageConfigurations
aws:kafka:clusterkafka:DescribeClusterV2,
kafka:ListClustersV2
aws:kafka:configurationkafka:ListConfigurations
aws:kafka:nodekafka:DescribeClusterV2,
kafka:ListClustersV2,
kafka:ListNodes
aws:kafka:replicatorkafka:DescribeReplicator,
kafka:ListReplicators
aws:kafka:vpc-connectionkafka:DescribeVpcConnection,
kafka:ListVpcConnections
aws:kafkaconnect:connectorkafkaconnect:DescribeConnector,
kafkaconnect:ListConnectors
aws:kafkaconnect:connector-operationkafkaconnect:DescribeConnector,
kafkaconnect:DescribeConnectorOperation,
kafkaconnect:ListConnectorOperations,
kafkaconnect:ListConnectors
aws:kafkaconnect:custom-pluginkafkaconnect:DescribeCustomPlugin,
kafkaconnect:ListCustomPlugins
aws:kafkaconnect:worker-configurationkafkaconnect:ListWorkerConfigurations
aws:keyspaces:keyspacecassandra:Select
aws:keyspaces:tablecassandra:Select,
cassandra:Select,
cassandra:Select
aws:kinesis:streamkinesis:DescribeStreamSummary,
kinesis:ListStreams
aws:kinesisvideo:channelkinesisvideo:ListSignalingChannels
aws:kinesisvideo:streamkinesisvideo:ListStreams
aws:kms:aliaskms:GetKeyPolicy,
kms:ListAliases
aws:kms:custom-key-storekms:DescribeCustomKeyStores
aws:kms:keykms:DescribeKey,
kms:GetKeyRotationStatus,
kms:ListKeys
aws:lakeformation:data-lake-settingslakeformation:GetDataLakeSettings
aws:lakeformation:permissionslakeformation:ListPermissions
aws:lambda:eventsourcemappinglambda:ListEventSourceMappings,
lambda:ListFunctions
aws:lambda:functionlambda:GetFunction,
lambda:GetPolicy,
lambda:ListFunctionUrlConfigs,
lambda:ListFunctions,
lambda:ListProvisionedConcurrencyConfigs
aws:lambda:codesigningconfiglambda:ListCodeSigningConfigs
aws:lambda:functionlambda:GetPolicy,
lambda:ListFunctions
aws:lambda:layerlambda:GetLayerVersionPolicy,
lambda:ListLayers
aws:launchwizard:deploymentlaunchwizard:GetDeployment,
launchwizard:ListDeployments
aws:lexv2:botlex:DescribeBot,
lex:ListBots
aws:lightsail:alarmlightsail:GetAlarms
aws:lightsail:bucketlightsail:GetBuckets
aws:lightsail:certificatelightsail:GetCertificates
aws:lightsail:container-servicelightsail:GetContainerServices
aws:lightsail:disklightsail:GetDisks
aws:lightsail:disk-snapshotlightsail:GetDiskSnapshots
aws:lightsail:distributionlightsail:GetDistributions
aws:lightsail:instancelightsail:GetInstancePortStates,
lightsail:GetInstances
aws:lightsail:loadbalancerlightsail:GetLoadBalancers
aws:lightsail:relational-databaselightsail:GetRelationalDatabaseParameters,
lightsail:GetRelationalDatabases
aws:lightsail:relational-database-snapshotlightsail:GetRelationalDatabaseSnapshots
aws:lightsail:static-iplightsail:GetStaticIps
aws:location:api-keygeo:DescribeKey,
geo:ListKeys
aws:location:geofence-collectiongeo:DescribeGeofenceCollection,
geo:ListGeofenceCollections
aws:location:mapgeo:DescribeMap,
geo:ListMaps
aws:location:place-indexgeo:DescribePlaceIndex,
geo:ListPlaceIndexes
aws:location:route-calculatorgeo:DescribeRouteCalculator,
geo:ListRouteCalculators
aws:location:trackergeo:DescribeTracker,
geo:ListTrackers
aws:m2:applicationm2:GetApplication,
m2:ListApplications
aws:m2:environmentm2:GetEnvironment,
m2:ListEnvironments
aws:macie2:allow-listmacie2:GetAllowList,
macie2:GetMacieSession,
macie2:ListAllowLists
aws:macie2:custom-data-identifiermacie2:GetCustomDataIdentifier,
macie2:GetMacieSession,
macie2:ListCustomDataIdentifiers
aws:macie2:membermacie2:GetMacieSession,
macie2:ListMembers
aws:macie2:settingsmacie2:GetMacieSession
aws:ses:addon-instanceses:ListAddonInstances
aws:ses:addon-subscriptionses:ListAddonSubscriptions
aws:ses:address-listses:ListAddressLists
aws:ses:archiveses:GetArchive,
ses:ListArchives
aws:ses:ingress-pointses:GetIngressPoint,
ses:ListIngressPoints
aws:ses:relayses:GetRelay,
ses:ListRelays
aws:ses:rule-setses:GetRuleSet,
ses:ListRuleSets
aws:ses:traffic-policyses:GetTrafficPolicy,
ses:ListTrafficPolicies
aws:managedblockchain:accessormanagedblockchain:GetAccessor,
managedblockchain:ListAccessors
aws:managedblockchain:invitationmanagedblockchain:ListInvitations
aws:managedblockchain:membermanagedblockchain:GetMember,
managedblockchain:ListMembers,
managedblockchain:ListNetworks
aws:managedblockchain:networkmanagedblockchain:GetNetwork,
managedblockchain:ListNetworks
aws:managedblockchain:nodemanagedblockchain:GetNode,
managedblockchain:ListMembers,
managedblockchain:ListNetworks,
managedblockchain:ListNodes
aws:managedblockchain:proposalmanagedblockchain:GetProposal,
managedblockchain:ListNetworks,
managedblockchain:ListProposals
aws:mediaconnect:bridgemediaconnect:DescribeBridge,
mediaconnect:ListBridges
aws:mediaconnect:entitlementmediaconnect:ListEntitlements
aws:mediaconnect:flowmediaconnect:DescribeFlow,
mediaconnect:ListFlows
aws:mediaconnect:gatewaymediaconnect:DescribeGateway,
mediaconnect:ListGateways
aws:mediaconnect:gatewayinstancemediaconnect:DescribeGatewayInstance,
mediaconnect:ListGatewayInstances
aws:medialive:channelmedialive:ListChannels
aws:medialive:channel-placement-groupmedialive:ListChannelPlacementGroups,
medialive:ListClusters
aws:medialive:cloudwatch-alarm-templatemedialive:ListCloudWatchAlarmTemplates
aws:medialive:cloudwatch-alarm-template-groupmedialive:ListCloudWatchAlarmTemplateGroups
aws:medialive:clustermedialive:ListClusters
aws:medialive:eventbridge-rule-templatemedialive:ListEventBridgeRuleTemplates
aws:medialive:eventbridge-rule-template-groupmedialive:ListEventBridgeRuleTemplateGroups
aws:medialive:inputmedialive:ListInputs
aws:medialive:input-devicemedialive:ListInputDevices
aws:medialive:input-security-groupmedialive:ListInputSecurityGroups
aws:medialive:multiplexmedialive:ListMultiplexes
aws:medialive:networkmedialive:ListNetworks
aws:medialive:nodemedialive:ListClusters,
medialive:ListNodes
aws:medialive:reservationmedialive:ListReservations
aws:medialive:sdi-sourcemedialive:ListSdiSources
aws:medialive:signal-mapmedialive:ListSignalMaps
aws:mediapackage:harvest-jobsmediapackage:ListHarvestJobs
aws:mediapackage:origin-endpointsmediapackage:ListOriginEndpoints
aws:mediapackage-v2:channelmediapackagev2:GetChannel,
mediapackagev2:GetChannelGroup,
mediapackagev2:GetChannelPolicy,
mediapackagev2:ListChannelGroups,
mediapackagev2:ListChannels
aws:mediapackage-v2:channel-groupmediapackagev2:GetChannelGroup,
mediapackagev2:ListChannelGroups
aws:mediapackage-v2:harvest-jobmediapackagev2:GetChannelGroup,
mediapackagev2:ListChannelGroups,
mediapackagev2:ListHarvestJobs
aws:mediapackage-v2:origin-endpointmediapackagev2:GetChannelGroup,
mediapackagev2:GetOriginEndpoint,
mediapackagev2:GetOriginEndpointPolicy,
mediapackagev2:ListChannelGroups,
mediapackagev2:ListChannels,
mediapackagev2:ListOriginEndpoints
aws:mediapackage-vod:assetsmediapackage-vod:DescribeAsset,
mediapackage-vod:ListAssets
aws:mediapackage-vod:packaging-configurationsmediapackage-vod:ListPackagingConfigurations
aws:mediapackage-vod:packaging-groupsmediapackage-vod:ListPackagingGroups
aws:memorydb:aclmemorydb:DescribeAcls
aws:memorydb:clustermemorydb:DescribeClusters,
memorydb:DescribeMultiRegionClusters
aws:memorydb:parameter-groupmemorydb:DescribeParameterGroups
aws:memorydb:reserved-nodememorydb:DescribeReservedNodes
aws:memorydb:snapshotmemorydb:DescribeSnapshots
aws:memorydb:subnet-groupmemorydb:DescribeSubnetGroups
aws:memorydb:usermemorydb:DescribeUsers
aws:cloudwatch:metricalarmcloudwatch:DescribeAlarms
aws:cloudwatchlogs:metricfilterlogs:DescribeMetricFilters
aws:migrationhubrefactorspaces:applicationrefactor-spaces:ListApplications,
refactor-spaces:ListEnvironments
aws:migrationhubrefactorspaces:environmentrefactor-spaces:ListEnvironments
aws:migrationhubrefactorspaces:routerefactor-spaces:ListApplications,
refactor-spaces:ListEnvironments,
refactor-spaces:ListRoutes
aws:migrationhubrefactorspaces:servicerefactor-spaces:ListApplications,
refactor-spaces:ListEnvironments,
refactor-spaces:ListServices
aws:mq:brokermq:DescribeBroker,
mq:ListBrokers
aws:mq:configurationmq:ListConfigurations
aws:mq:configurationrevisionmq:DescribeConfigurationRevision,
mq:ListConfigurationRevisions,
mq:ListConfigurations
aws:mq:usermq:DescribeBroker,
mq:DescribeUser,
mq:ListBrokers
aws:mwaa:environmentairflow:GetEnvironment,
airflow:ListEnvironments
aws:neptune:clusterrds:DescribeDBClusters
aws:neptune:cluster-snapshotrds:DescribeDBClusterSnapshotAttributes,
rds:DescribeDBClusterSnapshots
aws:neptune:dbinstancerds:DescribeDBInstances
aws:network-firewall:firewallnetwork-firewall:DescribeFirewall,
network-firewall:DescribeFirewallPolicy,
network-firewall:DescribeLoggingConfiguration,
network-firewall:ListFirewalls
aws:network-firewall:rulegroupnetwork-firewall:DescribeRuleGroup,
network-firewall:ListRuleGroups
aws:network-firewall:tls-configurationnetwork-firewall:DescribeTLSInspectionConfiguration,
network-firewall:ListTLSInspectionConfigurations
aws:network-firewall:vpc-endpoint-associationnetwork-firewall:DescribeVpcEndpointAssociation,
network-firewall:ListVpcEndpointAssociations
aws:networkmanager:attachmentnetworkmanager:ListAttachments
aws:networkmanager:connect-peernetworkmanager:GetConnectPeer,
networkmanager:ListConnectPeers
aws:networkmanager:connectionnetworkmanager:DescribeGlobalNetworks,
networkmanager:GetConnections
aws:networkmanager:core-networknetworkmanager:GetCoreNetwork,
networkmanager:ListCoreNetworks
aws:networkmanager:devicenetworkmanager:DescribeGlobalNetworks,
networkmanager:GetDevices
aws:networkmanager:global-networknetworkmanager:DescribeGlobalNetworks
aws:networkmanager:linknetworkmanager:DescribeGlobalNetworks,
networkmanager:GetLinks
aws:networkmanager:peeringnetworkmanager:ListPeerings
aws:networkmanager:sitenetworkmanager:DescribeGlobalNetworks,
networkmanager:GetSites
aws:opensearch:domaines:DescribeDomain,
es:ListDomainNames
aws:opensearchserverless:collectionaoss:BatchGetCollection,
aoss:ListCollections
aws:organizations:accountorganizations:DescribeOrganization,
organizations:ListAccountsForParent,
organizations:ListDelegatedAdministrators,
organizations:ListOrganizationalUnitsForParent,
organizations:ListPoliciesForTarget,
organizations:ListRoots
aws:organizations:featuresorganizations:DescribeOrganization,
organizations:ListDelegatedAdministrators,
iam:ListOrganizationsFeatures
aws:organizations:organizationorganizations:DescribeOrganization,
organizations:ListDelegatedAdministrators
aws:organizations:organizationalunitorganizations:DescribeOrganization,
organizations:ListAccountsForParent,
organizations:ListDelegatedAdministrators,
organizations:ListOrganizationalUnitsForParent,
organizations:ListPoliciesForTarget,
organizations:ListRoots
aws:organizations:policyorganizations:DescribeOrganization,
organizations:DescribePolicy,
organizations:ListDelegatedAdministrators,
organizations:ListPolicies,
organizations:ListTargetsForPolicy
aws:organizations:rootorganizations:DescribeOrganization,
organizations:ListAccountsForParent,
organizations:ListDelegatedAdministrators,
organizations:ListOrganizationalUnitsForParent,
organizations:ListPoliciesForTarget,
organizations:ListRoots
aws:osis:pipelineosis:GetPipeline,
osis:ListPipelines
aws:osis:pipeline-blueprintosis:GetPipelineBlueprint,
osis:ListPipelineBlueprints
aws:payment-cryptography:aliaspayment-cryptography:GetKey,
payment-cryptography:ListAliases,
payment-cryptography:ListKeys
aws:payment-cryptography:keypayment-cryptography:GetKey,
payment-cryptography:ListKeys
aws:pca-connector-ad:connectorpca-connector-ad:ListConnectors
aws:pca-connector-ad:directory-registrationpca-connector-ad:ListDirectoryRegistrations
aws:pca-connector-ad:templatepca-connector-ad:ListConnectors,
pca-connector-ad:ListTemplates
aws:pca-connector-scep:connectorpca-connector-scep:ListConnectors
aws:pcs:clusterpcs:GetCluster,
pcs:ListClusters
aws:pcs:compute-node-grouppcs:GetComputeNodeGroup,
pcs:ListClusters,
pcs:ListComputeNodeGroups
aws:pcs:queuepcs:GetQueue,
pcs:ListClusters,
pcs:ListQueues
aws:personalize:batch-inference-jobpersonalize:DescribeBatchInferenceJob,
personalize:ListBatchInferenceJobs
aws:personalize:batch-segment-jobpersonalize:DescribeBatchSegmentJob,
personalize:ListBatchSegmentJobs
aws:personalize:campaignpersonalize:DescribeCampaign,
personalize:ListCampaigns
aws:personalize:data-deletion-jobpersonalize:DescribeDataDeletionJob,
personalize:ListDataDeletionJobs
aws:personalize:datasetpersonalize:DescribeDataset,
personalize:ListDatasets
aws:personalize:dataset-export-jobpersonalize:DescribeDatasetExportJob,
personalize:ListDatasetExportJobs
aws:personalize:dataset-grouppersonalize:DescribeDatasetGroup,
personalize:ListDatasetGroups
aws:personalize:dataset-import-jobpersonalize:DescribeDatasetImportJob,
personalize:ListDatasetImportJobs
aws:personalize:event-trackerpersonalize:DescribeEventTracker,
personalize:ListEventTrackers
aws:personalize:filterpersonalize:DescribeFilter,
personalize:ListFilters
aws:personalize:metric-attributionpersonalize:DescribeMetricAttribution,
personalize:ListMetricAttributions
aws:personalize:recommenderpersonalize:DescribeRecommender,
personalize:ListRecommenders
aws:personalize:schemapersonalize:DescribeSchema,
personalize:ListSchemas
aws:personalize:solutionpersonalize:DescribeSolution,
personalize:ListSolutions
aws:personalize:algorithmpersonalize:DescribeAlgorithm,
personalize:DescribeRecipe,
personalize:ListRecipes
aws:personalize:feature-transformationpersonalize:DescribeFeatureTransformation,
personalize:DescribeRecipe,
personalize:ListRecipes
aws:personalize:recipepersonalize:DescribeRecipe,
personalize:ListRecipes
aws:pinpoint:appmobiletargeting:GetApps,
mobiletargeting:GetEventStream
aws:pinpoint:campaignmobiletargeting:GetApps,
mobiletargeting:GetCampaigns
aws:pinpoint:channelmobiletargeting:GetApps,
mobiletargeting:GetChannels
aws:pinpoint:journeymobiletargeting:GetApps,
mobiletargeting:ListJourneys
aws:pinpoint:segmentmobiletargeting:GetApps,
mobiletargeting:GetSegments
aws:pinpoint:templatemobiletargeting:ListTemplates
aws:smsvoice:configuration-setsms-voice:DescribeConfigurationSets
aws:smsvoice:opt-out-listsms-voice:DescribeOptOutLists
aws:smsvoice:phone-numbersms-voice:DescribePhoneNumbers
aws:smsvoice:poolsms-voice:DescribePools
aws:smsvoice:protect-configurationsms-voice:DescribeProtectConfigurations
aws:smsvoice:registrationsms-voice:DescribeRegistrations
aws:smsvoice:registration-attachmentsms-voice:DescribeRegistrationAttachments
aws:smsvoice:sender-idsms-voice:DescribeSenderIds
aws:smsvoice:verified-destination-numbersms-voice:DescribeVerifiedDestinationNumbers
aws:pipes:pipepipes:ListPipes
aws:proton:componentproton:GetComponent,
proton:ListComponents
aws:proton:deploymentproton:GetDeployment,
proton:ListDeployments
aws:proton:environmentproton:GetEnvironment,
proton:ListEnvironments
aws:proton:environment-account-connectionproton:GetEnvironmentAccountConnection,
proton:ListEnvironmentAccountConnections
aws:proton:environment-templateproton:GetEnvironmentTemplate,
proton:ListEnvironmentTemplates
aws:proton:environment-template-versionproton:GetEnvironmentTemplate,
proton:GetEnvironmentTemplateVersion,
proton:ListEnvironmentTemplateVersions,
proton:ListEnvironmentTemplates
aws:proton:repositoryproton:GetRepository,
proton:ListRepositories
aws:proton:serviceproton:GetService,
proton:ListServices
aws:proton:service-instanceproton:GetServiceInstance,
proton:ListServiceInstances
aws:proton:service-templateproton:GetServiceTemplate,
proton:ListServiceTemplates
aws:proton:service-template-versionproton:GetServiceTemplate,
proton:GetServiceTemplateVersion,
proton:ListServiceTemplateVersions,
proton:ListServiceTemplates
aws:qbusiness:applicationqbusiness:GetApplication,
qbusiness:ListApplications
aws:qbusiness:data-accessorqbusiness:GetApplication,
qbusiness:GetDataAccessor,
qbusiness:ListApplications,
qbusiness:ListDataAccessors
aws:qbusiness:data-sourceqbusiness:GetApplication,
qbusiness:GetDataSource,
qbusiness:GetIndex,
qbusiness:ListApplications,
qbusiness:ListDataSources,
qbusiness:ListIndices
aws:qbusiness:indexqbusiness:GetApplication,
qbusiness:GetIndex,
qbusiness:ListApplications,
qbusiness:ListIndices
aws:qbusiness:pluginqbusiness:GetApplication,
qbusiness:GetPlugin,
qbusiness:ListApplications,
qbusiness:ListPlugins
aws:qbusiness:retrieverqbusiness:GetApplication,
qbusiness:GetRetriever,
qbusiness:ListApplications,
qbusiness:ListRetrievers
aws:qbusiness:subscriptionqbusiness:GetApplication,
qbusiness:ListApplications,
qbusiness:ListSubscriptions
aws:qbusiness:web-experienceqbusiness:GetApplication,
qbusiness:GetWebExperience,
qbusiness:ListApplications,
qbusiness:ListWebExperiences
aws:quicksight:accountquicksight:DescribeAccountSettings
aws:quicksight:analysisquicksight:DescribeAccountSettings,
quicksight:DescribeAnalysis,
quicksight:ListAnalyses
aws:quicksight:brandquicksight:DescribeAccountSettings,
quicksight:DescribeBrand,
quicksight:ListBrands
aws:quicksight:custom-permissionquicksight:DescribeAccountSettings,
quicksight:ListCustomPermissions
aws:quicksight:dashboardquicksight:DescribeAccountSettings,
quicksight:DescribeDashboard,
quicksight:ListDashboards
aws:quicksight:data-setquicksight:DescribeAccountSettings,
quicksight:ListDataSets
aws:quicksight:data-sourcequicksight:DescribeAccountSettings,
quicksight:ListDataSources
aws:quicksight:folderquicksight:DescribeAccountSettings,
quicksight:DescribeFolder,
quicksight:ListFolders
aws:quicksight:groupquicksight:DescribeAccountSettings,
quicksight:ListGroups,
quicksight:ListNamespaces
aws:quicksight:ingestionquicksight:DescribeAccountSettings,
quicksight:ListDataSets,
quicksight:ListIngestions
aws:quicksight:namespacequicksight:DescribeAccountSettings,
quicksight:ListNamespaces
aws:quicksight:refresh-schedulequicksight:DescribeAccountSettings,
quicksight:ListDataSets,
quicksight:ListRefreshSchedules
aws:quicksight:templatequicksight:DescribeAccountSettings,
quicksight:DescribeTemplate,
quicksight:ListTemplates
aws:quicksight:themequicksight:DescribeAccountSettings,
quicksight:DescribeTheme,
quicksight:ListThemes
aws:quicksight:topicquicksight:DescribeAccountSettings,
quicksight:DescribeTopic,
quicksight:ListTopics
aws:quicksight:userquicksight:DescribeAccountSettings,
quicksight:ListUsers
aws:quicksight:vpc-connectionquicksight:DescribeAccountSettings,
quicksight:ListVPCConnections
aws:ram:customer-managed-permissionram:ListPermissions
aws:ram:resource-shareram:GetResourceShares
aws:ram:resource-share-invitationram:GetResourceShareInvitations
aws:ram:permissionram:ListPermissions
aws:rbin:rulerbin:GetRule,
rbin:ListRules
aws:rds:blue-green-deploymentrds:DescribeBlueGreenDeployments
aws:rds:clusterrds:DescribeDBClusters
aws:rds:cluster-endpointrds:DescribeDBClusterEndpoints,
rds:DescribeDBClusters
aws:rds:cluster-snapshotrds:DescribeDBClusterSnapshotAttributes,
rds:DescribeDBClusterSnapshots
aws:rds:db-cluster-automated-backuprds:DescribeDBClusterAutomatedBackups
aws:rds:db-shard-grouprds:DescribeDBShardGroups
aws:rds:dbclusterparametergrouprds:DescribeDBClusterParameterGroups
aws:rds:dbinstanceautomatedbackuprds:DescribeDBInstanceAutomatedBackups
aws:rds:dbparametergrouprds:DescribeDBParameterGroups
aws:rds:dbsubnetgrouprds:DescribeDBSubnetGroups
aws:rds:eventsubscriptionrds:DescribeEventSubscriptions
aws:rds:exporttaskrds:DescribeExportTasks
aws:rds:globalclusterrds:DescribeGlobalClusters
aws:rds:instancerds:DescribeDBInstances
aws:rds:integrationrds:DescribeIntegrations
aws:rds:optiongrouprds:DescribeOptionGroups
aws:rds:proxyrds:DescribeDBProxies
aws:rds:proxy-endpointrds:DescribeDBProxyEndpoints
aws:rds:proxy-target-grouprds:DescribeDBProxies,
rds:DescribeDBProxyTargetGroups,
rds:DescribeDBProxyTargets
aws:rds:securitygrouprds:DescribeDBSecurityGroups
aws:rds:snapshotrds:DescribeDBSnapshotAttributes,
rds:DescribeDBSnapshots
aws:rds:snapshot-tenant-databaserds:DescribeDBSnapshotTenantDatabases
aws:rds:tenant-databaserds:DescribeTenantDatabases
aws:rds:reserveddbinstancerds:DescribeReservedDBInstances
aws:redshift:clusterredshift:DescribeClusterParameters,
redshift:DescribeClusters,
redshift:DescribeEndpointAccess,
redshift:DescribeLoggingStatus
aws:redshift:eventsubscriptionredshift:DescribeEventSubscriptions
aws:redshift:hsm-client-certificateredshift:DescribeHsmClientCertificates
aws:redshift:hsm-configurationredshift:DescribeHsmConfigurations
aws:redshift:integrationredshift:DescribeIntegrations
aws:redshift:parametergroupredshift:DescribeClusterParameterGroups
aws:redshift:redshift-idc-applicationredshift:DescribeRedshiftIdcApplications
aws:redshift:securitygroupredshift:DescribeClusterSecurityGroups
aws:redshift:snapshotredshift:DescribeClusterSnapshots,
redshift:DescribeClusters
aws:redshift:subnetgroupredshift:DescribeClusterSubnetGroups,
redshift:DescribeClusters
aws:redshiftserverless:endpoint-accessredshift-serverless:ListEndpointAccess
aws:redshiftserverless:managed-workgroupredshift-serverless:ListManagedWorkgroups
aws:redshiftserverless:namespaceredshift-serverless:ListNamespaces
aws:redshiftserverless:recovery-pointredshift-serverless:ListNamespaces,
redshift-serverless:ListRecoveryPoints
aws:redshiftserverless:snapshotredshift-serverless:GetSnapshot,
redshift-serverless:ListNamespaces,
redshift-serverless:ListSnapshots
aws:redshiftserverless:workgroupredshift-serverless:ListWorkgroups
aws:rekognition:collectionrekognition:DescribeCollection,
rekognition:ListCollections
aws:rekognition:projectrekognition:DescribeProjects
aws:rekognition:project-versionrekognition:DescribeProjectVersions,
rekognition:DescribeProjects
aws:rekognition:stream-processorrekognition:DescribeStreamProcessor,
rekognition:ListStreamProcessors
aws:resiliencehub:app-assessmentresiliencehub:DescribeAppAssessment,
resiliencehub:ListAppAssessments
aws:resiliencehub:applicationresiliencehub:DescribeApp,
resiliencehub:ListApps
aws:resiliencehub:resiliency-policyresiliencehub:ListResiliencyPolicies
aws:resourceexplorer2:indexresource-explorer-2:GetIndex
aws:resourceexplorer2:viewresource-explorer-2:GetView,
resource-explorer-2:ListViews
aws:resourceexplorer2:managed-viewresource-explorer-2:GetManagedView,
resource-explorer-2:ListManagedViews
aws:resourcegroups:groupresource-groups:GetGroup,
resource-groups:ListGroups
aws:route53:hostedzoneroute53:GetDNSSEC,
route53:GetHostedZone,
route53:ListHostedZones
aws:route53:queryloggingconfigroute53:ListQueryLoggingConfigs
aws:route53:resourcerecordsetroute53:ListHostedZones,
route53:ListResourceRecordSets
aws:route53domains:domainroute53domains:ListDomains
aws:route53-recovery-control:assertion-safety-ruleroute53-recovery-control-config:ListControlPanels,
route53-recovery-control-config:ListSafetyRules
aws:route53-recovery-control:clusterroute53-recovery-control-config:ListClusters
aws:route53-recovery-control:control-panelroute53-recovery-control-config:ListControlPanels,
route53-recovery-control-config:ListSafetyRules
aws:route53-recovery-control:gating-safety-ruleroute53-recovery-control-config:ListControlPanels,
route53-recovery-control-config:ListSafetyRules
aws:route53-recovery-control:routing-controlroute53-recovery-control-config:ListControlPanels,
route53-recovery-control-config:ListRoutingControls
aws:route53-recovery-readiness:cellroute53-recovery-readiness:ListCells
aws:route53-recovery-readiness:readiness-checkroute53-recovery-readiness:ListReadinessChecks
aws:route53-recovery-readiness:recovery-grouproute53-recovery-readiness:ListRecoveryGroups
aws:route53-recovery-readiness:resource-setroute53-recovery-readiness:ListResourceSets
aws:route53resolver:firewall-configroute53resolver:ListFirewallConfigs
aws:route53resolver:firewall-domain-listroute53resolver:ListFirewallDomainLists
aws:route53resolver:firewall-rule-grouproute53resolver:ListFirewallRuleGroups,
route53resolver:ListFirewallRules
aws:route53resolver:firewall-rule-group-associationroute53resolver:ListFirewallRuleGroupAssociations
aws:route53resolver:outpost-resolverroute53resolver:ListOutpostResolvers
aws:route53resolver:resolver-configroute53resolver:ListResolverConfigs
aws:route53resolver:resolver-dnssec-configroute53resolver:ListResolverDnssecConfigs
aws:route53resolver:resolver-endpointroute53resolver:ListResolverEndpoints
aws:route53resolver:resolver-query-log-configroute53resolver:ListResolverQueryLogConfigs
aws:route53resolver:resolver-ruleroute53resolver:ListResolverRules
aws:rum:app-monitorrum:GetAppMonitor,
rum:ListAppMonitors
aws:s3:buckets3:GetBucketAcl,
s3:GetEncryptionConfiguration,
s3:GetLifecycleConfiguration,
s3:GetBucketLogging,
s3:GetBucketMetadataConfiguration,
s3:GetBucketNotification,
s3:GetBucketOwnershipControls,
s3:GetBucketPolicy,
s3:GetBucketPolicyStatus,
s3:GetReplicationConfiguration,
s3:GetBucketVersioning,
s3:GetBucketWebsite,
s3:GetBucketPublicAccessBlock,
s3:GetInventoryConfiguration,
s3:ListAllMyBuckets
aws:s3:accessgrants3:ListAccessGrants
aws:s3:accesspoints3:GetAccessPointPolicy,
s3:ListAccessPoints
aws:s3express:buckets3express:GetEncryptionConfiguration,
s3express:GetBucketPolicy,
s3express:ListAllMyDirectoryBuckets
aws:s3-object-lambda:object-lambda-access-points3:GetAccessPointForObjectLambda,
s3:ListAccessPointsForObjectLambda
aws:outposts:outposts3-outposts:ListOutpostsWithS3
aws:s3outposts:buckets3-outposts:ListOutpostsWithS3,
s3-outposts:ListRegionalBuckets
aws:s3outposts:endpoints3-outposts:ListEndpoints
aws:s3control:accountpublicaccessblocks3:GetBucketPublicAccessBlock
aws:sagemaker:notebookinstancesagemaker:DescribeNotebookInstance,
sagemaker:ListNotebookInstances
aws:sagemaker:inference-recommendations-jobsagemaker:DescribeInferenceRecommendationsJob,
sagemaker:ListInferenceRecommendationsJobs
aws:sagemaker:pipelinesagemaker:DescribePipeline,
sagemaker:ListPipelines
aws:scheduler:groupscheduler:ListScheduleGroups
aws:scheduler:schedulescheduler:GetSchedule,
scheduler:ListSchedules
aws:schemas:discovererschemas:ListDiscoverers
aws:schemas:registryschemas:ListRegistries
aws:schemas:schemaschemas:DescribeSchema,
schemas:ListRegistries,
schemas:ListSchemas
aws:schemas:aws-schemaschemas:DescribeSchema,
schemas:ListRegistries,
schemas:ListSchemas
aws:schemas:registryschemas:ListRegistries
aws:secretsmanager:secretsecretsmanager:DescribeSecret,
secretsmanager:GetResourcePolicy,
secretsmanager:ListSecrets
aws:securityhub:automation-rulesecurityhub:BatchGetAutomationRules,
securityhub:DescribeHub,
securityhub:ListAutomationRules
aws:securityhub:configuration-policysecurityhub:DescribeHub,
organizations:DescribeOrganization,
securityhub:GetConfigurationPolicy,
securityhub:ListConfigurationPolicies
aws:securityhub:finding-aggregatorsecurityhub:DescribeHub,
securityhub:GetFindingAggregator,
securityhub:ListFindingAggregators
aws:securityhub:hubsecurityhub:DescribeHub
aws:securityhub:productsecurityhub:DescribeHub,
securityhub:DescribeProducts
aws:securitylake:data-lakesecuritylake:ListDataLakes
aws:securitylake:subscribersecuritylake:ListSubscribers
aws:servicecatalog:applicationservicecatalog:GetApplication,
servicecatalog:ListApplications
aws:servicecatalog:attribute-groupservicecatalog:GetAttributeGroup,
servicecatalog:ListAttributeGroups
aws:servicecatalog:portfolioservicecatalog:DescribePortfolio,
servicecatalog:ListPortfolios
aws:servicecatalog:productservicecatalog:DescribeProduct,
servicecatalog:SearchProducts
aws:servicediscovery:namespaceservicediscovery:GetNamespace,
servicediscovery:ListNamespaces
aws:servicediscovery:serviceservicediscovery:GetService,
servicediscovery:ListServices
aws:servicequotas:quota-changeservicequotas:ListRequestedServiceQuotaChangeHistory,
servicequotas:ListServices
aws:ses:configuration-setses:DescribeConfigurationSet,
ses:ListConfigurationSets
aws:ses:custom-verification-email-templateses:GetCustomVerificationEmailTemplate,
ses:ListCustomVerificationEmailTemplates
aws:ses:identityses:GetIdentityDkimAttributes,
ses:GetIdentityMailFromDomainAttributes,
ses:GetIdentityVerificationAttributes,
ses:ListIdentities
aws:ses:templateses:GetTemplate,
ses:ListTemplates
aws:ses:contact-listses:GetContactList,
ses:ListContactLists
aws:ses:dedicated-ip-poolses:GetDedicatedIpPool,
ses:ListDedicatedIpPools
aws:ses:multi-region-endpointses:GetMultiRegionEndpoint,
ses:ListMultiRegionEndpoints
aws:sfn:statemachinestates:DescribeStateMachine,
states:ListStateMachines
aws:sfn:activitystates:DescribeActivity,
states:ListActivities
aws:sfn:executionstates:DescribeExecution,
states:ListExecutions,
states:ListStateMachines
aws:sfn:statemachinealiasstates:DescribeStateMachineAlias,
states:ListStateMachineAliases,
states:ListStateMachines
aws:shield:attackshield:DescribeAttack,
shield:ListAttacks
aws:shield:protectionshield:ListProtections
aws:shield:protection-groupshield:ListProtectionGroups,
shield:ListResourcesInProtectionGroup
aws:shield:settingsshield:DescribeEmergencyContactSettings,
shield:DescribeSubscription,
shield:GetSubscriptionState
aws:signer:signing-profilesigner:GetSigningProfile,
signer:ListSigningProfiles
aws:snowball:clustersnowball:DescribeCluster,
snowball:ListClusters
aws:snowball:jobsnowball:DescribeJob,
snowball:ListJobs
aws:sns:topicsns:GetTopicAttributes,
sns:ListTopics
aws:sns:platform-applicationsns:ListPlatformApplications
aws:socialmessaging:wabasocial-messaging:GetLinkedWhatsAppBusinessAccount,
social-messaging:ListLinkedWhatsAppBusinessAccounts
aws:sqs:queuesqs:GetQueueAttributes,
sqs:GetQueueUrl,
sqs:ListQueues
aws:ssm:documentssm:DescribeDocument,
ssm:DescribeDocumentPermission,
ssm:ListDocuments
aws:ssm:instancessm:DescribeInstanceInformation,
ssm:ListComplianceItems
aws:ssm-incidents:incident-recordssm-incidents:GetIncidentRecord,
ssm-incidents:ListIncidentRecords
aws:ssm-incidents:replication-setssm-incidents:GetReplicationSet,
ssm-incidents:ListReplicationSets
aws:ssm-incidents:response-planssm-incidents:GetResponsePlan,
ssm-incidents:ListResponsePlans
aws:sso:applicationorganizations:DescribeOrganization,
sso:GetApplicationAssignmentConfiguration,
sso:ListApplicationAssignments,
sso:ListApplications,
sso:ListInstances
aws:sso:instancesso:DescribeInstanceAccessControlAttributeConfiguration,
organizations:DescribeOrganization,
sso:ListInstances
aws:sso:permission-setorganizations:DescribeOrganization,
sso:DescribePermissionSet,
sso:GetInlinePolicyForPermissionSet,
sso:GetPermissionsBoundaryForPermissionSet,
sso:ListCustomerManagedPolicyReferencesInPermissionSet,
sso:ListInstances,
sso:ListManagedPoliciesInPermissionSet,
sso:ListPermissionSets
aws:sso:trusted-token-issuerorganizations:DescribeOrganization,
sso:DescribeTrustedTokenIssuer,
sso:ListInstances,
sso:ListTrustedTokenIssuers
aws:sso:application-providersso:ListApplicationProviders
aws:storagegateway:cache-reportstoragegateway:ListCacheReports
aws:storagegateway:devicestoragegateway:DescribeGatewayInformation,
storagegateway:DescribeVTLDevices,
storagegateway:ListGateways
aws:storagegateway:fs-associationstoragegateway:DescribeFileSystemAssociations,
storagegateway:ListFileSystemAssociations
aws:storagegateway:gatewaystoragegateway:DescribeGatewayInformation,
storagegateway:ListGateways
aws:storagegateway:nfs-filesharestoragegateway:DescribeNFSFileShares,
storagegateway:ListFileShares
aws:storagegateway:smb-filesharestoragegateway:DescribeSMBFileShares,
storagegateway:ListFileShares
aws:storagegateway:tapestoragegateway:DescribeGatewayInformation,
storagegateway:DescribeTapes,
storagegateway:ListGateways
aws:storagegateway:tapepoolstoragegateway:ListTapePools
aws:storagegateway:volumestoragegateway:ListVolumes
aws:ec2:subnetec2:DescribeSubnets
aws:synthetics:canarysynthetics:DescribeCanaries
aws:synthetics:groupsynthetics:GetGroup,
synthetics:ListGroups
aws:textract:adaptertextract:GetAdapter,
textract:ListAdapters
aws:textract:adapter-versiontextract:GetAdapterVersion,
textract:ListAdapterVersions,
textract:ListAdapters
aws:timestream:scheduled-querytimestream:ListScheduledQueries
aws:timestreamwrite:tabletimestream:ListTables
aws:transcribe:call-analytics-categorytranscribe:ListCallAnalyticsCategories
aws:transcribe:call-analytics-jobtranscribe:GetCallAnalyticsJob,
transcribe:ListCallAnalyticsJobs
aws:transcribe:language-modeltranscribe:ListLanguageModels
aws:transcribe:medical-scribe-jobtranscribe:GetMedicalScribeJob,
transcribe:ListMedicalScribeJobs
aws:transcribe:medical-transcription-jobtranscribe:GetMedicalTranscriptionJob,
transcribe:ListMedicalTranscriptionJobs
aws:transcribe:medical-vocabularytranscribe:GetMedicalVocabulary,
transcribe:ListMedicalVocabularies
aws:transcribe:transcription-jobtranscribe:GetTranscriptionJob,
transcribe:ListTranscriptionJobs
aws:transcribe:vocabularytranscribe:GetVocabulary,
transcribe:ListVocabularies
aws:transcribe:vocabulary-filtertranscribe:GetVocabularyFilter,
transcribe:ListVocabularyFilters
aws:transfer:agreementtransfer:DescribeAgreement,
transfer:DescribeServer,
transfer:ListAgreements,
transfer:ListServers
aws:transfer:certificatetransfer:DescribeCertificate,
transfer:ListCertificates
aws:transfer:connectortransfer:DescribeConnector,
transfer:ListConnectors
aws:transfer:host-keytransfer:DescribeHostKey,
transfer:DescribeServer,
transfer:ListHostKeys,
transfer:ListServers
aws:transfer:profiletransfer:DescribeProfile,
transfer:ListProfiles
aws:transfer:servertransfer:DescribeServer,
transfer:ListServers
aws:transfer:usertransfer:DescribeServer,
transfer:DescribeUser,
transfer:ListServers,
transfer:ListUsers
aws:transfer:webapptransfer:DescribeWebApp,
transfer:ListWebApps
aws:transfer:workflowtransfer:DescribeWorkflow,
transfer:ListWorkflows
aws:ec2:transitgatewayec2:DescribeTransitGateways
aws:ec2:transitgateway-routetable-announcementec2:DescribeTransitGatewayRouteTableAnnouncements
aws:ec2:transitgatewayattachmentec2:DescribeTransitGatewayAttachments
aws:ec2:transitgatewayconnectpeerec2:DescribeTransitGatewayConnectPeers
aws:ec2:transitgatewaymulticastdomainec2:DescribeTransitGatewayMulticastDomains
aws:ec2:transitgatewaypeeringattachmentec2:DescribeTransitGatewayPeeringAttachments
aws:ec2:transitgatewaypolicytableec2:DescribeTransitGatewayPolicyTables
aws:ec2:transitgatewayroutetableec2:DescribeTransitGatewayRouteTables,
ec2:GetTransitGatewayPrefixListReferences,
ec2:SearchTransitGatewayRoutes
aws:ec2:transitgatewayvpcattachmentec2:DescribeTransitGatewayVpcAttachments
aws:translate:parallel-datatranslate:GetParallelData,
translate:ListParallelData
aws:translate:terminologytranslate:GetTerminology,
translate:ListTerminologies
aws:verifiedpermissions:identity-sourceverifiedpermissions:GetPolicyStore,
verifiedpermissions:ListIdentitySources,
verifiedpermissions:ListPolicyStores
aws:verifiedpermissions:policyverifiedpermissions:GetPolicyStore,
verifiedpermissions:ListPolicies,
verifiedpermissions:ListPolicyStores
aws:verifiedpermissions:policy-storeverifiedpermissions:GetPolicyStore,
verifiedpermissions:ListPolicyStores
aws:verifiedpermissions:policy-templateverifiedpermissions:GetPolicyStore,
verifiedpermissions:ListPolicyStores,
verifiedpermissions:ListPolicyTemplates
aws:vpc-lattice:access-log-subscriptionvpc-lattice:GetService,
vpc-lattice:GetServiceNetwork,
vpc-lattice:ListAccessLogSubscriptions,
vpc-lattice:ListServiceNetworks,
vpc-lattice:ListServices
aws:vpc-lattice:listenervpc-lattice:GetListener,
vpc-lattice:GetService,
vpc-lattice:ListListeners,
vpc-lattice:ListServices
aws:vpc-lattice:resource-configurationvpc-lattice:GetResourceConfiguration,
vpc-lattice:ListResourceConfigurations
aws:vpc-lattice:resource-endpoint-associationvpc-lattice:GetResourceConfiguration,
vpc-lattice:ListResourceConfigurations,
vpc-lattice:ListResourceEndpointAssociations
aws:vpc-lattice:resource-gatewayvpc-lattice:GetResourceGateway,
vpc-lattice:ListResourceGateways
aws:vpc-lattice:rulevpc-lattice:GetListener,
vpc-lattice:GetRule,
vpc-lattice:GetService,
vpc-lattice:ListListeners,
vpc-lattice:ListRules,
vpc-lattice:ListServices
aws:vpc-lattice:servicevpc-lattice:GetService,
vpc-lattice:ListServices
aws:vpc-lattice:service-networkvpc-lattice:GetServiceNetwork,
vpc-lattice:ListServiceNetworks
aws:vpc-lattice:service-network-resource-associationvpc-lattice:ListServiceNetworkResourceAssociations
aws:vpc-lattice:service-network-service-associationvpc-lattice:GetServiceNetwork,
vpc-lattice:ListServiceNetworkServiceAssociations,
vpc-lattice:ListServiceNetworks
aws:vpc-lattice:service-network-vpc-associationvpc-lattice:GetServiceNetwork,
vpc-lattice:ListServiceNetworkVpcAssociations,
vpc-lattice:ListServiceNetworks
aws:vpc-lattice:target-groupvpc-lattice:GetTargetGroup,
vpc-lattice:ListTargetGroups
aws:waf:aclwaf:GetWebACL,
waf:ListWebACLs
aws:waf:rulewaf:GetRule,
waf:ListRules
aws:waf:rulegroupwaf:GetRuleGroup,
waf:ListRuleGroups
aws:wafregional:aclwaf-regional:GetWebACL,
waf-regional:ListWebACLs
aws:wafregional:rulewaf-regional:GetRule,
waf-regional:ListRules
aws:wafregional:rulegroupwaf-regional:GetRuleGroup,
waf-regional:ListRuleGroups
aws:wafv2:aclwafv2:GetLoggingConfiguration,
wafv2:GetWebACL,
wafv2:ListWebACLs
aws:wafv2:ipsetwafv2:GetIPSet,
wafv2:ListIPSets
aws:wafv2:regexpatternsetwafv2:GetRegexPatternSet,
wafv2:ListRegexPatternSets
aws:wafv2:rulegroupwafv2:GetRuleGroup,
wafv2:ListRuleGroups
aws:wafv2:aclwafv2:GetLoggingConfiguration,
wafv2:GetWebACL,
wafv2:ListResourcesForWebACL,
wafv2:ListWebACLs
aws:wafv2:ipsetwafv2:GetIPSet,
wafv2:ListIPSets
aws:wafv2:regexpatternsetwafv2:GetRegexPatternSet,
wafv2:ListRegexPatternSets
aws:wafv2:rulegroupwafv2:GetRuleGroup,
wafv2:ListRuleGroups
aws:workmail:organizationworkmail:DescribeOrganization,
workmail:ListOrganizations
aws:workspaces:applicationworkspaces:DescribeApplications
aws:workspaces:bundleworkspaces:DescribeWorkspaceBundles
aws:workspaces:connection-aliasworkspaces:DescribeConnectionAliases
aws:workspaces:directoryworkspaces:DescribeWorkspaceDirectories
aws:workspaces:imageworkspaces:DescribeWorkspaceImages
aws:workspaces:ip-groupworkspaces:DescribeIpGroups
aws:workspaces:poolworkspaces:DescribeWorkspacesPools
aws:workspaces:workspaceworkspaces:DescribeWorkspaces
aws:workspaces:amazon-bundleworkspaces:DescribeWorkspaceBundles
aws:workspaces-web:browser-settingsworkspaces-web:GetBrowserSettings,
workspaces-web:ListBrowserSettings
aws:workspaces-web:data-protection-settingsworkspaces-web:GetDataProtectionSettings,
workspaces-web:ListDataProtectionSettings
aws:workspaces-web:identity-providerworkspaces-web:GetIdentityProvider,
workspaces-web:ListIdentityProviders,
workspaces-web:ListPortals
aws:workspaces-web:ip-access-settingsworkspaces-web:GetIpAccessSettings,
workspaces-web:ListIpAccessSettings
aws:workspaces-web:network-settingsworkspaces-web:GetNetworkSettings,
workspaces-web:ListNetworkSettings
aws:workspaces-web:portalworkspaces-web:ListPortals
aws:workspaces-web:trust-storeworkspaces-web:GetTrustStore,
workspaces-web:ListTrustStores
aws:workspaces-web:user-access-logging-settingsworkspaces-web:GetUserAccessLoggingSettings,
workspaces-web:ListUserAccessLoggingSettings
aws:workspaces-web:user-settingsworkspaces-web:GetUserSettings,
workspaces-web:ListUserSettings
aws:xray:groupxray:GetGroups
aws:xray:sampling-rulexray:GetSamplingRules
aws:iam:credentialreportiam:GenerateCredentialReport,
iam:GetCredentialReport
Resource TypePermissions
aws:ec2:vpngatewayec2:DescribeVpnGateways
aws:ec2:egressonlyinternetgatewayec2:DescribeEgressOnlyInternetGateways
aws:ec2:vpcinternetgatewayec2:DescribeInternetGateways
aws:ec2:vpcnatgatewayec2:DescribeNatGateways
aws:ec2:vpcendpointconnectionnotificationec2:DescribeVpcEndpointConnectionNotifications
aws:ec2:vpcpeeringconnectionec2:DescribeVpcPeeringConnections
aws:network-firewall:firewallnetwork-firewall:DescribeFirewall,
network-firewall:DescribeFirewallPolicy,
network-firewall:DescribeLoggingConfiguration,
network-firewall:ListFirewalls
aws:ec2:transitgatewayec2:DescribeTransitGateways
Resource TypePermissions
aws:acm:acmacm:DescribeCertificate,
acm:ListCertificates
aws:applicationautoscaling:scalingpolicyapplicationautoscaling:DescribeScalingPolicies
aws:autoscaling:groupautoscaling:DescribeAutoScalingGroups
aws:cloudformation:stackcloudformation:DescribeStacks,
cloudformation:ListStacks
aws:cloudfront:distributioncloudfront:GetDistribution,
cloudfront:ListDistributions
aws:cloudfront:functioncloudfront:ListFunctions
aws:cloudtrail:trailcloudtrail:DescribeTrails,
cloudtrail:GetEventSelectors,
cloudtrail:GetTrailStatus
aws:cloudwatchlogs:log-grouplogs:DescribeLogGroups,
logs:DescribeSubscriptionFilters
aws:docdb:clusterrds:DescribeDBClusters
aws:dynamodb:tabledynamodb:DescribeContinuousBackups,
dynamodb:DescribeTable,
dynamodb:DescribeTimeToLive,
dynamodb:ListTables
aws:ec2:snapshotec2:DescribeSnapshotAttribute,
ec2:DescribeSnapshots
aws:ec2:volumeec2:DescribeVolumes
aws:ec2:imageec2:DescribeImageAttribute,
ec2:DescribeImages
aws:ec2:instanceec2:DescribeInstances
aws:ec2:networkaclec2:DescribeNetworkAcls
aws:ec2:networkinterfaceec2:DescribeNetworkInterfaces
aws:ec2:securitygroupec2:DescribeSecurityGroups
aws:ec2:vpcendpointec2:DescribeVpcEndpoints
aws:ec2:vpcendpoint-serviceec2:DescribeVpcEndpointServices
aws:ec2:vpcec2:DescribeVpcs
aws:ec2:vpcnatgatewayec2:DescribeNatGateways
aws:ec2:vpcpeeringconnectionec2:DescribeVpcPeeringConnections
aws:ecr:repositoryecr:DescribeRepositories,
ecr:GetLifecyclePolicy,
ecr:GetRepositoryPolicy
aws:ecrpublic:repositoryecr-public:DescribeImages,
ecr-public:DescribeRepositories,
ecr-public:GetRepositoryPolicy
aws:ecs:clusterecs:DescribeClusters,
ecs:ListClusters
aws:ecs:serviceecs:DescribeServices,
ecs:ListClusters,
ecs:ListServices
aws:ecs:taskecs:DescribeServices,
ecs:DescribeTasks,
ecs:ListClusters,
ecs:ListServices,
ecs:ListTasks
aws:ecs:task-definitionecs:DescribeServices,
ecs:DescribeTaskDefinition,
ecs:DescribeTasks,
ecs:ListClusters,
ecs:ListServices,
ecs:ListTasks
aws:efs:accesspointelasticfilesystem:DescribeAccessPoints
aws:efs:filesystemelasticfilesystem:DescribeFileSystems,
elasticfilesystem:DescribeLifecycleConfiguration
aws:eks:clustereks:DescribeCluster,
eks:ListClusters
aws:elasticache:clusterelasticache:DescribeCacheClusters
aws:elasticloadbalancing:loadbalancerelasticloadbalancing:DescribeInstanceHealth,
elasticloadbalancing:DescribeLoadBalancerAttributes,
elasticloadbalancing:DescribeLoadBalancerPolicies,
elasticloadbalancing:DescribeLoadBalancers
aws:elasticloadbalancingv2:loadbalancerelasticloadbalancing:DescribeListeners,
elasticloadbalancing:DescribeLoadBalancerAttributes,
elasticloadbalancing:DescribeLoadBalancers
aws:elasticsearchservice:domaines:DescribeElasticsearchDomains,
es:ListDomainNames
aws:emr:clusterelasticmapreduce:DescribeCluster,
elasticmapreduce:GetAutoTerminationPolicy,
elasticmapreduce:GetManagedScalingPolicy,
elasticmapreduce:ListClusters
aws:eventbridge:eventbusevents:ListEventBuses,
events:ListRules
aws:iam:accountorganizations:DescribeOrganization,
iam:GetAccountPasswordPolicy,
iam:GetAccountSummary
aws:iam:server-certificateiam:ListServerCertificates
aws:iam:policyiam:GetPolicy,
iam:GetPolicyVersion,
iam:ListPolicies
aws:iam:roleiam:GetAccountAuthorizationDetails,
iam:GetRole,
iam:ListAttachedRolePolicies
aws:iam:useriam:GetLoginProfile,
iam:GetUser,
iam:ListAttachedUserPolicies,
iam:ListGroupsForUser,
iam:ListMFADevices,
iam:ListSSHPublicKeys,
iam:ListUsers,
iam:ListVirtualMFADevices
aws:kms:keykms:DescribeKey,
kms:GetKeyRotationStatus,
kms:ListKeys
aws:lambda:functionlambda:GetFunction,
lambda:GetPolicy,
lambda:ListFunctionUrlConfigs,
lambda:ListFunctions,
lambda:ListProvisionedConcurrencyConfigs
aws:mq:brokermq:DescribeBroker,
mq:ListBrokers
aws:pipes:pipepipes:ListPipes
aws:rds:clusterrds:DescribeDBClusters
aws:rds:instancerds:DescribeDBInstances
aws:rds:snapshotrds:DescribeDBSnapshotAttributes,
rds:DescribeDBSnapshots
aws:redshift:clusterredshift:DescribeClusterParameters,
redshift:DescribeClusters,
redshift:DescribeEndpointAccess,
redshift:DescribeLoggingStatus
aws:s3:buckets3:GetBucketAcl,
s3:GetEncryptionConfiguration,
s3:GetLifecycleConfiguration,
s3:GetBucketLogging,
s3:GetBucketMetadataConfiguration,
s3:GetBucketNotification,
s3:GetBucketOwnershipControls,
s3:GetBucketPolicy,
s3:GetBucketPolicyStatus,
s3:GetReplicationConfiguration,
s3:GetBucketVersioning,
s3:GetBucketWebsite,
s3:GetBucketPublicAccessBlock,
s3:GetInventoryConfiguration,
s3:ListAllMyBuckets
aws:s3control:accountpublicaccessblocks3:GetBucketPublicAccessBlock
aws:secretsmanager:secretsecretsmanager:DescribeSecret,
secretsmanager:GetResourcePolicy,
secretsmanager:ListSecrets
aws:sfn:statemachinestates:DescribeStateMachine,
states:ListStateMachines
aws:sns:topicsns:GetTopicAttributes,
sns:ListTopics
aws:sqs:queuesqs:GetQueueAttributes,
sqs:GetQueueUrl,
sqs:ListQueues

Upcoming releases

The permissions listed here reflect resources planned to be added within the next 30 days. Include these permissions in your existing AWS integration IAM policy (with attached SecurityAudit policy) to get the full benefits of Datadog’s resource coverage and tracking.

Cloud Security

Setup

If you do not have the AWS integration set up for your AWS account, complete the set up process above. Ensure that you enable Cloud Security when mentioned.

Note: The AWS integration must be set up with Role delegation to use this feature.

To add Cloud Security to an existing AWS integration, follow the steps below to enable resource collection.

  1. Provide the necessary permissions to the Datadog IAM role by attaching the AWS managed SecurityAudit policy to your Datadog AWS IAM role. You can find this policy in the AWS console.

  2. Complete the setup in the Datadog AWS integration page with the steps below. Alternatively, you can use the Update an AWS Integration API endpoint.

    1. Select the AWS account where you wish to enable resource collection.
    2. On the Resource collection tab, click Enable next to Cloud Security. You are redirected to the Cloud Security Setup page, and a setup dialog automatically opens for the selected account.
    3. On the setup dialog, switch the Enable Resource Scanning toggle to the on position.
    4. Click Done to complete the setup.

Alarm collection

There are two ways to send AWS CloudWatch alarms to the Datadog Events Explorer:

  • Alarm polling: Alarm polling comes out of the box with the AWS integration and fetches metric alarms through the DescribeAlarmHistory API. If you follow this method, your alarms are categorized under the event source Amazon Web Services. Note: The crawler does not collect composite alarms.
  • SNS topic: You can see all AWS CloudWatch alarms in your Events Explorer by subscribing the alarms to an SNS topic, then forwarding the SNS messages to Datadog. To learn how to receive SNS messages as events in Datadog, see Receive SNS messages. If you follow this method, your alarms are categorized under the event source Amazon SNS.

Data Collected

Metrics

aws.logs.delivery_errors
(count)
The number of log events for which CloudWatch Logs received an error when forwarding data to the subscription destination.
Shown as event
aws.logs.delivery_throttling
(count)
The number of log events for which CloudWatch Logs was throttled when forwarding data to the subscription destination.
Shown as event
aws.logs.forwarded_bytes
(gauge)
The volume of log events in compressed bytes forwarded to the subscription destination.
Shown as byte
aws.logs.forwarded_log_events
(count)
The number of log events forwarded to the subscription destination.
Shown as event
aws.logs.incoming_bytes
(gauge)
The volume of log events in uncompressed bytes uploaded to Cloudwatch Logs.
Shown as byte
aws.logs.incoming_log_events
(count)
The number of log events uploaded to Cloudwatch Logs.
Shown as event
aws.usage.call_count
(count)
The number of specified operations performed in your account
Shown as operation
aws.usage.resource_count
(count)
The number of specified resources in your account
Shown as resource

Note: You can enable the collection of AWS custom metrics, as well as metrics from services that Datadog doesn’t have an integration for. See the AWS Integration and CloudWatch FAQ for more information.

Events

Events from AWS are collected on a per AWS-service basis. See your AWS service’s documentation to learn more about collected events.

Tags

The following tags are collected with the AWS integration. Note: Some tags only display on specific metrics.

IntegrationDatadog Tag Keys
Allregion
API Gatewayapiid, apiname, method, resource, stage
App Runnerinstance, serviceid, servicename
Auto Scalingautoscalinggroupname, autoscaling_group
Billingaccount_id, budget_name, budget_type, currency, servicename, time_unit
CloudFrontdistributionid
CodeBuildproject_name
CodeDeployapplication, creator, deployment_config, deployment_group, deployment_option, deployment_type, status
DirectConnectconnectionid
DynamoDBglobalsecondaryindexname, operation, streamlabel, tablename
EBSvolumeid, volume-name, volume-type
EC2autoscaling_group, availability-zone, image, instance-id, instance-type, kernel, name, security_group_name
ECSclustername, servicename, instance_id
EFSfilesystemid
ElastiCachecachenodeid, cache_node_type, cacheclusterid, cluster_name, engine, engine_version, preferred_availability-zone, replication_group
ElasticBeanstalkenvironmentname, enviromentid
ELBavailability-zone, hostname, loadbalancername, name, targetgroup
EMRcluster_name, jobflowid
ESdedicated_master_enabled, ebs_enabled, elasticsearch_version, instance_type, zone_awareness_enabled
Firehosedeliverystreamname
FSxfilesystemid, filesystemtype
Healthevent_category, status, service
IoTactiontype, protocol, rulename
Kinesisstreamname, name, state
KMSkeyid
Lambdafunctionname, resource, executedversion, memorysize, runtime
Machine Learningmlmodelid, requestmode
MQbroker, queue, topic
OpsWorksstackid, layerid, instanceid
Pollyoperation
RDSauto_minor_version_upgrade, dbinstanceclass, dbclusteridentifier, dbinstanceidentifier, dbname, engine, engineversion, hostname, name, publicly_accessible, secondary_availability-zone
RDS Proxyproxyname, target, targetgroup, targetrole
Redshiftclusteridentifier, latency, nodeid, service_class, stage, wlmid
Route 53healthcheckid
S3bucketname, filterid, storagetype
SESTag keys are custom set in AWS.
SNStopicname
SQSqueuename
VPCnategatewayid, vpnid, tunnelipaddress
WorkSpacesdirectoryid, workspaceid

Service Checks

aws.status

Returns CRITICAL if one or more AWS regions are experiencing issues. Returns OK otherwise.

Statuses: ok, critical

Troubleshooting

See the AWS Integration Troubleshooting guide to resolve issues related to the AWS integration.

Further Reading