概要

Amazon Web Services (AWS) を接続すると、次のことができるようになります。

  • イベントエクスプローラーで AWS ステータスの自動更新を確認する
  • Agent をインストールすることなく、EC2 ホストの CloudWatch メトリクスを取得する
  • EC2 ホストに EC2 固有の情報をタグ付けする
  • EC2 のスケジュール設定されたメンテナンス イベントをストリームに表示する
  • その他のさまざまな AWS 製品から CloudWatch メトリクスとイベントを収集する
  • イベントエクスプローラーで CloudWatch アラームを確認する

AWS インテグレーションをすぐに使い始めるには、AWS スタートガイドをご確認ください。

Datadog の Amazon Web Services インテグレーションは、90 以上の AWS サービスのログ、イベント、CloudWatch からのほとんどのメトリクスを収集します。

セットアップ

以下のいずれかの方法を使用して AWS アカウントを Datadog に統合し、メトリクス、イベント、タグ、ログを収集します。

自動

手動

  • ロールの委任 AWS インテグレーションをロールの委任で手動設定する場合は、手動設定ガイドを参照してください。

  • アクセス キー (GovCloud または China* のみ) アクセスキーによる AWS インテグレーションを設定する場合は、手動設定ガイドを参照してください。

    * 中国本土における (または中国本土内の環境に関連する) Datadog サービスの使用はすべて、当社 Web サイトのサービス制限地域セクションに掲載されている免責事項に従うものとします。

AWS IAM permissions

AWS IAM permissions enable Datadog to collect metrics, tags, EventBridge events and other data necessary to monitor your AWS environment. To correctly set up the AWS Integration, you must attach the relevant IAM policies to the Datadog AWS Integration IAM Role in your AWS account.

AWS integration IAM policy

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Action": [
        "account:GetAccountInformation",
        "airflow:GetEnvironment",
        "airflow:ListEnvironments",
        "apigateway:GET",
        "appsync:ListGraphqlApis",
        "autoscaling:Describe*",
        "backup:List*",
        "batch:DescribeJobDefinitions",
        "batch:DescribeJobQueues",
        "batch:DescribeJobs",
        "batch:ListJobs",
        "bcm-data-exports:GetExport",
        "bcm-data-exports:ListExports",
        "budgets:ViewBudget",
        "cloudfront:GetDistributionConfig",
        "cloudfront:ListDistributions",
        "cloudtrail:DescribeTrails",
        "cloudtrail:GetTrail",
        "cloudtrail:GetTrailStatus",
        "cloudtrail:ListTrails",
        "cloudtrail:LookupEvents",
        "cloudwatch:Describe*",
        "cloudwatch:Get*",
        "cloudwatch:List*",
        "codebuild:BatchGetProjects",
        "codebuild:ListProjects",
        "codedeploy:BatchGet*",
        "codedeploy:List*",
        "cur:DescribeReportDefinitions",
        "directconnect:Describe*",
        "dms:DescribeReplicationInstances",
        "dynamodb:Describe*",
        "dynamodb:List*",
        "ec2:Describe*",
        "ecs:Describe*",
        "ecs:List*",
        "eks:DescribeCluster",
        "eks:ListClusters",
        "elasticache:Describe*",
        "elasticache:List*",
        "elasticfilesystem:DescribeAccessPoints",
        "elasticfilesystem:DescribeFileSystems",
        "elasticfilesystem:DescribeTags",
        "elasticloadbalancing:Describe*",
        "elasticmapreduce:Describe*",
        "elasticmapreduce:List*",
        "es:DescribeElasticsearchDomains",
        "es:ListDomainNames",
        "es:ListTags",
        "events:CreateEventBus",
        "fsx:DescribeFileSystems",
        "fsx:ListTagsForResource",
        "health:DescribeAffectedEntities",
        "health:DescribeEventDetails",
        "health:DescribeEvents",
        "iam:ListAccountAliases",
        "kinesis:Describe*",
        "kinesis:List*",
        "lambda:List*",
        "logs:DeleteSubscriptionFilter",
        "logs:DescribeDeliveries",
        "logs:DescribeDeliverySources",
        "logs:DescribeLogGroups",
        "logs:DescribeLogStreams",
        "logs:DescribeSubscriptionFilters",
        "logs:FilterLogEvents",
        "logs:GetDeliveryDestination",
        "logs:PutSubscriptionFilter",
        "logs:TestMetricFilter",
        "network-firewall:DescribeLoggingConfiguration",
        "network-firewall:ListFirewalls",
        "oam:ListAttachedLinks",
        "oam:ListSinks",
        "organizations:Describe*",
        "organizations:List*",
        "rds:Describe*",
        "rds:List*",
        "redshift-serverless:ListNamespaces",
        "redshift:DescribeClusters",
        "redshift:DescribeLoggingStatus",
        "route53:List*",
        "route53resolver:ListResolverQueryLogConfigs",
        "s3:GetBucketLocation",
        "s3:GetBucketLogging",
        "s3:GetBucketNotification",
        "s3:GetBucketTagging",
        "s3:ListAllMyBuckets",
        "s3:PutBucketNotification",
        "ses:Get*",
        "ses:List*",
        "sns:GetSubscriptionAttributes",
        "sns:List*",
        "sns:Publish",
        "sqs:ListQueues",
        "ssm:GetServiceSetting",
        "ssm:ListCommands",
        "states:DescribeStateMachine",
        "states:ListStateMachines",
        "support:DescribeTrustedAdvisor*",
        "support:RefreshTrustedAdvisorCheck",
        "tag:GetResources",
        "tag:GetTagKeys",
        "tag:GetTagValues",
        "timestream:DescribeEndpoints",
        "wafv2:ListLoggingConfigurations",
        "xray:BatchGetTraces",
        "xray:GetTraceSummaries"
      ],
      "Effect": "Allow",
      "Resource": "*"
    }
  ]
}

AWS resource collection IAM policy

To use resource collection, you must attach AWS’s managed SecurityAudit Policy to your Datadog IAM role.

Notes:

  • Warning messages appear on the AWS integration tile in Datadog if you enable resource collection, but do not have the AWS Security Audit Policy attached to your Datadog IAM role.
  • To enable Datadog to collect account management resources from account.GetAlternateContact and account.GetContactInformation, you need to enable trusted access for AWS account management.
  • AWS China accounts are not supported.
  • Enabling resource collection can also impact your AWS CloudWatch costs. To avoid these charges, disable Usage (AWS/Usage) metrics in the Metric Collection tab of the Datadog AWS integration page.

ログ収集

AWSサービスログを Datadog に送信する方法はいくつかあります。

  • Amazon Data Firehose destination: Amazon Data Firehose 配信ストリームで Datadog の宛先を使用して、ログを Datadog に転送します。CloudWatch から非常に大量のログを送信する際は、このアプローチを使用することが推奨されます。
  • Forwarder Lambda 関数: S3 バケットまたは CloudWatch ロググループにサブスクライブする Datadog Forwarder Lambda 関数をデプロイし、ログを Datadog に転送します。また、S3 またはデータを Amazon Data Firehose に直接ストリーミングできないその他のリソースからログを送信する場合、Datadog ではこのアプローチを使用することをお勧めしています。

メトリクスの収集

メトリクスを Datadog に送信する方法は 2 つあります。

  • メトリクスのポーリング: AWS インテグレーションで利用できる API ポーリングです。CloudWatch API をメトリクス別にクロールしてデータを取得し、Datadog に送信します。新しいメトリクスの取得は平均 10 分毎に行われます。
  • Amazon Data Firehose でのメトリクスストリーム: Amazon CloudWatch Metric Streams と Amazon Data Firehose を使用してメトリクスを確認します。: このメソッドには 2 - 3 分のレイテンシーがあり、別途設定が必要となります。

利用可能なサブインテグレーションの一覧は、インテグレーションページでご確認いただけます。これらのインテグレーションの多くは、Datadog が AWS アカウントからのデータ入力を認識した際にデフォルトでインストールされます。コスト管理のために特定のリソースを除外するオプションについては、AWS インテグレーション請求ページをご参照ください。

リソース収集

一部の Datadog 製品は、AWS リソース (S3 バケット、RDS スナップショット、CloudFront ディストリビューションなど) の構成方法に関する情報を活用します。Datadog は、AWS アカウントに対して読み取り専用の API 呼び出しを行うことにより、この情報を収集します。

AWS resource collection IAM policy

To use resource collection, you must attach AWS’s managed SecurityAudit Policy to your Datadog IAM role.

Notes:

  • Warning messages appear on the AWS integration tile in Datadog if you enable resource collection, but do not have the AWS Security Audit Policy attached to your Datadog IAM role.
  • To enable Datadog to collect account management resources from account.GetAlternateContact and account.GetContactInformation, you need to enable trusted access for AWS account management.
  • AWS China accounts are not supported.
  • Enabling resource collection can also impact your AWS CloudWatch costs. To avoid these charges, disable Usage (AWS/Usage) metrics in the Metric Collection tab of the Datadog AWS integration page.

リソース タイプと権限

以下のセクションでは、Datadog の各プロダクトで収集されるリソース タイプと、Datadog IAM ロールが代理でデータを収集するために必要な権限をまとめています。これらの権限を、既存の AWS インテグレーション IAM ポリシー (SecurityAudit ポリシーをアタッチ済み) に追加してください。

Resource TypePermissions
aws:ec2:availabilityzoneec2:DescribeAvailabilityZones
aws:ec2:instanceec2:DescribeInstances
aws:ec2:volumeec2:DescribeVolumes
Resource TypePermissions
aws:apigateway:apiapigateway:GET
aws:apigatewayv2:apiapigateway:GetApis,
apigateway:GetRoutes
aws:autoscaling:groupautoscaling:DescribeAutoScalingGroups
aws:cloudfront:distributioncloudfront:GetDistribution,
cloudfront:ListDistributions
aws:directconnect:connectiondirectconnect:DescribeConnections
aws:docdb:clusterrds:DescribeDBClusters
aws:dynamodb:tabledynamodb:DescribeContinuousBackups,
dynamodb:DescribeTable,
dynamodb:DescribeTimeToLive,
dynamodb:ListTables
aws:ec2:availabilityzoneec2:DescribeAvailabilityZones
aws:ec2:customergatewayec2:DescribeCustomerGateways
aws:ec2:ebs-encryption-by-defaultec2:GetEbsEncryptionByDefault
aws:ec2:instanceec2:DescribeInstances
aws:ec2:securitygroupec2:DescribeSecurityGroups
aws:ec2:snapshotec2:DescribeSnapshotAttribute,
ec2:DescribeSnapshots
aws:ec2:subnetec2:DescribeSubnets
aws:ec2:transitgatewayec2:DescribeTransitGateways
aws:ec2:volumeec2:DescribeVolumes
aws:ec2:vpcec2:DescribeVpcs
aws:ec2:vpcendpointec2:DescribeVpcEndpoints
aws:ec2:vpcinternetgatewayec2:DescribeInternetGateways
aws:ec2:vpcnatgatewayec2:DescribeNatGateways
aws:ec2:vpnconnectionec2:DescribeVpnConnections
aws:ec2:vpngatewayec2:DescribeVpnGateways
aws:ecr:repositoryecr:DescribeRepositories,
ecr:GetLifecyclePolicy,
ecr:GetRepositoryPolicy
aws:ecrpublic:repositoryecr-public:DescribeImages,
ecr-public:DescribeRepositories,
ecr-public:GetRepositoryPolicy
aws:ecs:clusterecs:DescribeClusters,
ecs:ListClusters
aws:ecs:serviceecs:DescribeServices,
ecs:ListClusters,
ecs:ListServices
aws:ecs:taskecs:DescribeServices,
ecs:DescribeTasks,
ecs:ListClusters,
ecs:ListServices,
ecs:ListTasks
aws:efs:accesspointelasticfilesystem:DescribeAccessPoints
aws:efs:filesystemelasticfilesystem:DescribeFileSystems,
elasticfilesystem:DescribeLifecycleConfiguration
aws:efs:mounttargetelasticfilesystem:DescribeFileSystems,
elasticfilesystem:DescribeMountTargetSecurityGroups,
elasticfilesystem:DescribeMountTargets
aws:eks:clustereks:DescribeCluster,
eks:ListClusters
aws:eks:nodegroupeks:DescribeCluster,
eks:DescribeNodeGroup,
eks:ListClusters,
eks:ListNodeGroups
aws:elasticache:cachesubnetgroupelasticache:DescribeCacheSubnetGroups
aws:elasticache:clusterelasticache:DescribeCacheClusters
aws:elasticache:parametergroupelasticache:DescribeCacheParameterGroups
aws:elasticache:replicationgroupelasticache:DescribeReplicationGroups
aws:elasticache:securitygroupelasticache:DescribeCacheSecurityGroups
aws:elasticache:snapshotelasticache:DescribeSnapshots
aws:elasticache:userelasticache:DescribeUsers
aws:elasticache:usergroupelasticache:DescribeUserGroups
aws:elasticloadbalancing:loadbalancerelasticloadbalancing:DescribeInstanceHealth,
elasticloadbalancing:DescribeLoadBalancerAttributes,
elasticloadbalancing:DescribeLoadBalancerPolicies,
elasticloadbalancing:DescribeLoadBalancers
aws:elasticloadbalancingv2:loadbalancerelasticloadbalancing:DescribeListeners,
elasticloadbalancing:DescribeLoadBalancerAttributes,
elasticloadbalancing:DescribeLoadBalancers
aws:elasticsearchservice:domaines:DescribeElasticsearchDomains,
es:ListDomainNames
aws:eventbridge:eventbusevents:ListEventBuses,
events:ListRules
aws:fsx:backupfsx:DescribeBackups
aws:fsx:file-systemfsx:DescribeFileSystems
aws:glacier:vaultglacier:GetVaultNotifications,
glacier:ListVaults
aws:keyspaces:keyspacecassandra:Select
aws:kinesis:streamkinesis:DescribeStreamSummary,
kinesis:ListStreams
aws:lambda:functionlambda:GetFunction,
lambda:GetPolicy,
lambda:ListFunctionUrlConfigs,
lambda:ListFunctions,
lambda:ListProvisionedConcurrencyConfigs
aws:neptune:clusterrds:DescribeDBClusters
aws:neptune:cluster-snapshotrds:DescribeDBClusterSnapshotAttributes,
rds:DescribeDBClusterSnapshots
aws:neptune:dbinstancerds:DescribeDBInstances
aws:rds:clusterrds:DescribeDBClusters
aws:rds:cluster-snapshotrds:DescribeDBClusterSnapshotAttributes,
rds:DescribeDBClusterSnapshots
aws:rds:dbclusterparametergrouprds:DescribeDBClusterParameterGroups
aws:rds:dbinstanceautomatedbackuprds:DescribeDBInstanceAutomatedBackups
aws:rds:dbparametergrouprds:DescribeDBParameterGroups,
rds:DescribeDBParameters
aws:rds:dbsubnetgrouprds:DescribeDBSubnetGroups
aws:rds:eventsubscriptionrds:DescribeEventSubscriptions
aws:rds:exporttaskrds:DescribeExportTasks
aws:rds:instancerds:DescribeDBInstances
aws:rds:optiongrouprds:DescribeOptionGroups
aws:rds:reserveddbinstancerds:DescribeReservedDBInstances
aws:rds:securitygrouprds:DescribeDBSecurityGroups
aws:rds:snapshotrds:DescribeDBSnapshotAttributes,
rds:DescribeDBSnapshots
aws:redshift:eventsubscriptionredshift:DescribeEventSubscriptions
aws:redshift:parametergroupredshift:DescribeClusterParameterGroups
aws:redshift:securitygroupredshift:DescribeClusterSecurityGroups
aws:redshift:snapshotredshift:DescribeClusterSnapshots,
redshift:DescribeClusters
aws:redshift:subnetgroupredshift:DescribeClusterSubnetGroups,
redshift:DescribeClusters
aws:route53:hostedzoneroute53:GetDNSSEC,
route53:GetHostedZone,
route53:ListHostedZones
aws:s3:buckets3:GetBucketAbac,
s3:GetBucketAcl,
s3:GetBucketLogging,
s3:GetBucketMetadataConfiguration,
s3:GetBucketNotification,
s3:GetBucketObjectLockConfiguration,
s3:GetBucketOwnershipControls,
s3:GetBucketPolicy,
s3:GetBucketPolicyStatus,
s3:GetBucketPublicAccessBlock,
s3:GetBucketVersioning,
s3:GetBucketWebsite,
s3:GetEncryptionConfiguration,
s3:GetInventoryConfiguration,
s3:GetLifecycleConfiguration,
s3:GetReplicationConfiguration,
s3:ListAllMyBuckets
aws:ses:addon-instanceses:ListAddonInstances
aws:ses:addon-subscriptionses:ListAddonSubscriptions
aws:ses:address-listses:ListAddressLists
aws:ses:archiveses:GetArchive,
ses:ListArchives
aws:ses:configuration-setses:DescribeConfigurationSet,
ses:ListConfigurationSets
aws:ses:contact-listses:GetContactList,
ses:ListContactLists
aws:ses:custom-verification-email-templateses:GetCustomVerificationEmailTemplate,
ses:ListCustomVerificationEmailTemplates
aws:ses:dedicated-ip-poolses:GetDedicatedIpPool,
ses:ListDedicatedIpPools
aws:ses:identityses:GetIdentityDkimAttributes,
ses:GetIdentityMailFromDomainAttributes,
ses:GetIdentityVerificationAttributes,
ses:ListIdentities
aws:ses:ingress-pointses:GetIngressPoint,
ses:ListIngressPoints
aws:ses:multi-region-endpointses:GetMultiRegionEndpoint,
ses:ListMultiRegionEndpoints
aws:ses:relayses:GetRelay,
ses:ListRelays
aws:ses:rule-setses:GetRuleSet,
ses:ListRuleSets
aws:ses:templateses:GetTemplate,
ses:ListTemplates
aws:ses:traffic-policyses:GetTrafficPolicy,
ses:ListTrafficPolicies
aws:sns:subscriptionsns:ListSubscriptions
aws:sns:topicsns:GetTopicAttributes,
sns:ListTopics
aws:sqs:queuesqs:GetQueueAttributes,
sqs:GetQueueUrl,
sqs:ListQueues
aws:timestreamwrite:tabletimestream:ListTables
aws:waf:aclwaf:GetWebACL,
waf:ListWebACLs
aws:waf:rulewaf:GetRule,
waf:ListRules
aws:waf:rulegroupwaf:GetRuleGroup,
waf:ListRuleGroups
aws:wafregional:aclwaf-regional:GetWebACL,
waf-regional:ListWebACLs
aws:wafregional:rulewaf-regional:GetRule,
waf-regional:ListRules
aws:wafregional:rulegroupwaf-regional:GetRuleGroup,
waf-regional:ListRuleGroups
aws:wafv2:aclwafv2:GetLoggingConfiguration,
wafv2:GetWebACL,
wafv2:ListResourcesForWebACL,
wafv2:ListWebACLs
Resource TypePermissions
aws:accessanalyzer:analyzeraccess-analyzer:GetAnalyzer,
access-analyzer:ListAnalyzers
aws:account:accountaccount:GetAlternateContact,
account:GetContactInformation,
account:GetPrimaryEmail,
organizations:DescribeOrganization,
organizations:ListAccounts
aws:acm:acmacm:DescribeCertificate,
acm:ListCertificates
aws:acmpca:certificateauthorityacm-pca:DescribeCertificateAuthority,
acm-pca:ListCertificateAuthorities
aws:amp:rulegroupsnamespaceaps:DescribeRuleGroupsNamespace,
aps:DescribeWorkspace,
aps:ListRuleGroupsNamespaces,
aps:ListWorkspaces
aws:amp:scraperaps:DescribeScraper,
aps:ListScrapers
aws:amp:workspaceaps:DescribeWorkspace,
aps:ListWorkspaces
aws:amplify:appamplify:ListApps
aws:amplify:backend-environmentamplify:ListApps,
amplify:ListBackendEnvironments
aws:amplify:branchamplify:ListApps,
amplify:ListBranches
aws:amplify:domain-associationamplify:ListApps,
amplify:ListDomainAssociations
aws:amplify:jobamplify:ListApps,
amplify:ListBranches,
amplify:ListJobs
aws:amplify:webhookamplify:ListApps,
amplify:ListWebhooks
aws:apigateway:accountapigateway:GetAccount
aws:apigateway:apiapigateway:GET
aws:apigateway:apikeyapigateway:GetApiKeys
aws:apigateway:authorizerapigateway:GET,
apigateway:GetAuthorizers
aws:apigateway:basepathmappingapigateway:GetBasePathMappings,
apigateway:GetDomainNames
aws:apigateway:clientcertificateapigateway:GetClientCertificates
aws:apigateway:deploymentapigateway:GET,
apigateway:GetDeployments
aws:apigateway:documentationpartapigateway:GET,
apigateway:GetDocumentationParts
aws:apigateway:domainnameapigateway:GetDomainNames
aws:apigateway:domainnameaccessassociationapigateway:GetDomainNameAccessAssociations
aws:apigateway:gatewayresponseapigateway:GET,
apigateway:GetGatewayResponses
aws:apigateway:integrationapigateway:GET,
apigateway:GetMethod,
apigateway:GetResources
aws:apigateway:modelapigateway:GET,
apigateway:GetModels
aws:apigateway:requestvalidatorapigateway:GET,
apigateway:GetRequestValidators
aws:apigateway:resourceapigateway:GET,
apigateway:GetResources
aws:apigateway:stageapigateway:GET
aws:apigateway:usageplanapigateway:GetApiKeys,
apigateway:GetUsagePlans
aws:apigateway:usageplankeyapigateway:GetApiKeys,
apigateway:GetUsagePlanKeys,
apigateway:GetUsagePlans
aws:apigateway:vpclinkapigateway:GetVpcLinks
aws:apigatewayv2:apiapigateway:GetApis,
apigateway:GetRoutes
aws:apigatewayv2:apimappingapigateway:GetApiMappings,
apigateway:GetDomainNames
aws:apigatewayv2:authorizerapigateway:GetApis,
apigateway:GetAuthorizers
aws:apigatewayv2:deploymentapigateway:GetApis,
apigateway:GetDeployments
aws:apigatewayv2:domainnameapigateway:GetDomainNames
aws:apigatewayv2:integrationapigateway:GetApis,
apigateway:GetIntegrations
aws:apigatewayv2:integrationresponseapigateway:GetApis,
apigateway:GetIntegrationResponses,
apigateway:GetIntegrations
aws:apigatewayv2:modelapigateway:GetApis,
apigateway:GetModels
aws:apigatewayv2:routeapigateway:GetApis,
apigateway:GetRoutes
aws:apigatewayv2:routeresponseapigateway:GetApis,
apigateway:GetRouteResponses,
apigateway:GetRoutes
aws:apigatewayv2:stageapigateway:GetApis,
apigateway:GetStages
aws:apigatewayv2:vpclinkapigateway:GetVpcLinks
aws:appintegrations:applicationapp-integrations:GetApplication,
app-integrations:ListApplicationAssociations,
app-integrations:ListApplications
aws:appintegrations:application-associationapp-integrations:ListApplicationAssociations,
app-integrations:ListApplications
aws:appintegrations:data-integrationapp-integrations:GetDataIntegration,
app-integrations:ListDataIntegrationAssociations,
app-integrations:ListDataIntegrations
aws:appintegrations:data-integration-associationapp-integrations:ListDataIntegrationAssociations,
app-integrations:ListDataIntegrations
aws:appintegrations:event-integrationapp-integrations:ListEventIntegrations
aws:appintegrations:event-integration-associationapp-integrations:ListEventIntegrationAssociations,
app-integrations:ListEventIntegrations
aws:applicationautoscaling:scalingactivityapplicationautoscaling:DescribeScalingActivities
aws:applicationautoscaling:scalingpolicyapplicationautoscaling:DescribeScalingPolicies
aws:applicationautoscaling:scheduled-actionapplicationautoscaling:DescribeScheduledActions
aws:apprunner:autoscaling-configurationapprunner:DescribeAutoScalingConfiguration,
apprunner:ListAutoScalingConfigurations
aws:apprunner:connectionapprunner:ListConnections
aws:apprunner:observability-configurationapprunner:DescribeObservabilityConfiguration,
apprunner:ListObservabilityConfigurations
aws:apprunner:serviceapprunner:DescribeService,
apprunner:ListServices
aws:apprunner:vpc-connectorapprunner:DescribeVpcConnector,
apprunner:ListVpcConnectors
aws:apprunner:vpc-ingress-connectionapprunner:DescribeVpcIngressConnection,
apprunner:ListVpcIngressConnections
aws:appstream:app-blockappstream:DescribeAppBlocks
aws:appstream:app-block-builderappstream:DescribeAppBlockBuilders
aws:appstream:applicationappstream:DescribeApplications
aws:appstream:fleetappstream:DescribeFleets
aws:appstream:imageappstream:DescribeImages
aws:appstream:image-builderappstream:DescribeImageBuilders
aws:appstream:public-imageappstream:DescribeImages
aws:appstream:stackappstream:DescribeStacks
aws:appsync:apiappsync:ListApis
aws:appsync:channel-namespaceappsync:ListApis,
appsync:ListChannelNamespaces
aws:appsync:data-sourceappsync:ListDataSources,
appsync:ListGraphqlApis
aws:appsync:domain-nameappsync:ListDomainNames
aws:appsync:functionappsync:ListFunctions,
appsync:ListGraphqlApis
aws:appsync:graphqlapiappsync:GetGraphqlApi,
appsync:ListGraphqlApis
aws:appsync:source-api-associationappsync:ListGraphqlApis,
appsync:ListSourceApiAssociations
aws:athena:capacityreservationathena:ListCapacityReservations
aws:athena:datacatalogathena:ListDataCatalogs
aws:athena:named-queryathena:BatchGetNamedQuery,
athena:ListNamedQueries
aws:athena:prepared-statementathena:BatchGetPreparedStatement,
athena:GetWorkGroup,
athena:ListPreparedStatements,
athena:ListWorkGroups
aws:athena:workgroupathena:GetWorkGroup,
athena:ListWorkGroups
aws:auditmanager:assessmentauditmanager:GetAssessment,
auditmanager:ListAssessments
aws:auditmanager:assessmentcontrolsetauditmanager:GetAssessment,
auditmanager:ListAssessments
aws:auditmanager:assessmentframeworkauditmanager:GetAssessmentFramework,
auditmanager:ListAssessmentFrameworks
aws:auditmanager:controlauditmanager:GetControl,
auditmanager:ListControls
aws:autoscaling:groupautoscaling:DescribeAutoScalingGroups
aws:autoscaling:launchconfigurationautoscaling:DescribeLaunchConfigurations
aws:autoscaling:policyautoscaling:DescribePolicies
aws:autoscaling:scheduled-actionautoscaling:DescribeScheduledActions
aws:b2bi:capabilityb2bi:GetCapability,
b2bi:ListCapabilities
aws:b2bi:partnershipb2bi:GetPartnership,
b2bi:GetProfile,
b2bi:ListPartnerships,
b2bi:ListProfiles
aws:b2bi:profileb2bi:GetProfile,
b2bi:ListProfiles
aws:b2bi:transformerb2bi:GetTransformer,
b2bi:ListTransformers
aws:backup-gateway:gatewaybackup-gateway:GetGateway,
backup-gateway:ListGateways
aws:backup-gateway:hypervisorbackup-gateway:GetHypervisor,
backup-gateway:ListHypervisors
aws:backup-gateway:virtual-machinebackup-gateway:GetVirtualMachine,
backup-gateway:ListVirtualMachines
aws:backup:frameworkbackup:DescribeFramework,
backup:ListFrameworks
aws:backup:legalholdbackup:GetLegalHold,
backup:ListLegalHolds
aws:backup:planbackup:ListBackupPlans
aws:backup:protected-resourcebackup:ListProtectedResources
aws:backup:recoverypointbackup:ListBackupVaults,
backup:ListRecoveryPointsByBackupVault
aws:backup:vaultbackup:ListBackupVaults
aws:batch:compute-environmentbatch:DescribeComputeEnvironments
aws:batch:job-definitionbatch:DescribeJobDefinitions
aws:batch:job-queuebatch:DescribeJobQueues
aws:batch:scheduling-policybatch:DescribeSchedulingPolicies,
batch:ListSchedulingPolicies
aws:bedrock:agentbedrock:GetAgent,
bedrock:ListAgentCollaborators,
bedrock:ListAgentVersions,
bedrock:ListAgents
aws:bedrock:agent-action-groupbedrock:GetAgentActionGroup,
bedrock:ListAgentActionGroups,
bedrock:ListAgents
aws:bedrock:agent-aliasbedrock:GetAgentAlias,
bedrock:ListAgentAliases,
bedrock:ListAgents
aws:bedrock:application-inference-profilebedrock:GetInferenceProfile,
bedrock:ListInferenceProfiles
aws:bedrock:async-invokebedrock:GetAsyncInvoke,
bedrock:ListAsyncInvokes
aws:bedrock:blueprintbedrock:GetBlueprint,
bedrock:ListBlueprints
aws:bedrock:custom-modelbedrock:GetCustomModel,
bedrock:ListCustomModels
aws:bedrock:data-sourcebedrock:GetDataSource,
bedrock:GetKnowledgeBase,
bedrock:ListDataSources,
bedrock:ListKnowledgeBaseDocuments,
bedrock:ListKnowledgeBases
aws:bedrock:evaluation-jobbedrock:GetEvaluationJob,
bedrock:ListEvaluationJobs
aws:bedrock:flowbedrock:GetFlow,
bedrock:GetFlowVersion,
bedrock:ListFlows
aws:bedrock:flow-aliasbedrock:GetFlowAlias,
bedrock:ListFlowAliases,
bedrock:ListFlows
aws:bedrock:foundationmodelbedrock:GetFoundationModel,
bedrock:ListFoundationModels
aws:bedrock:guardrailbedrock:GetGuardrail,
bedrock:ListGuardrails
aws:bedrock:imported-modelbedrock:GetImportedModel,
bedrock:ListImportedModels
aws:bedrock:ingestion-jobbedrock:GetDataSource,
bedrock:GetIngestionJob,
bedrock:GetKnowledgeBase,
bedrock:ListDataSources,
bedrock:ListIngestionJobs,
bedrock:ListKnowledgeBases
aws:bedrock:knowledge-basebedrock:GetKnowledgeBase,
bedrock:ListKnowledgeBases
aws:bedrock:marketplace-model-endpointbedrock:GetMarketplaceModelEndpoint,
bedrock:ListMarketplaceModelEndpoints
aws:bedrock:model-copy-jobbedrock:GetModelCopyJob,
bedrock:ListModelCopyJobs
aws:bedrock:model-customization-jobbedrock:GetModelCustomizationJob,
bedrock:ListModelCustomizationJobs
aws:bedrock:model-invocation-jobbedrock:GetModelInvocationJob,
bedrock:ListModelInvocationJobs
aws:bedrock:promptbedrock:GetPrompt,
bedrock:ListPrompts
aws:bedrock:prompt-routerbedrock:ListPromptRouters
aws:bedrock:provisioned-model-throughputbedrock:ListProvisionedModelThroughputs
aws:bedrock:settingsbedrock:GetModelInvocationLoggingConfiguration
aws:bedrock:system-defined-inference-profilebedrock:GetInferenceProfile,
bedrock:ListInferenceProfiles
aws:cloudformation:generatedtemplatecloudformation:DescribeGeneratedTemplate,
cloudformation:ListGeneratedTemplates
aws:cloudformation:resourcescancloudformation:DescribeResourceScan,
cloudformation:ListResourceScans
aws:cloudformation:stackcloudformation:DescribeStacks,
cloudformation:ListStacks
aws:cloudformation:stacksetcloudformation:ListStackSets
aws:cloudformation:typecloudformation:ListTypes
aws:cloudfront:anycast-ip-listcloudfront:GetAnycastIpList,
cloudfront:ListAnycastIpLists
aws:cloudfront:cache-policycloudfront:GetCachePolicy,
cloudfront:ListCachePolicies
aws:cloudfront:continuous-deployment-policycloudfront:GetContinuousDeploymentPolicy,
cloudfront:ListContinuousDeploymentPolicies
aws:cloudfront:distributioncloudfront:GetDistribution,
cloudfront:ListDistributions
aws:cloudfront:field-level-encryption-configcloudfront:GetFieldLevelEncryptionConfig,
cloudfront:ListFieldLevelEncryptionConfigs
aws:cloudfront:field-level-encryption-profilecloudfront:GetFieldLevelEncryptionProfile,
cloudfront:ListFieldLevelEncryptionProfiles
aws:cloudfront:functioncloudfront:ListFunctions
aws:cloudfront:keygroupcloudfront:ListKeyGroups
aws:cloudfront:managed-cache-policycloudfront:GetCachePolicy,
cloudfront:ListCachePolicies
aws:cloudfront:managed-origin-request-policycloudfront:GetOriginRequestPolicy,
cloudfront:ListOriginRequestPolicies
aws:cloudfront:managed-response-headers-policycloudfront:GetResponseHeadersPolicy,
cloudfront:ListResponseHeadersPolicies
aws:cloudfront:origin-request-policycloudfront:GetOriginRequestPolicy,
cloudfront:ListOriginRequestPolicies
aws:cloudfront:originaccesscontrolcloudfront:ListOriginAccessControls
aws:cloudfront:publickeycloudfront:ListPublicKeys
aws:cloudfront:realtime-log-configcloudfront:ListRealtimeLogConfigs
aws:cloudfront:response-headers-policycloudfront:GetResponseHeadersPolicy,
cloudfront:ListResponseHeadersPolicies
aws:cloudfront:streaming-distributioncloudfront:GetStreamingDistribution,
cloudfront:ListStreamingDistributions
aws:cloudfront:vpc-origincloudfront:GetVpcOrigin,
cloudfront:ListVpcOrigins
aws:cloudhsm:backupcloudhsm:DescribeBackups
aws:cloudhsm:clustercloudhsm:DescribeClusters
aws:cloudtrail:trailcloudtrail:DescribeTrails,
cloudtrail:GetEventSelectors,
cloudtrail:GetTrailStatus
aws:cloudwatch:metricalarmcloudwatch:DescribeAlarms
aws:cloudwatchlogs:log-grouplogs:DescribeLogGroups,
logs:DescribeSubscriptionFilters
aws:cloudwatchlogs:metricfilterlogs:DescribeMetricFilters
aws:codeartifact:domaincodeartifact:DescribeDomain,
codeartifact:ListDomains
aws:codeartifact:packagecodeartifact:ListPackages,
codeartifact:ListRepositories
aws:codeartifact:package-groupcodeartifact:DescribePackageGroup,
codeartifact:ListDomains,
codeartifact:ListPackageGroups
aws:codeartifact:repositorycodeartifact:DescribeRepository,
codeartifact:ListRepositories
aws:codebuild:projectcodebuild:BatchGetProjects,
codebuild:ListProjects
aws:codebuild:source-credentialscodebuild:ListSourceCredentials
aws:codedeploy:applicationcodedeploy:BatchGetApplications,
codedeploy:ListApplications
aws:codedeploy:deployment-configcodedeploy:GetDeploymentConfig,
codedeploy:ListDeploymentConfigs
aws:codeguru-profiler:findingcodeguru-profiler:ListFindingsReports,
codeguru-profiler:ListProfilingGroups
aws:codeguru-profiler:profilinggroupcodeguru-profiler:ListProfilingGroups
aws:codeguru-reviewer:associationcodeguru-reviewer:ListRepositoryAssociations
aws:codeguru-reviewer:codereviewcodeguru-reviewer:ListCodeReviews
aws:codepipeline:actiontypecodepipeline:GetActionType,
codepipeline:ListActionTypes
aws:codepipeline:pipelinecodepipeline:GetPipeline,
codepipeline:ListPipelines
aws:codepipeline:webhookcodepipeline:ListWebhooks
aws:cognitoidentity:identitypoolcognito-identity:DescribeIdentityPool,
cognito-identity:GetIdentityPoolRoles,
cognito-identity:ListIdentityPools
aws:cognitoidentityprovider:userpoolcognito-idp:DescribeUserPool,
cognito-idp:ListIdentityProviders,
cognito-idp:ListUserPools
aws:comprehend:document-classification-jobcomprehend:ListDocumentClassificationJobs
aws:comprehend:document-classifiercomprehend:ListDocumentClassifiers
aws:comprehend:dominant-language-detection-jobcomprehend:ListDominantLanguageDetectionJobs
aws:comprehend:endpointcomprehend:ListEndpoints
aws:comprehend:entities-detection-jobcomprehend:ListEntitiesDetectionJobs
aws:comprehend:entity-recognizercomprehend:ListEntityRecognizers
aws:comprehend:events-detection-jobcomprehend:ListEventsDetectionJobs
aws:comprehend:flywheelcomprehend:DescribeFlywheel,
comprehend:ListFlywheels
aws:comprehend:flywheel-datasetcomprehend:DescribeFlywheel,
comprehend:ListDatasets,
comprehend:ListFlywheels
aws:comprehend:key-phrases-detection-jobcomprehend:ListKeyPhrasesDetectionJobs
aws:comprehend:pii-entities-detection-jobcomprehend:ListPiiEntitiesDetectionJobs
aws:comprehend:sentiment-detection-jobcomprehend:ListSentimentDetectionJobs
aws:comprehend:targeted-sentiment-detection-jobcomprehend:ListTargetedSentimentDetectionJobs
aws:comprehend:topics-detection-jobcomprehend:ListTopicsDetectionJobs
aws:configservice:recorderconfig:DescribeConfigurationRecorders
aws:configservice:recorderstatusconfig:DescribeConfigurationRecorderStatus
aws:connect:agent-statusconnect:DescribeAgentStatus,
connect:DescribeInstance,
connect:ListAgentStatuses,
connect:ListInstances
aws:connect:authentication-profileconnect:DescribeAuthenticationProfile,
connect:DescribeInstance,
connect:ListAuthenticationProfiles,
connect:ListInstances
aws:connect:contact-flowconnect:DescribeContactFlow,
connect:DescribeInstance,
connect:ListContactFlows,
connect:ListInstances
aws:connect:contact-flow-moduleconnect:DescribeContactFlowModule,
connect:DescribeInstance,
connect:ListContactFlowModules,
connect:ListInstances
aws:connect:hours-of-operationconnect:DescribeHoursOfOperation,
connect:DescribeInstance,
connect:ListHoursOfOperations,
connect:ListInstances
aws:connect:instanceconnect:DescribeInstance,
connect:ListInstances
aws:connect:integration-associationconnect:DescribeInstance,
connect:ListInstances,
connect:ListIntegrationAssociations
aws:connect:queueconnect:DescribeInstance,
connect:DescribeQueue,
connect:ListInstances,
connect:ListQueues
aws:connect:quick-connectconnect:DescribeInstance,
connect:DescribeQuickConnect,
connect:ListInstances,
connect:ListQuickConnects
aws:connect:routing-profileconnect:DescribeInstance,
connect:DescribeRoutingProfile,
connect:ListInstances,
connect:ListRoutingProfiles
aws:connect:security-profileconnect:DescribeInstance,
connect:DescribeSecurityProfile,
connect:ListInstances,
connect:ListSecurityProfiles
aws:connect:userconnect:DescribeInstance,
connect:DescribeUser,
connect:ListInstances,
connect:ListUsers
aws:controltower:enabled-baselinecontroltower:ListEnabledBaselines
aws:controltower:enabled-controlcontroltower:ListEnabledControls
aws:controltower:landing-zonecontroltower:GetLandingZone,
controltower:ListLandingZones
aws:costexplorer:anomalymonitorce:GetAnomalyMonitors
aws:costexplorer:anomalysubscriptionce:GetAnomalySubscriptions
aws:costexplorer:costcategoryce:DescribeCostCategoryDefinition,
ce:GetCostCategories
aws:databrew:datasetdatabrew:ListDatasets
aws:databrew:jobdatabrew:ListJobs
aws:databrew:projectdatabrew:ListProjects
aws:databrew:recipedatabrew:ListRecipes
aws:databrew:rulesetdatabrew:ListRulesets
aws:databrew:scheduledatabrew:ListSchedules
aws:datasync:agentdatasync:DescribeAgent,
datasync:ListAgents
aws:datasync:location-efsdatasync:DescribeLocationEfs,
datasync:ListLocations
aws:datasync:location-fsx-lustredatasync:DescribeLocationFsxLustre,
datasync:ListLocations
aws:datasync:location-fsx-ontapdatasync:DescribeLocationFsxOntap,
datasync:ListLocations
aws:datasync:location-fsx-openzfsdatasync:DescribeLocationFsxOpenZfs,
datasync:ListLocations
aws:datasync:location-fsx-windowsdatasync:DescribeLocationFsxWindows,
datasync:ListLocations
aws:datasync:location-hdfsdatasync:DescribeLocationHdfs,
datasync:ListLocations
aws:datasync:location-nfsdatasync:DescribeLocationNfs,
datasync:ListLocations
aws:datasync:location-objectstoragedatasync:DescribeLocationObjectStorage,
datasync:ListLocations
aws:datasync:location-s3datasync:DescribeLocationS3,
datasync:ListLocations
aws:datasync:location-smbdatasync:DescribeLocationSmb,
datasync:ListLocations
aws:datasync:taskdatasync:DescribeTask,
datasync:ListTasks
aws:datazone:domaindatazone:GetDomain,
datazone:ListDomains
aws:dax:clusterdax:DescribeClusters
aws:deadline:budgetdeadline:GetBudget,
deadline:ListBudgets,
deadline:ListFarms
aws:deadline:farmdeadline:ListFarms
aws:deadline:fleetdeadline:ListFarms,
deadline:ListFleets
aws:deadline:license-endpointdeadline:GetLicenseEndpoint,
deadline:ListLicenseEndpoints
aws:deadline:monitordeadline:ListMonitors
aws:deadline:queuedeadline:GetQueue,
deadline:ListFarms,
deadline:ListQueues
aws:deadline:workerdeadline:ListFarms,
deadline:ListFleets,
deadline:ListWorkers
aws:detective:graphdetective:ListGraphs
aws:devicefarm:devicedevicefarm:ListDevices,
devicefarm:ListProjects
aws:devicefarm:deviceinstancedevicefarm:ListDeviceInstances
aws:devicefarm:devicepooldevicefarm:ListDevicePools,
devicefarm:ListProjects
aws:devicefarm:instanceprofiledevicefarm:ListInstanceProfiles
aws:devicefarm:networkprofiledevicefarm:ListNetworkProfiles,
devicefarm:ListProjects
aws:devicefarm:projectdevicefarm:ListProjects
aws:devicefarm:sessiondevicefarm:ListProjects,
devicefarm:ListRemoteAccessSessions
aws:devicefarm:testgrid-projectdevicefarm:ListTestGridProjects
aws:devicefarm:testgrid-sessiondevicefarm:ListTestGridProjects,
devicefarm:ListTestGridSessions
aws:devicefarm:uploaddevicefarm:GetUpload,
devicefarm:ListProjects,
devicefarm:ListUploads
aws:devicefarm:vpceconfigurationdevicefarm:ListVPCEConfigurations
aws:directconnect:connectiondirectconnect:DescribeConnections
aws:directconnect:gatewaydirectconnect:DescribeDirectConnectGatewayAssociations,
directconnect:DescribeDirectConnectGateways
aws:directconnect:virtualinterfacedirectconnect:DescribeVirtualInterfaces
aws:dlm:policydlm:GetLifecyclePolicies,
dlm:GetLifecyclePolicy
aws:dms:certificatedms:DescribeCertificates
aws:dms:data-migrationdms:DescribeDataMigrations
aws:dms:data-providerdms:DescribeDataProviders
aws:dms:endpointdms:DescribeEndpoints
aws:dms:event-subscriptiondms:DescribeEventSubscriptions
aws:dms:instance-profiledms:DescribeInstanceProfiles
aws:dms:migration-projectdms:DescribeMigrationProjects
aws:dms:replication-configdms:DescribeReplicationConfigs
aws:dms:replication-subnet-groupdms:DescribeReplicationSubnetGroups
aws:dms:replicationinstancedms:DescribeReplicationInstances
aws:dms:replicationtaskdms:DescribeReplicationTasks
aws:docdb:clusterrds:DescribeDBClusters
aws:docdb:clustersnapshotrds:DescribeDBClusterSnapshotAttributes,
rds:DescribeDBClusterSnapshots,
rds:DescribeDBClusters
aws:docdb:dbinstancerds:DescribeDBInstances
aws:docdbelastic:clusterdocdb-elastic:GetCluster,
docdb-elastic:ListClusters
aws:docdbelastic:cluster-snapshotdocdb-elastic:GetClusterSnapshot,
docdb-elastic:ListClusterSnapshots
aws:drs:jobdrs:DescribeJobs
aws:drs:launch-configuration-templatedrs:DescribeLaunchConfigurationTemplates
aws:drs:recovery-instancedrs:DescribeRecoveryInstances
aws:drs:replication-configuration-templatedrs:DescribeReplicationConfigurationTemplates
aws:drs:source-networkdrs:DescribeSourceNetworks
aws:drs:source-serverdrs:DescribeSourceServers
aws:ds:directoryds:DescribeDirectories
aws:dsql:clusterdsql:GetCluster,
dsql:ListClusters
aws:dynamodb:backupdynamodb:DescribeBackup,
dynamodb:ListBackups
aws:dynamodb:exportdynamodb:DescribeExport,
dynamodb:ListExports
aws:dynamodb:global-tabledynamodb:DescribeGlobalTable,
dynamodb:ListGlobalTables
aws:dynamodb:streamdynamodb:DescribeStream,
dynamodb:ListStreams
aws:dynamodb:tabledynamodb:DescribeContinuousBackups,
dynamodb:DescribeTable,
dynamodb:DescribeTimeToLive,
dynamodb:ListTables
aws:ec2:availabilityzoneec2:DescribeAvailabilityZones
aws:ec2:awsmanagedprefixlistec2:DescribeManagedPrefixLists,
ec2:GetManagedPrefixListEntries
aws:ec2:capacityreservationec2:DescribeCapacityReservations
aws:ec2:capacityreservationfleetec2:DescribeCapacityReservationFleets
aws:ec2:carriergatewayec2:DescribeCarrierGateways
aws:ec2:client-vpn-endpointec2:DescribeClientVpnEndpoints
aws:ec2:co-ip-poolec2:DescribeCoipPools
aws:ec2:customergatewayec2:DescribeCustomerGateways
aws:ec2:customermanagedprefixlistec2:DescribeManagedPrefixLists,
ec2:GetManagedPrefixListEntries
aws:ec2:dedicatedhostec2:DescribeHosts
aws:ec2:dhcpoptionsec2:DescribeDhcpOptions
aws:ec2:ebs-encryption-by-defaultec2:GetEbsEncryptionByDefault
aws:ec2:egressonlyinternetgatewayec2:DescribeEgressOnlyInternetGateways
aws:ec2:elasticipec2:DescribeAddresses
aws:ec2:fleetec2:DescribeFleets
aws:ec2:fpga-imageec2:DescribeFpgaImages
aws:ec2:imageec2:DescribeImageAttribute,
ec2:DescribeImages
aws:ec2:instanceec2:DescribeInstances
aws:ec2:instance-event-windowec2:DescribeInstanceEventWindows
aws:ec2:instanceconnectendpointec2:DescribeInstanceConnectEndpoints
aws:ec2:instancetypeec2:DescribeInstanceTypes
aws:ec2:ipamec2:DescribeIpams
aws:ec2:ipam-external-resource-verification-tokenec2:DescribeIpamExternalResourceVerificationTokens
aws:ec2:ipam-poolec2:DescribeIpamPools
aws:ec2:ipam-resource-discoveryec2:DescribeIpamResourceDiscoveries
aws:ec2:ipam-resource-discovery-associationec2:DescribeIpamResourceDiscoveryAssociations
aws:ec2:ipam-scopeec2:DescribeIpamScopes
aws:ec2:ipv6pool-ec2ec2:DescribeIpv6Pools
aws:ec2:keypairec2:DescribeKeyPairs
aws:ec2:launchtemplateec2:DescribeLaunchTemplates
aws:ec2:launchtemplateversionec2:DescribeLaunchTemplateVersions,
ec2:DescribeLaunchTemplates
aws:ec2:local-gatewayec2:DescribeLocalGateways
aws:ec2:local-gateway-route-tableec2:DescribeLocalGatewayRouteTables
aws:ec2:local-gateway-route-table-vpc-associationec2:DescribeLocalGatewayRouteTableVpcAssociations
aws:ec2:local-gateway-virtual-interfaceec2:DescribeLocalGatewayVirtualInterfaces
aws:ec2:local-gateway-virtual-interface-groupec2:DescribeLocalGatewayVirtualInterfaceGroups
aws:ec2:networkaclec2:DescribeNetworkAcls
aws:ec2:networkinterfaceec2:DescribeNetworkInterfaces
aws:ec2:placementgroupec2:DescribePlacementGroups
aws:ec2:public-fpga-imageec2:DescribeFpgaImages
aws:ec2:publicimageec2:DescribeImages
aws:ec2:regionec2:DescribeRegions
aws:ec2:reservedinstanceec2:DescribeReservedInstances
aws:ec2:routetableec2:DescribeRouteTables
aws:ec2:securitygroupec2:DescribeSecurityGroups
aws:ec2:securitygroupruleec2:DescribeSecurityGroupRules,
ec2:DescribeSecurityGroups
aws:ec2:settingsec2:DescribeVpcBlockPublicAccessExclusions,
ec2:DescribeVpcBlockPublicAccessOptions,
ec2:GetAllowedImagesSettings,
ec2:GetEbsDefaultKmsKeyId,
ec2:GetEbsEncryptionByDefault,
ec2:GetImageBlockPublicAccessState,
ec2:GetInstanceMetadataDefaults,
ec2:GetSerialConsoleAccessStatus,
ec2:GetSnapshotBlockPublicAccessState
aws:ec2:snapshotec2:DescribeSnapshotAttribute,
ec2:DescribeSnapshots
aws:ec2:spotfleetrequestec2:DescribeSpotFleetRequests
aws:ec2:spotinstancerequestec2:DescribeSpotInstanceRequests
aws:ec2:subnetec2:DescribeSubnets
aws:ec2:traffic-mirror-filterec2:DescribeTrafficMirrorFilters
aws:ec2:traffic-mirror-filter-ruleec2:DescribeTrafficMirrorFilterRules,
ec2:DescribeTrafficMirrorFilters
aws:ec2:traffic-mirror-sessionec2:DescribeTrafficMirrorSessions
aws:ec2:traffic-mirror-targetec2:DescribeTrafficMirrorTargets
aws:ec2:transitgatewayec2:DescribeTransitGateways
aws:ec2:transitgateway-routetable-announcementec2:DescribeTransitGatewayRouteTableAnnouncements
aws:ec2:transitgatewayattachmentec2:DescribeTransitGatewayAttachments
aws:ec2:transitgatewayconnectpeerec2:DescribeTransitGatewayConnectPeers
aws:ec2:transitgatewaymulticastdomainec2:DescribeTransitGatewayMulticastDomains
aws:ec2:transitgatewaypeeringattachmentec2:DescribeTransitGatewayPeeringAttachments
aws:ec2:transitgatewaypolicytableec2:DescribeTransitGatewayPolicyTables
aws:ec2:transitgatewayroutetableec2:DescribeTransitGatewayRouteTables,
ec2:GetTransitGatewayPrefixListReferences,
ec2:SearchTransitGatewayRoutes
aws:ec2:transitgatewayvpcattachmentec2:DescribeTransitGatewayVpcAttachments
aws:ec2:verified-access-endpointec2:DescribeVerifiedAccessEndpoints,
ec2:GetVerifiedAccessEndpointPolicy,
ec2:GetVerifiedAccessEndpointTargets
aws:ec2:verified-access-groupec2:DescribeVerifiedAccessGroups,
ec2:GetVerifiedAccessGroupPolicy
aws:ec2:verified-access-instanceec2:DescribeVerifiedAccessInstances
aws:ec2:verified-access-trust-providerec2:DescribeVerifiedAccessTrustProviders
aws:ec2:volumeec2:DescribeVolumes
aws:ec2:vpcec2:DescribeVpcs
aws:ec2:vpcendpointec2:DescribeVpcEndpoints
aws:ec2:vpcendpoint-serviceec2:DescribeVpcEndpointServices
aws:ec2:vpcendpoint-service-permissionec2:DescribeVpcEndpointServicePermissions,
ec2:DescribeVpcEndpointServices
aws:ec2:vpcendpointconnectionnotificationec2:DescribeVpcEndpointConnectionNotifications
aws:ec2:vpcflowlogec2:DescribeFlowLogs
aws:ec2:vpcinternetgatewayec2:DescribeInternetGateways
aws:ec2:vpcnatgatewayec2:DescribeNatGateways
aws:ec2:vpcpeeringconnectionec2:DescribeVpcPeeringConnections
aws:ec2:vpnconnectionec2:DescribeVpnConnections
aws:ec2:vpngatewayec2:DescribeVpnGateways
aws:ecr:imageecr:DescribeImages,
ecr:DescribeRepositories
aws:ecr:registryecr:DescribeRegistry,
ecr:GetRegistryPolicy,
ecr:GetRegistryScanningConfiguration
aws:ecr:repositoryecr:DescribeRepositories,
ecr:GetLifecyclePolicy,
ecr:GetRepositoryPolicy
aws:ecrpublic:imageecr-public:DescribeImages,
ecr-public:DescribeRepositories
aws:ecrpublic:registryecr-public:DescribeRegistries
aws:ecrpublic:repositoryecr-public:DescribeImages,
ecr-public:DescribeRepositories,
ecr-public:GetRepositoryPolicy
aws:ecs:capacityproviderecs:DescribeCapacityProviders
aws:ecs:clusterecs:DescribeClusters,
ecs:ListClusters
aws:ecs:instanceecs:DescribeContainerInstances,
ecs:ListClusters,
ecs:ListContainerInstances
aws:ecs:serviceecs:DescribeServices,
ecs:ListClusters,
ecs:ListServices
aws:ecs:service-deploymentecs:DescribeServiceDeployments,
ecs:DescribeServices,
ecs:ListClusters,
ecs:ListServiceDeployments,
ecs:ListServices
aws:ecs:taskecs:DescribeServices,
ecs:DescribeTasks,
ecs:ListClusters,
ecs:ListServices,
ecs:ListTasks
aws:ecs:task-definitionecs:DescribeServices,
ecs:DescribeTaskDefinition,
ecs:DescribeTasks,
ecs:ListClusters,
ecs:ListServices,
ecs:ListTasks
aws:efs:accesspointelasticfilesystem:DescribeAccessPoints
aws:efs:filesystemelasticfilesystem:DescribeFileSystems,
elasticfilesystem:DescribeLifecycleConfiguration
aws:efs:mounttargetelasticfilesystem:DescribeFileSystems,
elasticfilesystem:DescribeMountTargetSecurityGroups,
elasticfilesystem:DescribeMountTargets
aws:eks:access-entryeks:DescribeAccessEntry,
eks:DescribeCluster,
eks:ListAccessEntries,
eks:ListClusters
aws:eks:access-policyeks:DescribeAccessEntry,
eks:DescribeCluster,
eks:ListAccessEntries,
eks:ListAssociatedAccessPolicies,
eks:ListClusters
aws:eks:addoneks:DescribeAddon,
eks:DescribeCluster,
eks:ListAddons,
eks:ListClusters
aws:eks:clustereks:DescribeCluster,
eks:ListClusters
aws:eks:eks-anywhere-subscriptioneks:ListEksAnywhereSubscriptions
aws:eks:fargateprofileeks:DescribeCluster,
eks:DescribeFargateProfile,
eks:ListClusters,
eks:ListFargateProfiles
aws:eks:identityproviderconfigeks:DescribeCluster,
eks:DescribeIdentityProviderConfig,
eks:ListClusters,
eks:ListIdentityProviderConfigs
aws:eks:insighteks:DescribeCluster,
eks:DescribeInsight,
eks:ListClusters,
eks:ListInsights
aws:eks:nodegroupeks:DescribeCluster,
eks:DescribeNodeGroup,
eks:ListClusters,
eks:ListNodeGroups
aws:eks:podidentityassociationeks:DescribeCluster,
eks:DescribePodIdentityAssociation,
eks:ListClusters,
eks:ListPodIdentityAssociations
aws:eks:updateeks:DescribeCluster,
eks:DescribeUpdate,
eks:ListClusters,
eks:ListUpdates
aws:elasticache:cachesubnetgroupelasticache:DescribeCacheSubnetGroups
aws:elasticache:clusterelasticache:DescribeCacheClusters
aws:elasticache:global-replicationgroupelasticache:DescribeGlobalReplicationGroups
aws:elasticache:parametergroupelasticache:DescribeCacheParameterGroups
aws:elasticache:replicationgroupelasticache:DescribeReplicationGroups
aws:elasticache:reserved-instanceelasticache:DescribeReservedCacheNodes
aws:elasticache:securitygroupelasticache:DescribeCacheSecurityGroups
aws:elasticache:serverless-cacheelasticache:DescribeServerlessCaches
aws:elasticache:serverless-cache-snapshotelasticache:DescribeServerlessCacheSnapshots
aws:elasticache:snapshotelasticache:DescribeSnapshots
aws:elasticache:userelasticache:DescribeUsers
aws:elasticache:usergroupelasticache:DescribeUserGroups
aws:elasticbeanstalk:environmentelasticbeanstalk:DescribeConfigurationSettings,
elasticbeanstalk:DescribeEnvironments
aws:elasticloadbalancing:loadbalancerelasticloadbalancing:DescribeInstanceHealth,
elasticloadbalancing:DescribeLoadBalancerAttributes,
elasticloadbalancing:DescribeLoadBalancerPolicies,
elasticloadbalancing:DescribeLoadBalancers
aws:elasticloadbalancingv2:listener-ruleelasticloadbalancing:DescribeListeners,
elasticloadbalancing:DescribeLoadBalancers,
elasticloadbalancing:DescribeRules
aws:elasticloadbalancingv2:loadbalancerelasticloadbalancing:DescribeListeners,
elasticloadbalancing:DescribeLoadBalancerAttributes,
elasticloadbalancing:DescribeLoadBalancers
aws:elasticloadbalancingv2:targetgroupelasticloadbalancing:DescribeTargetGroups,
elasticloadbalancing:DescribeTargetHealth
aws:elasticloadbalancingv2:truststoreelasticloadbalancing:DescribeTrustStores
aws:elasticsearchservice:domaines:DescribeElasticsearchDomains,
es:ListDomainNames
aws:emr:clusterelasticmapreduce:DescribeCluster,
elasticmapreduce:GetAutoTerminationPolicy,
elasticmapreduce:GetManagedScalingPolicy,
elasticmapreduce:ListClusters
aws:emr:instanceelasticmapreduce:ListClusters,
elasticmapreduce:ListInstances
aws:emr:instance-fleetelasticmapreduce:DescribeCluster,
elasticmapreduce:ListClusters,
elasticmapreduce:ListInstanceFleets
aws:emr:instance-groupelasticmapreduce:DescribeCluster,
elasticmapreduce:ListClusters,
elasticmapreduce:ListInstanceGroups
aws:emr:security-configurationelasticmapreduce:DescribeSecurityConfiguration,
elasticmapreduce:ListSecurityConfigurations
aws:emr:settingselasticmapreduce:GetBlockPublicAccessConfiguration
aws:emrcontainers:managed-endpointemr-containers:ListManagedEndpoints,
emr-containers:ListVirtualClusters
aws:emrcontainers:security-configurationemr-containers:ListSecurityConfigurations
aws:emrcontainers:virtual-clusteremr-containers:ListVirtualClusters
aws:emrserverless:applicationemr-serverless:GetApplication,
emr-serverless:ListApplications
aws:eventbridge:api-destinationevents:ListApiDestinations,
events:ListConnections
aws:eventbridge:archiveevents:ListArchives,
events:ListEventBuses
aws:eventbridge:connectionevents:ListConnections
aws:eventbridge:endpointevents:ListEndpoints
aws:eventbridge:event-sourceevents:ListEventSources
aws:eventbridge:eventbusevents:ListEventBuses,
events:ListRules
aws:eventbridge:replayevents:ListReplays
aws:eventbridge:ruleevents:ListEventBuses,
events:ListRules
aws:eventbridge:ruletargetevents:ListEventBuses,
events:ListRules,
events:ListTargetsByRule
aws:firehose:delivery-streamfirehose:DescribeDeliveryStream,
firehose:ListDeliveryStreams
aws:frauddetector:batch-import-jobfrauddetector:GetBatchImportJobs
aws:frauddetector:batch-prediction-jobfrauddetector:GetBatchPredictionJobs
aws:frauddetector:detectorfrauddetector:GetDetectors
aws:frauddetector:detector-versionfrauddetector:DescribeDetector,
frauddetector:GetDetectorVersion,
frauddetector:GetDetectors
aws:frauddetector:entity-typefrauddetector:GetEntityTypes
aws:frauddetector:event-typefrauddetector:GetEventTypes
aws:frauddetector:external-modelfrauddetector:GetExternalModels
aws:frauddetector:labelfrauddetector:GetLabels
aws:frauddetector:listfrauddetector:GetListsMetadata
aws:frauddetector:modelfrauddetector:GetModels
aws:frauddetector:model-versionfrauddetector:DescribeModelVersions
aws:frauddetector:outcomefrauddetector:GetOutcomes
aws:frauddetector:rulefrauddetector:GetDetectors,
frauddetector:GetRules
aws:frauddetector:variablefrauddetector:GetVariables
aws:fsx:associationfsx:DescribeDataRepositoryAssociations
aws:fsx:backupfsx:DescribeBackups
aws:fsx:file-cachefsx:DescribeFileCaches
aws:fsx:file-systemfsx:DescribeFileSystems
aws:fsx:snapshotfsx:DescribeSnapshots
aws:fsx:storage-virtual-machinefsx:DescribeStorageVirtualMachines
aws:fsx:taskfsx:DescribeDataRepositoryTasks
aws:fsx:volumefsx:DescribeVolumes
aws:gamelift:aliasgamelift:ListAliases
aws:gamelift:buildgamelift:ListBuilds
aws:gamelift:container-fleetgamelift:ListContainerFleets
aws:gamelift:container-group-definitiongamelift:ListContainerGroupDefinitions
aws:gamelift:game-server-groupgamelift:ListGameServerGroups
aws:gamelift:game-session-queuegamelift:DescribeGameSessionQueues
aws:gamelift:locationgamelift:ListLocations
aws:gamelift:matchmaking-configurationgamelift:DescribeMatchmakingConfigurations
aws:gamelift:matchmaking-rule-setgamelift:DescribeMatchmakingRuleSets
aws:gamelift:scriptgamelift:ListScripts
aws:glacier:vaultglacier:GetVaultNotifications,
glacier:ListVaults
aws:globalaccelerator:acceleratorglobalaccelerator:ListAccelerators
aws:globalaccelerator:endpointgroupglobalaccelerator:ListAccelerators,
globalaccelerator:ListEndpointGroups,
globalaccelerator:ListListeners
aws:globalaccelerator:listenerglobalaccelerator:ListAccelerators,
globalaccelerator:ListListeners
aws:glue:registryglue:ListRegistries
aws:grafana:workspacegrafana:DescribeWorkspace,
grafana:ListWorkspaces
aws:greengrass:bulk-deploymentgreengrass:GetBulkDeploymentStatus,
greengrass:ListBulkDeployments
aws:greengrass:componentgreengrass:GetComponent,
greengrass:ListComponents
aws:greengrass:connectivity-infogreengrass:GetConnectivityInfo,
greengrass:ListCoreDevices
aws:greengrass:connector-definitiongreengrass:ListConnectorDefinitions
aws:greengrass:core-definitiongreengrass:ListCoreDefinitions
aws:greengrass:core-devicegreengrass:GetCoreDevice,
greengrass:ListCoreDevices
aws:greengrass:deploymentgreengrass:ListDeployments,
greengrass:ListGroups
aws:greengrass:device-definitiongreengrass:ListDeviceDefinitions
aws:greengrass:function-definitiongreengrass:ListFunctionDefinitions
aws:greengrass:groupgreengrass:GetGroup,
greengrass:ListGroups
aws:greengrass:logger-definitiongreengrass:ListLoggerDefinitions
aws:greengrass:resource-definitiongreengrass:ListResourceDefinitions
aws:greengrass:subscription-definitiongreengrass:ListSubscriptionDefinitions
aws:guardduty:detectorguardduty:GetCoverageStatistics,
guardduty:GetDetector,
guardduty:ListDetectors
aws:guardduty:filterguardduty:GetFilter,
guardduty:ListDetectors,
guardduty:ListFilters
aws:guardduty:ipsetguardduty:GetIPSet,
guardduty:ListDetectors,
guardduty:ListIPSets
aws:guardduty:malwareprotectionplanguardduty:GetMalwareProtectionPlan,
guardduty:ListMalwareProtectionPlans
aws:guardduty:publishingdestinationguardduty:DescribePublishingDestination,
guardduty:ListDetectors,
guardduty:ListPublishingDestinations
aws:guardduty:settingsguardduty:GetAdministratorAccount,
guardduty:GetMalwareScanSettings,
guardduty:GetMasterAccount,
guardduty:ListDetectors
aws:guardduty:threatintelsetguardduty:GetThreatIntelSet,
guardduty:ListDetectors,
guardduty:ListThreatIntelSets
aws:health:settingshealth:DescribeHealthServiceStatusForOrganization,
organizations:DescribeOrganization
aws:healthlake:datastorehealthlake:ListFHIRDatastores
aws:iam:accesskeymetadataiam:GetUser,
iam:ListAccessKeys,
iam:ListUsers,
iam:ListVirtualMFADevices
aws:iam:accountiam:GetAccountPasswordPolicy,
iam:GetAccountSummary,
organizations:DescribeOrganization
aws:iam:aws-managed-policyiam:GetPolicyVersion,
iam:ListPolicies
aws:iam:credentialreportiam:GenerateCredentialReport,
iam:GetCredentialReport
aws:iam:groupiam:GetGroup,
iam:ListAttachedGroupPolicies,
iam:ListGroups
aws:iam:groupinlinepolicyiam:GetGroupPolicy,
iam:ListGroupPolicies,
iam:ListGroups
aws:iam:instanceprofileiam:GetInstanceProfile,
iam:ListInstanceProfiles
aws:iam:open-id-connect-provideriam:GetOpenIDConnectProvider,
iam:ListOpenIDConnectProviders
aws:iam:policyiam:GetPolicy,
iam:GetPolicyVersion,
iam:ListPolicies
aws:iam:roleiam:GetAccountAuthorizationDetails,
iam:GetRole,
iam:ListAttachedRolePolicies
aws:iam:roleinlinepolicyiam:GetAccountAuthorizationDetails,
iam:GetRole,
iam:GetRolePolicy,
iam:ListRolePolicies
aws:iam:saml-provideriam:GetSAMLProvider,
iam:ListSAMLProviders
aws:iam:server-certificateiam:ListServerCertificates
aws:iam:service-specific-credentialiam:ListServiceSpecificCredentials
aws:iam:useriam:GetLoginProfile,
iam:GetUser,
iam:ListAttachedUserPolicies,
iam:ListGroupsForUser,
iam:ListMFADevices,
iam:ListSSHPublicKeys,
iam:ListUsers,
iam:ListVirtualMFADevices
aws:iam:userinlinepolicyiam:GetUser,
iam:GetUserPolicy,
iam:ListUserPolicies,
iam:ListUsers,
iam:ListVirtualMFADevices
aws:iam:virtualmfadeviceiam:ListUsers,
iam:ListVirtualMFADevices
aws:identitystore:groupidentitystore:ListGroups,
organizations:DescribeOrganization,
sso:ListInstances
aws:identitystore:useridentitystore:ListGroupMembershipsForMember,
identitystore:ListUsers,
organizations:DescribeOrganization,
sso:ListInstances
aws:imagebuilder:component-versionimagebuilder:ListComponents
aws:imagebuilder:container-recipeimagebuilder:GetContainerRecipe,
imagebuilder:ListContainerRecipes
aws:imagebuilder:distribution-configurationimagebuilder:GetDistributionConfiguration,
imagebuilder:ListDistributionConfigurations
aws:imagebuilder:image-pipelineimagebuilder:ListImagePipelines
aws:imagebuilder:image-recipeimagebuilder:GetImageRecipe,
imagebuilder:ListImageRecipes
aws:imagebuilder:image-versionimagebuilder:ListImages
aws:imagebuilder:infrastructure-configurationimagebuilder:GetInfrastructureConfiguration,
imagebuilder:ListInfrastructureConfigurations
aws:imagebuilder:lifecycle-policyimagebuilder:GetLifecyclePolicy,
imagebuilder:ListLifecyclePolicies
aws:imagebuilder:public-componentimagebuilder:ListComponents
aws:imagebuilder:public-container-recipeimagebuilder:GetContainerRecipe,
imagebuilder:ListContainerRecipes
aws:imagebuilder:public-imageimagebuilder:ListImages
aws:imagebuilder:public-image-recipeimagebuilder:GetImageRecipe,
imagebuilder:ListImageRecipes
aws:imagebuilder:public-workflowimagebuilder:GetWorkflow,
imagebuilder:ListWorkflows
aws:imagebuilder:workflowimagebuilder:GetWorkflow,
imagebuilder:ListWorkflows
aws:inspector2:coveredresourceinspector2:ListCoverage
aws:iot:authorizeriot:DescribeAuthorizer,
iot:ListAuthorizers
aws:iot:certiot:DescribeCertificate,
iot:ListCertificates
aws:iot:certificateprovideriot:DescribeCertificateProvider,
iot:ListCertificateProviders
aws:iot:dimensioniot:DescribeDimension,
iot:ListDimensions
aws:iot:domainconfigurationiot:DescribeDomainConfiguration,
iot:ListDomainConfigurations
aws:iot:fleetmetriciot:DescribeFleetMetric,
iot:ListFleetMetrics
aws:iot:jobiot:DescribeJob,
iot:ListJobs
aws:iot:jobtemplateiot:DescribeJobTemplate,
iot:ListJobTemplates
aws:iot:policyiot:GetPolicy,
iot:ListPolicies
aws:iot:provisioningtemplateiot:DescribeProvisioningTemplate,
iot:ListProvisioningTemplates
aws:iot:rolealiasiot:DescribeRoleAlias,
iot:ListRoleAliases
aws:iot:securityprofileiot:DescribeSecurityProfile,
iot:ListSecurityProfiles
aws:iot:streamiot:DescribeStream,
iot:ListStreams
aws:iot:thingiot:DescribeThing,
iot:ListThings
aws:iot:thinggroupiot:DescribeThingGroup,
iot:ListThingGroups
aws:iot:thingtypeiot:DescribeThingType,
iot:ListThingTypes
aws:iot:tunneliot:DescribeTunnel,
iot:ListTunnels
aws:iotfleetwise:campaigniotfleetwise:GetCampaign,
iotfleetwise:ListCampaigns
aws:iotfleetwise:decoder-manifestiotfleetwise:ListDecoderManifests
aws:iotfleetwise:fleetiotfleetwise:ListFleets
aws:iotfleetwise:model-manifestiotfleetwise:ListModelManifests
aws:iotfleetwise:signal-catalogiotfleetwise:GetSignalCatalog,
iotfleetwise:ListSignalCatalogs
aws:iotfleetwise:state-templateiotfleetwise:GetStateTemplate,
iotfleetwise:ListStateTemplates
aws:iotfleetwise:vehicleiotfleetwise:GetVehicle,
iotfleetwise:ListVehicles
aws:iotsitewise:assetiotsitewise:DescribeAsset,
iotsitewise:DescribeAssetModel,
iotsitewise:ListAssetModels,
iotsitewise:ListAssets
aws:iotsitewise:asset-modeliotsitewise:DescribeAssetModel,
iotsitewise:ListAssetModels
aws:iotsitewise:dashboardiotsitewise:DescribeDashboard,
iotsitewise:DescribePortal,
iotsitewise:DescribeProject,
iotsitewise:ListDashboards,
iotsitewise:ListPortals,
iotsitewise:ListProjects
aws:iotsitewise:datasetiotsitewise:DescribeDataset,
iotsitewise:ListDatasets
aws:iotsitewise:gatewayiotsitewise:ListGateways
aws:iotsitewise:portaliotsitewise:DescribePortal,
iotsitewise:ListPortals
aws:iotsitewise:projectiotsitewise:DescribePortal,
iotsitewise:DescribeProject,
iotsitewise:ListPortals,
iotsitewise:ListProjects
aws:iotsitewise:timeseriesiotsitewise:ListTimeSeries
aws:iottwinmaker:component-typeiottwinmaker:GetComponentType,
iottwinmaker:GetWorkspace,
iottwinmaker:ListComponentTypes,
iottwinmaker:ListWorkspaces
aws:iottwinmaker:entityiottwinmaker:GetEntity,
iottwinmaker:GetWorkspace,
iottwinmaker:ListEntities,
iottwinmaker:ListWorkspaces
aws:iottwinmaker:sceneiottwinmaker:GetScene,
iottwinmaker:GetWorkspace,
iottwinmaker:ListScenes,
iottwinmaker:ListWorkspaces
aws:iottwinmaker:workspaceiottwinmaker:GetWorkspace,
iottwinmaker:ListWorkspaces
aws:iotwireless:destinationiotwireless:ListDestinations
aws:iotwireless:device-profileiotwireless:GetDeviceProfile,
iotwireless:ListDeviceProfiles
aws:iotwireless:gatewayiotwireless:GetWirelessGateway,
iotwireless:ListWirelessGateways
aws:iotwireless:multicast-groupiotwireless:GetMulticastGroup,
iotwireless:ListMulticastGroups
aws:iotwireless:network-analyzer-configurationiotwireless:GetNetworkAnalyzerConfiguration,
iotwireless:ListNetworkAnalyzerConfigurations
aws:iotwireless:service-profileiotwireless:GetServiceProfile,
iotwireless:ListServiceProfiles
aws:iotwireless:wireless-deviceiotwireless:GetWirelessDevice,
iotwireless:ListWirelessDevices
aws:ivs:channelivs:GetChannel,
ivs:ListChannels
aws:ivs:compositionivs:GetComposition,
ivs:ListCompositions
aws:ivs:encoder-configurationivs:GetEncoderConfiguration,
ivs:ListEncoderConfigurations
aws:ivs:ingest-configurationivs:GetIngestConfiguration,
ivs:ListIngestConfigurations
aws:ivs:playback-key-pairivs:ListPlaybackKeyPairs
aws:ivs:playback-restriction-policyivs:ListPlaybackRestrictionPolicies
aws:ivs:public-keyivs:GetPublicKey,
ivs:ListPublicKeys
aws:ivs:recording-configurationivs:GetRecordingConfiguration,
ivs:ListRecordingConfigurations
aws:ivs:stageivs:GetStage,
ivs:ListStages
aws:ivs:storage-configurationivs:ListStorageConfigurations
aws:ivs:stream-keyivs:GetChannel,
ivs:ListChannels,
ivs:ListStreamKeys
aws:ivschat:logging-configurationivschat:GetLoggingConfiguration,
ivschat:ListLoggingConfigurations
aws:ivschat:roomivschat:GetRoom,
ivschat:ListRooms
aws:kafka:clusterkafka:DescribeClusterV2,
kafka:ListClustersV2
aws:kafka:configurationkafka:ListConfigurations
aws:kafka:nodekafka:DescribeClusterV2,
kafka:ListClustersV2,
kafka:ListNodes
aws:kafka:replicatorkafka:DescribeReplicator,
kafka:ListReplicators
aws:kafka:vpc-connectionkafka:DescribeVpcConnection,
kafka:ListVpcConnections
aws:kafkaconnect:connectorkafkaconnect:DescribeConnector,
kafkaconnect:ListConnectors
aws:kafkaconnect:connector-operationkafkaconnect:DescribeConnector,
kafkaconnect:DescribeConnectorOperation,
kafkaconnect:ListConnectorOperations,
kafkaconnect:ListConnectors
aws:kafkaconnect:custom-pluginkafkaconnect:DescribeCustomPlugin,
kafkaconnect:ListCustomPlugins
aws:kafkaconnect:worker-configurationkafkaconnect:ListWorkerConfigurations
aws:keyspaces:keyspacecassandra:Select
aws:keyspaces:tablecassandra:Select
aws:kinesis:streamkinesis:DescribeStreamSummary,
kinesis:ListStreams
aws:kinesisvideo:channelkinesisvideo:ListSignalingChannels
aws:kinesisvideo:streamkinesisvideo:ListStreams
aws:kms:aliaskms:GetKeyPolicy,
kms:ListAliases
aws:kms:custom-key-storekms:DescribeCustomKeyStores
aws:kms:keykms:DescribeKey,
kms:GetKeyRotationStatus,
kms:ListKeys
aws:lakeformation:data-lake-settingslakeformation:GetDataLakeSettings
aws:lakeformation:permissionslakeformation:ListPermissions
aws:lambda:codesigningconfiglambda:ListCodeSigningConfigs
aws:lambda:eventsourcemappinglambda:ListEventSourceMappings,
lambda:ListFunctions
aws:lambda:functionlambda:GetFunction,
lambda:GetPolicy,
lambda:ListFunctionUrlConfigs,
lambda:ListFunctions,
lambda:ListProvisionedConcurrencyConfigs
aws:lambda:layerlambda:GetLayerVersionPolicy,
lambda:ListLayers
aws:launchwizard:deploymentlaunchwizard:GetDeployment,
launchwizard:ListDeployments
aws:lexv2:botlex:DescribeBot,
lex:ListBots
aws:lightsail:alarmlightsail:GetAlarms
aws:lightsail:bucketlightsail:GetBuckets
aws:lightsail:certificatelightsail:GetCertificates
aws:lightsail:container-servicelightsail:GetContainerServices
aws:lightsail:disklightsail:GetDisks
aws:lightsail:disk-snapshotlightsail:GetDiskSnapshots
aws:lightsail:distributionlightsail:GetDistributions
aws:lightsail:instancelightsail:GetInstancePortStates,
lightsail:GetInstances
aws:lightsail:loadbalancerlightsail:GetLoadBalancers
aws:lightsail:relational-databaselightsail:GetRelationalDatabaseParameters,
lightsail:GetRelationalDatabases
aws:lightsail:relational-database-snapshotlightsail:GetRelationalDatabaseSnapshots
aws:lightsail:static-iplightsail:GetStaticIps
aws:location:api-keygeo:DescribeKey,
geo:ListKeys
aws:location:geofence-collectiongeo:DescribeGeofenceCollection,
geo:ListGeofenceCollections
aws:location:mapgeo:DescribeMap,
geo:ListMaps
aws:location:place-indexgeo:DescribePlaceIndex,
geo:ListPlaceIndexes
aws:location:route-calculatorgeo:DescribeRouteCalculator,
geo:ListRouteCalculators
aws:location:trackergeo:DescribeTracker,
geo:ListTrackers
aws:m2:applicationm2:GetApplication,
m2:ListApplications
aws:m2:environmentm2:GetEnvironment,
m2:ListEnvironments
aws:macie2:allow-listmacie2:GetAllowList,
macie2:GetMacieSession,
macie2:ListAllowLists
aws:macie2:custom-data-identifiermacie2:GetCustomDataIdentifier,
macie2:GetMacieSession,
macie2:ListCustomDataIdentifiers
aws:macie2:membermacie2:GetMacieSession,
macie2:ListMembers
aws:macie2:settingsmacie2:GetMacieSession
aws:managedblockchain:accessormanagedblockchain:GetAccessor,
managedblockchain:ListAccessors
aws:managedblockchain:invitationmanagedblockchain:ListInvitations
aws:managedblockchain:membermanagedblockchain:GetMember,
managedblockchain:ListMembers,
managedblockchain:ListNetworks
aws:managedblockchain:networkmanagedblockchain:GetNetwork,
managedblockchain:ListNetworks
aws:managedblockchain:nodemanagedblockchain:GetNode,
managedblockchain:ListMembers,
managedblockchain:ListNetworks,
managedblockchain:ListNodes
aws:managedblockchain:proposalmanagedblockchain:GetProposal,
managedblockchain:ListNetworks,
managedblockchain:ListProposals
aws:mediaconnect:bridgemediaconnect:DescribeBridge,
mediaconnect:ListBridges
aws:mediaconnect:entitlementmediaconnect:ListEntitlements
aws:mediaconnect:flowmediaconnect:DescribeFlow,
mediaconnect:ListFlows
aws:mediaconnect:gatewaymediaconnect:DescribeGateway,
mediaconnect:ListGateways
aws:mediaconnect:gatewayinstancemediaconnect:DescribeGatewayInstance,
mediaconnect:ListGatewayInstances
aws:medialive:channelmedialive:ListChannels
aws:medialive:channel-placement-groupmedialive:ListChannelPlacementGroups,
medialive:ListClusters
aws:medialive:cloudwatch-alarm-templatemedialive:ListCloudWatchAlarmTemplates
aws:medialive:cloudwatch-alarm-template-groupmedialive:ListCloudWatchAlarmTemplateGroups
aws:medialive:clustermedialive:ListClusters
aws:medialive:eventbridge-rule-templatemedialive:ListEventBridgeRuleTemplates
aws:medialive:eventbridge-rule-template-groupmedialive:ListEventBridgeRuleTemplateGroups
aws:medialive:inputmedialive:ListInputs
aws:medialive:input-devicemedialive:ListInputDevices
aws:medialive:input-security-groupmedialive:ListInputSecurityGroups
aws:medialive:multiplexmedialive:ListMultiplexes
aws:medialive:networkmedialive:ListNetworks
aws:medialive:nodemedialive:ListClusters,
medialive:ListNodes
aws:medialive:reservationmedialive:ListReservations
aws:medialive:sdi-sourcemedialive:ListSdiSources
aws:medialive:signal-mapmedialive:ListSignalMaps
aws:mediapackage-v2:channelmediapackagev2:GetChannel,
mediapackagev2:GetChannelGroup,
mediapackagev2:GetChannelPolicy,
mediapackagev2:ListChannelGroups,
mediapackagev2:ListChannels
aws:mediapackage-v2:channel-groupmediapackagev2:GetChannelGroup,
mediapackagev2:ListChannelGroups
aws:mediapackage-v2:harvest-jobmediapackagev2:GetChannelGroup,
mediapackagev2:ListChannelGroups,
mediapackagev2:ListHarvestJobs
aws:mediapackage-v2:origin-endpointmediapackagev2:GetChannelGroup,
mediapackagev2:GetOriginEndpoint,
mediapackagev2:GetOriginEndpointPolicy,
mediapackagev2:ListChannelGroups,
mediapackagev2:ListChannels,
mediapackagev2:ListOriginEndpoints
aws:mediapackage-vod:assetsmediapackage-vod:DescribeAsset,
mediapackage-vod:ListAssets
aws:mediapackage-vod:packaging-configurationsmediapackage-vod:ListPackagingConfigurations
aws:mediapackage-vod:packaging-groupsmediapackage-vod:ListPackagingGroups
aws:mediapackage:harvest-jobsmediapackage:ListHarvestJobs
aws:mediapackage:origin-endpointsmediapackage:ListOriginEndpoints
aws:memorydb:aclmemorydb:DescribeAcls
aws:memorydb:clustermemorydb:DescribeClusters,
memorydb:DescribeMultiRegionClusters
aws:memorydb:parameter-groupmemorydb:DescribeParameterGroups
aws:memorydb:reserved-nodememorydb:DescribeReservedNodes
aws:memorydb:snapshotmemorydb:DescribeSnapshots
aws:memorydb:subnet-groupmemorydb:DescribeSubnetGroups
aws:memorydb:usermemorydb:DescribeUsers
aws:migrationhubrefactorspaces:applicationrefactor-spaces:ListApplications,
refactor-spaces:ListEnvironments
aws:migrationhubrefactorspaces:environmentrefactor-spaces:ListEnvironments
aws:migrationhubrefactorspaces:routerefactor-spaces:ListApplications,
refactor-spaces:ListEnvironments,
refactor-spaces:ListRoutes
aws:migrationhubrefactorspaces:servicerefactor-spaces:ListApplications,
refactor-spaces:ListEnvironments,
refactor-spaces:ListServices
aws:mq:brokermq:DescribeBroker,
mq:ListBrokers
aws:mq:configurationmq:ListConfigurations
aws:mq:configurationrevisionmq:DescribeConfigurationRevision,
mq:ListConfigurationRevisions,
mq:ListConfigurations
aws:mq:usermq:DescribeBroker,
mq:DescribeUser,
mq:ListBrokers
aws:mwaa:environmentairflow:GetEnvironment,
airflow:ListEnvironments
aws:neptune:clusterrds:DescribeDBClusters
aws:neptune:cluster-snapshotrds:DescribeDBClusterSnapshotAttributes,
rds:DescribeDBClusterSnapshots
aws:neptune:dbinstancerds:DescribeDBInstances
aws:network-firewall:firewallnetwork-firewall:DescribeFirewall,
network-firewall:DescribeFirewallPolicy,
network-firewall:DescribeLoggingConfiguration,
network-firewall:ListFirewalls
aws:network-firewall:rulegroupnetwork-firewall:DescribeRuleGroup,
network-firewall:ListRuleGroups
aws:network-firewall:tls-configurationnetwork-firewall:DescribeTLSInspectionConfiguration,
network-firewall:ListTLSInspectionConfigurations
aws:network-firewall:vpc-endpoint-associationnetwork-firewall:DescribeVpcEndpointAssociation,
network-firewall:ListVpcEndpointAssociations
aws:networkmanager:attachmentnetworkmanager:ListAttachments
aws:networkmanager:connect-peernetworkmanager:GetConnectPeer,
networkmanager:ListConnectPeers
aws:networkmanager:connectionnetworkmanager:DescribeGlobalNetworks,
networkmanager:GetConnections
aws:networkmanager:core-networknetworkmanager:GetCoreNetwork,
networkmanager:ListCoreNetworks
aws:networkmanager:devicenetworkmanager:DescribeGlobalNetworks,
networkmanager:GetDevices
aws:networkmanager:global-networknetworkmanager:DescribeGlobalNetworks
aws:networkmanager:linknetworkmanager:DescribeGlobalNetworks,
networkmanager:GetLinks
aws:networkmanager:peeringnetworkmanager:ListPeerings
aws:networkmanager:sitenetworkmanager:DescribeGlobalNetworks,
networkmanager:GetSites
aws:opensearch:domaines:DescribeDomain,
es:ListDomainNames
aws:opensearchserverless:collectionaoss:BatchGetCollection,
aoss:ListCollections
aws:organizations:accountorganizations:DescribeOrganization,
organizations:ListAccountsForParent,
organizations:ListDelegatedAdministrators,
organizations:ListOrganizationalUnitsForParent,
organizations:ListPoliciesForTarget,
organizations:ListRoots
aws:organizations:featuresiam:ListOrganizationsFeatures,
organizations:DescribeOrganization,
organizations:ListDelegatedAdministrators
aws:organizations:organizationorganizations:DescribeOrganization,
organizations:ListDelegatedAdministrators
aws:organizations:organizationalunitorganizations:DescribeOrganization,
organizations:ListAccountsForParent,
organizations:ListDelegatedAdministrators,
organizations:ListOrganizationalUnitsForParent,
organizations:ListPoliciesForTarget,
organizations:ListRoots
aws:organizations:policyorganizations:DescribeOrganization,
organizations:DescribePolicy,
organizations:ListDelegatedAdministrators,
organizations:ListPolicies,
organizations:ListTargetsForPolicy
aws:organizations:rootorganizations:DescribeOrganization,
organizations:ListAccountsForParent,
organizations:ListDelegatedAdministrators,
organizations:ListOrganizationalUnitsForParent,
organizations:ListPoliciesForTarget,
organizations:ListRoots
aws:osis:pipelineosis:GetPipeline,
osis:ListPipelines
aws:osis:pipeline-blueprintosis:GetPipelineBlueprint,
osis:ListPipelineBlueprints
aws:outposts:outpostoutposts:ListOutposts
aws:payment-cryptography:aliaspayment-cryptography:GetKey,
payment-cryptography:ListAliases,
payment-cryptography:ListKeys
aws:payment-cryptography:keypayment-cryptography:GetKey,
payment-cryptography:ListKeys
aws:pca-connector-ad:connectorpca-connector-ad:ListConnectors
aws:pca-connector-ad:directory-registrationpca-connector-ad:ListDirectoryRegistrations
aws:pca-connector-ad:templatepca-connector-ad:ListConnectors,
pca-connector-ad:ListTemplates
aws:pca-connector-scep:connectorpca-connector-scep:ListConnectors
aws:pcs:clusterpcs:GetCluster,
pcs:ListClusters
aws:pcs:compute-node-grouppcs:GetComputeNodeGroup,
pcs:ListClusters,
pcs:ListComputeNodeGroups
aws:pcs:queuepcs:GetQueue,
pcs:ListClusters,
pcs:ListQueues
aws:personalize:algorithmpersonalize:DescribeAlgorithm,
personalize:DescribeRecipe,
personalize:ListRecipes
aws:personalize:batch-inference-jobpersonalize:DescribeBatchInferenceJob,
personalize:ListBatchInferenceJobs
aws:personalize:batch-segment-jobpersonalize:DescribeBatchSegmentJob,
personalize:ListBatchSegmentJobs
aws:personalize:campaignpersonalize:DescribeCampaign,
personalize:ListCampaigns
aws:personalize:data-deletion-jobpersonalize:DescribeDataDeletionJob,
personalize:ListDataDeletionJobs
aws:personalize:datasetpersonalize:DescribeDataset,
personalize:ListDatasets
aws:personalize:dataset-export-jobpersonalize:DescribeDatasetExportJob,
personalize:ListDatasetExportJobs
aws:personalize:dataset-grouppersonalize:DescribeDatasetGroup,
personalize:ListDatasetGroups
aws:personalize:dataset-import-jobpersonalize:DescribeDatasetImportJob,
personalize:ListDatasetImportJobs
aws:personalize:event-trackerpersonalize:DescribeEventTracker,
personalize:ListEventTrackers
aws:personalize:feature-transformationpersonalize:DescribeFeatureTransformation,
personalize:DescribeRecipe,
personalize:ListRecipes
aws:personalize:filterpersonalize:DescribeFilter,
personalize:ListFilters
aws:personalize:metric-attributionpersonalize:DescribeMetricAttribution,
personalize:ListMetricAttributions
aws:personalize:recipepersonalize:DescribeRecipe,
personalize:ListRecipes
aws:personalize:recommenderpersonalize:DescribeRecommender,
personalize:ListRecommenders
aws:personalize:schemapersonalize:DescribeSchema,
personalize:ListSchemas
aws:personalize:solutionpersonalize:DescribeSolution,
personalize:ListSolutions
aws:pinpoint:appmobiletargeting:GetApps,
mobiletargeting:GetEventStream
aws:pinpoint:campaignmobiletargeting:GetApps,
mobiletargeting:GetCampaigns
aws:pinpoint:channelmobiletargeting:GetApps,
mobiletargeting:GetChannels
aws:pinpoint:journeymobiletargeting:GetApps,
mobiletargeting:ListJourneys
aws:pinpoint:segmentmobiletargeting:GetApps,
mobiletargeting:GetSegments
aws:pinpoint:templatemobiletargeting:ListTemplates
aws:pipes:pipepipes:ListPipes
aws:profile:domainprofile:GetDomain,
profile:ListDomains
aws:proton:componentproton:GetComponent,
proton:ListComponents
aws:proton:deploymentproton:GetDeployment,
proton:ListDeployments
aws:proton:environmentproton:GetEnvironment,
proton:ListEnvironments
aws:proton:environment-account-connectionproton:GetEnvironmentAccountConnection,
proton:ListEnvironmentAccountConnections
aws:proton:environment-templateproton:GetEnvironmentTemplate,
proton:ListEnvironmentTemplates
aws:proton:environment-template-versionproton:GetEnvironmentTemplate,
proton:GetEnvironmentTemplateVersion,
proton:ListEnvironmentTemplateVersions,
proton:ListEnvironmentTemplates
aws:proton:repositoryproton:GetRepository,
proton:ListRepositories
aws:proton:serviceproton:GetService,
proton:ListServices
aws:proton:service-instanceproton:GetServiceInstance,
proton:ListServiceInstances
aws:proton:service-templateproton:GetServiceTemplate,
proton:ListServiceTemplates
aws:proton:service-template-versionproton:GetServiceTemplate,
proton:GetServiceTemplateVersion,
proton:ListServiceTemplateVersions,
proton:ListServiceTemplates
aws:qbusiness:applicationqbusiness:GetApplication,
qbusiness:ListApplications
aws:qbusiness:data-accessorqbusiness:GetApplication,
qbusiness:GetDataAccessor,
qbusiness:ListApplications,
qbusiness:ListDataAccessors
aws:qbusiness:data-sourceqbusiness:GetApplication,
qbusiness:GetDataSource,
qbusiness:GetIndex,
qbusiness:ListApplications,
qbusiness:ListDataSources,
qbusiness:ListIndices
aws:qbusiness:indexqbusiness:GetApplication,
qbusiness:GetIndex,
qbusiness:ListApplications,
qbusiness:ListIndices
aws:qbusiness:pluginqbusiness:GetApplication,
qbusiness:GetPlugin,
qbusiness:ListApplications,
qbusiness:ListPlugins
aws:qbusiness:retrieverqbusiness:GetApplication,
qbusiness:GetRetriever,
qbusiness:ListApplications,
qbusiness:ListRetrievers
aws:qbusiness:subscriptionqbusiness:GetApplication,
qbusiness:ListApplications,
qbusiness:ListSubscriptions
aws:qbusiness:web-experienceqbusiness:GetApplication,
qbusiness:GetWebExperience,
qbusiness:ListApplications,
qbusiness:ListWebExperiences
aws:quicksight:accountquicksight:DescribeAccountSettings
aws:quicksight:analysisquicksight:DescribeAccountSettings,
quicksight:DescribeAnalysis,
quicksight:ListAnalyses
aws:quicksight:brandquicksight:DescribeAccountSettings,
quicksight:DescribeBrand,
quicksight:ListBrands
aws:quicksight:custom-permissionquicksight:DescribeAccountSettings,
quicksight:ListCustomPermissions
aws:quicksight:dashboardquicksight:DescribeAccountSettings,
quicksight:DescribeDashboard,
quicksight:ListDashboards
aws:quicksight:data-setquicksight:DescribeAccountSettings,
quicksight:ListDataSets
aws:quicksight:data-sourcequicksight:DescribeAccountSettings,
quicksight:ListDataSources
aws:quicksight:folderquicksight:DescribeAccountSettings,
quicksight:DescribeFolder,
quicksight:ListFolders
aws:quicksight:groupquicksight:DescribeAccountSettings,
quicksight:ListGroups,
quicksight:ListNamespaces
aws:quicksight:ingestionquicksight:DescribeAccountSettings,
quicksight:ListDataSets,
quicksight:ListIngestions
aws:quicksight:namespacequicksight:DescribeAccountSettings,
quicksight:ListNamespaces
aws:quicksight:refresh-schedulequicksight:DescribeAccountSettings,
quicksight:ListDataSets,
quicksight:ListRefreshSchedules
aws:quicksight:templatequicksight:DescribeAccountSettings,
quicksight:DescribeTemplate,
quicksight:ListTemplates
aws:quicksight:themequicksight:DescribeAccountSettings,
quicksight:DescribeTheme,
quicksight:ListThemes
aws:quicksight:topicquicksight:DescribeAccountSettings,
quicksight:DescribeTopic,
quicksight:ListTopics
aws:quicksight:userquicksight:DescribeAccountSettings,
quicksight:ListUsers
aws:quicksight:vpc-connectionquicksight:DescribeAccountSettings,
quicksight:ListVPCConnections
aws:ram:customer-managed-permissionram:ListPermissions
aws:ram:permissionram:ListPermissions
aws:ram:resource-shareram:GetResourceShares
aws:ram:resource-share-invitationram:GetResourceShareInvitations
aws:rbin:rulerbin:GetRule,
rbin:ListRules
aws:rds:blue-green-deploymentrds:DescribeBlueGreenDeployments
aws:rds:clusterrds:DescribeDBClusters
aws:rds:cluster-endpointrds:DescribeDBClusterEndpoints,
rds:DescribeDBClusters
aws:rds:cluster-snapshotrds:DescribeDBClusterSnapshotAttributes,
rds:DescribeDBClusterSnapshots
aws:rds:db-cluster-automated-backuprds:DescribeDBClusterAutomatedBackups
aws:rds:db-shard-grouprds:DescribeDBShardGroups
aws:rds:dbclusterparametergrouprds:DescribeDBClusterParameterGroups
aws:rds:dbinstanceautomatedbackuprds:DescribeDBInstanceAutomatedBackups
aws:rds:dbparametergrouprds:DescribeDBParameterGroups,
rds:DescribeDBParameters
aws:rds:dbsubnetgrouprds:DescribeDBSubnetGroups
aws:rds:eventsubscriptionrds:DescribeEventSubscriptions
aws:rds:exporttaskrds:DescribeExportTasks
aws:rds:globalclusterrds:DescribeGlobalClusters
aws:rds:instancerds:DescribeDBInstances
aws:rds:integrationrds:DescribeIntegrations
aws:rds:optiongrouprds:DescribeOptionGroups
aws:rds:proxyrds:DescribeDBProxies
aws:rds:proxy-endpointrds:DescribeDBProxyEndpoints
aws:rds:proxy-target-grouprds:DescribeDBProxies,
rds:DescribeDBProxyTargetGroups,
rds:DescribeDBProxyTargets
aws:rds:reserveddbinstancerds:DescribeReservedDBInstances
aws:rds:securitygrouprds:DescribeDBSecurityGroups
aws:rds:snapshotrds:DescribeDBSnapshotAttributes,
rds:DescribeDBSnapshots
aws:rds:snapshot-tenant-databaserds:DescribeDBSnapshotTenantDatabases
aws:rds:tenant-databaserds:DescribeTenantDatabases
aws:redshift:clusterredshift:DescribeClusterParameters,
redshift:DescribeClusters,
redshift:DescribeEndpointAccess,
redshift:DescribeLoggingStatus
aws:redshift:eventsubscriptionredshift:DescribeEventSubscriptions
aws:redshift:hsm-client-certificateredshift:DescribeHsmClientCertificates
aws:redshift:hsm-configurationredshift:DescribeHsmConfigurations
aws:redshift:integrationredshift:DescribeIntegrations
aws:redshift:parametergroupredshift:DescribeClusterParameterGroups
aws:redshift:redshift-idc-applicationredshift:DescribeRedshiftIdcApplications
aws:redshift:securitygroupredshift:DescribeClusterSecurityGroups
aws:redshift:snapshotredshift:DescribeClusterSnapshots,
redshift:DescribeClusters
aws:redshift:subnetgroupredshift:DescribeClusterSubnetGroups,
redshift:DescribeClusters
aws:redshiftserverless:endpoint-accessredshift-serverless:ListEndpointAccess
aws:redshiftserverless:managed-workgroupredshift-serverless:ListManagedWorkgroups
aws:redshiftserverless:namespaceredshift-serverless:ListNamespaces
aws:redshiftserverless:recovery-pointredshift-serverless:ListNamespaces,
redshift-serverless:ListRecoveryPoints
aws:redshiftserverless:snapshotredshift-serverless:GetSnapshot,
redshift-serverless:ListNamespaces,
redshift-serverless:ListSnapshots
aws:redshiftserverless:workgroupredshift-serverless:ListWorkgroups
aws:rekognition:collectionrekognition:DescribeCollection,
rekognition:ListCollections
aws:rekognition:projectrekognition:DescribeProjects
aws:rekognition:project-versionrekognition:DescribeProjectVersions,
rekognition:DescribeProjects
aws:rekognition:stream-processorrekognition:DescribeStreamProcessor,
rekognition:ListStreamProcessors
aws:resiliencehub:app-assessmentresiliencehub:DescribeAppAssessment,
resiliencehub:ListAppAssessments
aws:resiliencehub:applicationresiliencehub:DescribeApp,
resiliencehub:ListApps
aws:resiliencehub:resiliency-policyresiliencehub:ListResiliencyPolicies
aws:resourceexplorer2:indexresource-explorer-2:GetIndex
aws:resourceexplorer2:managed-viewresource-explorer-2:GetManagedView,
resource-explorer-2:ListManagedViews
aws:resourceexplorer2:viewresource-explorer-2:GetView,
resource-explorer-2:ListViews
aws:resourcegroups:groupresource-groups:GetGroup,
resource-groups:ListGroups
aws:route53-recovery-control:assertion-safety-ruleroute53-recovery-control-config:ListControlPanels,
route53-recovery-control-config:ListSafetyRules
aws:route53-recovery-control:clusterroute53-recovery-control-config:ListClusters
aws:route53-recovery-control:control-panelroute53-recovery-control-config:ListControlPanels,
route53-recovery-control-config:ListSafetyRules
aws:route53-recovery-control:gating-safety-ruleroute53-recovery-control-config:ListControlPanels,
route53-recovery-control-config:ListSafetyRules
aws:route53-recovery-control:routing-controlroute53-recovery-control-config:ListControlPanels,
route53-recovery-control-config:ListRoutingControls
aws:route53-recovery-readiness:cellroute53-recovery-readiness:ListCells
aws:route53-recovery-readiness:readiness-checkroute53-recovery-readiness:ListReadinessChecks
aws:route53-recovery-readiness:recovery-grouproute53-recovery-readiness:ListRecoveryGroups
aws:route53-recovery-readiness:resource-setroute53-recovery-readiness:ListResourceSets
aws:route53:hostedzoneroute53:GetDNSSEC,
route53:GetHostedZone,
route53:ListHostedZones
aws:route53:queryloggingconfigroute53:ListQueryLoggingConfigs
aws:route53:resourcerecordsetroute53:ListHostedZones,
route53:ListResourceRecordSets
aws:route53domains:domainroute53domains:ListDomains
aws:route53resolver:firewall-configroute53resolver:ListFirewallConfigs
aws:route53resolver:firewall-domain-listroute53resolver:ListFirewallDomainLists
aws:route53resolver:firewall-rule-grouproute53resolver:ListFirewallRuleGroups,
route53resolver:ListFirewallRules
aws:route53resolver:firewall-rule-group-associationroute53resolver:ListFirewallRuleGroupAssociations
aws:route53resolver:outpost-resolverroute53resolver:ListOutpostResolvers
aws:route53resolver:resolver-configroute53resolver:ListResolverConfigs
aws:route53resolver:resolver-dnssec-configroute53resolver:ListResolverDnssecConfigs
aws:route53resolver:resolver-endpointroute53resolver:ListResolverEndpoints
aws:route53resolver:resolver-query-log-configroute53resolver:ListResolverQueryLogConfigs
aws:route53resolver:resolver-ruleroute53resolver:ListResolverRules
aws:rum:app-monitorrum:GetAppMonitor,
rum:ListAppMonitors
aws:s3-object-lambda:object-lambda-access-points3:GetAccessPointForObjectLambda,
s3:ListAccessPointsForObjectLambda
aws:s3:accessgrants3:ListAccessGrants
aws:s3:accesspoints3:GetAccessPointPolicy,
s3:ListAccessPoints
aws:s3:buckets3:GetBucketAbac,
s3:GetBucketAcl,
s3:GetBucketLogging,
s3:GetBucketMetadataConfiguration,
s3:GetBucketNotification,
s3:GetBucketObjectLockConfiguration,
s3:GetBucketOwnershipControls,
s3:GetBucketPolicy,
s3:GetBucketPolicyStatus,
s3:GetBucketPublicAccessBlock,
s3:GetBucketVersioning,
s3:GetBucketWebsite,
s3:GetEncryptionConfiguration,
s3:GetInventoryConfiguration,
s3:GetLifecycleConfiguration,
s3:GetReplicationConfiguration,
s3:ListAllMyBuckets
aws:s3control:accountpublicaccessblocks3:GetBucketPublicAccessBlock
aws:s3express:buckets3express:GetBucketPolicy,
s3express:GetEncryptionConfiguration,
s3express:ListAllMyDirectoryBuckets
aws:s3outposts:buckets3-outposts:ListOutpostsWithS3,
s3-outposts:ListRegionalBuckets
aws:s3outposts:endpoints3-outposts:ListEndpoints
aws:s3outposts:outposts3-outposts:ListOutpostsWithS3
aws:sagemaker:inference-recommendations-jobsagemaker:DescribeInferenceRecommendationsJob,
sagemaker:ListInferenceRecommendationsJobs
aws:sagemaker:notebookinstancesagemaker:DescribeNotebookInstance,
sagemaker:ListNotebookInstances
aws:sagemaker:pipelinesagemaker:DescribePipeline,
sagemaker:ListPipelines
aws:scheduler:groupscheduler:ListScheduleGroups
aws:scheduler:schedulescheduler:GetSchedule,
scheduler:ListSchedules
aws:schemas:aws-schemaschemas:DescribeSchema,
schemas:ListRegistries,
schemas:ListSchemas
aws:schemas:discovererschemas:ListDiscoverers
aws:schemas:registryschemas:ListRegistries
aws:schemas:schemaschemas:DescribeSchema,
schemas:ListRegistries,
schemas:ListSchemas
aws:secretsmanager:secretsecretsmanager:DescribeSecret,
secretsmanager:GetResourcePolicy,
secretsmanager:ListSecrets
aws:securityhub:automation-rulesecurityhub:BatchGetAutomationRules,
securityhub:DescribeHub,
securityhub:ListAutomationRules
aws:securityhub:configuration-policyorganizations:DescribeOrganization,
securityhub:DescribeHub,
securityhub:GetConfigurationPolicy,
securityhub:ListConfigurationPolicies
aws:securityhub:finding-aggregatorsecurityhub:DescribeHub,
securityhub:GetFindingAggregator,
securityhub:ListFindingAggregators
aws:securityhub:hubsecurityhub:DescribeHub
aws:securityhub:productsecurityhub:DescribeHub,
securityhub:DescribeProducts
aws:securitylake:data-lakesecuritylake:ListDataLakes
aws:securitylake:subscribersecuritylake:ListSubscribers
aws:servicecatalog:applicationservicecatalog:GetApplication,
servicecatalog:ListApplications
aws:servicecatalog:attribute-groupservicecatalog:GetAttributeGroup,
servicecatalog:ListAttributeGroups
aws:servicecatalog:portfolioservicecatalog:DescribePortfolio,
servicecatalog:ListPortfolios
aws:servicecatalog:productservicecatalog:DescribeProduct,
servicecatalog:SearchProducts
aws:servicediscovery:namespaceservicediscovery:GetNamespace,
servicediscovery:ListNamespaces
aws:servicediscovery:serviceservicediscovery:GetService,
servicediscovery:ListServices
aws:servicequotas:quota-changeservicequotas:ListRequestedServiceQuotaChangeHistory,
servicequotas:ListServices
aws:ses:addon-instanceses:ListAddonInstances
aws:ses:addon-subscriptionses:ListAddonSubscriptions
aws:ses:address-listses:ListAddressLists
aws:ses:archiveses:GetArchive,
ses:ListArchives
aws:ses:configuration-setses:DescribeConfigurationSet,
ses:ListConfigurationSets
aws:ses:contact-listses:GetContactList,
ses:ListContactLists
aws:ses:custom-verification-email-templateses:GetCustomVerificationEmailTemplate,
ses:ListCustomVerificationEmailTemplates
aws:ses:dedicated-ip-poolses:GetDedicatedIpPool,
ses:ListDedicatedIpPools
aws:ses:identityses:GetIdentityDkimAttributes,
ses:GetIdentityMailFromDomainAttributes,
ses:GetIdentityVerificationAttributes,
ses:ListIdentities
aws:ses:ingress-pointses:GetIngressPoint,
ses:ListIngressPoints
aws:ses:multi-region-endpointses:GetMultiRegionEndpoint,
ses:ListMultiRegionEndpoints
aws:ses:relayses:GetRelay,
ses:ListRelays
aws:ses:rule-setses:GetRuleSet,
ses:ListRuleSets
aws:ses:templateses:GetTemplate,
ses:ListTemplates
aws:ses:traffic-policyses:GetTrafficPolicy,
ses:ListTrafficPolicies
aws:sfn:activitystates:DescribeActivity,
states:ListActivities
aws:sfn:executionstates:DescribeExecution,
states:ListExecutions,
states:ListStateMachines
aws:sfn:statemachinestates:DescribeStateMachine,
states:ListStateMachines
aws:sfn:statemachinealiasstates:DescribeStateMachineAlias,
states:ListStateMachineAliases,
states:ListStateMachines
aws:shield:attackshield:DescribeAttack,
shield:ListAttacks
aws:shield:protectionshield:ListProtections
aws:shield:protection-groupshield:ListProtectionGroups,
shield:ListResourcesInProtectionGroup
aws:shield:settingsshield:DescribeEmergencyContactSettings,
shield:DescribeSubscription,
shield:GetSubscriptionState
aws:signer:signing-profilesigner:GetSigningProfile,
signer:ListSigningProfiles
aws:smsvoice:configuration-setsms-voice:DescribeConfigurationSets
aws:smsvoice:opt-out-listsms-voice:DescribeOptOutLists
aws:smsvoice:phone-numbersms-voice:DescribePhoneNumbers
aws:smsvoice:poolsms-voice:DescribePools
aws:smsvoice:protect-configurationsms-voice:DescribeProtectConfigurations
aws:smsvoice:registrationsms-voice:DescribeRegistrations
aws:smsvoice:registration-attachmentsms-voice:DescribeRegistrationAttachments
aws:smsvoice:sender-idsms-voice:DescribeSenderIds
aws:smsvoice:verified-destination-numbersms-voice:DescribeVerifiedDestinationNumbers
aws:snowball:clustersnowball:DescribeCluster,
snowball:ListClusters
aws:snowball:jobsnowball:DescribeJob,
snowball:ListJobs
aws:sns:platform-applicationsns:ListPlatformApplications
aws:sns:topicsns:GetTopicAttributes,
sns:ListTopics
aws:socialmessaging:wabasocial-messaging:GetLinkedWhatsAppBusinessAccount,
social-messaging:ListLinkedWhatsAppBusinessAccounts
aws:sqs:queuesqs:GetQueueAttributes,
sqs:GetQueueUrl,
sqs:ListQueues
aws:ssm-incidents:incident-recordssm-incidents:GetIncidentRecord,
ssm-incidents:ListIncidentRecords
aws:ssm-incidents:replication-setssm-incidents:GetReplicationSet,
ssm-incidents:ListReplicationSets
aws:ssm-incidents:response-planssm-incidents:GetResponsePlan,
ssm-incidents:ListResponsePlans
aws:ssm:documentssm:DescribeDocument,
ssm:DescribeDocumentPermission,
ssm:ListDocuments
aws:ssm:instancessm:DescribeInstanceInformation,
ssm:ListComplianceItems,
ssm:ListInventoryEntries
aws:sso:applicationorganizations:DescribeOrganization,
sso:GetApplicationAssignmentConfiguration,
sso:ListApplicationAssignments,
sso:ListApplications,
sso:ListInstances
aws:sso:application-providersso:ListApplicationProviders
aws:sso:instanceorganizations:DescribeOrganization,
sso:DescribeInstanceAccessControlAttributeConfiguration,
sso:ListInstances
aws:sso:permission-setorganizations:DescribeOrganization,
sso:DescribePermissionSet,
sso:GetInlinePolicyForPermissionSet,
sso:GetPermissionsBoundaryForPermissionSet,
sso:ListCustomerManagedPolicyReferencesInPermissionSet,
sso:ListInstances,
sso:ListManagedPoliciesInPermissionSet,
sso:ListPermissionSets
aws:sso:trusted-token-issuerorganizations:DescribeOrganization,
sso:DescribeTrustedTokenIssuer,
sso:ListInstances,
sso:ListTrustedTokenIssuers
aws:storagegateway:cache-reportstoragegateway:ListCacheReports
aws:storagegateway:devicestoragegateway:DescribeGatewayInformation,
storagegateway:DescribeVTLDevices,
storagegateway:ListGateways
aws:storagegateway:fs-associationstoragegateway:DescribeFileSystemAssociations,
storagegateway:ListFileSystemAssociations
aws:storagegateway:gatewaystoragegateway:DescribeGatewayInformation,
storagegateway:ListGateways
aws:storagegateway:nfs-filesharestoragegateway:DescribeNFSFileShares,
storagegateway:ListFileShares
aws:storagegateway:smb-filesharestoragegateway:DescribeSMBFileShares,
storagegateway:ListFileShares
aws:storagegateway:tapestoragegateway:DescribeGatewayInformation,
storagegateway:DescribeTapes,
storagegateway:ListGateways
aws:storagegateway:tapepoolstoragegateway:ListTapePools
aws:storagegateway:volumestoragegateway:ListVolumes
aws:synthetics:canarysynthetics:DescribeCanaries
aws:synthetics:groupsynthetics:GetGroup,
synthetics:ListGroups
aws:textract:adaptertextract:GetAdapter,
textract:ListAdapters
aws:textract:adapter-versiontextract:GetAdapterVersion,
textract:ListAdapterVersions,
textract:ListAdapters
aws:timestream:scheduled-querytimestream:ListScheduledQueries
aws:timestreamwrite:tabletimestream:ListTables
aws:transcribe:call-analytics-categorytranscribe:ListCallAnalyticsCategories
aws:transcribe:call-analytics-jobtranscribe:GetCallAnalyticsJob,
transcribe:ListCallAnalyticsJobs
aws:transcribe:language-modeltranscribe:ListLanguageModels
aws:transcribe:medical-scribe-jobtranscribe:GetMedicalScribeJob,
transcribe:ListMedicalScribeJobs
aws:transcribe:medical-transcription-jobtranscribe:GetMedicalTranscriptionJob,
transcribe:ListMedicalTranscriptionJobs
aws:transcribe:medical-vocabularytranscribe:GetMedicalVocabulary,
transcribe:ListMedicalVocabularies
aws:transcribe:transcription-jobtranscribe:GetTranscriptionJob,
transcribe:ListTranscriptionJobs
aws:transcribe:vocabularytranscribe:GetVocabulary,
transcribe:ListVocabularies
aws:transcribe:vocabulary-filtertranscribe:GetVocabularyFilter,
transcribe:ListVocabularyFilters
aws:transfer:agreementtransfer:DescribeAgreement,
transfer:DescribeServer,
transfer:ListAgreements,
transfer:ListServers
aws:transfer:certificatetransfer:DescribeCertificate,
transfer:ListCertificates
aws:transfer:connectortransfer:DescribeConnector,
transfer:ListConnectors
aws:transfer:host-keytransfer:DescribeHostKey,
transfer:DescribeServer,
transfer:ListHostKeys,
transfer:ListServers
aws:transfer:profiletransfer:DescribeProfile,
transfer:ListProfiles
aws:transfer:servertransfer:DescribeServer,
transfer:ListServers
aws:transfer:usertransfer:DescribeServer,
transfer:DescribeUser,
transfer:ListServers,
transfer:ListUsers
aws:transfer:webapptransfer:DescribeWebApp,
transfer:ListWebApps
aws:transfer:workflowtransfer:DescribeWorkflow,
transfer:ListWorkflows
aws:translate:parallel-datatranslate:GetParallelData,
translate:ListParallelData
aws:translate:terminologytranslate:GetTerminology,
translate:ListTerminologies
aws:verifiedpermissions:identity-sourceverifiedpermissions:GetPolicyStore,
verifiedpermissions:ListIdentitySources,
verifiedpermissions:ListPolicyStores
aws:verifiedpermissions:policyverifiedpermissions:GetPolicyStore,
verifiedpermissions:ListPolicies,
verifiedpermissions:ListPolicyStores
aws:verifiedpermissions:policy-storeverifiedpermissions:GetPolicyStore,
verifiedpermissions:ListPolicyStores
aws:verifiedpermissions:policy-templateverifiedpermissions:GetPolicyStore,
verifiedpermissions:ListPolicyStores,
verifiedpermissions:ListPolicyTemplates
aws:vpc-lattice:access-log-subscriptionvpc-lattice:GetService,
vpc-lattice:GetServiceNetwork,
vpc-lattice:ListAccessLogSubscriptions,
vpc-lattice:ListServiceNetworks,
vpc-lattice:ListServices
aws:vpc-lattice:listenervpc-lattice:GetListener,
vpc-lattice:GetService,
vpc-lattice:ListListeners,
vpc-lattice:ListServices
aws:vpc-lattice:resource-configurationvpc-lattice:GetResourceConfiguration,
vpc-lattice:ListResourceConfigurations
aws:vpc-lattice:resource-endpoint-associationvpc-lattice:GetResourceConfiguration,
vpc-lattice:ListResourceConfigurations,
vpc-lattice:ListResourceEndpointAssociations
aws:vpc-lattice:resource-gatewayvpc-lattice:GetResourceGateway,
vpc-lattice:ListResourceGateways
aws:vpc-lattice:rulevpc-lattice:GetListener,
vpc-lattice:GetRule,
vpc-lattice:GetService,
vpc-lattice:ListListeners,
vpc-lattice:ListRules,
vpc-lattice:ListServices
aws:vpc-lattice:servicevpc-lattice:GetService,
vpc-lattice:ListServices
aws:vpc-lattice:service-networkvpc-lattice:GetServiceNetwork,
vpc-lattice:ListServiceNetworks
aws:vpc-lattice:service-network-resource-associationvpc-lattice:ListServiceNetworkResourceAssociations
aws:vpc-lattice:service-network-service-associationvpc-lattice:GetServiceNetwork,
vpc-lattice:ListServiceNetworkServiceAssociations,
vpc-lattice:ListServiceNetworks
aws:vpc-lattice:service-network-vpc-associationvpc-lattice:GetServiceNetwork,
vpc-lattice:ListServiceNetworkVpcAssociations,
vpc-lattice:ListServiceNetworks
aws:vpc-lattice:target-groupvpc-lattice:GetTargetGroup,
vpc-lattice:ListTargetGroups
aws:waf:aclwaf:GetWebACL,
waf:ListWebACLs
aws:waf:rulewaf:GetRule,
waf:ListRules
aws:waf:rulegroupwaf:GetRuleGroup,
waf:ListRuleGroups
aws:wafregional:aclwaf-regional:GetWebACL,
waf-regional:ListWebACLs
aws:wafregional:rulewaf-regional:GetRule,
waf-regional:ListRules
aws:wafregional:rulegroupwaf-regional:GetRuleGroup,
waf-regional:ListRuleGroups
aws:wafv2:aclwafv2:GetLoggingConfiguration,
wafv2:GetWebACL,
wafv2:ListResourcesForWebACL,
wafv2:ListWebACLs
aws:wafv2:ipsetwafv2:GetIPSet,
wafv2:ListIPSets
aws:wafv2:regexpatternsetwafv2:GetRegexPatternSet,
wafv2:ListRegexPatternSets
aws:wafv2:rulegroupwafv2:GetRuleGroup,
wafv2:ListRuleGroups
aws:workmail:organizationworkmail:DescribeOrganization,
workmail:ListOrganizations
aws:workspaces-web:browser-settingsworkspaces-web:GetBrowserSettings,
workspaces-web:ListBrowserSettings
aws:workspaces-web:data-protection-settingsworkspaces-web:GetDataProtectionSettings,
workspaces-web:ListDataProtectionSettings
aws:workspaces-web:identity-providerworkspaces-web:GetIdentityProvider,
workspaces-web:ListIdentityProviders,
workspaces-web:ListPortals
aws:workspaces-web:ip-access-settingsworkspaces-web:GetIpAccessSettings,
workspaces-web:ListIpAccessSettings
aws:workspaces-web:network-settingsworkspaces-web:GetNetworkSettings,
workspaces-web:ListNetworkSettings
aws:workspaces-web:portalworkspaces-web:ListPortals
aws:workspaces-web:trust-storeworkspaces-web:GetTrustStore,
workspaces-web:ListTrustStores
aws:workspaces-web:user-access-logging-settingsworkspaces-web:GetUserAccessLoggingSettings,
workspaces-web:ListUserAccessLoggingSettings
aws:workspaces-web:user-settingsworkspaces-web:GetUserSettings,
workspaces-web:ListUserSettings
aws:workspaces:amazon-bundleworkspaces:DescribeWorkspaceBundles
aws:workspaces:applicationworkspaces:DescribeApplications
aws:workspaces:bundleworkspaces:DescribeWorkspaceBundles
aws:workspaces:connection-aliasworkspaces:DescribeConnectionAliases
aws:workspaces:directoryworkspaces:DescribeWorkspaceDirectories
aws:workspaces:imageworkspaces:DescribeWorkspaceImages
aws:workspaces:ip-groupworkspaces:DescribeIpGroups
aws:workspaces:poolworkspaces:DescribeWorkspacesPools
aws:workspaces:workspaceworkspaces:DescribeWorkspaces
aws:xray:groupxray:GetGroups
aws:xray:sampling-rulexray:GetSamplingRules
Resource TypePermissions
aws:ec2:egressonlyinternetgatewayec2:DescribeEgressOnlyInternetGateways
aws:ec2:transitgatewayec2:DescribeTransitGateways
aws:ec2:vpcendpointconnectionnotificationec2:DescribeVpcEndpointConnectionNotifications
aws:ec2:vpcinternetgatewayec2:DescribeInternetGateways
aws:ec2:vpcnatgatewayec2:DescribeNatGateways
aws:ec2:vpcpeeringconnectionec2:DescribeVpcPeeringConnections
aws:ec2:vpngatewayec2:DescribeVpnGateways
aws:network-firewall:firewallnetwork-firewall:DescribeFirewall,
network-firewall:DescribeFirewallPolicy,
network-firewall:DescribeLoggingConfiguration,
network-firewall:ListFirewalls
Resource TypePermissions
aws:acm:acmacm:DescribeCertificate,
acm:ListCertificates
aws:applicationautoscaling:scalingpolicyapplicationautoscaling:DescribeScalingPolicies
aws:autoscaling:groupautoscaling:DescribeAutoScalingGroups
aws:cloudformation:stackcloudformation:DescribeStacks,
cloudformation:ListStacks
aws:cloudfront:distributioncloudfront:GetDistribution,
cloudfront:ListDistributions
aws:cloudfront:functioncloudfront:ListFunctions
aws:cloudtrail:trailcloudtrail:DescribeTrails,
cloudtrail:GetEventSelectors,
cloudtrail:GetTrailStatus
aws:cloudwatchlogs:log-grouplogs:DescribeLogGroups,
logs:DescribeSubscriptionFilters
aws:docdb:clusterrds:DescribeDBClusters
aws:dynamodb:tabledynamodb:DescribeContinuousBackups,
dynamodb:DescribeTable,
dynamodb:DescribeTimeToLive,
dynamodb:ListTables
aws:ec2:imageec2:DescribeImageAttribute,
ec2:DescribeImages
aws:ec2:instanceec2:DescribeInstances
aws:ec2:networkaclec2:DescribeNetworkAcls
aws:ec2:networkinterfaceec2:DescribeNetworkInterfaces
aws:ec2:securitygroupec2:DescribeSecurityGroups
aws:ec2:snapshotec2:DescribeSnapshotAttribute,
ec2:DescribeSnapshots
aws:ec2:volumeec2:DescribeVolumes
aws:ec2:vpcec2:DescribeVpcs
aws:ec2:vpcendpointec2:DescribeVpcEndpoints
aws:ec2:vpcendpoint-serviceec2:DescribeVpcEndpointServices
aws:ec2:vpcnatgatewayec2:DescribeNatGateways
aws:ec2:vpcpeeringconnectionec2:DescribeVpcPeeringConnections
aws:ecr:repositoryecr:DescribeRepositories,
ecr:GetLifecyclePolicy,
ecr:GetRepositoryPolicy
aws:ecrpublic:repositoryecr-public:DescribeImages,
ecr-public:DescribeRepositories,
ecr-public:GetRepositoryPolicy
aws:ecs:clusterecs:DescribeClusters,
ecs:ListClusters
aws:ecs:serviceecs:DescribeServices,
ecs:ListClusters,
ecs:ListServices
aws:ecs:taskecs:DescribeServices,
ecs:DescribeTasks,
ecs:ListClusters,
ecs:ListServices,
ecs:ListTasks
aws:ecs:task-definitionecs:DescribeServices,
ecs:DescribeTaskDefinition,
ecs:DescribeTasks,
ecs:ListClusters,
ecs:ListServices,
ecs:ListTasks
aws:efs:accesspointelasticfilesystem:DescribeAccessPoints
aws:efs:filesystemelasticfilesystem:DescribeFileSystems,
elasticfilesystem:DescribeLifecycleConfiguration
aws:eks:clustereks:DescribeCluster,
eks:ListClusters
aws:elasticache:clusterelasticache:DescribeCacheClusters
aws:elasticloadbalancing:loadbalancerelasticloadbalancing:DescribeInstanceHealth,
elasticloadbalancing:DescribeLoadBalancerAttributes,
elasticloadbalancing:DescribeLoadBalancerPolicies,
elasticloadbalancing:DescribeLoadBalancers
aws:elasticloadbalancingv2:loadbalancerelasticloadbalancing:DescribeListeners,
elasticloadbalancing:DescribeLoadBalancerAttributes,
elasticloadbalancing:DescribeLoadBalancers
aws:elasticsearchservice:domaines:DescribeElasticsearchDomains,
es:ListDomainNames
aws:emr:clusterelasticmapreduce:DescribeCluster,
elasticmapreduce:GetAutoTerminationPolicy,
elasticmapreduce:GetManagedScalingPolicy,
elasticmapreduce:ListClusters
aws:eventbridge:eventbusevents:ListEventBuses,
events:ListRules
aws:iam:accountiam:GetAccountPasswordPolicy,
iam:GetAccountSummary,
organizations:DescribeOrganization
aws:iam:policyiam:GetPolicy,
iam:GetPolicyVersion,
iam:ListPolicies
aws:iam:roleiam:GetAccountAuthorizationDetails,
iam:GetRole,
iam:ListAttachedRolePolicies
aws:iam:server-certificateiam:ListServerCertificates
aws:iam:useriam:GetLoginProfile,
iam:GetUser,
iam:ListAttachedUserPolicies,
iam:ListGroupsForUser,
iam:ListMFADevices,
iam:ListSSHPublicKeys,
iam:ListUsers,
iam:ListVirtualMFADevices
aws:kms:keykms:DescribeKey,
kms:GetKeyRotationStatus,
kms:ListKeys
aws:lambda:functionlambda:GetFunction,
lambda:GetPolicy,
lambda:ListFunctionUrlConfigs,
lambda:ListFunctions,
lambda:ListProvisionedConcurrencyConfigs
aws:mq:brokermq:DescribeBroker,
mq:ListBrokers
aws:pipes:pipepipes:ListPipes
aws:rds:clusterrds:DescribeDBClusters
aws:rds:instancerds:DescribeDBInstances
aws:rds:snapshotrds:DescribeDBSnapshotAttributes,
rds:DescribeDBSnapshots
aws:redshift:clusterredshift:DescribeClusterParameters,
redshift:DescribeClusters,
redshift:DescribeEndpointAccess,
redshift:DescribeLoggingStatus
aws:s3:buckets3:GetBucketAbac,
s3:GetBucketAcl,
s3:GetBucketLogging,
s3:GetBucketMetadataConfiguration,
s3:GetBucketNotification,
s3:GetBucketObjectLockConfiguration,
s3:GetBucketOwnershipControls,
s3:GetBucketPolicy,
s3:GetBucketPolicyStatus,
s3:GetBucketPublicAccessBlock,
s3:GetBucketVersioning,
s3:GetBucketWebsite,
s3:GetEncryptionConfiguration,
s3:GetInventoryConfiguration,
s3:GetLifecycleConfiguration,
s3:GetReplicationConfiguration,
s3:ListAllMyBuckets
aws:s3control:accountpublicaccessblocks3:GetBucketPublicAccessBlock
aws:secretsmanager:secretsecretsmanager:DescribeSecret,
secretsmanager:GetResourcePolicy,
secretsmanager:ListSecrets
aws:sfn:statemachinestates:DescribeStateMachine,
states:ListStateMachines
aws:sns:topicsns:GetTopicAttributes,
sns:ListTopics
aws:sqs:queuesqs:GetQueueAttributes,
sqs:GetQueueUrl,
sqs:ListQueues

今後のリリース

ここに記載している権限は、今後 30 日以内に追加予定のリソースを反映したものです。Datadog のリソース カバレッジとトラッキングを最大限に活用するため、これらの権限を既存の AWS インテグレーション IAM ポリシー (SecurityAudit ポリシーをアタッチ済み) に含めてください。

[
  "There are no future permissions currently"
]

Cloud Security

セットアップ

AWS アカウントに AWS インテグレーションをまだ設定していない場合は、上記の セットアップ手順 を完了してください。手順内で案内される箇所では Cloud Security を必ず有効化してください。

注: この機能を使用するには、AWS インテグレーションにロールの委任を設定する必要があります。

既存の AWS インテグレーションに Cloud Security を追加するには、以下の手順に従ってリソースの収集を有効化してください。

  1. Datadog IAM ロールに必要な権限を付与するには、AWS マネージドの SecurityAudit ポリシーを Datadog の AWS IAM ロールにアタッチしてください。このポリシーは AWS コンソール で確認できます。

  2. Datadog AWS インテグレーションページで、以下の手順で設定を完了させます。または、Update an AWS Integration API エンドポイントを利用することも可能です。

    1. リソース収集を有効化したい AWS アカウントを選択します。
    2. Resource collection タブで、Cloud Security の横にある Enable をクリックします。Cloud Security Setup ページへリダイレクトされ、選択したアカウントのセットアップ ダイアログが自動的に開きます。
    3. セットアップダイアログで、Enable Resource Scanning トグルをオンに切り替えます。
    4. Done をクリックしてセットアップを完了します。

アラームの収集

AWS CloudWatch アラームを Datadog イベントエクスプローラーに送信する方法は 2 つあります。

  • Alarm polling: Alarm polling は AWS インテグレーションに標準で含まれており、DescribeAlarmHistory API を通じてメトリクス アラームを取得します。この方法を採用すると、アラームはイベント ソース Amazon Web Services として分類されます。: クローラはコンポジット アラームを収集しません。
  • SNS トピック: アラームを SNS トピックにサブスクライブしてから、SNS メッセージを Datadog に転送することで、イベントエクスプローラー内のすべての AWS CloudWatch アラームを確認できます。Datadog でイベントとして SNS メッセージを受信する方法については、SNS メッセージの受信を参照してください。この方法に従うと、イベントソース Amazon SNS の下にアラームが分類されます。

収集されるデータ

メトリクス

: AWS カスタムメトリクスの収集を有効にしたり、Datadog がインテグレーションを提供していないサービスからのメトリクスを収集することも可能です。詳しくは、AWS インテグレーションと CloudWatch の FAQ をご参照ください。

イベント

AWS からのイベントは、AWS サービス単位で収集されます。収集されるイベントの詳細については、お使いの AWS サービスのドキュメントを参照してください。

タグ

AWS インテグレーションにより以下のタグが収集されます。: 一部のタグは、特定のメトリクスにのみ表示されます。

インテグレーションDatadog タグキー
Allregion
API Gatewayapiid、apinamemethodresourcestage`
App Runnerinstanceserviceidservicename
Auto Scalingautoscalinggroupnameautoscaling_group
Billingaccount_idbudget_namebudget_typecurrencyservicenametime_unit
CloudFrontdistributionid
CodeBuildproject_name
CodeDeployapplicationcreatordeployment_configdeployment_groupdeployment_optiondeployment_typestatus
DirectConnectconnectionid
DynamoDBglobalsecondaryindexnameoperationstreamlabeltablename
EBSvolumeidvolume-namevolume-type
EC2autoscaling_groupavailability-zoneimageinstance-idinstance-typekernelnamesecurity_group_name
ECSclusternameservicenameinstance_id
EFSfilesystemid
ElastiCachecachenodeidcache_node_typecacheclusteridcluster_nameengineengine_versionpreferred_availability-zonereplication_group
ElasticBeanstalkenvironmentnameenviromentid
ELBavailability-zonehostnameloadbalancernamenametargetgroup
EMRcluster_namejobflowid
ESdedicated_master_enabledebs_enabledelasticsearch_versioninstance_typezone_awareness_enabled
Firehosedeliverystreamname
FSxfilesystemidfilesystemtype
Healthevent_categorystatusservice
IoTactiontypeprotocolrulename
Kinesisstreamnamenamestate
KMSkeyid
Lambdafunctionnameresourceexecutedversionmemorysizeruntime
Machine Learningmlmodelidrequestmode
MQbrokerqueuetopic
OpsWorksstackidlayeridinstanceid
Pollyoperation
RDSauto_minor_version_upgradedbinstanceclassdbclusteridentifierdbinstanceidentifierdbnameengineengineversionhostnamenamepublicly_accessiblesecondary_availability-zone
RDS Proxyproxynametargettargetgrouptargetrole
Redshiftclusteridentifierlatencynodeidservice_classstagewlmid
Route 53healthcheckid
S3bucketnamefilteridstoragetype
SESタグキーは AWS でカスタム設定されます。
SNStopicname
SQSqueuename
VPCnategatewayidvpnidtunnelipaddress
WorkSpacesdirectoryidworkspaceid

サービス チェック

トラブルシューティング

AWS インテグレーションに関する問題解決は、AWS インテグレーションのトラブルシューティングガイドをご参照ください。

その他の参考資料

お役に立つドキュメント、リンクや記事: