| applicationinsights:* |
applicationinsights |
| autoscaling:AttachInstances |
autoscaling |
| autoscaling:CreateAutoScalingGroup |
autoscaling |
| autoscaling:CreateLaunchConfiguration |
autoscaling |
| autoscaling:CreateOrUpdateTags |
autoscaling |
| autoscaling:DeleteAutoScalingGroup |
autoscaling |
| autoscaling:DeleteLaunchConfiguration |
autoscaling |
| autoscaling:Describe* |
autoscaling |
| autoscaling:UpdateAutoScalingGroup |
autoscaling |
| cloudformation:CreateStack |
cloudformation |
| cloudformation:DeleteStack |
cloudformation |
| cloudformation:Describe* |
cloudformation |
| cloudformation:DescribeAccountLimits |
cloudformation |
| cloudformation:DescribeStack* |
cloudformation |
| cloudformation:DescribeStackDriftDetectionStatus |
cloudformation |
| cloudformation:Get* |
cloudformation |
| cloudformation:GetTemplateSummary |
cloudformation |
| cloudformation:List* |
cloudformation |
| cloudformation:List* |
cloudformation |
| cloudformation:ListStacks |
cloudformation |
| cloudformation:SignalResource |
cloudformation |
| cloudformation:TagResource |
cloudformation |
| cloudformation:ValidateTemplate |
cloudformation |
| cloudwatch:DeleteAlarms |
cloudwatch |
| cloudwatch:Describe* |
cloudwatch |
| cloudwatch:DescribeAlarms |
cloudwatch |
| cloudwatch:Get* |
cloudwatch |
| cloudwatch:List* |
cloudwatch |
| cloudwatch:PutMetricAlarm |
cloudwatch |
| ds:AddIpRoutes |
ds |
| ds:CreateComputer |
ds |
| ds:CreateMicrosoftAD |
ds |
| ds:DeleteDirectory |
ds |
| ds:Describe* |
ds |
| ds:ListAuthorizedApplications |
ds |
| dynamodb:CreateTable |
dynamodb |
| dynamodb:DeleteTable |
dynamodb |
| dynamodb:DescribeTable |
dynamodb |
| ec2:AllocateAddress |
ec2 |
| ec2:AllocateHosts |
ec2 |
| ec2:AssignPrivateIpAddresses |
ec2 |
| ec2:AssociateAddress |
ec2 |
| ec2:AssociateDhcpOptions |
ec2 |
| ec2:AssociateRouteTable |
ec2 |
| ec2:AssociateSubnetCidrBlock |
ec2 |
| ec2:AssociateVpcCidrBlock |
ec2 |
| ec2:AttachInternetGateway |
ec2 |
| ec2:AttachNetworkInterface |
ec2 |
| ec2:AttachVolume |
ec2 |
| ec2:AuthorizeSecurityGroupEgress |
ec2 |
| ec2:AuthorizeSecurityGroupIngress |
ec2 |
| ec2:CreateDhcpOptions |
ec2 |
| ec2:CreateEgressOnlyInternetGateway |
ec2 |
| ec2:CreateInternetGateway |
ec2 |
| ec2:CreateKeyPair |
ec2 |
| ec2:CreateNatGateway |
ec2 |
| ec2:CreateNetworkInterface |
ec2 |
| ec2:CreatePlacementGroup |
ec2 |
| ec2:CreateRoute |
ec2 |
| ec2:CreateRouteTable |
ec2 |
| ec2:CreateSecurityGroup |
ec2 |
| ec2:CreateSubnet |
ec2 |
| ec2:CreateTags |
ec2 |
| ec2:CreateVolume |
ec2 |
| ec2:CreateVpc |
ec2 |
| ec2:CreateVpcEndpoint |
ec2 |
| ec2:DeleteDhcpOptions |
ec2 |
| ec2:DeleteInternetGateway |
ec2 |
| ec2:DeleteKeyPair |
ec2 |
| ec2:DeleteNatGateway |
ec2 |
| ec2:DeleteNetworkAcl |
ec2 |
| ec2:DeleteNetworkInterface |
ec2 |
| ec2:DeleteNetworkInterfacePermission |
ec2 |
| ec2:DeletePlacementGroup |
ec2 |
| ec2:DeleteRoute |
ec2 |
| ec2:DeleteRouteTable |
ec2 |
| ec2:DeleteSecurityGroup |
ec2 |
| ec2:DeleteSnapshot |
ec2 |
| ec2:DeleteSubnet |
ec2 |
| ec2:DeleteTags |
ec2 |
| ec2:DeleteVolume |
ec2 |
| ec2:DeleteVpc |
ec2 |
| ec2:Describe* |
ec2 |
| ec2:DetachInternetGateway |
ec2 |
| ec2:DetachNetworkInterface |
ec2 |
| ec2:DetachVolume |
ec2 |
| ec2:DisassociateAddress |
ec2 |
| ec2:DisassociateIamInstanceProfile |
ec2 |
| ec2:DisassociateRouteTable |
ec2 |
| ec2:DisassociateSubnetCidrBlock |
ec2 |
| ec2:DisassociateVpcCidrBlock |
ec2 |
| ec2:Get* |
ec2 |
| ec2:GetConsoleOutput |
ec2 |
| ec2:GetLaunchTemplateData |
ec2 |
| ec2:GetPasswordData |
ec2 |
| ec2:ModifyInstanceAttribute |
ec2 |
| ec2:ModifyInstancePlacement |
ec2 |
| ec2:ModifyNetworkInterfaceAttribute |
ec2 |
| ec2:ModifySubnetAttribute |
ec2 |
| ec2:ModifyVolume |
ec2 |
| ec2:ModifyVolumeAttribute |
ec2 |
| ec2:ModifyVpcAttribute |
ec2 |
| ec2:ReleaseAddress |
ec2 |
| ec2:ReplaceRoute |
ec2 |
| ec2:ReplaceRouteTableAssociation |
ec2 |
| ec2:RevokeSecurityGroupEgress |
ec2 |
| ec2:RevokeSecurityGroupIngress |
ec2 |
| ec2:RunInstances |
ec2 |
| ec2:StartInstances |
ec2 |
| ec2:StopInstances |
ec2 |
| ec2:TerminateInstances |
ec2 |
| elasticfilesystem:CreateFileSystem |
elasticfilesystem |
| elasticfilesystem:CreateMountTarget |
elasticfilesystem |
| elasticfilesystem:DeleteFileSystem |
elasticfilesystem |
| elasticfilesystem:DeleteMountTarget |
elasticfilesystem |
| elasticfilesystem:DescribeFileSystems |
elasticfilesystem |
| elasticfilesystem:DescribeMountTargetSecurityGroups |
elasticfilesystem |
| elasticfilesystem:DescribeMountTargets |
elasticfilesystem |
| elasticfilesystem:TagResource |
elasticfilesystem |
| elasticfilesystem:UntagResource |
elasticfilesystem |
| fsx:CreateFileSystem |
fsx |
| fsx:CreateStorageVirtualMachine |
fsx |
| fsx:CreateVolume |
fsx |
| fsx:DeleteFileSystem |
fsx |
| fsx:DeleteStorageVirtualMachine |
fsx |
| fsx:DeleteVolume |
fsx |
| fsx:DescribeFileSystems |
fsx |
| fsx:DescribeStorageVirtualMachines |
fsx |
| fsx:DescribeVolumes |
fsx |
| fsx:ListTagsForResource |
fsx |
| fsx:TagResource |
fsx |
| fsx:UntagResource |
fsx |
| iam:AddRoleToInstanceProfile |
iam |
| iam:CreateInstanceProfile |
iam |
| iam:CreateServiceLinkedRole |
iam |
| iam:DeleteInstanceProfile |
iam |
| iam:GetInstanceProfile |
iam |
| iam:GetPolicy |
iam |
| iam:GetPolicyVersion |
iam |
| iam:GetRole |
iam |
| iam:GetRolePolicy |
iam |
| iam:GetUser |
iam |
| iam:List* |
iam |
| iam:PassRole |
iam |
| iam:RemoveRoleFromInstanceProfile |
iam |
| kms:ListAliases |
kms |
| kms:ListKeys |
kms |
| lambda:CreateFunction |
lambda |
| lambda:DeleteFunction |
lambda |
| lambda:GetFunction |
lambda |
| lambda:GetFunctionConfiguration |
lambda |
| lambda:InvokeFunction |
lambda |
| launchwizard:* |
launchwizard |
| logs:CreateLogGroup |
logs |
| logs:CreateLogStream |
logs |
| logs:DeleteLogGroup |
logs |
| logs:DeleteLogStream |
logs |
| logs:DescribeLogGroups |
logs |
| logs:DescribeLogStreams |
logs |
| logs:GetLogDelivery |
logs |
| logs:GetLogEvents |
logs |
| logs:GetLogGroupFields |
logs |
| logs:GetLogRecord |
logs |
| logs:ListLogDeliveries |
logs |
| logs:PutLogEvents |
logs |
| logs:TagResource |
logs |
| logs:UntagResource |
logs |
| resource-groups:CreateGroup |
resource-groups |
| resource-groups:DeleteGroup |
resource-groups |
| resource-groups:Get* |
resource-groups |
| resource-groups:List* |
resource-groups |
| resource-groups:List* |
resource-groups |
| route53:ChangeResourceRecordSets |
route53 |
| route53:GetChange |
route53 |
| route53:ListHostedZones |
route53 |
| route53:ListHostedZones |
route53 |
| route53:ListHostedZonesByName |
route53 |
| route53:ListResourceRecordSets |
route53 |
| s3:CreateBucket |
s3 |
| s3:DeleteBucket |
s3 |
| s3:GetBucketLocation |
s3 |
| s3:GetObject |
s3 |
| s3:ListAllMyBuckets |
s3 |
| s3:ListBucket |
s3 |
| s3:PutBucketVersioning |
s3 |
| s3:PutObject |
s3 |
| secretsmanager:CreateSecret |
secretsmanager |
| secretsmanager:DeleteResourcePolicy |
secretsmanager |
| secretsmanager:DeleteSecret |
secretsmanager |
| secretsmanager:GetRandomPassword |
secretsmanager |
| secretsmanager:GetSecretValue |
secretsmanager |
| secretsmanager:ListSecretVersionIds |
secretsmanager |
| secretsmanager:ListSecrets |
secretsmanager |
| secretsmanager:PutResourcePolicy |
secretsmanager |
| secretsmanager:TagResource |
secretsmanager |
| secretsmanager:UntagResource |
secretsmanager |
| servicecatalog:AssociatePrincipalWithPortfolio |
servicecatalog |
| servicecatalog:AssociateProductWithPortfolio |
servicecatalog |
| servicecatalog:CreateConstraint |
servicecatalog |
| servicecatalog:CreatePortfolio |
servicecatalog |
| servicecatalog:CreateProduct |
servicecatalog |
| servicecatalog:CreateProvisioningArtifact |
servicecatalog |
| servicecatalog:DescribePortfolio |
servicecatalog |
| servicecatalog:TagResource |
servicecatalog |
| servicecatalog:UntagResource |
servicecatalog |
| servicequotas:GetServiceQuota |
servicequotas |
| servicequotas:ListServiceQuotas |
servicequotas |
| sns:CreateTopic |
sns |
| sns:DeleteTopic |
sns |
| sns:ListSubscriptions |
sns |
| sns:ListSubscriptionsByTopic |
sns |
| sns:ListTopics |
sns |
| sns:Publish |
sns |
| sns:Subscribe |
sns |
| sns:Unsubscribe |
sns |
| sqs:AddPermission |
sqs |
| sqs:CreateQueue |
sqs |
| sqs:DeleteQueue |
sqs |
| sqs:GetQueueAttributes |
sqs |
| sqs:GetQueueUrl |
sqs |
| sqs:ListQueueTags |
sqs |
| sqs:ListQueues |
sqs |
| sqs:SetQueueAttributes |
sqs |
| sqs:TagQueue |
sqs |
| ssm:AddTagsToResource |
ssm |
| ssm:CreateAssociation |
ssm |
| ssm:CreateDocument |
ssm |
| ssm:CreateOpsMetadata |
ssm |
| ssm:DeleteAssociation |
ssm |
| ssm:DeleteDocument |
ssm |
| ssm:DeleteOpsMetadata |
ssm |
| ssm:DeleteParameter* |
ssm |
| ssm:DescribeAutomation* |
ssm |
| ssm:DescribeDocument |
ssm |
| ssm:DescribeDocument* |
ssm |
| ssm:DescribeInstanceInformation |
ssm |
| ssm:DescribeParameters |
ssm |
| ssm:GetAutomationExecution |
ssm |
| ssm:GetCommandInvocation |
ssm |
| ssm:GetConnectionStatus |
ssm |
| ssm:GetDocument |
ssm |
| ssm:GetDocument |
ssm |
| ssm:GetDocument |
ssm |
| ssm:GetParameter* |
ssm |
| ssm:ListCommand* |
ssm |
| ssm:ListDocument* |
ssm |
| ssm:ListInstanceAssociations |
ssm |
| ssm:ListTagsForResource |
ssm |
| ssm:PutParameter |
ssm |
| ssm:RemoveTagsFromResource |
ssm |
| ssm:SendAutomationSignal |
ssm |
| ssm:SendCommand |
ssm |
| ssm:SendCommand |
ssm |
| ssm:StartAutomationExecution |
ssm |
| ssm:StopAutomationExecution |
ssm |
| sts:GetCallerIdentity |
sts |
| tag:Get* |
tag |