AWS AddPermission20150331v2
Adds a statement to a Lambda resource-based policy.
All events with tag AWS.
Adds a statement to a Lambda resource-based policy.
Adds one IAM role to an existing instance profile.
Adds an IAM user to a group, changing the policies that apply to the user.
Archives specified GuardDuty findings in a regional detector.
Associates an instance profile with a running or stopped EC2 instance.
Returns temporary security credentials for assuming an IAM role. Allows an entity (user, service, or account) to act with the role's permissions.
Exchanges a validated SAML assertion for temporary IAM role credentials.
Exchanges a web-identity token for temporary IAM role credentials.
Attaches a managed permissions policy to an IAM group.
Attaches a managed permissions policy to an IAM role.
Attaches a managed permissions policy to an IAM user.
Authorizes ingress to an RDS DB security group through a legacy networking API.
Adds outbound allow rules to an EC2 security group.
Adds inbound allow rules to an EC2 security group.
Changes the calling IAM user’s console password.
Records a sign-in attempt to the AWS Management Console, capturing success or failure status and whether MFA was used.
Copies an S3 object to another key or bucket.
Creates an EKS access entry for an existing IAM principal.
Creates a new long-term access key for an IAM user, enabling programmatic access to AWS services.
Requests creation of an AWS Organizations member account.
Creates a Systems Manager State Manager association.
Starts creation of a manual RDS DB instance snapshot.
Creates a legacy AWS Glue development endpoint.
Creates a GuardDuty finding filter, optionally with an automatic archive action.
Starts creation of an EBS-backed AMI from an EC2 instance.
Starts an eligible EC2 instance export to an S3 bucket.
Creates a GuardDuty trusted IP list and optionally requests activation.
Creates an EC2 key pair and returns its private key to the API caller.
Creates a console password for an IAM user.
Adds an inbound or outbound allow/deny rule to a VPC network ACL.
Registers an OIDC identity provider in IAM.
Creates a customer-managed IAM policy with an initial default version.
Creates a customer-managed policy version, optionally making it the operative version.
Creates an IAM role with a trust policy and optional role settings.
Registers SAML identity-provider metadata in IAM.
Creates an IAM role linked to a specific AWS service.
Starts creation of a point-in-time EBS volume snapshot.
Requests provisioning of a CloudFormation stack from a template.
Creates an IAM user without automatically creating sign-in credentials.
Creates a virtual MFA device that must be enabled separately for an IAM user.
Deactivates a specified MFA device and removes its association with a user.
Deletes an IAM access key permanently.
Deletes specified CloudWatch alarms in an account and Region.
Deletes an empty S3 bucket, after all object versions and delete markers are removed.
Removes an S3 bucket policy without resetting other access controls.
Deletes an AWS Config rule and its evaluation results.
Deletes a customer-managed AWS Config recorder in one Region.
Deletes an RDS DB cluster with configurable final-snapshot and backup handling.
Deletes an RDS DB instance with configurable final-snapshot and backup handling.
Deletes an AWS Config delivery channel after customer-managed recording is stopped.
Deletes a regional GuardDuty detector, disabling GuardDuty for that account and Region.
Disables a CloudTrail Lake event data store and starts a seven-day deletion window.
Deletes an EFS file system after mount-target and replication prerequisites are satisfied.
Deletes selected VPC Flow Log configurations without deleting their previously delivered log data.
Deletes an empty Aurora global-database container after regional members are detached or deleted.
Deletes a CloudWatch Logs group and permanently removes its stored log events.
Deletes the target user’s AWS console password without deleting access keys.
Deletes a CloudWatch Logs stream and permanently removes its stored events.
Deletes GuardDuty member records from an administrator’s regional detector.
Deletes a nondefault VPC network ACL that has no subnet associations.
Deletes a numbered inbound or outbound rule from a VPC network ACL.
Deletes an S3 object or a specified version, depending on versioning state.
Requests deletion of multiple S3 object keys or specific versions in one batch.
Removes the permissions boundary on an IAM role, potentially changing effective access.
Deletes a named inline permissions policy from an IAM role.
Deletes an AWS WAFv2 rule group identified by name, ID, and scope.
Deletes an EBS snapshot, subject to protection and retention controls.
Deletes a CloudTrail trail and stops its future collection without deleting previously delivered logs.
Deletes an IAM user after dependent credentials and associations are removed.
Removes the permissions boundary on an IAM user, potentially changing effective access.
Deletes a named inline permissions policy from an IAM user.
Deletes an unassigned virtual MFA device resource.
Deletes an available EBS volume without deleting its snapshots.
Deletes an unassociated AWS WAFv2 web ACL not managed by Firewall Manager.
Detaches a managed policy from an IAM role without deleting the policy.
Detaches a managed policy from an IAM user without deleting the policy.
Disables a KMS key for cryptographic operations until re-enabled.
Legacy API for disassociating a GuardDuty member from its administrator.
Disassociates specified members from a regional GuardDuty administrator.
Requests activation of an opt-in AWS Region for an account.
Enables EC2 Serial Console access for the account in the current Region.
Requests a temporary authentication token for private Amazon ECR registries.
Issues temporary federated-user credentials using long-term IAM-user credentials.
Retrieves an S3 object or selected version, optionally as a byte range.
Retrieves up to ten named Parameter Store parameters, optionally decrypting SecureString values.
Retrieves encrypted Windows administrator password data for an EC2 instance.
Retrieves the selected version of a Secrets Manager secret.
Issues temporary credentials for an IAM user, optionally with MFA context.
Requests a federation sign-in token for AWS console access.
Registers an existing public key as an EC2 key pair.
Requests synchronous, asynchronous, or dry-run Lambda invocation.
Removes the calling member account from its AWS organization.
Modifies RDS DB instance settings, subject to parameter-specific application rules.
Changes sharing attributes of a manual RDS DB snapshot.
Changes an AMI attribute, including launch permissions for other accounts.
Changes a supported EC2 instance attribute, including user data or security groups.
Changes EBS snapshot attributes, including volume-creation permissions.
An IAM permission checked when a caller assigns a role to an AWS service; not an API event.
Records initiation of an AWS root-user password recovery request.
Replaces an S3 bucket ACL where ACLs are enabled.
Creates or replaces S3 lifecycle rules for expiration and storage management.
Creates or replaces an S3 bucket lifecycle configuration.
Creates or replaces an S3 bucket resource policy.
Sets the four bucket-level S3 Block Public Access controls.
Creates or replaces an S3 bucket replication configuration.
Configures basic or advanced selectors that determine which events a CloudTrail trail records.
Adds or replaces a named inline permissions policy on an IAM group.
Registers an ECR image manifest and associated tag after layer upload.
Replaces the policy on a KMS key.
Sets or replaces the permissions boundary on an IAM role, potentially changing effective access.
Adds or replaces a named inline permissions policy on an IAM role.
Creates or updates an EventBridge rule.
Adds or updates targets associated with an EventBridge rule.
Sets or replaces the permissions boundary on an IAM user, potentially changing effective access.
Adds or replaces a named inline permissions policy on an IAM user.
Removes a specified member account from an AWS organization.
Removes an IAM user from a group, changing the policies that apply to the user.
Replaces the instance profile associated with a running EC2 instance.
Creates a new RDS DB instance from a snapshot.
Reconnects to a disconnected SSM Session Manager session.
Schedules KMS key deletion and makes the pending key unavailable for cryptographic operations.
Submits an SSM Run Command document to managed nodes.
Publishes an SSH key for a 60-second EC2 serial-console connection window.
Publishes a temporary SSH key through EC2 Instance Connect.
Selects an existing customer-managed IAM policy version as the operative version.
Service event indicating use of a shared EBS snapshot to initiate a copy.
Service event indicating use of a shared EBS snapshot to create a volume.
Starts a CodeBuild build with optional execution overrides.
Starts an RDS data export to Amazon S3.
Starts an SSM Session Manager session.
Stops the named customer-managed AWS Config recorder from recording its configured resource types.
Stops logging API activity for a CloudTrail trail, disabling audit log collection for that trail.
Suspends GuardDuty monitoring for specified member accounts in a Region.
Terminates EC2 instances, with storage impact determined by their configuration.
Sets an IAM access key to Active or Inactive.
Replaces an IAM role trust policy, changing the conditions for assuming it.
Updates a regional GuardDuty detector, including its enabled state and protection features.
Changes a Glue development endpoint’s keys, arguments, or libraries.
Marks specified GuardDuty findings as useful or not useful.
Updates the unpublished code of a Lambda function.
Updates a Lambda function’s unpublished configuration.
Updates a GuardDuty trusted IP list configuration and activation request.
Updates an IAM user console password or password-reset requirement.
Changes a CloudTrail trail configuration, including delivery destinations, regional scope, and log-file validation.