Skip to content

Commit ddba34b

Browse files
author
MAMIP Bot
committed
SageMakerStudioProjectUserRolePolicy - Policy Version v21
1 parent 2c13f1f commit ddba34b

File tree

1 file changed

+20
-7
lines changed

1 file changed

+20
-7
lines changed

policies/SageMakerStudioProjectUserRolePolicy

Lines changed: 20 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"PolicyVersion": {
3-
"CreateDate": "2025-11-14T23:04:07Z",
4-
"VersionId": "v20",
3+
"CreateDate": "2025-11-20T14:49:11Z",
4+
"VersionId": "v21",
55
"Document": {
66
"Version": "2012-10-17",
77
"Statement": [
@@ -1702,7 +1702,20 @@
17021702
]
17031703
}
17041704
},
1705-
"Sid": "KmsWithEncryptPermissions"
1705+
"Sid": "KmsWithEncrypt"
1706+
},
1707+
{
1708+
"Action": [
1709+
"kms:Decrypt"
1710+
],
1711+
"Resource": "arn:aws:kms:*:*:key/${aws:PrincipalTag/KmsKeyId}",
1712+
"Effect": "Allow",
1713+
"Condition": {
1714+
"Null": {
1715+
"kms:EncryptionContext:aws:scheduler:schedule:arn": "false"
1716+
}
1717+
},
1718+
"Sid": "EBDecrypt"
17061719
},
17071720
{
17081721
"Action": [
@@ -1755,7 +1768,7 @@
17551768
]
17561769
}
17571770
},
1758-
"Sid": "KmsManagementPermissions"
1771+
"Sid": "KmsManagement"
17591772
},
17601773
{
17611774
"Action": [
@@ -1805,7 +1818,7 @@
18051818
"aws:ResourceAccount": "${aws:PrincipalAccount}"
18061819
}
18071820
},
1808-
"Sid": "AwsOwnedKmsManagementPermissions"
1821+
"Sid": "AwsOwnedKmsManagement"
18091822
},
18101823
{
18111824
"Action": [
@@ -1818,7 +1831,7 @@
18181831
"aws:ResourceAccount": "${aws:PrincipalAccount}"
18191832
}
18201833
},
1821-
"Sid": "ListKMSPermissions"
1834+
"Sid": "ListKMS"
18221835
},
18231836
{
18241837
"Action": [
@@ -1847,7 +1860,7 @@
18471860
"aws:PrincipalTag/EnableAmazonBedrockIDEPermissions": "true"
18481861
}
18491862
},
1850-
"Sid": "InvokeBedrockModelPermissions"
1863+
"Sid": "InvokeBedrockModel"
18511864
},
18521865
{
18531866
"Action": [

0 commit comments

Comments
 (0)