|
1 | 1 | { |
2 | 2 | "PolicyVersion": { |
3 | | - "CreateDate": "2025-07-28T20:37:08Z", |
4 | | - "VersionId": "v60", |
| 3 | + "CreateDate": "2025-10-07T20:04:07Z", |
| 4 | + "VersionId": "v61", |
5 | 5 | "Document": { |
6 | 6 | "Version": "2012-10-17", |
7 | 7 | "Statement": [ |
|
26 | 26 | "airflow:ListTagsForResource", |
27 | 27 | "amplify:GetApp", |
28 | 28 | "amplify:GetBranch", |
| 29 | + "amplify:GetDomainAssociation", |
29 | 30 | "amplify:ListApps", |
30 | 31 | "amplify:ListBranches", |
| 32 | + "amplify:ListDomainAssociations", |
| 33 | + "amplify:ListTagsForResource", |
31 | 34 | "amplifyuibuilder:ExportThemes", |
32 | 35 | "amplifyuibuilder:GetTheme", |
33 | 36 | "amplifyuibuilder:ListThemes", |
|
100 | 103 | "appstream:ListTagsForResource", |
101 | 104 | "appsync:GetApiCache", |
102 | 105 | "appsync:GetGraphqlApi", |
| 106 | + "appsync:GetSourceApiAssociation", |
103 | 107 | "appsync:ListGraphqlApis", |
| 108 | + "appsync:ListSourceApiAssociations", |
104 | 109 | "aps:DescribeAlertManagerDefinition", |
105 | 110 | "aps:DescribeLoggingConfiguration", |
106 | 111 | "APS:DescribeRuleGroupsNamespace", |
|
165 | 170 | "bcm-data-exports:GetExport", |
166 | 171 | "bcm-data-exports:ListExports", |
167 | 172 | "bcm-data-exports:ListTagsForResource", |
| 173 | + "bedrock-agentcore:GetAgentRuntime", |
| 174 | + "bedrock-agentcore:GetAgentRuntimeEndpoint", |
| 175 | + "bedrock-agentcore:GetBrowser", |
| 176 | + "bedrock-agentcore:GetCodeInterpreter", |
| 177 | + "bedrock-agentcore:ListAgentRuntimeEndpoints", |
| 178 | + "bedrock-agentcore:ListAgentRuntimes", |
| 179 | + "bedrock-agentcore:ListBrowsers", |
| 180 | + "bedrock-agentcore:ListCodeInterpreters", |
168 | 181 | "bedrock:GetAgent", |
169 | 182 | "bedrock:GetAgentActionGroup", |
170 | 183 | "bedrock:GetAgentKnowledgeBase", |
171 | 184 | "bedrock:GetDataSource", |
| 185 | + "bedrock:GetFlow", |
172 | 186 | "bedrock:GetFlowAlias", |
173 | 187 | "bedrock:GetFlowVersion", |
174 | 188 | "bedrock:GetGuardrail", |
175 | 189 | "bedrock:GetInferenceProfile", |
176 | 190 | "bedrock:GetKnowledgeBase", |
177 | 191 | "bedrock:GetModelInvocationLoggingConfiguration", |
178 | 192 | "bedrock:ListAgentActionGroups", |
| 193 | + "bedrock:ListAgentCollaborators", |
179 | 194 | "bedrock:ListAgentKnowledgeBases", |
180 | 195 | "bedrock:ListAgents", |
181 | 196 | "bedrock:ListDataSources", |
182 | 197 | "bedrock:ListFlowAliases", |
183 | 198 | "bedrock:ListFlowVersions", |
| 199 | + "bedrock:ListFlows", |
184 | 200 | "bedrock:ListGuardrails", |
185 | 201 | "bedrock:ListInferenceProfiles", |
186 | 202 | "bedrock:ListKnowledgeBases", |
| 203 | + "bedrock:ListPrompts", |
187 | 204 | "bedrock:ListTagsForResource", |
188 | 205 | "billingconductor:ListAccountAssociations", |
189 | 206 | "billingconductor:ListBillingGroups", |
|
213 | 230 | "cloud9:ListEnvironments", |
214 | 231 | "cloud9:ListTagsForResource", |
215 | 232 | "cloudformation:BatchDescribeTypeConfigurations", |
| 233 | + "cloudformation:DescribePublisher", |
216 | 234 | "cloudformation:DescribeStackInstance", |
217 | 235 | "cloudformation:DescribeStackSet", |
218 | 236 | "cloudformation:DescribeType", |
|
241 | 259 | "cloudtrail:GetEventDataStore", |
242 | 260 | "cloudtrail:GetEventSelectors", |
243 | 261 | "cloudtrail:GetInsightSelectors", |
| 262 | + "cloudtrail:GetResourcePolicy", |
244 | 263 | "cloudtrail:GetTrailStatus", |
245 | 264 | "cloudTrail:ListChannels", |
246 | 265 | "cloudtrail:ListEventDataStores", |
|
255 | 274 | "cloudwatch:ListMetricStreams", |
256 | 275 | "cloudwatch:ListTagsForResource", |
257 | 276 | "codeartifact:DescribeDomain", |
| 277 | + "codeartifact:DescribePackageGroup", |
258 | 278 | "codeartifact:DescribeRepository", |
259 | 279 | "codeartifact:GetDomainPermissionsPolicy", |
260 | 280 | "codeartifact:GetRepositoryPermissionsPolicy", |
| 281 | + "codeartifact:ListAllowedRepositoriesForGroup", |
261 | 282 | "codeartifact:ListDomains", |
| 283 | + "codeartifact:ListPackageGroups", |
262 | 284 | "codeartifact:ListPackages", |
263 | 285 | "codeartifact:ListPackageVersions", |
264 | 286 | "codeartifact:ListRepositories", |
|
281 | 303 | "codeguru-reviewer:ListRepositoryAssociations", |
282 | 304 | "codepipeline:GetPipeline", |
283 | 305 | "codepipeline:GetPipelineState", |
| 306 | + "codepipeline:ListActionTypes", |
284 | 307 | "codepipeline:ListPipelines", |
| 308 | + "codepipeline:ListTagsForResource", |
| 309 | + "codepipeline:ListWebhooks", |
285 | 310 | "cognito-identity:DescribeIdentityPool", |
286 | 311 | "cognito-identity:GetIdentityPoolRoles", |
287 | 312 | "cognito-identity:GetPrincipalTagAttributeMap", |
|
319 | 344 | "connect:DescribeRoutingProfile", |
320 | 345 | "connect:DescribeRule", |
321 | 346 | "connect:DescribeSecurityProfile", |
| 347 | + "connect:DescribeTrafficDistributionGroup", |
322 | 348 | "connect:DescribeUser", |
323 | 349 | "connect:GetTaskTemplate", |
324 | 350 | "connect:ListApprovedOrigins", |
|
342 | 368 | "connect:ListSecurityProfiles", |
343 | 369 | "connect:ListTagsForResource", |
344 | 370 | "connect:ListTaskTemplates", |
| 371 | + "connect:ListTrafficDistributionGroups", |
345 | 372 | "connect:ListUsers", |
346 | 373 | "connect:SearchAvailablePhoneNumbers", |
347 | 374 | "databrew:DescribeDataset", |
|
380 | 407 | "dax:ListTags", |
381 | 408 | "deadline:GetFleet", |
382 | 409 | "deadline:GetQueueFleetAssociation", |
| 410 | + "deadline:ListFarms", |
383 | 411 | "deadline:ListFleets", |
384 | 412 | "deadline:ListQueueFleetAssociations", |
385 | 413 | "deadline:ListTagsForResource", |
|
446 | 474 | "ec2:GetNetworkInsightsAccessScopeAnalysisFindings", |
447 | 475 | "ec2:GetNetworkInsightsAccessScopeContent", |
448 | 476 | "ec2:GetSnapshotBlockPublicAccessState", |
| 477 | + "ec2:GetTransitGatewayRouteTablePropagations", |
| 478 | + "ec2:SearchLocalGatewayRoutes", |
| 479 | + "ec2:SearchTransitGatewayMulticastGroups", |
449 | 480 | "ecr-public:DescribeRepositories", |
450 | 481 | "ecr-public:GetRepositoryCatalogData", |
451 | 482 | "ecr-public:GetRepositoryPolicy", |
|
536 | 567 | "emr-serverless:ListApplications", |
537 | 568 | "emr-serverless:ListJobRuns", |
538 | 569 | "entityresolution:GetIdMappingWorkflow", |
| 570 | + "entityresolution:GetMatchingWorkflow", |
539 | 571 | "entityresolution:GetSchemaMapping", |
540 | 572 | "entityresolution:ListIdMappingWorkflows", |
| 573 | + "entityresolution:ListMatchingWorkflows", |
541 | 574 | "entityresolution:ListSchemaMappings", |
542 | 575 | "entityresolution:ListTagsForResource", |
543 | 576 | "es:DescribeDomain", |
|
862 | 895 | "iotsitewise:DescribePortal", |
863 | 896 | "iotsitewise:DescribeProject", |
864 | 897 | "iotsitewise:ListAccessPolicies", |
| 898 | + "iotsitewise:ListAssetModelCompositeModels", |
| 899 | + "iotsitewise:ListAssetModelProperties", |
865 | 900 | "iotsitewise:ListAssetModels", |
| 901 | + "iotsitewise:ListAssetProperties", |
866 | 902 | "iotsitewise:ListAssets", |
| 903 | + "iotsitewise:ListAssociatedAssets", |
867 | 904 | "iotsitewise:ListDashboards", |
868 | 905 | "iotsitewise:ListGateways", |
869 | 906 | "iotsitewise:ListPortals", |
|
910 | 947 | "ivs:ListEncoderConfigurations", |
911 | 948 | "ivs:ListPlaybackKeyPairs", |
912 | 949 | "ivs:ListPlaybackRestrictionPolicies", |
| 950 | + "ivs:ListPublicKeys", |
913 | 951 | "ivs:ListRecordingConfigurations", |
914 | 952 | "ivs:ListStages", |
915 | 953 | "ivs:ListStorageConfigurations", |
|
974 | 1012 | "lambda:GetFunctionCodeSigningConfig", |
975 | 1013 | "lambda:GetLayerVersion", |
976 | 1014 | "lambda:GetPolicy", |
| 1015 | + "lambda:GetProvisionedConcurrencyConfig", |
| 1016 | + "lambda:GetRuntimeManagementConfig", |
977 | 1017 | "lambda:ListAliases", |
978 | 1018 | "lambda:ListCodeSigningConfigs", |
979 | 1019 | "lambda:ListEventSourceMappings", |
| 1020 | + "lambda:ListFunctionEventInvokeConfigs", |
| 1021 | + "lambda:ListFunctionUrlConfigs", |
980 | 1022 | "lambda:ListFunctions", |
981 | 1023 | "lambda:ListLayers", |
982 | 1024 | "lambda:ListLayerVersions", |
|
1191 | 1233 | "personalize:ListSchemas", |
1192 | 1234 | "personalize:ListSolutions", |
1193 | 1235 | "personalize:ListTagsForResource", |
| 1236 | + "pipes:DescribePipe", |
| 1237 | + "pipes:ListPipes", |
1194 | 1238 | "profile:GetDomain", |
1195 | 1239 | "profile:GetIntegration", |
1196 | 1240 | "profile:GetProfileObjectType", |
|
1211 | 1255 | "quicksight:DescribeDataSetRefreshProperties", |
1212 | 1256 | "quicksight:DescribeDataSource", |
1213 | 1257 | "quicksight:DescribeDataSourcePermissions", |
| 1258 | + "quicksight:DescribeRefreshSchedule", |
1214 | 1259 | "quicksight:DescribeTemplate", |
1215 | 1260 | "quicksight:DescribeTemplatePermissions", |
1216 | 1261 | "quicksight:DescribeTheme", |
|
1219 | 1264 | "quicksight:ListDashboards", |
1220 | 1265 | "quicksight:ListDataSets", |
1221 | 1266 | "quicksight:ListDataSources", |
| 1267 | + "quicksight:ListRefreshSchedules", |
1222 | 1268 | "quicksight:ListTagsForResource", |
1223 | 1269 | "quicksight:ListTemplates", |
1224 | 1270 | "quicksight:ListThemes", |
|
1258 | 1304 | "redshift-serverless:GetNamespace", |
1259 | 1305 | "redshift-serverless:GetWorkgroup", |
1260 | 1306 | "redshift-serverless:ListNamespaces", |
| 1307 | + "redshift-serverless:ListSnapshotCopyConfigurations", |
1261 | 1308 | "redshift-serverless:ListTagsForResource", |
1262 | 1309 | "redshift-serverless:ListWorkgroups", |
1263 | 1310 | "redshift:DescribeClusterParameterGroups", |
|
1273 | 1320 | "redshift:DescribeLoggingStatus", |
1274 | 1321 | "redshift:DescribeScheduledActions", |
1275 | 1322 | "redshift:DescribeTags", |
| 1323 | + "redshift:GetResourcePolicy", |
1276 | 1324 | "refactor-spaces:GetEnvironment", |
1277 | 1325 | "refactor-spaces:GetService", |
1278 | 1326 | "refactor-spaces:ListApplications", |
|
1302 | 1350 | "robomaker:DescribeSimulationApplication", |
1303 | 1351 | "robomaker:ListRobotApplications", |
1304 | 1352 | "robomaker:ListSimulationApplications", |
| 1353 | + "rolesanywhere:GetCrl", |
1305 | 1354 | "rolesanywhere:GetProfile", |
1306 | 1355 | "rolesanywhere:GetTrustAnchor", |
| 1356 | + "rolesanywhere:ListCrls", |
1307 | 1357 | "rolesanywhere:ListProfiles", |
1308 | 1358 | "rolesanywhere:ListTagsForResource", |
1309 | 1359 | "rolesanywhere:ListTrustAnchors", |
|
1429 | 1479 | "s3tables:GetTableBucketEncryption", |
1430 | 1480 | "s3tables:GetTableBucketMaintenanceConfiguration", |
1431 | 1481 | "s3tables:ListTableBuckets", |
| 1482 | + "sagemaker:DescribeApp", |
1432 | 1483 | "sagemaker:DescribeAppImageConfig", |
1433 | 1484 | "sagemaker:DescribeCluster", |
1434 | 1485 | "sagemaker:DescribeCodeRepository", |
|
1452 | 1503 | "sagemaker:DescribePipeline", |
1453 | 1504 | "sagemaker:DescribeProject", |
1454 | 1505 | "sagemaker:DescribeStudioLifecycleConfig", |
| 1506 | + "sagemaker:DescribeUserProfile", |
1455 | 1507 | "sagemaker:DescribeWorkteam", |
1456 | 1508 | "sagemaker:ListAppImageConfigs", |
| 1509 | + "sagemaker:ListApps", |
1457 | 1510 | "sagemaker:ListClusters", |
1458 | 1511 | "sagemaker:ListCodeRepositories", |
1459 | 1512 | "sagemaker:ListDataQualityJobDefinitions", |
|
1468 | 1521 | "sagemaker:ListMlflowTrackingServers", |
1469 | 1522 | "sagemaker:ListModelBiasJobDefinitions", |
1470 | 1523 | "sagemaker:ListModelExplainabilityJobDefinitions", |
| 1524 | + "sagemaker:ListModelPackages", |
1471 | 1525 | "sagemaker:ListModelQualityJobDefinitions", |
1472 | 1526 | "sagemaker:ListModels", |
1473 | 1527 | "sagemaker:ListMonitoringSchedules", |
|
1477 | 1531 | "sagemaker:ListProjects", |
1478 | 1532 | "sagemaker:ListStudioLifecycleConfigs", |
1479 | 1533 | "sagemaker:ListTags", |
| 1534 | + "sagemaker:ListUserProfiles", |
1480 | 1535 | "sagemaker:ListWorkteams", |
1481 | 1536 | "scheduler:GetSchedule", |
1482 | 1537 | "scheduler:GetScheduleGroup", |
|
1493 | 1548 | "sdb:GetAttributes", |
1494 | 1549 | "sdb:ListDomains", |
1495 | 1550 | "secretsmanager:DescribeSecret", |
| 1551 | + "secretsmanager:GetResourcePolicy", |
1496 | 1552 | "secretsmanager:ListSecrets", |
1497 | 1553 | "secretsmanager:ListSecretVersionIds", |
1498 | 1554 | "securityhub:DescribeHub", |
|
1501 | 1557 | "securitylake:ListDataLakeExceptions", |
1502 | 1558 | "securitylake:ListDataLakes", |
1503 | 1559 | "securitylake:ListLogSources", |
| 1560 | + "securitylake:ListSubscribers", |
| 1561 | + "securitylake:ListTagsForResource", |
1504 | 1562 | "serviceCatalog:DescribePortfolioShares", |
| 1563 | + "servicecatalog:DescribeServiceAction", |
1505 | 1564 | "servicecatalog:GetAttributeGroup", |
| 1565 | + "servicecatalog:ListApplications", |
| 1566 | + "servicecatalog:ListAssociatedResources", |
1506 | 1567 | "servicecatalog:ListAttributeGroups", |
1507 | 1568 | "servicecatalog:ListServiceActions", |
1508 | 1569 | "servicecatalog:ListServiceActionsForProvisioningArtifact", |
|
1535 | 1596 | "shield:DescribeDRTAccess", |
1536 | 1597 | "shield:DescribeProtection", |
1537 | 1598 | "shield:DescribeSubscription", |
| 1599 | + "shield:ListProtectionGroups", |
| 1600 | + "shield:ListTagsForResource", |
1538 | 1601 | "signer:GetSigningProfile", |
1539 | 1602 | "signer:ListProfilePermissions", |
1540 | 1603 | "signer:ListSigningProfiles", |
|
1553 | 1616 | "ssm-contacts:GetContactChannel", |
1554 | 1617 | "ssm-contacts:ListContactChannels", |
1555 | 1618 | "ssm-contacts:ListContacts", |
| 1619 | + "ssm-incidents:GetReplicationSet", |
1556 | 1620 | "ssm-incidents:GetResponsePlan", |
| 1621 | + "ssm-incidents:ListReplicationSets", |
1557 | 1622 | "ssm-incidents:ListResponsePlans", |
1558 | 1623 | "ssm-incidents:ListTagsForResource", |
1559 | 1624 | "ssm-quicksetup:GetConfigurationManager", |
1560 | 1625 | "ssm-quicksetup:ListConfigurationManagers", |
1561 | 1626 | "ssm-sap:ListTagsForResource", |
| 1627 | + "ssm:DescribeAssociation", |
1562 | 1628 | "ssm:DescribeAutomationExecutions", |
1563 | 1629 | "ssm:DescribeDocument", |
1564 | 1630 | "ssm:DescribeDocumentPermission", |
1565 | 1631 | "ssm:DescribeInstanceInformation", |
1566 | 1632 | "ssm:DescribeParameters", |
| 1633 | + "ssm:DescribePatchBaselines", |
1567 | 1634 | "ssm:GetAutomationExecution", |
| 1635 | + "ssm:GetDefaultPatchBaseline", |
1568 | 1636 | "ssm:GetDocument", |
| 1637 | + "ssm:GetPatchBaseline", |
| 1638 | + "ssm:GetResourcePolicies", |
1569 | 1639 | "ssm:GetServiceSetting", |
| 1640 | + "ssm:ListAssociations", |
1570 | 1641 | "ssm:ListDocuments", |
| 1642 | + "ssm:ListResourceDataSync", |
1571 | 1643 | "ssm:ListTagsForResource", |
1572 | 1644 | "sso:DescribeInstanceAccessControlAttributeConfiguration", |
1573 | 1645 | "sso:DescribePermissionSet", |
|
1637 | 1709 | "waf:GetWebACL", |
1638 | 1710 | "wafv2:GetLoggingConfiguration", |
1639 | 1711 | "wafv2:GetRuleGroup", |
| 1712 | + "wafv2:ListLoggingConfigurations", |
1640 | 1713 | "wafv2:ListRuleGroups", |
1641 | 1714 | "wafv2:ListTagsForResource", |
1642 | 1715 | "workspaces:DescribeConnectionAliases", |
|
1705 | 1778 | } |
1706 | 1779 | ] |
1707 | 1780 | }, |
1708 | | - "IsDefaultVersion": false |
| 1781 | + "IsDefaultVersion": true |
1709 | 1782 | } |
1710 | 1783 | } |
0 commit comments