View a markdown version of this page

Actions, resources, and condition keys for AWS App Runner - Service Authorization Reference

Actions, resources, and condition keys for AWS App Runner

AWS App Runner (service prefix: apprunner) provides the following service-specific operations, resources, actions, and condition keys for use in IAM permission policies.

References:

API operations defined by AWS App Runner

The following table maps API operations to the IAM actions they authorize. Only condition keys that have static values for the given API and action are listed; for the full set of condition keys supported by each action, see the Actions table.

Operation IAM action Condition key Possible value(s) Access level

AssociateCustomDomain

apprunner:AssociateCustomDomain

Write

CreateAutoScalingConfiguration

apprunner:CreateAutoScalingConfiguration

Write

apprunner:TagResource

Tagging, Write

CreateConnection

apprunner:CreateConnection

Write

apprunner:TagResource

Tagging, Write

CreateObservabilityConfiguration

apprunner:CreateObservabilityConfiguration

Write

apprunner:TagResource

Tagging, Write

CreateService

apprunner:CreateService

Write

apprunner:TagResource

Tagging, Write

iam:PassRole

iam:PassedToService

bullet.amazonaws.com

Write

CreateVpcConnector

apprunner:CreateVpcConnector

Write

apprunner:TagResource

Tagging, Write

CreateVpcIngressConnection

apprunner:CreateVpcIngressConnection

Write

apprunner:TagResource

Tagging, Write

DeleteAutoScalingConfiguration

apprunner:DeleteAutoScalingConfiguration

Write

DeleteConnection

apprunner:DeleteConnection

Write

DeleteObservabilityConfiguration

apprunner:DeleteObservabilityConfiguration

Write

DeleteService

apprunner:DeleteService

Write

apprunner:DisassociateCustomDomain

Write

DeleteVpcConnector

apprunner:DeleteVpcConnector

Write

DeleteVpcIngressConnection

apprunner:DeleteVpcIngressConnection

Write

DescribeAutoScalingConfiguration

apprunner:DescribeAutoScalingConfiguration

Read

DescribeCustomDomains

apprunner:DescribeCustomDomains

Read

DescribeObservabilityConfiguration

apprunner:DescribeObservabilityConfiguration

Read

DescribeService

apprunner:DescribeService

Read

DescribeVpcConnector

apprunner:DescribeVpcConnector

Read

DescribeVpcIngressConnection

apprunner:DescribeVpcIngressConnection

Read

DisassociateCustomDomain

apprunner:DisassociateCustomDomain

Write

ListAutoScalingConfigurations

apprunner:ListAutoScalingConfigurations

List

ListConnections

apprunner:ListConnections

List

ListObservabilityConfigurations

apprunner:ListObservabilityConfigurations

List

ListOperations

apprunner:ListOperations

List

ListServices

apprunner:ListServices

List

ListServicesForAutoScalingConfiguration

apprunner:ListServicesForAutoScalingConfiguration

List

ListTagsForResource

apprunner:ListTagsForResource

Read

ListVpcConnectors

apprunner:ListVpcConnectors

List

ListVpcIngressConnections

apprunner:ListVpcIngressConnections

List

PauseService

apprunner:PauseService

Write

ResumeService

apprunner:ResumeService

Write

StartDeployment

apprunner:StartDeployment

Write

TagResource

apprunner:TagResource

Tagging, Write

UntagResource

apprunner:UntagResource

Tagging, Write

UpdateDefaultAutoScalingConfiguration

apprunner:UpdateDefaultAutoScalingConfiguration

Write

UpdateService

apprunner:UpdateService

Write

iam:PassRole

iam:PassedToService

bullet.amazonaws.com

Write

UpdateVpcIngressConnection

apprunner:UpdateVpcIngressConnection

Write

Actions defined by AWS App Runner

You can specify the following actions in the Action element of an IAM policy statement. Use policies to grant permissions to perform an operation in AWS. When you use an action in a policy, you usually allow or deny access to the API operation or CLI command with the same name. However, in some cases, a single action controls access to more than one operation. Alternatively, some operations require several different actions.

Actions Description Resource types (*required) Condition keys Access level

AssociateCustomDomain

Grants permission to associate your own domain name with the AWS App Runner subdomain URL of your App Runner service

service*

aws:ResourceTag/${TagKey}

Write

CreateAutoScalingConfiguration

Grants permission to create an AWS App Runner automatic scaling configuration resource