Actions, resources, and condition keys for AWS CodeDeploy
AWS CodeDeploy (service prefix: codedeploy) provides the following
service-specific operations, resources, actions, and condition keys for use in IAM permission
policies.
References:
-
Learn how to configure this service.
-
View a list of the API operations available for this service.
-
Learn how to secure this service and its resources by using IAM permission policies.
-
View the programmatic service authorization reference
for this service.
Topics
API operations defined by AWS CodeDeploy
The following table maps API operations to the IAM actions they authorize. Only condition keys that have static values for the given API and action are listed; for the full set of condition keys supported by each action, see the Actions table.
| Operation | IAM action | Condition key | Possible value(s) | Access level |
|---|---|---|---|---|
|
AddTagsToOnPremisesInstances |
Tagging, Write |
|||
|
BatchGetApplicationRevisions |
Read |
|||
|
BatchGetApplications |
Read |
|||
|
BatchGetDeploymentGroups |
Read |
|||
|
BatchGetDeploymentInstances |
Read |
|||
|
BatchGetDeploymentTargets |
Read |
|||
|
BatchGetDeployments |
Read |
|||
|
BatchGetOnPremisesInstances |
Read |
|||
|
ContinueDeployment |
Write |
|||
Write |
||||
|
CreateApplication |
Write |
|||
Tagging, Write |
||||
|
CreateDeployment |
Write |
|||
List |
||||
List |
||||
Write |
||||
Write |
||||
|
CreateDeploymentConfig |
Write |
|||
|
CreateDeploymentGroup |
Write |
|||
Tagging, Write |
||||
iam:PassedToService |
codedeploy.amazonaws.com |
Write |
||
|
DeleteApplication |
Write |
|||
|
DeleteDeploymentConfig |
Write |
|||
|
DeleteDeploymentGroup |
Write |
|||
|
DeleteGitHubAccountToken |
Write |
|||
|
DeleteResourcesByExternalId |
Write |
|||
|
DeregisterOnPremisesInstance |
Write |
|||
|
GetApplication |
List |
|||
|
GetApplicationRevision |
List |
|||
|
GetDeployment |
List |
|||
|
GetDeploymentConfig |
List |
|||
|
GetDeploymentGroup |
List |
|||
|
GetDeploymentInstance |
List |
|||
|
GetDeploymentTarget |
Read |
|||
|
GetOnPremisesInstance |
List |
|||
|
ListApplicationRevisions |
List |
|||
|
ListApplications |
List |
|||
|
ListDeploymentConfigs |
List |
|||
|
ListDeploymentGroups |
List |
|||
|
ListDeploymentInstances |
List |
|||
|
ListDeploymentTargets |
List |
|||
|
ListDeployments |
List |
|||
|
ListGitHubAccountTokenNames |
List |
|||
|
ListOnPremisesInstances |
List |
|||
|
ListTagsForResource |
List |
|||
|
PutLifecycleEventHookExecutionStatus |
Write |
|||
Write |
||||
|
RegisterApplicationRevision |
Write |
|||
|
RegisterOnPremisesInstance |
Write |
|||
|
RemoveTagsFromOnPremisesInstances |
Tagging, Write |
|||
|
SkipWaitTimeForInstanceTermination |
Write |
|||
Write |
||||
|
StopDeployment |
Write |
|||
Write |
||||
|
TagResource |
Tagging, Write |
|||
|
UntagResource |
Tagging, Write |
|||
|
UpdateApplication |
Write |
|||
|
UpdateDeploymentGroup |
Write |
|||
iam:PassedToService |
codedeploy.amazonaws.com |
Write |
Actions defined by AWS CodeDeploy
You can specify the following actions in the Action element of an IAM
policy statement. Use policies to grant permissions to perform an operation in AWS. When
you use an action in a policy, you usually allow or deny access to the API operation or CLI
command with the same name. However, in some cases, a single action controls access to more
than one operation. Alternatively, some operations require several different actions.
| Actions | Description | Resource types (*required) | Condition keys | Access level |
|---|---|---|---|---|
Grants permission to add tags to one or more on-premises instances |
Tagging, Write |
|||
Grants permission to get information about one or more application revisions |
Read |
|||
Grants permission to get information about multiple applications associated with the IAM user |
Read |
|||
Grants permission to get information about one or more deployment groups |
Read |
|||
Grants permission to get information about one or more instance that are part of a deployment group |
Read |
|||
Grants permission to return an array of one or more targets associated with a deployment. This method works with all compute types and should be used instead of the deprecated BatchGetDeploymentInstances. The maximum number of targets that can be returned is 25 |
Read |
|||
Grants permission to get information about multiple deployments associated with the IAM user |
Read |
|||
Grants permission to get information about one or more on-premises instances |
Read |
|||
Grants permission to start the process of rerouting traffic from instances in the original environment to instances in thereplacement environment without waiting for a specified wait time to elapse |
Write |
|||
Grants permission to create an application associated with the IAM user |
Write |
|||
Grants permission to create a deployment for an application associated with the IAM user |
Write |
|||
Grants permission to create a custom deployment configuration associated with the IAM user |
Write |
|||
Grants permission to create a deployment group for an application associated with the IAM user |
Write |
|||
Grants permission to delete an application associated with the IAM user |
Write |
|||
Grants permission to delete a custom deployment configuration associated with the IAM user |
Write |
|||
Grants permission to delete a deployment group for an application associated with the IAM user |
Write |
|||
Grants permission to delete a GitHub account connection |
Write |
|||
Grants permission to delete resources associated with the given external Id |
Write |
|||
Grants permission to deregister an on-premises instance |
Write |
|||
Grants permission to get information about a single application associated with the IAM user |
List |
|||
Grants permission to get information about a single application revision for an application associated with the IAM user |
List |
|||
Grants permission to get information about a single deployment to a deployment group for an application associated with the IAM user |
List |
|||
Grants permission to get information about a single deployment configuration associated with the IAM user |
List |
|||
Grants permission to get information about a single deployment group for an application associated with the IAM user |
List |
|||
Grants permission to get information about a single instance in a deployment associated with the IAM user |
List |
|||
Grants permission to return information about a deployment target |
Read |
|||
Grants permission to get information about a single on-premises instance |
List |
|||
Grants permission to get information about all application revisions for an application associated with the IAM user |
List |
|||
Grants permission to get information about all applications associated with the IAM user |
List |
|||
Grants permission to get information about all deployment configurations associated with the IAM user |
List |
|||
|
|