View a markdown version of this page

Actions, resources, and condition keys for AWS Device Farm - Service Authorization Reference

Actions, resources, and condition keys for AWS Device Farm

AWS Device Farm (service prefix: devicefarm) provides the following service-specific operations, resources, actions, and condition keys for use in IAM permission policies.

References:

API operations defined by AWS Device Farm

The following table maps API operations to the IAM actions they authorize. Only condition keys that have static values for the given API and action are listed; for the full set of condition keys supported by each action, see the Actions table.

Operation IAM action Condition key Possible value(s) Access level

CreateDevicePool

devicefarm:CreateDevicePool

Write

CreateInstanceProfile

devicefarm:CreateInstanceProfile

Write

CreateNetworkProfile

devicefarm:CreateNetworkProfile

Write

CreateProject

devicefarm:CreateProject

Write

iam:PassRole

iam:PassedToService

devicefarm.amazonaws.com

Write

CreateRemoteAccessSession

devicefarm:CreateRemoteAccessSession

Write

CreateTestGridProject

devicefarm:CreateTestGridProject

Write

CreateTestGridUrl

devicefarm:CreateTestGridUrl

Write

CreateUpload

devicefarm:CreateUpload

Write

CreateVPCEConfiguration

devicefarm:CreateVPCEConfiguration

Write

DeleteDevicePool

devicefarm:DeleteDevicePool

Write

DeleteInstanceProfile

devicefarm:DeleteInstanceProfile

Write

DeleteNetworkProfile

devicefarm:DeleteNetworkProfile

Write

DeleteProject

devicefarm:DeleteProject

Write

DeleteRemoteAccessSession

devicefarm:DeleteRemoteAccessSession

Write

DeleteRun

devicefarm:DeleteRun

Write

DeleteTestGridProject

devicefarm:DeleteTestGridProject

Write

DeleteUpload

devicefarm:DeleteUpload

Write

DeleteVPCEConfiguration

devicefarm:DeleteVPCEConfiguration

Write

GetAccountSettings

devicefarm:GetAccountSettings

Read

GetDevice

devicefarm:GetDevice

Read

GetDeviceInstance

devicefarm:GetDeviceInstance

Read

GetDevicePool

devicefarm:GetDevicePool

Read

GetDevicePoolCompatibility

devicefarm:GetDevicePoolCompatibility

Read

GetInstanceProfile

devicefarm:GetInstanceProfile

Read

GetJob

devicefarm:GetJob

Read

GetNetworkProfile

devicefarm:GetNetworkProfile

Read

GetOfferingStatus

devicefarm:GetOfferingStatus

Read

GetProject

devicefarm:GetProject

Read

GetRemoteAccessSession

devicefarm:GetRemoteAccessSession

Read

GetRun

devicefarm:GetRun

Read

GetSuite

devicefarm:GetSuite

Read

GetTest

devicefarm:GetTest

Read

GetTestGridProject

devicefarm:GetTestGridProject

Read

GetTestGridSession

devicefarm:GetTestGridSession

Read

GetUpload

devicefarm:GetUpload

Read

GetVPCEConfiguration

devicefarm:GetVPCEConfiguration

Read

InstallToRemoteAccessSession

devicefarm:InstallToRemoteAccessSession

Write

ListArtifacts

devicefarm:ListArtifacts

List

ListDeviceInstances

devicefarm:ListDeviceInstances

List

ListDevicePools

devicefarm:ListDevicePools

List

ListDevices

devicefarm:ListDevices

List

ListInstanceProfiles

devicefarm:ListInstanceProfiles

List

ListJobs

devicefarm:ListJobs

List

ListNetworkProfiles

devicefarm:ListNetworkProfiles

List

ListOfferingPromotions

devicefarm:ListOfferingPromotions

List

ListOfferingTransactions

devicefarm:ListOfferingTransactions

List

ListOfferings

devicefarm:ListOfferings

List

ListProjects

devicefarm:ListProjects

List

ListRemoteAccessSessions

devicefarm:ListRemoteAccessSessions

List

ListRuns

devicefarm:ListRuns

List

ListSamples

devicefarm:ListSamples

List

ListSuites

devicefarm:ListSuites

List

ListTagsForResource

devicefarm:ListTagsForResource

List

ListTestGridProjects

devicefarm:ListTestGridProjects

List

ListTestGridSessionActions

devicefarm:ListTestGridSessionActions

List

ListTestGridSessionArtifacts

devicefarm:ListTestGridSessionArtifacts

List

ListTestGridSessions

devicefarm:ListTestGridSessions

List

ListTests

devicefarm:ListTests

List

ListUniqueProblems

devicefarm:ListUniqueProblems

List

ListUploads

devicefarm:ListUploads

List

ListVPCEConfigurations

devicefarm:ListVPCEConfigurations

List

PurchaseOffering

devicefarm:PurchaseOffering

Write

RenewOffering

devicefarm:RenewOffering

Write

ScheduleRun

devicefarm:ScheduleRun

Write

iam:PassRole

iam:PassedToService

devicefarm.amazonaws.com

Write

StopJob

devicefarm:StopJob

Write

StopRemoteAccessSession

devicefarm:StopRemoteAccessSession

Write

StopRun

devicefarm:StopRun

Write

TagResource

devicefarm:TagResource

Tagging, Write

UntagResource

devicefarm:UntagResource

Tagging, Write

UpdateDeviceInstance

devicefarm:UpdateDeviceInstance

Write

UpdateDevicePool

devicefarm:UpdateDevicePool

Write

UpdateInstanceProfile

devicefarm:UpdateInstanceProfile

Write

UpdateNetworkProfile

devicefarm:UpdateNetworkProfile

Write

UpdateProject

devicefarm:UpdateProject

Write

iam:PassRole

iam:PassedToService

devicefarm.amazonaws.com

Write

UpdateTestGridProject

devicefarm:UpdateTestGridProject

Write

UpdateUpload

devicefarm:UpdateUpload

Write

UpdateVPCEConfiguration

devicefarm:UpdateVPCEConfiguration

Write

Actions defined by AWS Device Farm

You can specify the following actions in the Action element of an IAM policy statement. Use policies to grant permissions to perform an operation in AWS. When you use an action in a policy, you usually allow or deny access to the API operation or CLI command with the same name. However, in some cases, a single action controls access to more than one operation. Alternatively, some operations require several different actions.

Actions Description Resource types (*required) Condition keys Access level

CreateDevicePool

Grants permission to create a device pool within a project

project*

aws:ResourceTag/${TagKey}

Write

CreateInstanceProfile

Grants permission to create a device instance profile

Write

CreateNetworkProfile

Grants permission to create a network profile within a project

project*

aws:ResourceTag/${TagKey}

Write

CreateProject

Grants permission to create a project for mobile testing

Write

CreateRemoteAccessSession

Grants permission to start a remote access session to a device instance

device*

aws:ResourceTag/${TagKey}

Write

deviceinstance

aws:ResourceTag/${TagKey}

project*

aws:ResourceTag/${TagKey}

upload

CreateTestGridProject

Grants permission to create a project for desktop testing

Write

CreateTestGridUrl

Grants permission to generate a new pre-signed url used to access our test grid service

testgrid-project*

aws:ResourceTag/${TagKey}

Write

CreateUpload

Grants permission to upload a new file or app within a project

project*

aws:ResourceTag/${TagKey}

Write

CreateVPCEConfiguration

Grants permission to create an Amazon Virtual Private Cloud (VPC) endpoint configuration

Write

DeleteDevicePool

Grants permission to delete a user-generated device pool

devicepool*

aws:ResourceTag/${TagKey}

Write

DeleteInstanceProfile

Grants permission to delete a user-generated instance profile

instanceprofile*

aws:ResourceTag/${TagKey}

Write

DeleteNetworkProfile

Grants permission to delete a user-generated network profile

networkprofile*

aws:ResourceTag/${TagKey}

Write

DeleteProject

Grants permission to delete a mobile testing project

project*

aws:ResourceTag/${TagKey}

Write

DeleteRemoteAccessSession

Grants permission to delete a completed remote access session and its results

session*

aws:ResourceTag/${TagKey}

Write

DeleteRun

Grants permission to delete a run

run*

aws:ResourceTag/${TagKey}

Write

DeleteTestGridProject

Grants permission to delete a desktop testing project

testgrid-project*

aws:ResourceTag/${TagKey}

Write

DeleteUpload

Grants permission to delete a user-uploaded file

upload*

Write

DeleteVPCEConfiguration

Grants permission to delete an Amazon Virtual Private Cloud (VPC) endpoint configuration

vpceconfiguration*

aws:ResourceTag/${TagKey}

Write