View a markdown version of this page

Actions, resources, and condition keys for AWS DevOps Agent Service - Service Authorization Reference

Actions, resources, and condition keys for AWS DevOps Agent Service

AWS DevOps Agent Service (service prefix: aidevops) provides the following service-specific operations, resources, actions, and condition keys for use in IAM permission policies.

References:

API operations defined by AWS DevOps Agent Service

The following table maps API operations to the IAM actions they authorize. Only condition keys that have static values for the given API and action are listed; for the full set of condition keys supported by each action, see the Actions table.

Operation IAM action Condition key Possible value(s) Access level

AssociateService

aidevops:AssociateService

Write

iam:PassRole

iam:PassedToService

aidevops.amazonaws.com

Write

CreateAgentSpace

aidevops:CreateAgentSpace

Write

aidevops:TagResource

Tagging, Write

CreatePrivateConnection

aidevops:CreatePrivateConnection

Write

aidevops:TagResource

Tagging, Write

DeleteAgentSpace

aidevops:DeleteAgentSpace

Write

DeletePrivateConnection

aidevops:DeletePrivateConnection

Write

DeregisterService

aidevops:DeregisterService

Write

DescribePrivateConnection

aidevops:DescribePrivateConnection

Read

DisableOperatorApp

aidevops:DisableOperatorApp

Write

DisassociateService

aidevops:DisassociateService

Write

EnableOperatorApp

aidevops:EnableOperatorApp

Write

iam:PassRole

iam:PassedToService

aidevops.amazonaws.com

Write

GetAgentSpace

aidevops:GetAgentSpace

Read

GetAssociation

aidevops:GetAssociation

Read

GetOperatorApp

aidevops:GetOperatorApp

Read

GetService

aidevops:GetService

Read

ListAgentSpaces

aidevops:ListAgentSpaces

List

ListAssociations

aidevops:ListAssociations

List

ListPrivateConnections

aidevops:ListPrivateConnections

List

ListServices

aidevops:ListServices

List

ListTagsForResource

aidevops:ListTagsForResource

Read

ListWebhooks

aidevops:ListWebhooks

List

RegisterService

aidevops:RegisterService

Write

aidevops:TagResource

Tagging, Write

iam:PassRole

iam:PassedToService

aidevops.amazonaws.com

Write

TagResource

aidevops:TagResource

Tagging, Write

UntagResource

aidevops:UntagResource

Tagging, Write

UpdateAgentSpace

aidevops:UpdateAgentSpace

Write

UpdateAssociation

aidevops:UpdateAssociation

Write

iam:PassRole

iam:PassedToService

aidevops.amazonaws.com

Write

UpdateOperatorAppIdpConfig

aidevops:UpdateOperatorAppIdpConfig

Write

UpdatePrivateConnectionCertificate

aidevops:UpdatePrivateConnectionCertificate

Write

ValidateAwsAssociations

aidevops:ValidateAwsAssociations

Write

Actions defined by AWS DevOps Agent Service

You can specify the following actions in the Action element of an IAM policy statement. Use policies to grant permissions to perform an operation in AWS. When you use an action in a policy, you usually allow or deny access to the API operation or CLI command with the same name. However, in some cases, a single action controls access to more than one operation. Alternatively, some operations require several different actions.

Actions Description Resource types (*required) Condition keys Access level

AssociateService

Grants permission to associate service

agentspace*

aws:ResourceTag/${TagKey}

Write

CreateAccessToken

Grants permission to create an access token

agentspace*

aws:ResourceTag/${TagKey}

Write

CreateAgentSpace

Grants permission to create agentspace

agentspace*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

CreateAsset

Grants permission to create an asset

agentspace*

aws:ResourceTag/${TagKey}

Write

CreateAssetFile

Grants permission to create an asset file

agentspace*

aws:ResourceTag/${TagKey}

Write

CreateBacklogTask

Grants permission to create a new backlog task

agentspace*

aidevops:SourceAgentSpaceArn

aidevops:TargetAgentSpaceArn