View a markdown version of this page

Actions, resources, and condition keys for AWS Elastic Disaster Recovery - Service Authorization Reference

Actions, resources, and condition keys for AWS Elastic Disaster Recovery

AWS Elastic Disaster Recovery (service prefix: drs) provides the following service-specific operations, resources, actions, and condition keys for use in IAM permission policies.

References:

API operations defined by AWS Elastic Disaster Recovery

The following table maps API operations to the IAM actions they authorize. Only condition keys that have static values for the given API and action are listed; for the full set of condition keys supported by each action, see the Actions table.

Operation IAM action Condition key Possible value(s) Access level

AssociateSourceNetworkStack

drs:AssociateSourceNetworkStack

Write

CreateExtendedSourceServer

drs:CreateExtendedSourceServer

Write

drs:TagResource

Tagging, Write

CreateLaunchConfigurationTemplate

drs:CreateLaunchConfigurationTemplate

Write

drs:TagResource

Tagging, Write

CreateRecoveryPlan

drs:CreateRecoveryPlan

Write

drs:TagResource

Tagging, Write

CreateRecoveryPlanStep

drs:CreateRecoveryPlanStep

Write

CreateReplicationConfigurationTemplate

drs:CreateReplicationConfigurationTemplate

Write

drs:TagResource

Tagging, Write

CreateSourceNetwork

drs:CreateSourceNetwork

Write

drs:TagResource

Tagging, Write

DeleteJob

drs:DeleteJob

Write

DeleteLaunchAction

drs:DeleteLaunchAction

Write

DeleteLaunchConfigurationTemplate

drs:DeleteLaunchConfigurationTemplate

Write

DeleteRecoveryInstance

drs:DeleteRecoveryInstance

Write

DeleteRecoveryPlan

drs:DeleteRecoveryPlan

Write

DeleteRecoveryPlanStep

drs:DeleteRecoveryPlanStep

Write

DeleteReplicationConfigurationTemplate

drs:DeleteReplicationConfigurationTemplate

Write

DeleteSourceNetwork

drs:DeleteSourceNetwork

Write

DeleteSourceServer

drs:DeleteSourceServer

Write

DescribeJobLogItems

drs:DescribeJobLogItems

Read

DescribeJobs

drs:DescribeJobs

Read

DescribeLaunchConfigurationTemplates

drs:DescribeLaunchConfigurationTemplates

Read

DescribeRecoveryInstances

drs:DescribeRecoveryInstances

Read

DescribeRecoverySnapshots

drs:DescribeRecoverySnapshots

Read

DescribeReplicationConfigurationTemplates

drs:DescribeReplicationConfigurationTemplates

Read

DescribeSourceNetworks

drs:DescribeSourceNetworks

Read

DescribeSourceServers

drs:DescribeSourceServers

Read

DisconnectRecoveryInstance

drs:DisconnectRecoveryInstance

Write

DisconnectSourceServer

drs:DisconnectSourceServer

Write

ExportSourceNetworkCfnTemplate

drs:ExportSourceNetworkCfnTemplate

Write

GetFailbackReplicationConfiguration

drs:GetFailbackReplicationConfiguration

Read

GetLaunchConfiguration

drs:GetLaunchConfiguration

Read

GetRecoveryPlan

drs:GetRecoveryPlan

Read

GetRecoveryPlanExecution

drs:GetRecoveryPlanExecution

Read

GetRecoveryPlanStep

drs:GetRecoveryPlanStep

Read

GetReplicationConfiguration

drs:GetReplicationConfiguration

Read

InitializeService

drs:InitializeService

Write

ListExtensibleSourceServers

drs:ListExtensibleSourceServers

Read

ListLaunchActions

drs:ListLaunchActions

Read

ListRecoveryPlanExecutions

drs:ListRecoveryPlanExecutions

Read

ListRecoveryPlanSteps

drs:ListRecoveryPlanSteps

Read

ListRecoveryPlans

drs:ListRecoveryPlans

Read

ListStagingAccounts

drs:ListStagingAccounts

Read

ListTagsForResource

drs:ListTagsForResource

Read

PutLaunchAction

drs:PutLaunchAction

Write

ReorderRecoveryPlanSteps

drs:ReorderRecoveryPlanSteps

Write

RetryDataReplication

drs:RetryDataReplication

Write

ReverseReplication

drs:ReverseReplication

Write

StartRecovery

drs:StartRecovery

Write

drs:TagResource

Tagging, Write

StartReplication

drs:StartReplication

Write

StartSourceNetworkRecovery

drs:StartSourceNetworkRecovery

Write

drs:TagResource

Tagging, Write

StartSourceNetworkReplication

drs:StartSourceNetworkReplication

Write

StopFailback

drs:StopFailback

Write

StopReplication

drs:StopReplication

Write

StopSourceNetworkReplication

drs:StopSourceNetworkReplication

Write

TagResource

drs:TagResource

Tagging, Write

TerminateRecoveryInstances

drs:TerminateRecoveryInstances

Write

UntagResource

drs:UntagResource

Tagging, Write

UpdateFailbackReplicationConfiguration

drs:UpdateFailbackReplicationConfiguration

Write

UpdateLaunchConfiguration

drs:UpdateLaunchConfiguration

Write

UpdateLaunchConfigurationTemplate

drs:UpdateLaunchConfigurationTemplate

Write

UpdateRecoveryPlan

drs:UpdateRecoveryPlan

Write

UpdateRecoveryPlanStep

drs:UpdateRecoveryPlanStep

Write

UpdateReplicationConfiguration

drs:UpdateReplicationConfiguration

Write

UpdateReplicationConfigurationTemplate

drs:UpdateReplicationConfigurationTemplate

Write

Actions defined by AWS Elastic Disaster Recovery

You can specify the following actions in the Action element of an IAM policy statement. Use policies to grant permissions to perform an operation in AWS. When you use an action in a policy, you usually allow or deny access to the API operation or CLI command with the same name. However, in some cases, a single action controls access to more than one operation. Alternatively, some operations require several different actions.

Actions Description Resource types (*required) Condition keys Access level

AssociateSourceNetworkStack

Grants permission to associate CloudFormation stack with source network

SourceNetworkResource*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

CancelRecoveryPlanExecution

Grants permission to cancel a recovery plan execution

RecoveryPlanExecutionResource*

aws:ResourceTag/${TagKey}

Write

CreateExtendedSourceServer

Grants permission to extend a source server

aws:RequestTag/${TagKey}

aws:TagKeys

Write

CreateLaunchConfigurationTemplate

Grants permission to create launch configuration template

aws:RequestTag/${TagKey}

aws:TagKeys

Write

CreateRecoveryPlan

Grants permission to create a recovery plan

aws:RequestTag/${TagKey}

aws:TagKeys

Write

CreateRecoveryPlanStep

Grants permission to create a step in a recovery plan

RecoveryPlanResource*

aws:ResourceTag/${TagKey}

Write

CreateReplicationConfigurationTemplate

Grants permission to create replication configuration template

aws:RequestTag/${TagKey}

aws:TagKeys

Write

CreateSourceNetwork

Grants permission to create a source network

aws:RequestTag/${TagKey}

aws:TagKeys

Write

DeleteJob

Grants permission to delete a job

JobResource*

aws:ResourceTag/${TagKey}

Write

DeleteLaunchAction

Grants permission to delete a launch action

LaunchConfigurationTemplateResource

aws:ResourceTag/${TagKey}

Write

SourceServerResource

aws:ResourceTag/${TagKey}

DeleteLaunchConfigurationTemplate

Grants permission to delete launch configuration template

LaunchConfigurationTemplateResource*

aws:ResourceTag/${TagKey}

Write

DeleteRecoveryInstance

Grants permission to delete recovery instance

RecoveryInstanceResource*

aws:ResourceTag/${TagKey}

drs:EC2InstanceARN

Write

DeleteRecoveryPlan

Grants permission to delete a recovery plan

RecoveryPlanResource*

aws:ResourceTag/${TagKey}

Write

DeleteRecoveryPlanExecution

Grants permission to delete a recovery plan execution

RecoveryPlanExecutionResource*

aws:ResourceTag/${TagKey}

Write

DeleteRecoveryPlanStep

Grants permission to delete a recovery plan step

RecoveryPlanResource*

aws:ResourceTag/${TagKey}

Write

DeleteReplicationConfigurationTemplate

Grants permission to delete replication configuration template

ReplicationConfigurationTemplateResource*

aws:ResourceTag/${TagKey}

Write

DeleteSourceNetwork

Grants permission to delete source network

SourceNetworkResource*

aws:ResourceTag/${TagKey}

Write

DeleteSourceServer

Grants permission to delete source server

SourceServerResource*

aws:ResourceTag/${TagKey}

Write

DescribeJobLogItems

Grants permission to describe job log items

JobResource*

aws:ResourceTag/${TagKey}

Read

DescribeJobs

Grants permission to describe jobs

Read

DescribeLaunchConfigurationTemplates

Grants permission to describe launch configuration template

Read

DescribeRecoveryInstances