Actions, resources, and condition keys for AWS Elastic Beanstalk
AWS Elastic Beanstalk (service prefix: elasticbeanstalk) provides the following
service-specific operations, resources, actions, and condition keys for use in IAM permission
policies.
References:
-
Learn how to configure this service.
-
View a list of the API operations available for this service.
-
Learn how to secure this service and its resources by using IAM permission policies.
-
View the programmatic service authorization reference
for this service.
Topics
API operations defined by AWS Elastic Beanstalk
The following table maps API operations to the IAM actions they authorize. Only condition keys that have static values for the given API and action are listed; for the full set of condition keys supported by each action, see the Actions table.
| Operation | IAM action | Condition key | Possible value(s) | Access level |
|---|---|---|---|---|
|
DescribeEnvironments |
List |
Actions defined by AWS Elastic Beanstalk
You can specify the following actions in the Action element of an IAM
policy statement. Use policies to grant permissions to perform an operation in AWS. When
you use an action in a policy, you usually allow or deny access to the API operation or CLI
command with the same name. However, in some cases, a single action controls access to more
than one operation. Alternatively, some operations require several different actions.
| Actions | Description | Resource types (*required) | Condition keys | Access level |
|---|---|---|---|---|
Grants permission to cancel in-progress environment configuration update or application version deployment |
Write |
|||
Grants permission to add tags to an Elastic Beanstalk resource and to update tag values |
Tagging, Write |
|||
Grants permission to apply a scheduled managed action immediately |
Write |
|||
Grants permission to associate an operations role with an environment |
Write |
|||
Grants permission to check CNAME availability |
Read |
|||
Grants permission to create or update a group of environments, each running a separate component of a single application |
Write |
|||
Grants permission to create a new application |
Write |
|||
Grants permission to create an application version for an application |
Write |
|||
Grants permission to create a configuration template |
elasticbeanstalk:FromApplication elasticbeanstalk:FromApplicationVersion elasticbeanstalk:FromConfigurationTemplate elasticbeanstalk:FromEnvironment |
Write |
||
Grants permission to launch an environment for an application |
elasticbeanstalk:FromApplicationVersion elasticbeanstalk:FromConfigurationTemplate |
Write |
||
Grants permission to create a new version of a custom platform |
Write |
|||
Grants permission to create the Amazon S3 storage location for the account |
Write |
|||
Grants permission to delete an application along with all associated versions and configurations |
Write |
|||
Grants permission to delete an application version from an application |
Write |
|||
Grants permission to delete a configuration template |
Write |
|||
Grants permission to delete the draft configuration associated with the running environment |
Write |
|||
Grants permission to delete a version of a custom platform |
Write |
|||
Grants permission to retrieve a list of account attributes, including resource quotas |
Read |
|||
Grants permission to retrieve a list of application versions stored in an AWS Elastic Beanstalk storage bucket |
List |
|||
Grants permission to retrieve the descriptions of existing applications |
List |
|||
Grants permission to retrieve descriptions of environment configuration options |
Read |
|||