View a markdown version of this page

Actions, resources, and condition keys for AWS Elastic Beanstalk - Service Authorization Reference

Actions, resources, and condition keys for AWS Elastic Beanstalk

AWS Elastic Beanstalk (service prefix: elasticbeanstalk) provides the following service-specific operations, resources, actions, and condition keys for use in IAM permission policies.

References:

API operations defined by AWS Elastic Beanstalk

The following table maps API operations to the IAM actions they authorize. Only condition keys that have static values for the given API and action are listed; for the full set of condition keys supported by each action, see the Actions table.

Operation IAM action Condition key Possible value(s) Access level

DescribeEnvironments

elasticbeanstalk:DescribeEnvironments

List

Actions defined by AWS Elastic Beanstalk

You can specify the following actions in the Action element of an IAM policy statement. Use policies to grant permissions to perform an operation in AWS. When you use an action in a policy, you usually allow or deny access to the API operation or CLI command with the same name. However, in some cases, a single action controls access to more than one operation. Alternatively, some operations require several different actions.

Actions Description Resource types (*required) Condition keys Access level

AbortEnvironmentUpdate

Grants permission to cancel in-progress environment configuration update or application version deployment

environment*

aws:ResourceTag/${TagKey}

elasticbeanstalk:InApplication

Write

AddTags

Grants permission to add tags to an Elastic Beanstalk resource and to update tag values

application

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Tagging, Write

applicationversion

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

elasticbeanstalk:InApplication

configurationtemplate

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

elasticbeanstalk:InApplication

environment

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

elasticbeanstalk:InApplication

platform

aws:RequestTag/${TagKey}

aws:TagKeys

ApplyEnvironmentManagedAction

Grants permission to apply a scheduled managed action immediately

environment*

aws:ResourceTag/${TagKey}

elasticbeanstalk:InApplication

Write

AssociateEnvironmentOperationsRole

Grants permission to associate an operations role with an environment

environment*

aws:ResourceTag/${TagKey}

elasticbeanstalk:InApplication

Write

CheckDNSAvailability

Grants permission to check CNAME availability

Read

ComposeEnvironments

Grants permission to create or update a group of environments, each running a separate component of a single application

application*

aws:ResourceTag/${TagKey}

Write

applicationversion*

aws:ResourceTag/${TagKey}

elasticbeanstalk:InApplication

CreateApplication

Grants permission to create a new application

application*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

CreateApplicationVersion

Grants permission to create an application version for an application

application*

aws:ResourceTag/${TagKey}

Write

applicationversion*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

elasticbeanstalk:InApplication

CreateConfigurationTemplate

Grants permission to create a configuration template

configurationtemplate*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

elasticbeanstalk:FromApplication

elasticbeanstalk:FromApplicationVersion

elasticbeanstalk:FromConfigurationTemplate

elasticbeanstalk:FromEnvironment

elasticbeanstalk:FromPlatform

elasticbeanstalk:FromSolutionStack

elasticbeanstalk:InApplication

Write

CreateEnvironment

Grants permission to launch an environment for an application

environment*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

elasticbeanstalk:FromApplicationVersion

elasticbeanstalk:FromConfigurationTemplate

elasticbeanstalk:FromPlatform

elasticbeanstalk:FromSolutionStack

elasticbeanstalk:InApplication

Write

CreatePlatformVersion

Grants permission to create a new version of a custom platform

platform*

aws:RequestTag/${TagKey}

aws:TagKeys

Write

CreateStorageLocation

Grants permission to create the Amazon S3 storage location for the account

Write

DeleteApplication

Grants permission to delete an application along with all associated versions and configurations

application*

aws:ResourceTag/${TagKey}

Write

DeleteApplicationVersion

Grants permission to delete an application version from an application

applicationversion*

aws:ResourceTag/${TagKey}

elasticbeanstalk:InApplication

Write

DeleteConfigurationTemplate

Grants permission to delete a configuration template

configurationtemplate*

aws:ResourceTag/${TagKey}

elasticbeanstalk:InApplication

Write

DeleteEnvironmentConfiguration

Grants permission to delete the draft configuration associated with the running environment

environment*

aws:ResourceTag/${TagKey}

elasticbeanstalk:InApplication

Write

DeletePlatformVersion

Grants permission to delete a version of a custom platform

platform*

Write

DescribeAccountAttributes

Grants permission to retrieve a list of account attributes, including resource quotas

Read

DescribeApplicationVersions

Grants permission to retrieve a list of application versions stored in an AWS Elastic Beanstalk storage bucket

applicationversion

aws:ResourceTag/${TagKey}

elasticbeanstalk:InApplication

List

DescribeApplications

Grants permission to retrieve the descriptions of existing applications

application

aws:ResourceTag/${TagKey}

List

DescribeConfigurationOptions

Grants permission to retrieve descriptions of environment configuration options

configurationtemplate

aws:ResourceTag/${TagKey}

elasticbeanstalk:InApplication

Read