View a markdown version of this page

Actions, resources, and condition keys for AWS Fault Injection Service - Service Authorization Reference

Actions, resources, and condition keys for AWS Fault Injection Service

AWS Fault Injection Service (service prefix: fis) provides the following service-specific operations, resources, actions, and condition keys for use in IAM permission policies.

References:

API operations defined by AWS Fault Injection Service

The following table maps API operations to the IAM actions they authorize. Only condition keys that have static values for the given API and action are listed; for the full set of condition keys supported by each action, see the Actions table.

Operation IAM action Condition key Possible value(s) Access level

CreateExperimentTemplate

fis:CreateExperimentTemplate

Write

fis:TagResource

Tagging, Write

iam:PassRole

iam:PassedToService

fis.amazonaws.com

Write

CreateTargetAccountConfiguration

fis:CreateTargetAccountConfiguration

Write

DeleteExperimentTemplate

fis:DeleteExperimentTemplate

Write

DeleteTargetAccountConfiguration

fis:DeleteTargetAccountConfiguration

Write

GetAction

fis:GetAction

Read

GetExperiment

fis:GetExperiment

Read

GetExperimentTargetAccountConfiguration

fis:GetExperimentTargetAccountConfiguration

Read

GetExperimentTemplate

fis:GetExperimentTemplate

Read

GetSafetyLever

fis:GetSafetyLever

Read

GetTargetAccountConfiguration

fis:GetTargetAccountConfiguration

Read

GetTargetResourceType

fis:GetTargetResourceType

Read

ListActions

fis:ListActions

List

ListExperimentResolvedTargets

fis:ListExperimentResolvedTargets

List

ListExperimentTargetAccountConfigurations

fis:ListExperimentTargetAccountConfigurations

List

ListExperimentTemplates

fis:ListExperimentTemplates

List

ListExperiments

fis:ListExperiments

List

ListTagsForResource

fis:ListTagsForResource

Read

ListTargetAccountConfigurations

fis:ListTargetAccountConfigurations

List

ListTargetResourceTypes

fis:ListTargetResourceTypes

List

StartExperiment

fis:StartExperiment

Write

fis:TagResource

Tagging, Write

StopExperiment

fis:StopExperiment

Write

TagResource

fis:TagResource

Tagging, Write

UntagResource

fis:UntagResource

Tagging, Write

UpdateExperimentTemplate

fis:UpdateExperimentTemplate

Write

iam:PassRole

iam:PassedToService

fis.amazonaws.com

Write

UpdateSafetyLeverState

fis:UpdateSafetyLeverState

Write

UpdateTargetAccountConfiguration

fis:UpdateTargetAccountConfiguration

Write

Actions defined by AWS Fault Injection Service

You can specify the following actions in the Action element of an IAM policy statement. Use policies to grant permissions to perform an operation in AWS. When you use an action in a policy, you usually allow or deny access to the API operation or CLI command with the same name. However, in some cases, a single action controls access to more than one operation. Alternatively, some operations require several different actions.

Actions Description Resource types (*required) Condition keys Access level

CreateExperimentTemplate

Grants permission to create an AWS FIS experiment template

action*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

experiment-template*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

CreateTargetAccountConfiguration

Grants permission to create an AWS FIS target account configuration

experiment-template*

aws:ResourceTag/${TagKey}

Write

DeleteExperimentTemplate

Grants permission to delete the AWS FIS experiment template

experiment-template*

aws:ResourceTag/${TagKey}

Write

DeleteTargetAccountConfiguration

Grants permission to delete an AWS FIS target account configuration

experiment-template*

aws:ResourceTag/${TagKey}

Write