Actions, resources, and condition keys for AWS IoT Managed Integrations
AWS IoT Managed Integrations (service prefix: iotmanagedintegrations) provides the following
service-specific operations, resources, actions, and condition keys for use in IAM permission
policies.
References:
-
Learn how to configure this service.
-
View a list of the API operations available for this service.
-
Learn how to secure this service and its resources by using IAM permission policies.
-
View the programmatic service authorization reference
for this service.
Topics
API operations defined by AWS IoT Managed Integrations
The following table maps API operations to the IAM actions they authorize. Only condition keys that have static values for the given API and action are listed; for the full set of condition keys supported by each action, see the Actions table.
| Operation | IAM action | Condition key | Possible value(s) | Access level |
|---|---|---|---|---|
|
CreateAccountAssociation |
Write |
|||
Tagging, Write |
||||
|
CreateCloudConnector |
Write |
|||
|
CreateConnectorDestination |
Write |
|||
|
CreateCredentialLocker |
Write |
|||
Tagging, Write |
||||
|
CreateDestination |
Write |
|||
Write |
||||
|
CreateEventLogConfiguration |
Write |
|||
|
CreateManagedThing |
Write |
|||
Tagging, Write |
||||
|
CreateNotificationConfiguration |
Write |
|||
|
CreateOtaTask |
Write |
|||
Tagging, Write |
||||
|
CreateOtaTaskConfiguration |
Write |
|||
|
CreateProvisioningProfile |
Write |
|||
Tagging, Write |
||||
|
DeleteAccountAssociation |
Write |
|||
|
DeleteCloudConnector |
Write |
|||
|
DeleteConnectorDestination |
Write |
|||
|
DeleteCredentialLocker |
Write |
|||
|
DeleteDestination |
Write |
|||
|
DeleteEventLogConfiguration |
Write |
|||
|
DeleteManagedThing |
Write |
|||
|
DeleteNotificationConfiguration |
Write |
|||
|
DeleteOtaTask |
Write |
|||
|
DeleteOtaTaskConfiguration |
Write |
|||
|
DeleteProvisioningProfile |
Write |
|||
|
DeregisterAccountAssociation |
Write |
|||
|
GetAccountAssociation |
Read |
|||
|
GetCloudConnector |
Read |
|||
|
GetConnectorDestination |
Read |
|||
|
GetCredentialLocker |
Read |
|||
|
GetCustomEndpoint |
Read |
|||
|
GetDefaultEncryptionConfiguration |
Read |
|||
|
GetDestination |
Read |
|||
|
GetDeviceDiscovery |
Read |
|||
|
GetEventLogConfiguration |
Read |
|||
|
GetHubConfiguration |
Read |
|||
|
GetManagedThing |
Read |
|||
|
GetManagedThingCapabilities |
Read |
|||
|
GetManagedThingConnectivityData |
Read |
|||
|
GetManagedThingMetaData |
Read |
|||
|
GetManagedThingState |
Read |
|||
|
GetNotificationConfiguration |
Read |
|||
|
GetOtaTask |
Read |
|||
|
GetOtaTaskConfiguration |
Read |
|||
|
GetProvisioningProfile |
Read |
|||
|
GetRuntimeLogConfiguration |
Read |
|||
|
GetSchemaVersion |
Read |
|||
|
ListAccountAssociations |
List |
|||
|
ListCloudConnectors |
List |
|||
|
ListConnectorDestinations |
List |
|||
|
ListCredentialLockers |
List |
|||
|
ListDestinations |
List |
|||
|
ListDeviceDiscoveries |
List |
|||
|
ListDiscoveredDevices |
Read |
|||
|
ListEventLogConfigurations |
Read |
|||
|
ListManagedThingAccountAssociations |
List |
|||
|
ListManagedThingSchemas |
Read |
|||
|
ListManagedThings |
List |
|||
|
ListNotificationConfigurations |
Read |
|||
|
ListOtaTaskConfigurations |
Read |
|||
|
ListOtaTaskExecutions |
Read |
|||
|
ListOtaTasks |
List |
|||
|
ListProvisioningProfiles |
List |
|||
|
ListSchemaVersions |
List |
|||
|
ListTagsForResource |
Read |
|||
|
PutDefaultEncryptionConfiguration |
Write |
|||
|
PutHubConfiguration |
Write |
|||
|
PutRuntimeLogConfiguration |
Write |
|||
|
RegisterAccountAssociation |
Write |
|||
|
RegisterCustomEndpoint |
Write |
|||
|
ResetRuntimeLogConfiguration |
Write |
|||
|
SendConnectorEvent |
Write |
|||
|
SendManagedThingCommand |
Write |
|||
|
StartAccountAssociationRefresh |
Write |
|||
|
StartDeviceDiscovery |
Write |
|||
|
TagResource |
Tagging, Write |
|||
|
UntagResource |
Tagging, Write |
|||
|
UpdateAccountAssociation |
Write |
|||
|
UpdateCloudConnector |
Write |
|||
|
UpdateConnectorDestination |
Write |
|||
|
UpdateDestination |
Write |
|||
|
UpdateEventLogConfiguration |
Write |
|||
|
UpdateManagedThing |
Write |
|||
|
UpdateNotificationConfiguration |
Write |
|||
|
UpdateOtaTask |
Write |
Actions defined by AWS IoT Managed Integrations
You can specify the following actions in the Action element of an IAM
policy statement. Use policies to grant permissions to perform an operation in AWS. When
you use an action in a policy, you usually allow or deny access to the API operation or CLI
command with the same name. However, in some cases, a single action controls access to more
than one operation. Alternatively, some operations require several different actions.
| Actions | Description | Resource types (*required) | Condition keys | Access level |
|---|---|---|---|---|
Grants permission to create a new account association |
Write |
|||
Grants permission to create a new cloud connector |
Write |
|||
Grants permission to create a new connector destination |
Write |
|||
Grants permission to create a product credential locker |
Write |
|||
Grants permission to create a new destination |
Write |
|||
Grants permission to create a new event configuration |
Write |
|||
Grants permission to create a new managed thing |
Write |
|||
Grants permission to create a new notification configuration |
Write |
|||
Grants permission to create a new ota task |
Write |
|||
Grants permission to create a new ota task configuration |
Write |
|||
Grants permission to create a new provisioning profile |
Write |
|||
Grants permission to delete an account association |
Write |
|||
Grants permission to delete a cloud connector |
Write |
|||
Grants permission to delete a connector destination |
Write |
|||
Grants permission to delete a credential locker |
Write |
|||
Grants permission to delete destination |
Write |
|||
Grants permission to delete event log configuration |
Write |
|||
Grants permission to delete managed thing |
Write |
|||
Grants permission to delete notification configuration |
Write |
|||
Grants permission to delete ota task |
Write |
|||
Grants permission to delete ota task configuration |
Write |
|||
Grants permission to delete provisioning profile |
Write |
|||
Grants permission to deregister account association |
Write |
|||
Grants permission to get information about an account association |
Read |
|||
Grants permission to get information about a cloud connector |
Read |
|||
Grants permission to get information about a cloud destination |
Read |
|||
Grants permission to get information about a credential locker |
Read |
|||
Grants permission to get information about a custom endpoint |
Read |
|||
Grants permission to get information about a default encryption configuration |
Read |
|||
Grants permission to get information about a destination |
Read |
|||
Grants permission to get information about a device discovery |
Read |
|||
Grants permission to get information about an event log configuration |
Read |
|||
Grants permission to get information about a hub configuration |
Read |
|||
Grants permission to get information about a managed thing |
Read |
|||
Grants permission to get the capability report for a managed thing |
Read |
|||
Grants permission to get the certificate pem for a managed thing |
Read |
|||
Grants permission to get the connectivity data for a managed thing |
Read |
|||
Grants permission to get the meta data information for a managed thing |
Read |
|||
Grants permission to get the device state information for a managed thing |
Read |
|||
Grants permission to get information for a notification configuration |
Read |
|||
Grants permission to get information for an ota task |
Read |
|||
Grants permission to get information for an ota task configuration |
Read |
|||
Grants permission to get information for a provisioning profile |
Read |
|||
Grants permission to get information for a runtime log configuration |
Read |
|||
|
|