View a markdown version of this page

Actions, resources, and condition keys for AWS Elemental MediaTailor - Service Authorization Reference

Actions, resources, and condition keys for AWS Elemental MediaTailor

AWS Elemental MediaTailor (service prefix: mediatailor) provides the following service-specific operations, resources, actions, and condition keys for use in IAM permission policies.

References:

API operations defined by AWS Elemental MediaTailor

The following table maps API operations to the IAM actions they authorize. Only condition keys that have static values for the given API and action are listed; for the full set of condition keys supported by each action, see the Actions table.

Operation IAM action Condition key Possible value(s) Access level

ConfigureLogsForChannel

mediatailor:ConfigureLogsForChannel

Write

ConfigureLogsForPlaybackConfiguration

mediatailor:ConfigureLogsForPlaybackConfiguration

Write

CreateChannel

mediatailor:CreateChannel

Write

mediatailor:TagResource

Tagging, Write

CreateLiveSource

mediatailor:CreateLiveSource

Write

mediatailor:TagResource

Tagging, Write

CreatePrefetchSchedule

mediatailor:CreatePrefetchSchedule

Write

mediatailor:TagResource

Tagging, Write

CreateProgram

mediatailor:CreateProgram

Write

mediatailor:TagResource

Tagging, Write

CreateSourceLocation

mediatailor:CreateSourceLocation

Write

mediatailor:TagResource

Tagging, Write

CreateVodSource

mediatailor:CreateVodSource

Write

mediatailor:TagResource

Tagging, Write

DeleteChannel

mediatailor:DeleteChannel

Write

DeleteChannelPolicy

mediatailor:DeleteChannelPolicy

Permissions management, Write

DeleteLiveSource

mediatailor:DeleteLiveSource

Write

DeletePlaybackConfiguration

mediatailor:DeletePlaybackConfiguration

Write

DeletePrefetchSchedule

mediatailor:DeletePrefetchSchedule

Write

DeleteProgram

mediatailor:DeleteProgram

Write

DeleteSourceLocation

mediatailor:DeleteSourceLocation

Write

DeleteVodSource

mediatailor:DeleteVodSource

Write

DescribeChannel

mediatailor:DescribeChannel

Read

DescribeLiveSource

mediatailor:DescribeLiveSource

Read

DescribeProgram

mediatailor:DescribeProgram

Read

DescribeSourceLocation

mediatailor:DescribeSourceLocation

Read

DescribeVodSource

mediatailor:DescribeVodSource

Read

GetChannelPolicy

mediatailor:GetChannelPolicy

Read

GetChannelSchedule

mediatailor:GetChannelSchedule

Read

GetPlaybackConfiguration

mediatailor:GetPlaybackConfiguration

Read

GetPrefetchSchedule

mediatailor:GetPrefetchSchedule

Read

ListAlerts

mediatailor:ListAlerts

Read

ListChannels

mediatailor:ListChannels

Read

ListLiveSources

mediatailor:ListLiveSources

Read

ListPlaybackConfigurations

mediatailor:ListPlaybackConfigurations

List

ListPrefetchSchedules

mediatailor:ListPrefetchSchedules

List

ListSourceLocations

mediatailor:ListSourceLocations

Read

ListTagsForResource

mediatailor:ListTagsForResource

Read

ListVodSources

mediatailor:ListVodSources

Read

PutChannelPolicy

mediatailor:PutChannelPolicy

Permissions management, Write

PutFunction

mediatailor:TagResource

Tagging, Write

PutPlaybackConfiguration

mediatailor:PutPlaybackConfiguration

Write

mediatailor:TagResource

Tagging, Write

StartChannel

mediatailor:StartChannel

Write

StopChannel

mediatailor:StopChannel

Write

TagResource

mediatailor:TagResource

Tagging, Write

UntagResource

mediatailor:UntagResource

Tagging, Write

UpdateChannel

mediatailor:UpdateChannel

Write

UpdateLiveSource

mediatailor:UpdateLiveSource

Write

UpdateProgram

mediatailor:UpdateProgram

Write

UpdateSourceLocation

mediatailor:UpdateSourceLocation

Write

UpdateVodSource

mediatailor:UpdateVodSource

Write

Actions defined by AWS Elemental MediaTailor

You can specify the following actions in the Action element of an IAM policy statement. Use policies to grant permissions to perform an operation in AWS. When you use an action in a policy, you usually allow or deny access to the API operation or CLI command with the same name. However, in some cases, a single action controls access to more than one operation. Alternatively, some operations require several different actions.

Actions Description Resource types (*required) Condition keys Access level

ConfigureLogsForChannel

Grants permission to configure logs on the channel with the specified channel name

channel*

aws:ResourceTag/${TagKey}

Write

ConfigureLogsForPlaybackConfiguration

Grants permission to configure logs for a playback configuration

playbackConfiguration*

aws:ResourceTag/${TagKey}

Write

CreateChannel

Grants permission to create a new channel

aws:RequestTag/${TagKey}

aws:TagKeys

Write

CreateLiveSource

Grants permission to create a new live source on the source location with the specified source location name

aws:RequestTag/${TagKey}

aws:TagKeys

Write

CreatePrefetchSchedule

Grants permission to create a prefetch schedule for the playback configuration with the specified playback configuration name

playbackConfiguration*

aws:ResourceTag/${TagKey}

Write

CreateProgram

Grants permission to create a new program on the channel with the specified channel name

Write

CreateSourceLocation

Grants permission to create a new source location

aws:RequestTag/${TagKey}

aws:TagKeys