View a markdown version of this page

Actions, resources, and condition keys for AWS RoboMaker - Service Authorization Reference

Actions, resources, and condition keys for AWS RoboMaker

AWS RoboMaker (service prefix: robomaker) provides the following service-specific operations, resources, actions, and condition keys for use in IAM permission policies.

References:

Actions defined by AWS RoboMaker

You can specify the following actions in the Action element of an IAM policy statement. Use policies to grant permissions to perform an operation in AWS. When you use an action in a policy, you usually allow or deny access to the API operation or CLI command with the same name. However, in some cases, a single action controls access to more than one operation. Alternatively, some operations require several different actions.

Actions Description Resource types (*required) Condition keys Access level

BatchDeleteWorlds

Delete one or more worlds in a batch operation

Write

BatchDescribeSimulationJob

Describe multiple simulation jobs

Read

CancelDeploymentJob

Cancel a deployment job

deploymentJob*

aws:ResourceTag/${TagKey}

Write

CancelSimulationJob

Cancel a simulation job

simulationJob*

aws:ResourceTag/${TagKey}

Write

CancelSimulationJobBatch

Cancel a simulation job batch

simulationJobBatch*

aws:ResourceTag/${TagKey}

Write

CancelWorldExportJob

Cancel a world export job

worldExportJob*

aws:ResourceTag/${TagKey}

Write

CancelWorldGenerationJob

Cancel a world generation job

worldGenerationJob*

aws:ResourceTag/${TagKey}

Write

CreateDeploymentJob

Create a deployment job

aws:RequestTag/${TagKey}

aws:TagKeys

Write

CreateFleet

Create a deployment fleet that represents a logical group of robots running the same robot application

aws:RequestTag/${TagKey}

aws:TagKeys

Write

CreateRobot

Create a robot that can be registered to a fleet

aws:RequestTag/${TagKey}

aws:TagKeys

Write

CreateRobotApplication

Create a robot application

aws:RequestTag/${TagKey}

aws:TagKeys

Write

CreateRobotApplicationVersion

Create a snapshot of a robot application

robotApplication*

aws:ResourceTag/${TagKey}

Write

CreateSimulationApplication

Create a simulation application

aws:RequestTag/${TagKey}

aws:TagKeys

Write

CreateSimulationApplicationVersion

Create a snapshot of a simulation application

simulationApplication*

aws:ResourceTag/${TagKey}

Write

CreateSimulationJob

Create a simulation job

aws:RequestTag/${TagKey}

aws:TagKeys

Write

CreateWorldExportJob

Create a world export job

world*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

CreateWorldGenerationJob

Create a world generation job

worldTemplate*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

CreateWorldTemplate

Create a world template

aws:RequestTag/${TagKey}

aws:TagKeys

Write

DeleteFleet

Delete a deployment fleet

deploymentFleet*

aws:ResourceTag/${TagKey}

Write

DeleteRobot

Delete a robot

robot*

aws:ResourceTag/${TagKey}

Write

DeleteRobotApplication

Delete a robot application

robotApplication*

aws:ResourceTag/${TagKey}

Write

DeleteSimulationApplication

Delete a simulation application

simulationApplication*

aws:ResourceTag/${TagKey}

Write

DeleteWorldTemplate

Delete a world template

worldTemplate*

aws:ResourceTag/${TagKey}

Write

DeregisterRobot

Deregister a robot from a fleet

deploymentFleet*

aws:ResourceTag/${TagKey}

Write

robot*

aws:ResourceTag/${TagKey}

DescribeDeploymentJob

Describe a deployment job

deploymentJob*

aws:ResourceTag/${TagKey}

Read

DescribeFleet

Describe a deployment fleet

deploymentFleet*

aws:ResourceTag/${TagKey}

Read

DescribeRobot

Describe a robot

robot*

aws:ResourceTag/${TagKey}

Read

DescribeRobotApplication

Describe a robot application

robotApplication*

aws:ResourceTag/${TagKey}

Read

DescribeSimulationApplication

Describe a simulation application

simulationApplication*

aws:ResourceTag/${TagKey}

Read

DescribeSimulationJob

Describe a simulation job

simulationJob*

aws:ResourceTag/${TagKey}

Read

DescribeSimulationJobBatch

Describe a simulation job batch

simulationJobBatch*

aws:ResourceTag/${TagKey}

Read

DescribeWorld

Describe a world

world*

aws:ResourceTag/${TagKey}

Read

DescribeWorldExportJob

Describe a world export job

worldExportJob*

aws:ResourceTag/${TagKey}

Read

DescribeWorldGenerationJob

Describe a world generation job

worldGenerationJob*

aws:ResourceTag/${TagKey}

Read

DescribeWorldTemplate

Describe a world template

worldTemplate*

aws:ResourceTag/${TagKey}

Read

GetWorldTemplateBody

Get the body of a world template

worldTemplate*

aws:ResourceTag/${TagKey}

Read

ListDeploymentJobs

List deployment jobs

List

ListFleets

List fleets

List

ListRobotApplications

List robot applications

List

ListRobots

List robots

List

ListSimulationApplications

List simulation applications

List

ListSimulationJobBatches

List simulation job batches

List

ListSimulationJobs

List simulation jobs

List

ListTagsForResource

List tags for a RoboMaker resource

deploymentFleet

aws:ResourceTag/${TagKey}

List

deploymentJob

aws:ResourceTag/${TagKey}

robot

aws:ResourceTag/${TagKey}

robotApplication

aws:ResourceTag/${TagKey}

simulationApplication

aws:ResourceTag/${TagKey}

simulationJob

aws:ResourceTag/${TagKey}

simulationJobBatch

aws:ResourceTag/${TagKey}

world

aws:ResourceTag/${TagKey}

worldExportJob

aws:ResourceTag/${TagKey}

worldGenerationJob

aws:ResourceTag/${TagKey}

worldTemplate

aws:ResourceTag/${TagKey}

ListWorldExportJobs

List world export jobs

List

ListWorldGenerationJobs

List world generation jobs

List

ListWorldTemplates

List world templates

List

ListWorlds

List worlds

List

RegisterRobot

Register a robot to a fleet

deploymentFleet*

aws:ResourceTag/${TagKey}

Write

robot*

aws:ResourceTag/${TagKey}

RestartSimulationJob

Restart a running simulation job

simulationJob*

aws:ResourceTag/${TagKey}

Write

StartSimulationJobBatch

Create a simulation job batch

aws:RequestTag/${TagKey}

aws:TagKeys

Write

SyncDeploymentJob

Ensures the most recently deployed robot application is deployed to all robots in the fleet

deploymentFleet*

aws:ResourceTag/${TagKey}

Write

TagResource

Add tags to a RoboMaker resource

deploymentFleet

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Tagging, Write

deploymentJob

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

robot

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

robotApplication

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

simulationApplication

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

simulationJob

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

simulationJobBatch

aws:RequestTag/${TagKey}