View a markdown version of this page

Actions, resources, and condition keys for AWS Transform custom - Service Authorization Reference

Actions, resources, and condition keys for AWS Transform custom

AWS Transform custom (service prefix: transform-custom) provides the following service-specific operations, resources, actions, and condition keys for use in IAM permission policies.

References:

Actions defined by AWS Transform custom

You can specify the following actions in the Action element of an IAM policy statement. Use policies to grant permissions to perform an operation in AWS. When you use an action in a policy, you usually allow or deny access to the API operation or CLI command with the same name. However, in some cases, a single action controls access to more than one operation. Alternatively, some operations require several different actions.

Actions Description Resource types (*required) Condition keys Access level

BatchCreateFindings

Grants permission to invoke BatchCreateFindings on AWS Transform custom

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

BatchUpdateFindings

Grants permission to invoke BatchUpdateFindings on AWS Transform custom

Write

CompleteTransformationPackageUpload

Grants permission to invoke CompleteTransformationPackageUpload on AWS Transform custom

package*

aws:ResourceTag/${TagKey}

Write

ConverseStream

Grants permission to invoke ConverseStream on AWS Transform custom

Write

CreateAnalysis

Grants permission to invoke CreateAnalysis on AWS Transform custom

analysis*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

CreateCampaign

Grants permission to invoke CreateCampaign on AWS Transform custom

campaign*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

CreateRemediation

Grants permission to invoke CreateRemediation on AWS Transform custom

remediation*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

CreateRepository

Grants permission to invoke CreateRepository on AWS Transform custom

repository*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

CreateSource

Grants permission to invoke CreateSource on AWS Transform custom

source*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

CreateTransformationPackageUrl

Grants permission to invoke CreateTransformationPackageUrl on AWS Transform custom

package*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

DeleteAnalysis

Grants permission to invoke DeleteAnalysis on AWS Transform custom

analysis*

aws:ResourceTag/${TagKey}

Write

DeleteCampaign

Grants permission to invoke DeleteCampaign on AWS Transform custom

campaign*

aws:ResourceTag/${TagKey}

Write

DeleteFinding

Grants permission to invoke DeleteFinding on AWS Transform custom

finding*

aws:ResourceTag/${TagKey}

Write

DeleteKnowledgeItem

Grants permission to invoke DeleteKnowledgeItem on AWS Transform custom

knowledge-item*

aws:ResourceTag/${TagKey}

Write

DeleteRemediation

Grants permission to invoke DeleteRemediation on AWS Transform custom

remediation*

aws:ResourceTag/${TagKey}

Write

DeleteRepository

Grants permission to invoke DeleteRepository on AWS Transform custom

repository*

aws:ResourceTag/${TagKey}

Write

DeleteSource

Grants permission to invoke DeleteSource on AWS Transform custom

source*

aws:ResourceTag/${TagKey}

Write

DeleteTransformationPackage

Grants permission to invoke DeleteTransformationPackage on AWS Transform custom

package*

aws:ResourceTag/${TagKey}

Write

ExecuteTransformation

Grants permission to invoke ExecuteTransformation on AWS Transform custom

package*

aws:ResourceTag/${TagKey}

Write

GetAnalysis

Grants permission to invoke GetAnalysis on AWS Transform custom

analysis*

aws:ResourceTag/${TagKey}

Read

GetAnalysisArtifactDownloadUrl

Grants permission to invoke GetAnalysisArtifactDownloadUrl on AWS Transform custom

analysis*

aws:ResourceTag/${TagKey}

Read

GetCampaign

Grants permission to invoke GetCampaign on AWS Transform custom

campaign*

aws:ResourceTag/${TagKey}

Read

GetFinding

Grants permission to invoke GetFinding on AWS Transform custom

finding*

aws:ResourceTag/${TagKey}

Read

GetFindingGroups

Grants permission to invoke GetFindingGroups on AWS Transform custom

Read

GetKnowledgeItem

Grants permission to invoke GetKnowledgeItem on AWS Transform custom

knowledge-item*

aws:ResourceTag/${TagKey}

Read

GetRemediation

Grants permission to invoke GetRemediation on AWS Transform custom

remediation*

aws:ResourceTag/${TagKey}

Read

GetRepository

Grants permission to invoke GetRepository on AWS Transform custom

repository*

aws:ResourceTag/${TagKey}

Read