Actions, resources, and condition keys for AWS CodeDeploy
AWS CodeDeploy (service prefix: codedeploy) provides the following
service-specific operations, resources, actions, and condition keys for use in IAM permission
policies.
References:
-
Learn how to configure this service.
-
View a list of the API operations available for this service.
-
Learn how to secure this service and its resources by using IAM permission policies.
-
View the programmatic service authorization reference
for this service.
Topics
API operations defined by AWS CodeDeploy
The following table maps API operations to the IAM actions they authorize. Only condition keys that have static values for the given API and action are listed; for the full set of condition keys supported by each action, see the Actions table.
| Operation | IAM action | Condition key | Possible value(s) | Access level |
|---|---|---|---|---|
|
AddTagsToOnPremisesInstances |
Tagging, Write |
|||
|
BatchGetApplicationRevisions |
Read |
|||
|
BatchGetApplications |
Read |
|||
|
BatchGetDeploymentGroups |
Read |
|||
|
BatchGetDeploymentInstances |
Read |
|||
|
BatchGetDeploymentTargets |
Read |
|||
|
BatchGetDeployments |
Read |
|||
|
BatchGetOnPremisesInstances |
Read |
|||
|
ContinueDeployment |
Write |
|||
Write |
||||
|
CreateApplication |
Write |
|||
Tagging, Write |
||||
|
CreateDeployment |
Write |
|||
List |
||||
List |
||||
Write |
||||
Write |
||||
|
CreateDeploymentConfig |
Write |
|||
|
CreateDeploymentGroup |
Write |
|||
Tagging, Write |
||||
iam:PassedToService |
codedeploy.amazonaws.com |
Write |
||
|
DeleteApplication |
Write |
|||
|
DeleteDeploymentConfig |
Write |
|||
|
DeleteDeploymentGroup |
Write |
|||
|
DeleteGitHubAccountToken |
Write |
|||
|
DeleteResourcesByExternalId |
Write |
|||
|
DeregisterOnPremisesInstance |
Write |
|||
|
GetApplication |
List |
|||
|
GetApplicationRevision |
List |
|||
|
GetDeployment |
List |
|||
|
GetDeploymentConfig |
List |
|||
|
GetDeploymentGroup |
List |
|||
|
GetDeploymentInstance |
List |
|||
|
GetDeploymentTarget |
Read |
|||
|
GetOnPremisesInstance |
List |
|||
|
ListApplicationRevisions |
List |
|||
|
ListApplications |
List |
|||
|
ListDeploymentConfigs |
List |
|||
|
ListDeploymentGroups |
List |
|||
|
ListDeploymentInstances |
List |
|||
|
ListDeploymentTargets |
List |
|||
|
ListDeployments |
List |
|||
|
ListGitHubAccountTokenNames |
List |
|||
|
ListOnPremisesInstances |
List |
|||
|
ListTagsForResource |
List |
|||
|
PutLifecycleEventHookExecutionStatus |
Write |
|||
Write |
||||
|
RegisterApplicationRevision |
Write |
|||
|
RegisterOnPremisesInstance |
Write |
|||
|
RemoveTagsFromOnPremisesInstances |
Tagging, Write |
|||
|
SkipWaitTimeForInstanceTermination |
Write |
|||
Write |
||||
|
StopDeployment |
Write |
|||
Write |
||||
|
TagResource |
Tagging, Write |
|||
|
UntagResource |
Tagging, Write |
|||
|
UpdateApplication |
Write |
|||
|
UpdateDeploymentGroup |
Write |
|||
iam:PassedToService |
codedeploy.amazonaws.com |
Write |
Actions defined by AWS CodeDeploy
You can specify the following actions in the Action element of an IAM
policy statement. Use policies to grant permissions to perform an operation in AWS. When
you use an action in a policy, you usually allow or deny access to the API operation or CLI
command with the same name. However, in some cases, a single action controls access to more
than one operation. Alternatively, some operations require several different actions.
| Actions | Description | Resource types (*required) | Condition keys | Access level |
|---|---|---|---|---|
Grants permission to add tags to one or more on-premises instances |
Tagging, Write |
|||
Grants permission to get information about one or more application revisions |
Read |
|||
Grants permission to get information about multiple applications associated with the IAM user |
Read |
|||
Grants permission to get information about one or more deployment groups |
Read |
|||
Grants permission to get information about one or more instance that are part of a deployment group |
Read |
|||
Grants permission to return an array of one or more targets associated with a deployment. This method works with all compute types and should be used instead of the deprecated BatchGetDeploymentInstances. The maximum number of targets that can be returned is 25 |
Read |
|||
Grants permission to get information about multiple deployments associated with the IAM user |
Read |
|||
Grants permission to get information about one or more on-premises instances |
Read |
|||
Grants permission to start the process of rerouting traffic from instances in the original environment to instances in thereplacement environment without waiting for a specified wait time to elapse |
Write |
|||
Grants permission to create an application associated with the IAM user |
Write |
|||
Grants permission to create a deployment for an application associated with the IAM user |
Write |
|||
Grants permission to create a custom deployment configuration associated with the IAM user |
Write |
|||
Grants permission to create a deployment group for an application associated with the IAM user |
Write |
|||
Grants permission to delete an application associated with the IAM user |
Write |
|||
Grants permission to delete a custom deployment configuration associated with the IAM user |
Write |
|||
Grants permission to delete a deployment group for an application associated with the IAM user |
Write |
|||
Grants permission to delete a GitHub account connection |
Write |
|||
Grants permission to delete resources associated with the given external Id |
Write |
|||
Grants permission to deregister an on-premises instance |
Write |
|||
Grants permission to get information about a single application associated with the IAM user |
List |
|||
Grants permission to get information about a single application revision for an application associated with the IAM user |
List |
|||
Grants permission to get information about a single deployment to a deployment group for an application associated with the IAM user |
List |
|||
Grants permission to get information about a single deployment configuration associated with the IAM user |
List |
|||
Grants permission to get information about a single deployment group for an application associated with the IAM user |
List |
|||
Grants permission to get information about a single instance in a deployment associated with the IAM user |
List |
|||
Grants permission to return information about a deployment target |
Read |
|||
Grants permission to get information about a single on-premises instance |
List |
|||
Grants permission to get information about all application revisions for an application associated with the IAM user |
List |
|||
Grants permission to get information about all applications associated with the IAM user |
List |
|||
Grants permission to get information about all deployment configurations associated with the IAM user |
List |
|||
Grants permission to get information about all deployment groups for an application associated with the IAM user |
List |
|||
Grants permission to get information about all instances in a deployment associated with the IAM user |
List |
|||
Grants permission to return an array of target IDs that are associated a deployment |
List |
|||
Grants permission to get information about all deployments to a deployment group associated with the IAM user, or to get all deployments associated with the IAM user |
List |
|||
Grants permission to list the names of stored connections to GitHub accounts |
List |
|||
Grants permission to get a list of one or more on-premises instance names |
List |
|||
Grants permission to return a list of tags for the resource identified by a specified ARN. Tags are used to organize and categorize your CodeDeploy resources |
List |
|||
Grants permission to notify a lifecycle event hook execution status for associated deployment with the IAM user |
Write |
|||
Grants permission to register information about an application revision for an application associated with the IAM user |
Write |
|||
Grants permission to register an on-premises instance |
Write |
|||
Grants permission to remove tags from one or more on-premises instances |
Tagging, Write |
|||
Grants permission to override any specified wait time and starts terminating instances immediately after the traffic routing is complete. This action applies to blue-green deployments only |
Write |
|||
Grants permission to stop a deployment |
Write |
|||
Grants permission to associate the list of tags in the input Tags parameter with the resource identified by the ResourceArn input parameter |
Tagging, Write |
|||
Grants permission to disassociate a resource from a list of tags. The resource is identified by the ResourceArn input parameter. The tags are identfied by the list of keys in the TagKeys input parameter |
Tagging, Write |
|||
Grants permission to update an application |
Write |
|||