View a markdown version of this page

Actions, resources, and condition keys for AWS DevOps Agent Service - Service Authorization Reference

Actions, resources, and condition keys for AWS DevOps Agent Service

AWS DevOps Agent Service (service prefix: aidevops) provides the following service-specific operations, resources, actions, and condition keys for use in IAM permission policies.

References:

API operations defined by AWS DevOps Agent Service

The following table maps API operations to the IAM actions they authorize. Only condition keys that have static values for the given API and action are listed; for the full set of condition keys supported by each action, see the Actions table.

Operation IAM action Condition key Possible value(s) Access level

AssociateService

aidevops:AssociateService

Write

iam:PassRole

iam:PassedToService

aidevops.amazonaws.com

Write

CreateAgentSpace

aidevops:CreateAgentSpace

Write

aidevops:TagResource

Tagging, Write

CreatePrivateConnection

aidevops:CreatePrivateConnection

Write

aidevops:TagResource

Tagging, Write

DeleteAgentSpace

aidevops:DeleteAgentSpace

Write

DeletePrivateConnection

aidevops:DeletePrivateConnection

Write

DeregisterService

aidevops:DeregisterService

Write

DescribePrivateConnection

aidevops:DescribePrivateConnection

Read

DisableOperatorApp

aidevops:DisableOperatorApp

Write

DisassociateService

aidevops:DisassociateService

Write

EnableOperatorApp

aidevops:EnableOperatorApp

Write

iam:PassRole

iam:PassedToService

aidevops.amazonaws.com

Write

GetAgentSpace

aidevops:GetAgentSpace

Read

GetAssociation

aidevops:GetAssociation

Read

GetOperatorApp

aidevops:GetOperatorApp

Read

GetService

aidevops:GetService

Read

ListAgentSpaces

aidevops:ListAgentSpaces

List

ListAssociations

aidevops:ListAssociations

List

ListPrivateConnections

aidevops:ListPrivateConnections

List

ListServices

aidevops:ListServices

List

ListTagsForResource

aidevops:ListTagsForResource

Read

ListWebhooks

aidevops:ListWebhooks

List

RegisterService

aidevops:RegisterService

Write

aidevops:TagResource

Tagging, Write

iam:PassRole

iam:PassedToService

aidevops.amazonaws.com

Write

TagResource

aidevops:TagResource

Tagging, Write

UntagResource

aidevops:UntagResource

Tagging, Write

UpdateAgentSpace

aidevops:UpdateAgentSpace

Write

UpdateAssociation

aidevops:UpdateAssociation

Write

iam:PassRole

iam:PassedToService

aidevops.amazonaws.com

Write

UpdateOperatorAppIdpConfig

aidevops:UpdateOperatorAppIdpConfig

Write

UpdatePrivateConnectionCertificate

aidevops:UpdatePrivateConnectionCertificate

Write

ValidateAwsAssociations

aidevops:ValidateAwsAssociations

Write

Actions defined by AWS DevOps Agent Service

You can specify the following actions in the Action element of an IAM policy statement. Use policies to grant permissions to perform an operation in AWS. When you use an action in a policy, you usually allow or deny access to the API operation or CLI command with the same name. However, in some cases, a single action controls access to more than one operation. Alternatively, some operations require several different actions.

Actions Description Resource types (*required) Condition keys Access level

AssociateService

Grants permission to associate service

agentspace*

aws:ResourceTag/${TagKey}

Write

CreateAccessToken

Grants permission to create an access token

agentspace*

aws:ResourceTag/${TagKey}

Write

CreateAgentSpace

Grants permission to create agentspace

agentspace*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

CreateAsset

Grants permission to create an asset

agentspace*

aws:ResourceTag/${TagKey}

Write

CreateAssetFile

Grants permission to create an asset file

agentspace*

aws:ResourceTag/${TagKey}

Write

CreateBacklogTask

Grants permission to create a new backlog task

agentspace*

aidevops:SourceAgentSpaceArn

aidevops:TargetAgentSpaceArn

aws:ResourceTag/${TagKey}

Write

CreateChat

Grants permission to create a chat

agentspace*

aws:ResourceTag/${TagKey}

Write

CreateKnowledgeItem

Grants permission to create a new knowledge item

agentspace*

aws:ResourceTag/${TagKey}

Write

CreateOneTimeLoginSession

Grants permission to generate secure one-time session for initiating off-console Application login

agentspace*

aws:ResourceTag/${TagKey}

Write

CreatePrivateConnection

Grants permission to create a private connection

private-connection*

aws:RequestTag/${TagKey}

aws:ResourceTag/${TagKey}

aws:TagKeys

Write

CreateTrigger

Grants permission to create a trigger

agentspace*

aws:ResourceTag/${TagKey}

Write

DeleteAgentSpace

Grants permission to delete agentspace

agentspace*

aws:ResourceTag/${TagKey}

Write

DeleteAsset

Grants permission to delete an asset

agentspace*

aws:ResourceTag/${TagKey}

Write

DeleteAssetFile

Grants permission to delete an asset file

agentspace*

aws:ResourceTag/${TagKey}

Write

DeleteKnowledgeItem

Grants permission to delete a knowledge item

agentspace*

aws:ResourceTag/${TagKey}

Write

DeletePrivateConnection

Grants permission to delete a private connection

private-connection*

aws:ResourceTag/${TagKey}

Write

DeleteTrigger

Grants permission to delete a trigger

agentspace*

aws:ResourceTag/${TagKey}

Write

DeregisterService

Grants permission to deregister a service

service*

aws:ResourceTag/${TagKey}

Write

DescribePrivateConnection

Grants permission to describe a private connection

private-connection*

aws:ResourceTag/${TagKey}

Read

DescribeServices

Grants permission to describe support services

agentspace*

aws:ResourceTag/${TagKey}

Read

DescribeSupportLevel

Grants permission to describe customer support level

agentspace*

aws:ResourceTag/${TagKey}

Write

DisableOperatorApp

Grants permission to disable the Operator App access to the given AgentSpace

agentspace*

aws:ResourceTag/${TagKey}

Write

DisassociateService

Grants permission to disassociate service

agentspace*

aws:ResourceTag/${TagKey}

Write

associations*

DiscoverTopology

Grants permission to discover topology information

agentspace*

aws:ResourceTag/${TagKey}

Write

EnableOperatorApp

Grants permission to enable the Operator App to access the given AgentSpace

agentspace*

aws:ResourceTag/${TagKey}

Write

EndChatForCase

Grants permission to end a chat for a case

agentspace*

aws:ResourceTag/${TagKey}

Write

GetAccessToken

Grants permission to get access token details

agentspace*

aws:ResourceTag/${TagKey}

Read

GetAccountUsage

Grants permission to retrieve account usage information

Read

GetAgentSpace

Grants permission to get agentspace

agentspace*

aws:ResourceTag/${TagKey}

Read

GetAsset

Grants permission to get an asset

agentspace*

aidevops:SourceAgentSpaceArn

aidevops:TargetAgentSpaceArn

aws:ResourceTag/${TagKey}

Read

GetAssetContent

Grants permission to get asset content

agentspace*

aidevops:SourceAgentSpaceArn

aidevops:TargetAgentSpaceArn

aws:ResourceTag/${TagKey}

Read

GetAssetFile

Grants permission to get an asset file

agentspace*

aidevops:SourceAgentSpaceArn

aidevops:TargetAgentSpaceArn

aws:ResourceTag/${TagKey}

Read

GetAssociation

Grants permission to get association

agentspace*

aws:ResourceTag/${TagKey}

Read

associations*

GetBacklogTask

Grants permission to get a backlog task

agentspace*

aidevops:SourceAgentSpaceArn

aidevops:TargetAgentSpaceArn

aws:ResourceTag/${TagKey}

Read

GetKnowledgeItem

Grants permission to get a knowledge item

agentspace*

aws:ResourceTag/${TagKey}

Read

GetOperatorApp

Grants permission to get operator auth config for any enabled auth flow

agentspace*

aws:ResourceTag/${TagKey}

Read

GetRecommendation

Grants permission to get a recommendation

agentspace*

aws:ResourceTag/${TagKey}

Read

GetService

Grants permission to get services

service*

aws:ResourceTag/${TagKey}

Read

GetTrigger

Grants permission to get a trigger

agentspace*

aws:ResourceTag/${TagKey}

Read

InitiateChatForCase

Grants permission to initiate a chat for a case

agentspace*

aws:ResourceTag/${TagKey}

Write

ListAccessTokens

Grants permission to list access tokens

agentspace*

aws:ResourceTag/${TagKey}

List

ListAgentSpaces

Grants permission to list agentspace

List

ListAssetFiles

Grants permission to list asset files

agentspace*

aidevops:SourceAgentSpaceArn

aidevops:TargetAgentSpaceArn

aws:ResourceTag/${TagKey}

List

ListAssetTypes

Grants permission to list asset types

List

ListAssetVersions

Grants permission to list asset versions

agentspace*

aws:ResourceTag/${TagKey}